Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Independence
- Evolution of Elastic licensing and the emergence of forks.
- Comparative analysis of OpenSearch and Elasticsearch feature sets during 2025-2026.
- Key application areas: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest functions.
- Security configurations: TLS between nodes, certificate management, and PKI integration.
- Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and defining mappings.
- Utilizing Beats, Fluent Bit, and Logstash for data pipelines.
- Integrating the OpenTelemetry Collector for trace and metric ingestion.
Search and Dashboards
- Query DSL components: match, term, range queries, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and performing anomaly detection.
Index Management
- Index Lifecycle Management (ILM): strategies for rollover, shrinking, and deletion.
- Implementing hot-warm-cold storage architectures.
- Optimizing mappings and text analysis processes.
Security and Access Control
- Implementing RBAC through user, role, and tenant management.
- Authenticating via SAML and OpenID Connect.
- Enforcing document-level security and field masking techniques.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery procedures.
Requirements
- Familiarity with search engine concepts and inverted index structures.
- Proficiency in working with REST APIs and JSON data formats.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams in the process of replacing managed Elasticsearch or Splunk instances.
- Security analysts developing independent SIEM infrastructure.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs