Get in Touch

Course Outline

Open-Source Search and Analytics Independence

  • Evolution of Elastic licensing and the emergence of forks.
  • Comparative analysis of OpenSearch and Elasticsearch feature sets during 2025-2026.
  • Key application areas: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest functions.
  • Security configurations: TLS between nodes, certificate management, and PKI integration.
  • Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.

Data Ingestion

  • Indexing via REST API, bulk loading techniques, and defining mappings.
  • Utilizing Beats, Fluent Bit, and Logstash for data pipelines.
  • Integrating the OpenTelemetry Collector for trace and metric ingestion.

Search and Dashboards

  • Query DSL components: match, term, range queries, aggregations, and nested fields.
  • Creating visualizations and dashboards in OpenSearch Dashboards.
  • SIEM applications: configuring alert rules and performing anomaly detection.

Index Management

  • Index Lifecycle Management (ILM): strategies for rollover, shrinking, and deletion.
  • Implementing hot-warm-cold storage architectures.
  • Optimizing mappings and text analysis processes.

Security and Access Control

  • Implementing RBAC through user, role, and tenant management.
  • Authenticating via SAML and OpenID Connect.
  • Enforcing document-level security and field masking techniques.

Backup and Recovery

  • Configuring snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM.
  • Restoring specific indices and executing cluster-wide disaster recovery procedures.

Requirements

  • Familiarity with search engine concepts and inverted index structures.
  • Proficiency in working with REST APIs and JSON data formats.
  • Foundational Linux administration skills, including systemd, log management, and package handling.

Target Audience

  • Engineers specializing in search and log analytics.
  • Teams in the process of replacing managed Elasticsearch or Splunk instances.
  • Security analysts developing independent SIEM infrastructure.
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories