Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- General overview of the Elastic Stack (ELK).
ELK Stack Architecture and Review of Existing Environment
- Review of the current architecture of Altor CB.
- ELK architecture: Elasticsearch, Logstash, Kibana, and Beats.
- Ingest node versus Logstash.
- Scalability and performance considerations in on-premise installations.
- Administration best practices.
Beats – Distributed Monitoring
- Configuration and utilisation of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
- Secure shipping with SSL.
- Preconfigured modules versus custom inputs.
- Integration with Logstash and Ingest Pipelines.
Parsing and Ingesting Logs from Applications and Databases
- Ingesting custom logs from applications.
- Utilising Logstash for data parsing and transformation.
- Application of filters: grok, dissect, kv, mutate, and date.
- Database connections (Oracle, PostgreSQL, SQL Server) using the JDBC input plugin.
- Practical cases: error logs, audit trails, traces, and slow queries.
Advanced Search and Regular Expressions
- Advanced search syntax in Kibana.
- Use of regular expressions (regex).
- Filters and OR/AND combinations.
- Nested fields and arrays.
- Saving reusable queries and filters.
Custom Dashboards and Visualisations in Kibana
- Visualisation types: bar, line, maps, and tables.
- Aggregations and metrics.
- Dynamic filters, controls, and drill-down features.
- Dashboard sharing.
- Exercises: creating dashboards from database and system logs.
Alerts and Email Notifications
- Introduction to Watcher and alternatives (ElastAlert, Kibana Alerts).
- Creating custom conditions and triggers.
- Email output configuration.
- Exercise: send an alert when a critical event is detected in Windows or database logs.
User and Permission Management
- Introduction to X-Pack and free options.
- Creating users and roles.
- Access control by index, dashboard, and query.
- Exercise: define roles for audit and operations.
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API.
- GET / POST queries.
- Manual and automated indexing.
- Utilising tools such as curl and Postman.
- Exercises: searching, inserting, deleting, and updating documents.
Requirements
- A foundational understanding of the basic ELK Stack architecture and its components.
- Practical experience with ingesting and visualising logs using Kibana and Logstash.
- Familiarity with the Linux command line and basic scripting.
Target Audience
- System administrators.
- Infrastructure engineers.
- Technical teams looking to advance their log centralisation capabilities.
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations