Get in Touch

Course Outline

Introduction

  • General overview of the Elastic Stack (ELK).

ELK Stack Architecture and Review of Existing Environment

  • Review of the current architecture of Altor CB.
  • ELK architecture: Elasticsearch, Logstash, Kibana, and Beats.
  • Ingest node versus Logstash.
  • Scalability and performance considerations in on-premise installations.
  • Administration best practices.

Beats – Distributed Monitoring

  • Configuration and utilisation of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
  • Secure shipping with SSL.
  • Preconfigured modules versus custom inputs.
  • Integration with Logstash and Ingest Pipelines.

Parsing and Ingesting Logs from Applications and Databases

  • Ingesting custom logs from applications.
  • Utilising Logstash for data parsing and transformation.
  • Application of filters: grok, dissect, kv, mutate, and date.
  • Database connections (Oracle, PostgreSQL, SQL Server) using the JDBC input plugin.
  • Practical cases: error logs, audit trails, traces, and slow queries.

Advanced Search and Regular Expressions

  • Advanced search syntax in Kibana.
  • Use of regular expressions (regex).
  • Filters and OR/AND combinations.
  • Nested fields and arrays.
  • Saving reusable queries and filters.

Custom Dashboards and Visualisations in Kibana

  • Visualisation types: bar, line, maps, and tables.
  • Aggregations and metrics.
  • Dynamic filters, controls, and drill-down features.
  • Dashboard sharing.
  • Exercises: creating dashboards from database and system logs.

Alerts and Email Notifications

  • Introduction to Watcher and alternatives (ElastAlert, Kibana Alerts).
  • Creating custom conditions and triggers.
  • Email output configuration.
  • Exercise: send an alert when a critical event is detected in Windows or database logs.

User and Permission Management

  • Introduction to X-Pack and free options.
  • Creating users and roles.
  • Access control by index, dashboard, and query.
  • Exercise: define roles for audit and operations.

Elasticsearch REST API

  • Foundations of the Elasticsearch RESTful API.
  • GET / POST queries.
  • Manual and automated indexing.
  • Utilising tools such as curl and Postman.
  • Exercises: searching, inserting, deleting, and updating documents.

Requirements

  • A foundational understanding of the basic ELK Stack architecture and its components.
  • Practical experience with ingesting and visualising logs using Kibana and Logstash.
  • Familiarity with the Linux command line and basic scripting.

Target Audience

  • System administrators.
  • Infrastructure engineers.
  • Technical teams looking to advance their log centralisation capabilities.
 21 Hours

Testimonials (2)

Upcoming Courses

Related Categories