Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- Elastic license changes and subsequent forks.
- Feature parity between OpenSearch and Elasticsearch in 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master nodes.
Data Ingestion
- Indexing via REST API, bulk loading, and mapping definitions.
- Utilizing Beats, Fluent Bit, and Logstash pipelines.
- Employing the OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Query DSL techniques: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: defining alert rules and detecting anomalies.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion.
- Hot-warm-cold architecture strategies.
- Mapping optimization and text analysis techniques.
Security and Access Control
- Role-Based Access Control (RBAC) using users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Implementing document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories to MinIO, S3, or NFS.
- Automating snapshots with Curator/ISM.
- Restoring specific indices and managing cluster-wide disaster recovery.
Requirements
- A solid understanding of search engines and inverted indexes.
- Practical experience with REST APIs and JSON.
- Basic Linux administration skills, including systemd, logging, and package management.
Target Audience
- Search and log analytics engineers.
- Teams migrating away from managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs