Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- An analysis of Elastic license changes and the emergence of forks.
- Comparing OpenSearch and Elasticsearch feature parity for 2025-2026.
- Exploring key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Understanding node roles: master, data, coordinating, and ingest.
- Configuring the Security plugin: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios using discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Techniques for REST API indexing, bulk loading, and defining mappings.
- Building pipelines with Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for handling traces and metrics.
Search and Dashboards
- Mastering the Query DSL: match, term, range, aggregations, and nested fields.
- Designing visualizations and dashboards in OpenSearch Dashboards.
- Applying SIEM use cases, including alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Implementing hot-warm-cold architecture patterns.
- Optimizing mappings and enhancing text analysis.
Security and Access Control
- Implementing RBAC through users, roles, and tenants.
- Configuring authentication via SAML and OpenID Connect.
- Applying document-level security and field masking techniques.
Backup and Recovery
- Setting up snapshot repositories on MinIO, S3, or NFS.
- Automating snapshot tasks using Curator or ISM.
- Executing restoration of specific indices and cluster-wide disaster recovery.
Requirements
- A solid understanding of search engine mechanics and inverted indexes.
- Practical experience working with REST APIs and JSON structures.
- Familiarity with basic Linux administration, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Technical teams currently evaluating or executing a migration away from managed Elasticsearch or Splunk.
- Security analysts focused on building sovereign SIEM backends.
14 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3200 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
the trainer was very good and made the training perfect for my needs