Get in Touch

Course Outline

Open-Source Search and Analytics Sovereignty

  • An analysis of Elastic license changes and the emergence of forks.
  • Comparing OpenSearch and Elasticsearch feature parity for 2025-2026.
  • Exploring key use cases: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Understanding node roles: master, data, coordinating, and ingest.
  • Configuring the Security plugin: TLS internode communication, certificates, and PKI.
  • Preventing split-brain scenarios using discovery.seed_hosts and minimum master node settings.

Data Ingestion

  • Techniques for REST API indexing, bulk loading, and defining mappings.
  • Building pipelines with Beats, Fluent Bit, and Logstash.
  • Utilizing the OpenTelemetry Collector for handling traces and metrics.

Search and Dashboards

  • Mastering the Query DSL: match, term, range, aggregations, and nested fields.
  • Designing visualizations and dashboards in OpenSearch Dashboards.
  • Applying SIEM use cases, including alert rules and anomaly detection.

Index Management

  • Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
  • Implementing hot-warm-cold architecture patterns.
  • Optimizing mappings and enhancing text analysis.

Security and Access Control

  • Implementing RBAC through users, roles, and tenants.
  • Configuring authentication via SAML and OpenID Connect.
  • Applying document-level security and field masking techniques.

Backup and Recovery

  • Setting up snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshot tasks using Curator or ISM.
  • Executing restoration of specific indices and cluster-wide disaster recovery.

Requirements

  • A solid understanding of search engine mechanics and inverted indexes.
  • Practical experience working with REST APIs and JSON structures.
  • Familiarity with basic Linux administration, including systemd, log management, and package handling.

Target Audience

  • Engineers specializing in search and log analytics.
  • Technical teams currently evaluating or executing a migration away from managed Elasticsearch or Splunk.
  • Security analysts focused on building sovereign SIEM backends.
 14 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3200 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (1)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories