Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Evolving Elastic license models and community forks.
- Feature comparisons between OpenSearch and Elasticsearch for 2025-2026.
- Key applications: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: internode TLS, certificates, and PKI.
- Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk data loading, and mapping definitions.
- Pipeline integration with Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for trace and metric collection.
Search and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Designing visualizations and dashboards in OpenSearch Dashboards.
- SIEM-specific tasks: defining alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Implementing a hot-warm-cold storage architecture.
- Optimizing mappings and text analysis processes.
Security and Access Control
- Role-based access control (RBAC) involving users, roles, and tenants.
- Authentication through SAML and OpenID Connect.
- Implementing document-level security and field masking techniques.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Executing restoration of specific indices and cluster-wide disaster recovery.
Requirements
- Familiarity with search engines and the concept of inverted indexes.
- Practical experience with REST APIs and JSON structures.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams seeking to migrate from managed Elasticsearch or Splunk solutions.
- Security analysts developing independent SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs