Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Day 1: Foundations, Architecture, and In-Depth Differences (ELK vs. OpenSearch)
Morning Session: Core Concepts & Architecture Review
- Introduction & History:
- Grasping the origins of the ELK Stack (Elasticsearch, Logstash, Kibana)
- The 2021 fork: Why OpenSearch emerged (AWS vs. Elastic licensing changes, Apache 2.0 vs. SSPL/Elastic License) - Under the Hood (The Shared DNA):
- Apache Lucene core engine: Shards, segments, inverted indices, and document storage
- Distributed cluster architecture: Nodes (Master, Data, Coordinator), clusters, and cluster state management
- Data Ingestion and Processing Fundamentals:
- Logstash pipelines, Beats, and modern alternatives (Fluentbit, OpenTelemetry/Data Prepper)
Afternoon Session: Feature Divergence & Ecosystem Differences
- Security & Enterprise Features Comparison:
- Elasticsearch: Limitations of the free tier security vs. Paid features (SSO, advanced alerting, machine learning, cross-cluster replication tiers)
- OpenSearch: Out-of-the-box free fine-grained access control, internal user database, SAML/LDAP integration, and security plugins - UI & Query Languages:
- Kibana vs. OpenSearch Dashboards: Interface layouts, management tools, and developer experience
- Query Languages: Elasticsearch's ES|QL vs. OpenSearch's PPL (Piped Processing Language) and SQL support - Advanced Workloads (Vector Search & AI):
- HNSW implementations, k-NN search performance, and machine learning integration approaches.
Day 2: Installation, Migration Strategies, Operations, and Troubleshooting
Morning Session: Installation & Cluster Setup
- Deploying OpenSearch:
- System requirements, kernel parameters (vm.max_map_count), and JVM heap tuning
- Bare-metal/VM installation via tarball and package managers
- Containerized deployment using Docker and Docker Compose
- Multi-node cluster bootstrap and security plugin initialization (opensearch-security-install) - OpenSearch Dashboards Configuration:
- Connecting Dashboards to the OpenSearch cluster
- Configuring SSL/TLS certificates and authentication backends
Afternoon Session: Migration Path, Operations & Best Practices
- Migration Strategies (ELK to OpenSearch):
- Assessing current ES version compatibility (recommended paths from pre-7.10/7.11 vs. newer versions)
- Snapshot & Restore Method: Using shared repository storage (AWS S3, NFS) for seamless data transfer
- Reindex-from-Remote & Logstash Rolling Migrations: Handling live data cutovers with minimal downtime
- API and client SDK adjustments (updating endpoints, connection strings, and client libraries) - Lifecycle Management & Operational Differences:
- Elasticsearch ILM (Index Lifecycle Management) vs. OpenSearch ISM (Index State Management) syntax and policies
- Rollover, shrinking, downsampling, and index retention strategies - Monitoring, Backup, and Troubleshooting:
- Cluster health APIs, cluster stats, and tracking shard allocation issues
- Common failure scenarios (circuit breaker exceptions, JVM garbage collection pauses, split-brain mitigation)
Q&A and Wrap-up: Open forum for specific company migration roadblocks and architecture reviews
Practical exercises and Hand-On Labs will be a key focus of the course. Participants will gain experience with OpenSearch deployment, configuration, data ingestion, security, migration, monitoring, and troubleshooting through realistic, real-world scenarios.
Requirements
Participants should possess:
- Foundational knowledge of Linux command-line operations.
- Familiarity with networking concepts (TCP/IP, HTTP/HTTPS, DNS).
- A basic understanding of log management and monitoring principles.
- General awareness of containers (Docker) is advantageous but not mandatory.
- Basic experience with Elasticsearch or the ELK Stack.
14 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations