Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- The evolution of Elastic licensing and the emergence of forks.
- Comparing OpenSearch and Elasticsearch feature parity for 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugins: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master nodes.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Utilising Beats, Fluent Bit, and Logstash for data pipelines.
- Implementing the OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Mastering Query DSL: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Designing hot-warm-cold architectures.
- Optimising mappings and enhancing text analysis.
Security and Access Control
- Implementing RBAC through users, roles, and tenants.
- Integrating SAML and OpenID Connect for authentication.
- Applying document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Executing specific index restorations and cluster-wide disaster recovery.
Requirements
- A solid grasp of search engine fundamentals and inverted indexes.
- Practical experience with REST APIs and JSON structures.
- Basic proficiency in Linux administration, including systemd, log management, and package handling.
Target Audience
- Engineers specialising in search and log analytics.
- Teams seeking to migrate away from managed Elasticsearch or Splunk instances.
- Security analysts focused on building sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs