Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction
- A general overview of the Elastic Stack (ELK)
ELK Stack Architecture and Current Environment Review
- Assessment of the existing Altor CB architecture
- ELK components: Elasticsearch, Logstash, Kibana, and Beats
- Comparison of Ingest nodes versus Logstash
- Scalability and performance considerations for on-premise deployments
- Best practices for administration
Beats – Distributed Monitoring
- Configuring and utilizing Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Implementing secure data transmission with SSL
- Distinguishing between preconfigured modules and custom inputs
- Integration strategies with Logstash and Ingest Pipelines
Parsing and Ingesting Logs from Applications and Databases
- Ingesting custom application logs
- Leveraging Logstash for data parsing and transformation
- Applying filters: grok, dissect, kv, mutate, and date
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
- Practical scenarios: analyzing error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Mastering advanced search syntax in Kibana
- Utilizing regular expressions (regex) for precision
- Combining filters with OR/AND logic
- Handling nested fields and arrays
- Saving reusable queries and filters for efficiency
Custom Dashboards and Visualizations in Kibana
- Exploring visualization types: bar charts, line graphs, maps, and tables
- Working with aggregations and metrics
- Implementing dynamic filters, controls, and drill-down features
- Dashboard sharing strategies
- Practical exercise: constructing dashboards from database and system logs
Alerts and Email Notifications
- Overview of Watcher and alternatives such as ElastAlert and Kibana Alerts
- Designing custom conditions and triggers
- Configuring email output parameters
- Practical exercise: configuring alerts for critical events in Windows or database logs
User and Permission Management
- Introduction to X-Pack and available free options
- Creating users and defining roles
- Implementing access control at the index, dashboard, and query levels
- Practical exercise: defining roles for audit and operations teams
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API
- Executing GET and POST queries
- Manual and automated indexing processes
- Utilizing tools such as curl and Postman
- Practical exercises: searching, inserting, deleting, and updating documents
Requirements
- A foundational understanding of the basic ELK Stack architecture and its core components.
- Practical experience in ingesting and visualizing logs using Kibana and Logstash.
- Proficiency with the Linux command line and basic scripting techniques.
Target Audience
- System administrators.
- Infrastructure engineers.
- Technical teams aiming to advance their log centralization capabilities.
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations