Get in Touch

Course Outline

Day 1: Foundations, Architecture, and Deep-Dive Differences (ELK vs. OpenSearch)

Morning Session: Core Concepts & Architecture Review

  •  Introduction & History:
       - Tracing the origins of the ELK Stack (Elasticsearch, Logstash, Kibana)
       - The 2021 fork: Rationale behind OpenSearch (AWS versus Elastic licensing shifts, Apache 2.0 versus SSPL/Elastic License)
  •  Under the Hood (The Shared DNA):
       - The Apache Lucene core engine: Shards, segments, inverted indices, and document storage mechanisms
       - Distributed cluster architecture: Node roles (Master, Data, Coordinator), clusters, and cluster state management
       - Fundamentals of Data Ingestion and Processing:
       - Logstash pipelines, Beats, and contemporary alternatives (Fluentbit, OpenTelemetry/Data Prepper)

Afternoon Session: Feature Divergence & Ecosystem Differences

  •  Security & Enterprise Features Comparison:
       - Elasticsearch: Limitations of the free tier regarding security versus paid capabilities (SSO, advanced alerting, machine learning, cross-cluster replication tiers)
       - OpenSearch: Native free fine-grained access control, internal user databases, SAML/LDAP integration, and dedicated security plugins
  •  UI & Query Languages:
       - Kibana versus OpenSearch Dashboards: Interface layouts, management utilities, and developer experience
       - Query Languages: Elasticsearch's ES|QL compared to OpenSearch's PPL (Piped Processing Language) and SQL support
  •  Advanced Workloads (Vector Search & AI):
       - HNSW implementations, k-NN search performance, and approaches to machine learning integration.

Day 2: Installation, Migration Strategies, Operations, and Troubleshooting

Morning Session: Installation & Cluster Setup

  • Deploying OpenSearch:
       - System requirements, kernel parameters (vm.max_map_count), and JVM heap tuning
       - Bare-metal/VM installation via tarball archives and package managers
       - Containerized deployment utilizing Docker and Docker Compose
       - Bootstrap of multi-node clusters and initialization of the security plugin (opensearch-security-install)
  •  OpenSearch Dashboards Configuration:
       - Establishing connections between Dashboards and the OpenSearch cluster
       - Configuring SSL/TLS certificates and authentication backends

Afternoon Session: Migration Path, Operations & Best Practices

  • Migration Strategies (ELK to OpenSearch):
       - Evaluating current ES version compatibility (optimal paths for pre-7.10/7.11 versus newer versions)
       - Snapshot & Restore Method: Leveraging shared repository storage (AWS S3, NFS) for seamless data transfer
       - Reindex-from-Remote & Logstash Rolling Migrations: Managing live data cutovers with minimal downtime
       - API and client SDK adjustments (updating endpoints, connection strings, and client libraries)
  • Lifecycle Management & Operational Differences:
       - Elasticsearch ILM (Index Lifecycle Management) versus OpenSearch ISM (Index State Management) syntax and policies
       - Strategies for rollover, shrinking, downsampling, and index retention
  • Monitoring, Backup, and Troubleshooting:
       - Utilizing cluster health APIs, cluster stats, and monitoring shard allocation issues
       - Addressing common failure scenarios (circuit breaker exceptions, JVM garbage collection pauses, split-brain mitigation)

Q&A and Wrap-up: Open forum for specific company migration roadblocks and architecture reviews

Practical exercises and Hand-On Labs will be a key focus of the course. Participants will gain experience with OpenSearch deployment, configuration, data ingestion, security, migration, monitoring, and troubleshooting through realistic, real-world scenarios.

Requirements

Participants are expected to possess:

  • Fundamental proficiency in Linux command-line interfaces.
  • Familiarity with core networking principles (TCP/IP, HTTP/HTTPS, DNS).
  • A foundational grasp of log management and monitoring paradigms.
  • General awareness of containerization technologies (Docker) is advantageous but not mandatory.
  • Basic practical experience with Elasticsearch or the ELK Stack.
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories