Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Day 1: Foundations, Architecture, and Deep-Dive Differences (ELK vs. OpenSearch)
Morning Session: Core Concepts & Architecture Review
- Introduction & History:
- Tracing the origins of the ELK Stack (Elasticsearch, Logstash, Kibana)
- The 2021 fork: Rationale behind OpenSearch (AWS versus Elastic licensing shifts, Apache 2.0 versus SSPL/Elastic License) - Under the Hood (The Shared DNA):
- The Apache Lucene core engine: Shards, segments, inverted indices, and document storage mechanisms
- Distributed cluster architecture: Node roles (Master, Data, Coordinator), clusters, and cluster state management
- Fundamentals of Data Ingestion and Processing:
- Logstash pipelines, Beats, and contemporary alternatives (Fluentbit, OpenTelemetry/Data Prepper)
Afternoon Session: Feature Divergence & Ecosystem Differences
- Security & Enterprise Features Comparison:
- Elasticsearch: Limitations of the free tier regarding security versus paid capabilities (SSO, advanced alerting, machine learning, cross-cluster replication tiers)
- OpenSearch: Native free fine-grained access control, internal user databases, SAML/LDAP integration, and dedicated security plugins - UI & Query Languages:
- Kibana versus OpenSearch Dashboards: Interface layouts, management utilities, and developer experience
- Query Languages: Elasticsearch's ES|QL compared to OpenSearch's PPL (Piped Processing Language) and SQL support - Advanced Workloads (Vector Search & AI):
- HNSW implementations, k-NN search performance, and approaches to machine learning integration.
Day 2: Installation, Migration Strategies, Operations, and Troubleshooting
Morning Session: Installation & Cluster Setup
- Deploying OpenSearch:
- System requirements, kernel parameters (vm.max_map_count), and JVM heap tuning
- Bare-metal/VM installation via tarball archives and package managers
- Containerized deployment utilizing Docker and Docker Compose
- Bootstrap of multi-node clusters and initialization of the security plugin (opensearch-security-install) - OpenSearch Dashboards Configuration:
- Establishing connections between Dashboards and the OpenSearch cluster
- Configuring SSL/TLS certificates and authentication backends
Afternoon Session: Migration Path, Operations & Best Practices
- Migration Strategies (ELK to OpenSearch):
- Evaluating current ES version compatibility (optimal paths for pre-7.10/7.11 versus newer versions)
- Snapshot & Restore Method: Leveraging shared repository storage (AWS S3, NFS) for seamless data transfer
- Reindex-from-Remote & Logstash Rolling Migrations: Managing live data cutovers with minimal downtime
- API and client SDK adjustments (updating endpoints, connection strings, and client libraries) - Lifecycle Management & Operational Differences:
- Elasticsearch ILM (Index Lifecycle Management) versus OpenSearch ISM (Index State Management) syntax and policies
- Strategies for rollover, shrinking, downsampling, and index retention - Monitoring, Backup, and Troubleshooting:
- Utilizing cluster health APIs, cluster stats, and monitoring shard allocation issues
- Addressing common failure scenarios (circuit breaker exceptions, JVM garbage collection pauses, split-brain mitigation)
Q&A and Wrap-up: Open forum for specific company migration roadblocks and architecture reviews
Practical exercises and Hand-On Labs will be a key focus of the course. Participants will gain experience with OpenSearch deployment, configuration, data ingestion, security, migration, monitoring, and troubleshooting through realistic, real-world scenarios.
Requirements
Participants are expected to possess:
- Fundamental proficiency in Linux command-line interfaces.
- Familiarity with core networking principles (TCP/IP, HTTP/HTTPS, DNS).
- A foundational grasp of log management and monitoring paradigms.
- General awareness of containerization technologies (Docker) is advantageous but not mandatory.
- Basic practical experience with Elasticsearch or the ELK Stack.
14 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations