Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Implications of Elastic license changes and resulting forks.
- Comparing feature parity between OpenSearch and Elasticsearch in 2025-2026.
- Key applications: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios using discovery.seed_hosts and minimum master node settings.
Data Ingestion Pipelines
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Configuring Beats, Fluent Bit, and Logstash pipelines.
- Utilizing the OpenTelemetry Collector for trace and metric collection.
Search Mechanics and Dashboards
- Mastering Query DSL: match, term, range, aggregations, and nested fields.
- Building visualizations and comprehensive dashboards in OpenSearch Dashboards.
- SIEM implementations: defining alert rules and anomaly detection models.
Index Lifecycle Management
- Implementing ILM strategies: rollover, shrinking, and deletion.
- Designing hot-warm-cold data architectures.
- Optimizing mappings and refining text analysis.
Security and Access Control
- Configuring RBAC through users, roles, and tenants.
- Integrating SAML and OpenID Connect for authentication.
- Enforcing document-level security and field-level masking.
Backup and Disaster Recovery
- Establishing snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery plans.
Requirements
- Familiarity with search engine mechanics and inverted indexes.
- Proficiency in REST APIs and JSON data structures.
- Foundational knowledge of Linux administration, including systemd, logging, and package management.
Target Audience
- Engineers specializing in search and log analytics.
- Teams aiming to replace managed Elasticsearch or Splunk solutions.
- Security analysts constructing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs