Get in Touch

Course Outline

Sovereignty in Open-Source Search and Analytics

  • Implications of Elastic license changes and resulting forks.
  • Comparing feature parity between OpenSearch and Elasticsearch in 2025-2026.
  • Key applications: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest.
  • Security plugin configuration: TLS internode communication, certificates, and PKI.
  • Preventing split-brain scenarios using discovery.seed_hosts and minimum master node settings.

Data Ingestion Pipelines

  • Indexing via REST API, bulk loading techniques, and mapping definitions.
  • Configuring Beats, Fluent Bit, and Logstash pipelines.
  • Utilizing the OpenTelemetry Collector for trace and metric collection.

Search Mechanics and Dashboards

  • Mastering Query DSL: match, term, range, aggregations, and nested fields.
  • Building visualizations and comprehensive dashboards in OpenSearch Dashboards.
  • SIEM implementations: defining alert rules and anomaly detection models.

Index Lifecycle Management

  • Implementing ILM strategies: rollover, shrinking, and deletion.
  • Designing hot-warm-cold data architectures.
  • Optimizing mappings and refining text analysis.

Security and Access Control

  • Configuring RBAC through users, roles, and tenants.
  • Integrating SAML and OpenID Connect for authentication.
  • Enforcing document-level security and field-level masking.

Backup and Disaster Recovery

  • Establishing snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM.
  • Restoring specific indices and executing cluster-wide disaster recovery plans.

Requirements

  • Familiarity with search engine mechanics and inverted indexes.
  • Proficiency in REST APIs and JSON data structures.
  • Foundational knowledge of Linux administration, including systemd, logging, and package management.

Target Audience

  • Engineers specializing in search and log analytics.
  • Teams aiming to replace managed Elasticsearch or Splunk solutions.
  • Security analysts constructing sovereign SIEM backends.
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories