Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Achieving Sovereignty in Open-Source Search and Analytics
- Overview of Elastic license changes and resulting forks.
- Comparing feature parity between OpenSearch and Elasticsearch for 2025-2026.
- Use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin: inter-node TLS, certificates, and PKI.
- Preventing split-brain scenarios: utilizing discovery.seed_hosts and minimum_master_nodes settings.
Data Ingestion
- REST API indexing, bulk loading, and mapping definitions.
- Utilizing Beats, Fluent Bit, and Logstash pipelines.
- Using the OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Query DSL: match, term, range, aggregations, and nested fields.
- OpenSearch Dashboards: creating visualizations and dashboards.
- SIEM use cases: setting up alert rules and anomaly detection.
Index Management
- ILM processes: rollover, shrinking, and deletion.
- Implementing hot-warm-cold architecture.
- Optimizing mappings and text analysis.
Security and Access Control
- RBAC implementation with users, roles, and tenants.
- SAML and OpenID Connect authentication methods.
- Document-level security and field masking techniques.
Backup and Recovery
- Configuring snapshot repositories for MinIO, S3, or NFS.
- Automating snapshots with Curator/ISM.
- Restoring specific indices and ensuring cluster-wide disaster recovery.
Requirements
- Familiarity with search engines and inverted indexes.
- Experience working with REST APIs and JSON.
- Basic Linux administration skills: systemd, logs, and package management.
Target Audience
- Engineers specializing in search and log analytics.
- Teams transitioning away from managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs