Get in Touch

Course Outline

Introduction

  • Comprehensive overview of the Elastic Stack (ELK).

Module 1: ELK Stack Architecture and Review of Existing Environment

  • Review of the current Altor CB architecture.
  • ELK architecture breakdown: Elasticsearch, Logstash, Kibana, and Beats.
  • Differences between Ingest nodes and Logstash.
  • Scalability and performance strategies for on-premise deployments.
  • Best practices for administration.

Module 2: Beats – Distributed Monitoring (2 hours)

  • Configuration and application of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
  • Secure data transmission using SSL.
  • Comparing preconfigured modules with custom inputs.
  • Integration with Logstash and Ingest Pipelines.

Module 3: Parsing and Ingesting Logs from Applications and Databases (4 hours)

  • Strategies for ingesting custom application logs.
  • Utilizing Logstash for data parsing and transformation.
  • Employing filters such as grok, dissect, kv, mutate, and date.
  • Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
  • Practical scenarios: processing error logs, audit trails, traces, and slow queries.

Module 4: Advanced Search and Regular Expressions (2 hours)

  • Mastering advanced search syntax in Kibana.
  • Effective use of regular expressions (regex).
  • Combining filters using OR and AND logic.
  • Navigating nested fields and arrays.
  • Saving and reusing queries and filters.

Module 5: Custom Dashboards and Visualizations in Kibana (3 hours)

  • Overview of visualization types: bar charts, line graphs, maps, and tables.
  • Understanding aggregations and metrics.
  • Implementing dynamic filters, controls, and drill-down capabilities.
  • Dashboards sharing protocols.
  • Hands-on exercises: building dashboards from database and system logs.

Module 6: Alerts and Email Notifications (3 hours)

  • Introduction to Watcher and alternative solutions like ElastAlert and Kibana Alerts.
  • Designing custom conditions and triggers.
  • Configuring email output settings.
  • Exercise: setting up alerts for critical events in Windows or database logs.

Module 7: User and Permission Management (2 hours)

  • Introduction to X-Pack and free-tier options.
  • Creating users and defining roles.
  • Implementing access control across indices, dashboards, and queries.
  • Exercise: defining specific roles for audit and operational teams.

Module 8: Elasticsearch REST API (3 hours)

  • Core concepts of the Elasticsearch RESTful API.
  • Executing GET and POST queries.
  • Manual and automated indexing techniques.
  • Utilizing tools such as curl and Postman.
  • Exercises: performing search, insert, delete, and update operations on documents.

Summary and Next Steps

Requirements

  • Foundational knowledge of ELK Stack architecture and its core components.
  • Hands-on experience with log ingestion and visualization using Kibana and Logstash.
  • Proficiency in Linux command-line operations and basic scripting.

Target Audience

  • System administrators.
  • Infrastructure engineers.
  • Technical teams aiming to implement advanced log centralization solutions.
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories