Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Elastic license changes and the emergence of forks.
- Comparison of feature parity between OpenSearch and Elasticsearch in 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: TLS for internode communication, certificates, and PKI.
- Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk loading, and defining mappings.
- Building pipelines with Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for traces and metrics.
Search Capabilities and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Implementing hot-warm-cold architectures.
- Optimizing mappings and text analysis.
Security and Access Control
- Implementing RBAC through users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Document-level security and field masking techniques.
Backup and Recovery
- Configuring snapshot repositories to MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Familiarity with search engines and the concept of inverted indexes.
- Practical experience with REST APIs and JSON.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Search and log analytics engineers.
- Teams transitioning away from managed Elasticsearch or Splunk instances.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs