Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- Impact of Elastic licence changes and the emergence of forks.
- Comparative analysis of OpenSearch and Elasticsearch feature parity for 2025-2026.
- Key applications: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: intra-cluster TLS, certificates, and PKI.
- Preventing split-brain scenarios through discovery.seed_hosts and minimum master node settings.
Data Ingestion
- REST API indexing, bulk data loading, and mapping definition.
- Pipelines using Beats, Fluent Bit, and Logstash.
- Utilising the OpenTelemetry Collector for tracing and metrics.
Search and Dashboards
- Query DSL elements: match, term, range, aggregations, and nested fields.
- Creating visualisations and dashboards in OpenSearch Dashboards.
- SIEM-specific use cases: alert rule configuration and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion policies.
- Designing hot-warm-cold storage architectures.
- Optimising mappings and text analysis techniques.
Security and Access Control
- Implementing RBAC using users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Document-level security controls and field masking.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Fundamental understanding of search engines and inverted index structures.
- Practical experience with REST APIs and JSON data formats.
- Basic Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specialising in search and log analytics.
- Teams seeking to replace managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM infrastructure.
14 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 2600 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (1)
the trainer was very good and made the training perfect for my needs