Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- High-level overview of the Elastic Stack (ELK)
ELK Stack Architecture and Environment Review
- Assessment of the current Altor CB architecture
- ELK components: Elasticsearch, Logstash, Kibana, and Beats
- Distinguishing between Ingest nodes and Logstash
- Scalability and performance factors for on-premise setups
- Best practices in administration
Beats – Distributed Monitoring
- Configuring and utilizing Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Secure data transmission via SSL
- Comparison of preconfigured modules and custom inputs
- Integration with Logstash and Ingest Pipelines
Parsing and Ingesting Logs from Apps and Databases
- Incorporating custom application logs
- Employing Logstash for data parsing and transformation
- Applying filters: grok, dissect, kv, mutate, and date
- Connecting to databases (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
- Practical scenarios: error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Advanced Kibana search syntax
- Application of regular expressions (regex)
- Using filters with OR/AND logic combinations
- Handling nested fields and arrays
- Storing reusable queries and filters
Custom Dashboards and Visualizations in Kibana
- Visualization options: bar charts, line graphs, maps, and tables
- Working with aggregations and metrics
- Implementing dynamic filters, controls, and drill-downs
- Sharing dashboards effectively
- Practical exercises: building dashboards from database and system logs
Alerts and Email Notifications
- Overview of Watcher and alternatives like ElastiAlert and Kibana Alerts
- Defining custom conditions and triggers
- Setting up email output
- Exercise: Trigger alerts for critical events in Windows or database logs
User and Permission Management
- Introduction to X-Pack and available free features
- Creating users and defining roles
- Managing access control across indexes, dashboards, and queries
- Exercise: Establishing roles for audit and operational purposes
Elasticsearch REST API
- Basics of the Elasticsearch RESTful API
- Executing GET and POST requests
- Manual and automated indexing processes
- Utilizing tools such as curl and Postman
- Exercises: Searching, adding, removing, and modifying documents
Requirements
- Fundamental knowledge of the ELK Stack architecture and its core components
- Practical experience in log ingestion and visualization using Kibana and Logstash
- Proficiency with the Linux command line and basic scripting
Target Audience
- System Administrators
- Infrastructure Engineers
- Technical teams aiming for advanced log centralization
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations