Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Achieving Sovereignty in Open-Source Search and Analytics
- Impact of Elastic license changes and subsequent forks.
- Feature parity between OpenSearch and Elasticsearch in 2025-2026.
- Use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin: TLS for inter-node communication, certificates, and PKI.
- Preventing split-brain scenarios using discovery.seed_hosts and minimum master nodes settings.
Data Ingestion
- REST API indexing, bulk loading, and mapping definitions.
- Utilizing Beats, Fluent Bit, and Logstash pipelines.
- Employing the OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Query DSL: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM use cases: defining alert rules and detecting anomalies.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion.
- Implementing hot-warm-cold data architecture.
- Optimizing mappings and text analysis.
Security and Access Control
- RBAC implementation with users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories for MinIO, S3, or NFS.
- Automating snapshots using Curator and ISM.
- Restoring specific indices and establishing cluster-wide disaster recovery.
Requirements
- Understanding of search engines and inverted indexes.
- Experience with REST APIs and JSON.
- Basic Linux administration skills: systemd, logs, and packages.
Target Audience
- Search and log analytics engineers.
- Teams migrating away from managed Elasticsearch or Splunk solutions.
- Security analysts constructing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs