Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Evolving licensing models and software forks.
- Comparative analysis of OpenSearch and Elasticsearch features for the 2025-2026 landscape.
- Application scenarios: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security configurations: internal TLS, certificate management, and PKI.
- Preventing split-brain issues via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk data loading, and mapping definitions.
- Integrating Beats, Fluent Bit, and Logstash pipelines.
- Utilizing the OpenTelemetry Collector for trace and metric collection.
Search Operations and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Creating visualizations and comprehensive dashboards in OpenSearch Dashboards.
- SIEM applications: defining alert rules and detecting anomalies.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Designing hot-warm-cold tiered architectures.
- Optimizing mappings and refining text analysis.
Security and Access Control
- Implementing RBAC across users, roles, and tenants.
- Configuring SAML and OpenID Connect authentication.
- Enforcing document-level security and field-level masking.
Backup and Recovery
- Establishing snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Familiarity with search engines and the concept of inverted indexes.
- Practical experience working with REST APIs and JSON structures.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams transitioning away from managed Elasticsearch or Splunk instances.
- Security analysts developing sovereign SIEM infrastructure.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs