Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Analysis of Elastic licensing transitions and the emergence of independent forks.
- Assessment of feature equivalence between OpenSearch and Elasticsearch during the 2025–2026 period.
- Key operational applications: enterprise-wide search, log analysis, Security Information and Event Management (SIEM), and system observability.
Cluster Architecture Standards
- Node role definitions: master, data, coordinating, and ingest responsibilities.
- Security enhancements: TLS for inter-node communication, certificate management, and Public Key Infrastructure (PKI) integration.
- Cluster stability mechanisms: prevention of split-brain scenarios using discovery.seed_hosts and minimum master node configurations.
Data Ingestion Protocols
- Indexing via REST API, bulk loading procedures, and structured mapping definitions.
- Implementation of data pipelines using Beats, Fluent Bit, and Logstash.
- Integration of the OpenTelemetry Collector for standardized trace and metric processing.
Search Interface and Dashboard Development
- Query Domain-Specific Language (DSL) components: match, term, range, aggregations, and nested field handling.
- Construction of visualizations and interactive dashboards within OpenSearch Dashboards.
- SIEM-specific workflows: configuration of alert rules and automated anomaly detection.
Index Management Strategies
- Index Lifecycle Management (ILM): policies for rollover, shrinkage, and retention-based deletion.
- Implementation of hot-warm-cold storage architectures for efficiency.
- Optimization of data mappings and text analysis techniques.
Security Posture and Access Governance
- Role-Based Access Control (RBAC) frameworks utilizing users, roles, and tenant isolation.
- Authentication standards via SAML and OpenID Connect.
- Granular security features: document-level access controls and field-level data masking.
Backup and Disaster Recovery
- Configuration of snapshot repositories on MinIO, AWS S3, or Network File System (NFS).
- Automated snapshot execution utilizing Curator or Index State Management (ISM).
- Recovery procedures for specific indices and full-cluster disaster recovery restoration.
Requirements
- Foundational understanding of search engine mechanics and inverted index structures.
- Proficiency with RESTful APIs and JSON data formats.
- Basic Linux administration skills, including systemd management, log review, and package handling.
Target Audience
- Search and log analytics engineering professionals.
- Technical teams transitioning away from managed Elasticsearch or Splunk solutions.
- Security analysts responsible for establishing independent SIEM backends for government compliance.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs