Get in Touch

Course Outline

Sovereignty in Open-Source Search and Analytics

  • The impact of Elastic license changes and subsequent forks.
  • Comparing OpenSearch and Elasticsearch feature parity across 2025-2026.
  • Key applications: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest nodes.
  • Security plugin configuration: TLS internode communication, certificates, and PKI.
  • Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master node requirements.

Data Ingestion

  • Indexing via REST API, bulk loading techniques, and mapping definitions.
  • Pipeline integration using Beats, Fluent Bit, and Logstash.
  • Utilizing the OpenTelemetry Collector for trace and metric collection.

Search and Dashboards

  • Query DSL fundamentals: match, term, range, aggregations, and nested field queries.
  • Creating visualizations and comprehensive dashboards in OpenSearch Dashboards.
  • SIEM applications: configuring alert rules and detecting anomalies.

Index Management

  • Index Lifecycle Management (ILM): rollover, shrinking, and deletion processes.
  • Implementing hot-warm-cold architectural tiers.
  • Optimizing mappings and enhancing text analysis.

Security and Access Control

  • Implementing Role-Based Access Control (RBAC) through users, roles, and tenants.
  • Authentication via SAML and OpenID Connect.
  • Enforcing document-level security and field masking.

Backup and Recovery

  • Configuring snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM.
  • Restoring specific indices and managing cluster-wide disaster recovery.

Requirements

  • Familiarity with search engine mechanics and inverted indexing concepts.
  • Proficiency with REST APIs and JSON data structures.
  • Foundational Linux administration skills, including systemd, log management, and package handling.

Target Audience

  • Engineers specializing in search and log analytics.
  • Teams looking to migrate away from managed Elasticsearch or Splunk deployments.
  • Security analysts focused on establishing sovereign SIEM backends.
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories