Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- The impact of Elastic license changes and subsequent forks.
- Comparing OpenSearch and Elasticsearch feature parity across 2025-2026.
- Key applications: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master node requirements.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Pipeline integration using Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for trace and metric collection.
Search and Dashboards
- Query DSL fundamentals: match, term, range, aggregations, and nested field queries.
- Creating visualizations and comprehensive dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and detecting anomalies.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion processes.
- Implementing hot-warm-cold architectural tiers.
- Optimizing mappings and enhancing text analysis.
Security and Access Control
- Implementing Role-Based Access Control (RBAC) through users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Enforcing document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and managing cluster-wide disaster recovery.
Requirements
- Familiarity with search engine mechanics and inverted indexing concepts.
- Proficiency with REST APIs and JSON data structures.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams looking to migrate away from managed Elasticsearch or Splunk deployments.
- Security analysts focused on establishing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs