Course Outline
Introduction
- A general overview of the Elastic Stack (ELK).
Module 1: ELK Stack Architecture and Environmental Review
- An analysis of the current Altor CB architecture.
- Core ELK components: Elasticsearch, Logstash, Kibana, and Beats.
- Comparing Ingest nodes with Logstash.
- Scalability and performance factors in on-premise deployments.
- Best practices for administration.
Module 2: Beats – Distributed Monitoring (2 hours)
- Configuring and utilizing Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
- Ensuring secure data transmission via SSL.
- Distinguishing between preconfigured modules and custom inputs.
- Integrating with Logstash and Ingest Pipelines.
Module 3: Parsing and Ingesting Logs from Applications and Databases (4 hours)
- Ingesting custom application logs.
- Employing Logstash for data parsing and transformation.
- Applying filters such as grok, dissect, kv, mutate, and date.
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
- Practical scenarios: error logs, audit trails, traces, and slow queries.
Module 4: Advanced Search and Regular Expressions (2 hours)
- Advanced search syntax within Kibana.
- Application of regular expressions (regex).
- Utilizing filters and OR/AND logical combinations.
- Handling nested fields and arrays.
- Saving reusable queries and filters for future use.
Module 5: Custom Dashboards and Visualizations in Kibana (3 hours)
- Exploring visualization types: bar, line, maps, and tables.
- Working with aggregations and metrics.
- Implementing dynamic filters, controls, and drill-down features.
- Sharing dashboards effectively.
- Practical exercise: constructing dashboards from database and system logs.
Module 6: Alerts and Email Notifications (3 hours)
- Overview of Watcher and alternative solutions like ElastAlert and Kibana Alerts.
- Developing custom conditions and triggers.
- Configuring email outputs.
- Practical exercise: triggering alerts upon detection of critical events in Windows or database logs.
Module 7: User and Permission Management (2 hours)
- Introduction to X-Pack and available free options.
- Creating and managing users and roles.
- Implementing access control across indices, dashboards, and queries.
- Practical exercise: defining roles for audit and operations teams.
Module 8: Elasticsearch REST API (3 hours)
- Foundations of the Elasticsearch RESTful API.
- Executing GET and POST queries.
- Performing manual and automated indexing.
- Using tools such as curl and Postman.
- Practical exercises: searching, inserting, deleting, and updating documents.
Summary and Next Steps
Requirements
- A solid grasp of fundamental ELK Stack architecture and its core components.
- Practical experience in ingesting and visualizing logs through Kibana and Logstash.
- Competence with the Linux command line and basic scripting techniques.
Target Audience
- System administrators.
- Infrastructure engineers.
- Technical teams aiming to achieve advanced log centralization capabilities.
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations