Get in Touch

Course Outline

Introduction

  • A general overview of the Elastic Stack (ELK).

Module 1: ELK Stack Architecture and Environmental Review

  • An analysis of the current Altor CB architecture.
  • Core ELK components: Elasticsearch, Logstash, Kibana, and Beats.
  • Comparing Ingest nodes with Logstash.
  • Scalability and performance factors in on-premise deployments.
  • Best practices for administration.

Module 2: Beats – Distributed Monitoring (2 hours)

  • Configuring and utilizing Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
  • Ensuring secure data transmission via SSL.
  • Distinguishing between preconfigured modules and custom inputs.
  • Integrating with Logstash and Ingest Pipelines.

Module 3: Parsing and Ingesting Logs from Applications and Databases (4 hours)

  • Ingesting custom application logs.
  • Employing Logstash for data parsing and transformation.
  • Applying filters such as grok, dissect, kv, mutate, and date.
  • Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
  • Practical scenarios: error logs, audit trails, traces, and slow queries.

Module 4: Advanced Search and Regular Expressions (2 hours)

  • Advanced search syntax within Kibana.
  • Application of regular expressions (regex).
  • Utilizing filters and OR/AND logical combinations.
  • Handling nested fields and arrays.
  • Saving reusable queries and filters for future use.

Module 5: Custom Dashboards and Visualizations in Kibana (3 hours)

  • Exploring visualization types: bar, line, maps, and tables.
  • Working with aggregations and metrics.
  • Implementing dynamic filters, controls, and drill-down features.
  • Sharing dashboards effectively.
  • Practical exercise: constructing dashboards from database and system logs.

Module 6: Alerts and Email Notifications (3 hours)

  • Overview of Watcher and alternative solutions like ElastAlert and Kibana Alerts.
  • Developing custom conditions and triggers.
  • Configuring email outputs.
  • Practical exercise: triggering alerts upon detection of critical events in Windows or database logs.

Module 7: User and Permission Management (2 hours)

  • Introduction to X-Pack and available free options.
  • Creating and managing users and roles.
  • Implementing access control across indices, dashboards, and queries.
  • Practical exercise: defining roles for audit and operations teams.

Module 8: Elasticsearch REST API (3 hours)

  • Foundations of the Elasticsearch RESTful API.
  • Executing GET and POST queries.
  • Performing manual and automated indexing.
  • Using tools such as curl and Postman.
  • Practical exercises: searching, inserting, deleting, and updating documents.

Summary and Next Steps

Requirements

  • A solid grasp of fundamental ELK Stack architecture and its core components.
  • Practical experience in ingesting and visualizing logs through Kibana and Logstash.
  • Competence with the Linux command line and basic scripting techniques.

Target Audience

  • System administrators.
  • Infrastructure engineers.
  • Technical teams aiming to achieve advanced log centralization capabilities.
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories