Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Examining Elastic license changes and the emergence of forks.
- Comparing feature parity between OpenSearch and Elasticsearch in the 2025-2026 landscape.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin configurations: internode TLS, certificates, and PKI.
- Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Pipelines using Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for trace and metric data.
Search and Dashboards
- Query DSL concepts: match, term, range, aggregations, and nested fields.
- Developing visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion policies.
- Implementing hot-warm-cold data architectures.
- Optimizing mappings and text analysis.
Security and Access Control
- Role-Based Access Control (RBAC) managing users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Advanced security features: document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- A solid understanding of search engine mechanics and inverted indexes.
- Practical experience with REST APIs and JSON data formats.
- Foundational knowledge of Linux administration, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams seeking to transition from managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs