Get in Touch

Course Outline

Sovereignty in Open-Source Search and Analytics

  • Examining Elastic license changes and the emergence of forks.
  • Comparing feature parity between OpenSearch and Elasticsearch in the 2025-2026 landscape.
  • Key use cases: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest nodes.
  • Security plugin configurations: internode TLS, certificates, and PKI.
  • Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.

Data Ingestion

  • Indexing via REST API, bulk loading techniques, and mapping definitions.
  • Pipelines using Beats, Fluent Bit, and Logstash.
  • Utilizing the OpenTelemetry Collector for trace and metric data.

Search and Dashboards

  • Query DSL concepts: match, term, range, aggregations, and nested fields.
  • Developing visualizations and dashboards in OpenSearch Dashboards.
  • SIEM applications: configuring alert rules and anomaly detection.

Index Management

  • Index Lifecycle Management (ILM): rollover, shrinking, and deletion policies.
  • Implementing hot-warm-cold data architectures.
  • Optimizing mappings and text analysis.

Security and Access Control

  • Role-Based Access Control (RBAC) managing users, roles, and tenants.
  • Authentication via SAML and OpenID Connect.
  • Advanced security features: document-level security and field masking.

Backup and Recovery

  • Configuring snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM.
  • Restoring specific indices and executing cluster-wide disaster recovery.

Requirements

  • A solid understanding of search engine mechanics and inverted indexes.
  • Practical experience with REST APIs and JSON data formats.
  • Foundational knowledge of Linux administration, including systemd, log management, and package handling.

Target Audience

  • Engineers specializing in search and log analytics.
  • Teams seeking to transition from managed Elasticsearch or Splunk solutions.
  • Security analysts developing sovereign SIEM backends.
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories