Get in Touch

Course Outline

Introduction

  • General overview of the Elastic Stack (ELK)

ELK Stack Architecture and Review of Existing Environment

  • Assessment of Altor CB's current architecture
  • ELK architecture components: Elasticsearch, Logstash, Kibana, Beats
  • Comparison between Ingest nodes and Logstash
  • Scalability and performance considerations for on-premise installations
  • Best practices for administration

Beats – Distributed Monitoring

  • Configuration and utilization of Filebeat, Auditbeat, Winlogbeat, and Packetbeat
  • Secure data shipping via SSL
  • Differences between preconfigured modules and custom inputs
  • Integration with Logstash and Ingest Pipelines

Parsing and Ingesting Logs from Applications and Databases

  • Ingestion of custom logs from applications
  • Employing Logstash for data parsing and transformation
  • Application of filters: grok, dissect, kv, mutate, date
  • Establishing database connections (Oracle, PostgreSQL, SQL Server) using the JDBC input plugin
  • Practical scenarios: error logs, audit trails, traces, and slow queries

Advanced Search and Regular Expressions

  • Advanced search syntax within Kibana
  • Implementation of regular expressions (regex)
  • Utilizing filters and OR/AND logical combinations
  • Handling nested fields and arrays
  • Preserving reusable queries and filters

Custom Dashboards and Visualizations in Kibana

  • Visualization types: bar charts, line graphs, maps, and tables
  • Aggregations and metric calculations
  • Dynamic filters, controls, and drill-down features
  • Sharing dashboards with stakeholders
  • Exercises: constructing dashboards based on database and system logs

Alerts and Email Notifications

  • Overview of Watcher and alternative tools (ElastAlert, Kibana Alerts)
  • Defining custom conditions and triggers
  • Configuring email outputs
  • Exercise: configuring alerts for critical events detected in Windows or database logs

User and Permission Management

  • Introduction to X-Pack and available free options
  • Creation of users and roles
  • Access control at the index, dashboard, and query levels
  • Exercise: defining roles for audit and operations teams

Elasticsearch REST API

  • Foundations of the Elasticsearch RESTful API
  • Execution of GET and POST queries
  • Manual and automated indexing processes
  • Utilization of tools such as curl and Postman
  • Exercises: searching, inserting, deleting, and updating documents

Requirements

  • A foundational understanding of the basic ELK Stack architecture and its components
  • Practical experience with ingesting and visualizing logs using Kibana and Logstash
  • Proficiency with the Linux command line and basic scripting

Target Audience

  • System administrators
  • Infrastructure engineers
  • Technical teams aiming for advanced log centralization capabilities
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories