Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- General overview of the Elastic Stack (ELK)
ELK Stack Architecture and Review of Existing Environment
- Assessment of Altor CB's current architecture
- ELK architecture components: Elasticsearch, Logstash, Kibana, Beats
- Comparison between Ingest nodes and Logstash
- Scalability and performance considerations for on-premise installations
- Best practices for administration
Beats – Distributed Monitoring
- Configuration and utilization of Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Secure data shipping via SSL
- Differences between preconfigured modules and custom inputs
- Integration with Logstash and Ingest Pipelines
Parsing and Ingesting Logs from Applications and Databases
- Ingestion of custom logs from applications
- Employing Logstash for data parsing and transformation
- Application of filters: grok, dissect, kv, mutate, date
- Establishing database connections (Oracle, PostgreSQL, SQL Server) using the JDBC input plugin
- Practical scenarios: error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Advanced search syntax within Kibana
- Implementation of regular expressions (regex)
- Utilizing filters and OR/AND logical combinations
- Handling nested fields and arrays
- Preserving reusable queries and filters
Custom Dashboards and Visualizations in Kibana
- Visualization types: bar charts, line graphs, maps, and tables
- Aggregations and metric calculations
- Dynamic filters, controls, and drill-down features
- Sharing dashboards with stakeholders
- Exercises: constructing dashboards based on database and system logs
Alerts and Email Notifications
- Overview of Watcher and alternative tools (ElastAlert, Kibana Alerts)
- Defining custom conditions and triggers
- Configuring email outputs
- Exercise: configuring alerts for critical events detected in Windows or database logs
User and Permission Management
- Introduction to X-Pack and available free options
- Creation of users and roles
- Access control at the index, dashboard, and query levels
- Exercise: defining roles for audit and operations teams
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API
- Execution of GET and POST queries
- Manual and automated indexing processes
- Utilization of tools such as curl and Postman
- Exercises: searching, inserting, deleting, and updating documents
Requirements
- A foundational understanding of the basic ELK Stack architecture and its components
- Practical experience with ingesting and visualizing logs using Kibana and Logstash
- Proficiency with the Linux command line and basic scripting
Target Audience
- System administrators
- Infrastructure engineers
- Technical teams aiming for advanced log centralization capabilities
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations