Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Review of Elastic license changes and resulting forks.
- Comparison of OpenSearch versus Elasticsearch feature parity for 2025–2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios via discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk loading, and mapping definitions.
- Integrating Beats, Fluent Bit, and Logstash pipelines.
- Utilizing the OpenTelemetry Collector for trace and metric collection.
Search and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: alert rules and anomaly detection workflows.
Index Management
- ILM operations: rollover, shrinking, and deletion strategies.
- Designing hot-warm-cold storage architectures.
- Optimizing mappings and refining text analysis pipelines.
Security and Access Control
- Implementing RBAC through users, roles, and tenants.
- Configuring SAML and OpenID Connect authentication.
- Enforcing document-level security and field-level masking.
Backup and Recovery
- Establishing snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Executing targeted index restores and cluster-wide disaster recovery.
Requirements
- Familiarity with search engine mechanics and inverted indexes.
- Proficiency with REST APIs and JSON structures.
- Foundational Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Specialists in search and log analytics.
- Teams aiming to replace managed Elasticsearch or Splunk instances.
- Security analysts constructing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs