Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- Impact of Elastic license changes and the emergence of forks.
- Feature comparison between OpenSearch and Elasticsearch in 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin configuration: TLS for inter-node communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master nodes.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Processing pipelines using Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion policies.
- Designing hot-warm-cold storage architectures.
- Optimizing mappings and text analysis processes.
Security and Access Control
- Implementing RBAC with users, roles, and tenants.
- Authentication integration via SAML and OpenID Connect.
- Document-level security measures and field-level masking.
Backup and Recovery
- Configuring snapshot repositories on MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Familiarity with search engine concepts and inverted indexes.
- Working experience with REST APIs and JSON formats.
- Basic Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams looking to replace managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM infrastructures.
14 Hours
Testimonials (1)
Teacher's Competence
Lorenzo - Banca D'Italia
Course - Search and Analytics with Amazon OpenSearch
Machine Translated