Get in Touch

Course Outline

Open-Source Search and Analytics Sovereignty

  • Elastic license changes and the emergence of forks.
  • Comparing OpenSearch and Elasticsearch feature parity in 2025-2026.
  • Key use cases: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest.
  • Security plugin: TLS for internode communication, certificates, and PKI.
  • Preventing split-brain scenarios: discovery.seed_hosts and minimum master nodes.

Data Ingestion

  • Indexing via REST API, bulk loading, and defining mappings.
  • Utilizing Beats, Fluent Bit, and Logstash pipelines.
  • Using the OpenTelemetry Collector for traces and metrics.

Search and Dashboards

  • Query DSL: match, term, range, aggregations, and nested fields.
  • OpenSearch Dashboards: creating visualizations and dashboards.
  • SIEM applications: alert rules and anomaly detection.

Index Management

  • Index Lifecycle Management (ILM): rollover, shrinking, and deletion.
  • Hot-warm-cold architecture strategies.
  • Mapping optimization and text analysis techniques.

Security and Access Control

  • Role-based access control (RBAC) involving users, roles, and tenants.
  • Authentication via SAML and OpenID Connect.
  • Document-level security and field masking.

Backup and Recovery

  • Configuring snapshot repositories on MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM.
  • Restoring specific indices and performing cluster-wide disaster recovery.

Requirements

  • A solid understanding of search engines and inverted indexes.
  • Practical experience with REST APIs and JSON.
  • Foundational Linux administration skills, including systemd, logging, and package management.

Audience

  • Search and log analytics engineers.
  • Teams looking to replace managed Elasticsearch or Splunk solutions.
  • Security analysts focused on building sovereign SIEM backends.
 14 Hours

Testimonials (1)

Related Categories