Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- High-level overview of the Elastic Stack (ELK)
ELK Stack Architecture and Environment Review
- Assessment of Altor CB's current architecture
- Core ELK components: Elasticsearch, Logstash, Kibana, and Beats
- Comparing Ingest nodes with Logstash
- Scalability and performance optimization for on-premise deployments
- Best practices for administration
Beats – Distributed Monitoring
- Configuration and deployment of Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Implementing secure data transmission via SSL
- Distinguishing between preconfigured modules and custom inputs
- Seamless integration with Logstash and Ingest Pipelines
Parsing and Ingesting Logs from Applications and Databases
- Capturing custom logs from application environments
- Leveraging Logstash for data parsing and transformation
- Applying filters: grok, dissect, kv, mutate, and date
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
- Practical scenarios: handling error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Mastery of advanced search syntax in Kibana
- Application of regular expressions (regex)
- Utilizing filters with OR/AND logic combinations
- Working with nested fields and arrays
- Persisting reusable queries and filter configurations
Custom Dashboards and Visualizations in Kibana
- Visualization techniques: bar charts, line graphs, maps, and tables
- Defining aggregations and calculating metrics
- Implementing dynamic filters, controls, and drill-down capabilities
- Dashboard sharing protocols
- Practical exercises: building dashboards from database and system logs
Alerts and Email Notifications
- Overview of Watcher and alternative solutions (ElastAlert, Kibana Alerts)
- Defining custom conditions and trigger events
- Configuring email output settings
- Exercise: generating alerts for critical events detected in Windows or database logs
User and Permission Management
- Introduction to X-Pack and available free-tier options
- Creating users and assigning roles
- Implementing access controls based on indices, dashboards, and queries
- Exercise: establishing distinct roles for audit and operations teams
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API
- Executing GET and POST requests
- Managing manual and automated indexing processes
- Utilizing tools such as curl and Postman
- Exercises: performing searches, inserts, deletions, and updates on documents
Requirements
- Fundamental comprehension of ELK Stack architecture and its core components
- Hands-on experience with log ingestion and visualization via Kibana and Logstash
- Proficiency with Linux command-line interfaces and basic scripting
Target Audience
- System Administrators
- Infrastructure Engineers
- Technical teams looking to advance their log centralization capabilities
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations