Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- General overview of the Elastic Stack (ELK)
ELK Stack Architecture and Environment Review
- Assessment of the current Altor CB architecture
- Core ELK components: Elasticsearch, Logstash, Kibana, and Beats
- Distinction between Ingest nodes and Logstash
- Scalability and performance strategies for on-premise deployments
- Best practices for administration
Beats: Distributed Monitoring
- Configuration and deployment of Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Implementing secure data shipping via SSL
- Comparison of preconfigured modules versus custom inputs
- Integration strategies with Logstash and Ingest Pipelines
Log Parsing and Ingestion from Applications and Databases
- Process for ingesting custom application logs
- Leveraging Logstash for data parsing and transformation
- Application of filters: grok, dissect, kv, mutate, and date
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
- Practical scenarios: handling error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Mastering advanced search syntax in Kibana
- Utilizing regular expressions (regex)
- Constructing filters using OR/AND logical combinations
- Navigating nested fields and arrays
- Saving reusable queries and filter definitions
Custom Dashboards and Visualizations in Kibana
- Exploration of visualization types: bar charts, line graphs, maps, and tables
- Understanding aggregations and metrics
- Utilizing dynamic filters, controls, and drill-down functionalities
- Protocols for dashboard sharing
- Practical exercise: designing dashboards based on database and system logs
Alerting and Email Notifications
- Overview of Watcher and alternative solutions (ElastAlert, Kibana Alerts)
- Defining custom conditions and triggers
- Configuring email output settings
- Practical exercise: triggering alerts for critical events detected in Windows or database logs
User and Permission Management
- Introduction to X-Pack and free tier options
- Procedures for creating users and roles
- Implementing access controls across indices, dashboards, and queries
- Practical exercise: defining specific roles for audit and operations teams
Elasticsearch REST API
- Fundamentals of the Elasticsearch RESTful API
- Executing GET and POST queries
- Techniques for manual and automated indexing
- Utilization of tools such as curl and Postman
- Practical exercises: performing document search, insertion, deletion, and update operations
Requirements
- Fundamental understanding of the ELK Stack architecture and its core components
- Practical experience in log ingestion and visualization using Kibana and Logstash
- Proficiency with the Linux command line and basic scripting concepts
Target Audience
- System administrators
- Infrastructure engineers
- Technical teams aiming to enhance log centralization capabilities
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations