Get in Touch

Course Outline

Introduction

  • High-level overview of the Elastic Stack (ELK)

ELK Stack Architecture and Environment Review

  • Assessment of the current Altor CB architecture
  • ELK components: Elasticsearch, Logstash, Kibana, and Beats
  • Distinguishing between Ingest nodes and Logstash
  • Scalability and performance factors for on-premise setups
  • Best practices in administration

Beats – Distributed Monitoring

  • Configuring and utilizing Filebeat, Auditbeat, Winlogbeat, and Packetbeat
  • Secure data transmission via SSL
  • Comparison of preconfigured modules and custom inputs
  • Integration with Logstash and Ingest Pipelines

Parsing and Ingesting Logs from Apps and Databases

  • Incorporating custom application logs
  • Employing Logstash for data parsing and transformation
  • Applying filters: grok, dissect, kv, mutate, and date
  • Connecting to databases (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
  • Practical scenarios: error logs, audit trails, traces, and slow queries

Advanced Search and Regular Expressions

  • Advanced Kibana search syntax
  • Application of regular expressions (regex)
  • Using filters with OR/AND logic combinations
  • Handling nested fields and arrays
  • Storing reusable queries and filters

Custom Dashboards and Visualizations in Kibana

  • Visualization options: bar charts, line graphs, maps, and tables
  • Working with aggregations and metrics
  • Implementing dynamic filters, controls, and drill-downs
  • Sharing dashboards effectively
  • Practical exercises: building dashboards from database and system logs

Alerts and Email Notifications

  • Overview of Watcher and alternatives like ElastiAlert and Kibana Alerts
  • Defining custom conditions and triggers
  • Setting up email output
  • Exercise: Trigger alerts for critical events in Windows or database logs

User and Permission Management

  • Introduction to X-Pack and available free features
  • Creating users and defining roles
  • Managing access control across indexes, dashboards, and queries
  • Exercise: Establishing roles for audit and operational purposes

Elasticsearch REST API

  • Basics of the Elasticsearch RESTful API
  • Executing GET and POST requests
  • Manual and automated indexing processes
  • Utilizing tools such as curl and Postman
  • Exercises: Searching, adding, removing, and modifying documents

Requirements

  • Fundamental knowledge of the ELK Stack architecture and its core components
  • Practical experience in log ingestion and visualization using Kibana and Logstash
  • Proficiency with the Linux command line and basic scripting

Target Audience

  • System Administrators
  • Infrastructure Engineers
  • Technical teams aiming for advanced log centralization
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories