Get in Touch

Course Outline

Introduction

  • Comprehensive overview of the Elastic Stack (ELK).

ELK Stack Architecture and Current Environment Review

  • Assessment of the current Altor CB architecture.
  • Overview of ELK components: Elasticsearch, Logstash, Kibana, and Beats.
  • Distinguishing between Ingest nodes and Logstash.
  • Scalability and performance factors in on-premise deployments.
  • Best practices for administration.

Beats: Distributed Monitoring

  • Setup and application of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
  • Securing data transmission using SSL.
  • Comparison of preconfigured modules versus custom inputs.
  • Integration strategies with Logstash and Ingest Pipelines.

Log Parsing and Ingestion from Applications and Databases

  • Inggestion of custom application logs.
  • Leveraging Logstash for data parsing and transformation.
  • Application of filters: grok, dissect, kv, mutate, and date.
  • Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
  • Practical scenarios: handling error logs, audit trails, traces, and slow queries.

Advanced Search Techniques and Regular Expressions

  • Mastering advanced search syntax within Kibana.
  • Utilizing regular expressions (regex).
  • Employing filters and OR/AND logical combinations.
  • Managing nested fields and arrays.
  • Storing reusable queries and filters for future use.

Custom Dashboards and Visualizations in Kibana

  • Exploring visualization types: bar charts, line graphs, maps, and tables.
  • Working with aggregations and metrics.
  • Incorporating dynamic filters, controls, and drill-down features.
  • Dashboard sharing mechanisms.
  • Practical exercises: building dashboards from database and system logs.

Alerts and Email Notifications

  • Introduction to Watcher and alternative solutions (ElastAlert, Kibana Alerts).
  • Defining custom conditions and triggers.
  • Configuring email outputs.
  • Practical exercise: triggering alerts upon detection of critical events in Windows or database logs.

User and Permission Administration

  • Overview of X-Pack features and available free options.
  • Creation of users and roles.
  • Implementing access controls at the index, dashboard, and query level.
  • Practical exercise: establishing roles for audit and operational teams.

Elasticsearch REST API

  • Foundations of the Elasticsearch RESTful API.
  • Executing GET and POST queries.
  • Manual and automated indexing processes.
  • Utilization of tools such as curl and Postman.
  • Practical exercises: searching, inserting, deleting, and updating documents.

Requirements

  • A solid grasp of the fundamental ELK Stack architecture and its core components.
  • Practical experience in log ingestion and visualization using Kibana and Logstash.
  • Proficiency with the Linux command line and basic scripting tasks.

Target Audience

  • System administrators.
  • Infrastructure engineers.
  • Technical teams looking to enhance their log centralization capabilities.
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories