Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- Comprehensive overview of the Elastic Stack (ELK).
ELK Stack Architecture and Current Environment Review
- Assessment of the current Altor CB architecture.
- Overview of ELK components: Elasticsearch, Logstash, Kibana, and Beats.
- Distinguishing between Ingest nodes and Logstash.
- Scalability and performance factors in on-premise deployments.
- Best practices for administration.
Beats: Distributed Monitoring
- Setup and application of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
- Securing data transmission using SSL.
- Comparison of preconfigured modules versus custom inputs.
- Integration strategies with Logstash and Ingest Pipelines.
Log Parsing and Ingestion from Applications and Databases
- Inggestion of custom application logs.
- Leveraging Logstash for data parsing and transformation.
- Application of filters: grok, dissect, kv, mutate, and date.
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
- Practical scenarios: handling error logs, audit trails, traces, and slow queries.
Advanced Search Techniques and Regular Expressions
- Mastering advanced search syntax within Kibana.
- Utilizing regular expressions (regex).
- Employing filters and OR/AND logical combinations.
- Managing nested fields and arrays.
- Storing reusable queries and filters for future use.
Custom Dashboards and Visualizations in Kibana
- Exploring visualization types: bar charts, line graphs, maps, and tables.
- Working with aggregations and metrics.
- Incorporating dynamic filters, controls, and drill-down features.
- Dashboard sharing mechanisms.
- Practical exercises: building dashboards from database and system logs.
Alerts and Email Notifications
- Introduction to Watcher and alternative solutions (ElastAlert, Kibana Alerts).
- Defining custom conditions and triggers.
- Configuring email outputs.
- Practical exercise: triggering alerts upon detection of critical events in Windows or database logs.
User and Permission Administration
- Overview of X-Pack features and available free options.
- Creation of users and roles.
- Implementing access controls at the index, dashboard, and query level.
- Practical exercise: establishing roles for audit and operational teams.
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API.
- Executing GET and POST queries.
- Manual and automated indexing processes.
- Utilization of tools such as curl and Postman.
- Practical exercises: searching, inserting, deleting, and updating documents.
Requirements
- A solid grasp of the fundamental ELK Stack architecture and its core components.
- Practical experience in log ingestion and visualization using Kibana and Logstash.
- Proficiency with the Linux command line and basic scripting tasks.
Target Audience
- System administrators.
- Infrastructure engineers.
- Technical teams looking to enhance their log centralization capabilities.
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations