Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
- General overview of the Elastic Stack (ELK).
ELK Stack Architecture and Current Environment Review
- Assessment of the current Altor CB architecture.
- Core ELK components: Elasticsearch, Logstash, Kibana, and Beats.
- Comparing Ingest nodes versus Logstash.
- Scalability and performance considerations for on-premise installations.
- Best practices in administration.
Beats – Distributed Monitoring
- Configuring and deploying Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
- Securing data transmission via SSL.
- Choosing between preconfigured modules and custom inputs.
- Integrating Beats with Logstash and Ingest Pipelines.
Parsing and Ingesting Logs from Applications and Databases
- Ingesting custom application logs.
- Utilising Logstash for data parsing and transformation.
- Applying filters: grok, dissect, kv, mutate, and date.
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
- Practical scenarios: error logs, audit trails, traces, and slow queries.
Advanced Search and Regular Expressions
- Advanced search syntax in Kibana.
- Application of regular expressions (regex).
- Constructing filters and OR/AND logic combinations.
- Handling nested fields and arrays.
- Saving queries and filters for reuse.
Custom Dashboards and Visualisations in Kibana
- Exploration of visualisation types: bar, line, maps, and tables.
- Utilising aggregations and metrics.
- Implementing dynamic filters, controls, and drill-down features.
- Dashboard sharing protocols.
- Exercise: building dashboards from database and system logs.
Alerts and Email Notifications
- Introduction to Watcher and alternative tools (ElastAlert, Kibana Alerts).
- Defining custom conditions and triggers.
- Configuring email outputs.
- Exercise: triggering alerts upon detection of critical events in Windows or database logs.
User and Permission Management
- Overview of X-Pack and available free options.
- Creating user accounts and defining roles.
- Managing access control by index, dashboard, and query.
- Exercise: defining roles for audit and operations teams.
Elasticsearch REST API
- Foundations of the Elasticsearch RESTful API.
- Executing GET and POST queries.
- Manual and automated indexing processes.
- Utilising tools such as curl and Postman.
- Exercise: searching, inserting, deleting, and updating documents.
Requirements
- A solid grasp of basic ELK Stack architecture and its core components.
- Practical experience ingesting and visualising logs using Kibana and Logstash.
- Competency with the Linux command line and foundational scripting.
Target Audience
- System administrators.
- Infrastructure engineers.
- Technical teams aiming to advance their log centralisation capabilities.
21 Hours
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations