Course Outline
Introduction
- Comprehensive overview of the Elastic Stack (ELK).
Module 1: ELK Stack Architecture and Review of Existing Environment
- Assessment of the current Altor CB architecture.
- Overview of ELK architecture: Elasticsearch, Logstash, Kibana, and Beats.
- Differences between Ingest nodes and Logstash.
- Scalability and performance optimization for on-premise deployments.
- Administration best practices.
Module 2: Beats – Distributed Monitoring (2 hours)
- Configuration and application of Filebeat, Auditbeat, Winlogbeat, and Packetbeat.
- Secure data transmission via SSL.
- Utilizing preconfigured modules versus custom inputs.
- Integration with Logstash and Ingest Pipelines.
Module 3: Parsing and Ingesting Logs from Applications and Databases (4 hours)
- Ingesting custom logs from various applications.
- Employing Logstash for data parsing and transformation.
- Utilization of filters: grok, dissect, kv, mutate, and date.
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin.
- Practical scenarios: analyzing error logs, audit trails, traces, and slow queries.
Module 4: Advanced Search and Regular Expressions (2 hours)
- Advanced search syntax within Kibana.
- Application of regular expressions (regex).
- Filters and logical combinations of OR/AND operators.
- Navigating nested fields and arrays.
- Saving reusable queries and filters.
Module 5: Custom Dashboards and Visualizations in Kibana (3 hours)
- Visualization types: bar charts, line graphs, maps, and tables.
- Aggregations and metrics.
- Dynamic filters, controls, and drill-down capabilities.
- Dashboard sharing functionalities.
- Exercises: constructing dashboards from database and system logs.
Module 6: Alerts and Email Notifications (3 hours)
- Introduction to Watcher and alternatives such as ElastAlert and Kibana Alerts.
- Designing custom conditions and triggers.
- Configuring email output settings.
- Exercise: configuring alerts for critical events in Windows or database logs.
Module 7: User and Permission Management (2 hours)
- Overview of X-Pack and free-tier options.
- Creation of users and roles.
- Access control mechanisms based on index, dashboard, and query criteria.
- Exercise: defining roles for audit and operational tasks.
Module 8: Elasticsearch REST API (3 hours)
- Foundations of the Elasticsearch RESTful API.
- Executing GET and POST queries.
- Manual and automated indexing techniques.
- Utilizing tools such as curl and Postman.
- Exercises: performing search, insert, delete, and update operations on documents.
Summary and Next Steps
Requirements
- Foundational knowledge of the ELK Stack architecture and its components.
- Practical experience with log ingestion and visualization using Kibana and Logstash.
- Proficiency in Linux command line operations and basic scripting.
Audience
- System administrators.
- Infrastructure engineers.
- Technical teams requiring advanced log centralization functionalities.
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations