This Kibana training (Data Analysis with Kibana) makes you autonomous at analyzing data: searching, visualizing, presenting, alerting, machine learning and advanced features (Lens, runtime fields, Canvas, Vega).
It relies on the Sample eCommerce and Sample web logs datasets shipped with Kibana, with hands-on labs at every step. The course prepares for the Elastic Certified Data Analyst certification.
Learning objectives
- Navigate Kibana and use Spaces, Saved Objects and Data Views.
- Search, filter and visualize data from Discover.
- Build rich visualizations with Lens and Maps.
- Design interactive dashboards with drilldowns.
- Present and share results: PDF/PNG reports, Canvas, RBAC, anonymous access.
- Detect anomalies with machine learning and AIOps.
- Implement advanced features: Lens formulas, runtime fields, Vega.
- Define and manage alerting rules.
Course outline
Module 1 — Getting started
- Introduction to Kibana: the UI on top of Elasticsearch, the data journey (Beats / Agent / Logstash → Elasticsearch → Kibana), sample datasets.
- Hello, Dashboard!: home page, importing a sample dataset, opening a first dashboard.
- Your space: Spaces and scope, Data Views (indices, data streams, aliases), Saved Objects, Copy to spaces.
- Lab: create a Nova space and copy a dashboard into it.
Module 2 — Searching data
- Discover and Data Visualizer: documents, fields, values; Elasticsearch types (text vs keyword, searchable vs aggregatable), histogram and statistics.
- KQL and filters: Kibana filters vs query bar, pinning, boolean operators, saved queries vs saved searches.
- Focus on fields: visualize from the field list (Lens, Maps for geo points), top values, suggestions panel.
- Labs: query and filter logs with KQL, create visualizations from Discover.
Module 3 — Visualizing data
- Lens editor: workspace, fields list, layer pane; types Tabular, Bar, Goal, Line/Area, Magnitude, Map, Proportion; multi-layers and quick functions.
- Adjusting visualizations: visual options, legends, axes, time shift, series colors, value formatting.
- Creating maps: Maps editor, layer management (fit to data, show/hide, edit, clone), stacking layers.
- Labs: build Lens visualizations, adjust visualizations and create maps.
Module 4 — Complementary visualizations
- Text and metrics: Markdown panels (links, images, navigation), Metric visualization (primary, secondary, break down by, supporting visualization).
- Tables: rows, split metrics, metrics, conditional coloring of values.
- Interactive dashboards: click-to-filter, add filter, drilldowns to another dashboard or a parameterized URL.
- Labs: Metrics and Markdown, tables and interactive dashboards.
Module 5 — Presenting data
- Sharing a dashboard: custom branding, direct links (saved object vs snapshot), embed / iframe, anonymous authentication, PDF/PNG reports.
- Sharing with users: Kibana RBAC, Elasticsearch roles (cluster / index privileges, field/document-level access), Kibana roles.
- Canvas: workpads and templates, static elements and visualizations, data sources, expressions, infographic PDF export.
- Labs: sharing links and PDF, viewer role and user, Canvas presentation.
Module 6 — Analyzing data with Machine Learning
- Introduction to Elastic ML: supervised / unsupervised, detectors, functions, influencers, job wizard (single / multi-metric, population, rare…), bucket span, forecasting.
- Analyzing results: Anomaly Explorer and Single Metric Viewer, bucket / record score, influencers, annotations.
- Data Frame Analytics: transforms (Pivot, Latest), outlier detection.
- AIOps Labs: explain log rate spikes, log pattern analysis, change point detection.
- Labs: single- and multi-metric jobs, AIOps Labs.
Module 7 — Advanced Kibana
- Lens formulas: filter ratio, week-over-week,
percent of total; time series functions
(
cumulative_sum,moving_average), examples withshift='1w'. - Runtime fields: schema on write vs schema on
read, Painless (
emit), creation from Data Views, Discover or Lens, benefits and trade-offs. - Vega: custom visualizations in Vega /
Vega-Lite, data sources,
dataclause, dynamic tokens (%timefield%,%context%,%timefilter%). - Labs: runtime fields and Vega visualizations.
Module 8 — Alerting
- Rules and connectors: anatomy of a rule (schedule, conditions, actions), built-in connectors (Email, Index, Slack, PagerDuty, ServiceNow, Webhook…).
- In-app alerts: Discover (Elasticsearch query), Maps (tracking containment), ML (anomaly detection, Bucket / Record / Influencer types, severity).
- Managing alerts: Stack Management > Rules, statuses, history, snooze, maintenance windows, troubleshooting.
- Lab: create in-app alerts.
The Instructor
Mathieu ELIE is your instructor. With over 110 training sessions delivered on Elastic technologies, your instructor also spends 50% of his time in production as an elk and elastic stack consultant . So you get an instructor who also has real production experience.
3 to 4 days
The duration can be adjusted for your company, essentially by modulating hands-on lab time and the level of detail of the topics covered.
WITH QUOTE
Rates are defined for you, in inter or intra company.
Custom
Go back to me. I will adapt duration, location and course content.
Who should attend
Data analysts, business users (marketing, finance, operations) and Kibana administrators in charge of sharing and securing dashboards.
Prerequisites
Basic knowledge of datasets and business metrics. Notions of APIs and the JSON format are a plus but not required.
Method
Concept → instructor demo → lab in Strigo → summary, with an end-of-lesson quiz. 15 hands-on labs on the eCommerce and web logs datasets.
Certification
This course prepares for the Elastic Certified Data Analyst certification.
Training materials
You will get PDF training materials for all of my courses and code for Hands-on labs.
