Elastic stack ELK training

Deploy, setup and operate ELK.

This Elastic Stack training, also known as ELK (Elasticsearch, Logstash, Kibana), will teach you how to ingest your logs and data into Elasticsearch and leverage them in Kibana.

You will learn how to monitor and oversee your infrastructure, store data on a massive and long-term scale, including logs, metrics, and APM traces. You will have the ability to search your data and investigate the activities of your information system.

The training covers data ingestion with various agents, data structuring, search, and analytics as well. You will also gain knowledge in monitoring your stack, operating it, and scaling it.

Course outline

Introducing the stack

  • - elasticsearch: history and core principles
  • - logstash
  • - eco-system beats
  • - kibana
  • - stack elements versions
  • - use cases

Elasticsearch

  • - basics: index, shard, type, document
  • - architecture, clustering and scalability with sharding and replication
  • - mapping and data typing
  • - document storage
  • - data analysis
  • - querying overview
  • - filters
  • - aggregations
  • - ingest node: prepare data before storage

Kibana

  • - data discovery
  • - create visualisation
  • - timelion: time series
  • - dashboards
  • - Filters and real time search on your dashboards

Logstash

  • - swiss knife
  • - input
  • - filtering and pattern matching with grok
  • - output
  • - collaborating with beats
  • - scalability / performances

Beats

  • - filebeat
  • - metricbeat
  • - packet beat

Elastic agent

  • Install / deploy
  • Setup data streams
  • Security

Integrations

  • List all integrations.
  • Deployment strategies.

Data management

  • Alias
  • ILM : index life cycle management and policies
  • Data streams

Ingest pipelines

  • Use existing pipelines
  • Configure processors
  • Manage errors

Administration / operations

  • - metrics to watch / monitoring
  • - deploy in production and typical architectures
  • - sizing / scalability
  • - hot / warm architecture

Clustering / distributed system

  • elasticsearch behavior in distributed mode
  • Nodes and data balancing
  • High avaibility

Monitoring

  • Cat api
  • Monitoring integrated to elastic
  • Metrics to watch

Architecture

  • Topologie / connecting elements
  • Resilient architecture
  • Multi data center

Scalabilty / sizing / performance

  • Sizing shards and nodes
  • Managing hosts
  • Requests and performance

Security

  • Communications encryption
  • Users and roles
  • Good practices

Observability

  • Kibana interface
  • Alerting
  • APM
  • Uptime

Elastic security

  • Rules and alerts
  • Compatible data sources
  • Case / investigation
  • Threat hunting

The Training Instructor

With over 110 training sessions conducted on Elastic technologies, your instructor is engaged in production work for 50% of the time, serving as an Elk and Elastic Stack consultant . You have an instructor who also possesses hands-on production experience.

Learn more about your instructor.

Duration

2 days up to 4 days.

I can modulate the duration for your company.

Rates

WITH QUOTE

Rates are defined for you, in inter or intra company.

GET A QUOTE

Custom

Go back to me. I will adapt duration, location and course content.

Who should attend

CTO, COO, technical project manager, project manager, system administrator, developper.

Method

50 % theorie, 50% practice. Course include Hands-on labs on each topics to really understand each concept.

Training materials

You will get PDF training materials for all of my courses and code for Hands-on labs.