Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Day 1: Foundations, Architecture, and Deep-Dive Differences (ELK vs. OpenSearch)
Morning Session: Core Concepts & Architecture Review
- Introduction & History:
- Understanding the ELK Stack origins (Elasticsearch, Logstash, Kibana)
- The 2021 fork: Why OpenSearch (AWS vs. Elastic licensing shifts, Apache 2.0 vs. SSPL/Elastic License) - Under the Hood (The Shared DNA):
- Apache Lucene core engine: Shards, segments, inverted indices, and document storage
- Distributed cluster architecture: Nodes (Master, Data, Coordinator), clusters, and cluster state management
- Data Ingestion and Processing Fundamentals:
- Logstash pipelines, Beats, and modern alternatives (Fluentbit, OpenTelemetry/Data Prepper)
Afternoon Session: Feature Divergence & Ecosystem Differences
- Security & Enterprise Features Comparison:
- Elasticsearch: Free tier security limitations vs. Paid features (SSO, advanced alerting, machine learning, cross-cluster replication tiers)
- OpenSearch: Out-of-the-box free fine-grained access control, internal user database, SAML/LDAP integration, and security plugins - UI & Query Languages:
- Kibana vs. OpenSearch Dashboards: Interface layouts, management tools, and developer experience
- Query Languages: Elasticsearch's ES|QL vs. OpenSearch's PPL (Piped Processing Language) and SQL support - Advanced Workloads (Vector Search & AI):
- HNSW implementations, k-NN search performance, and machine learning integration approaches.
Day 2: Installation, Migration Strategies, Operations, and Troubleshooting
Morning Session: Installation & Cluster Setup
- Deploying OpenSearch:
- System requirements, kernel parameters (vm.max_map_count), and JVM heap tuning
- Bare-metal/VM installation via tarball and package managers
- Containerized deployment using Docker and Docker Compose
- Multi-node cluster bootstrap and security plugin initialization (opensearch-security-install) - OpenSearch Dashboards Configuration:
- Connecting Dashboards to the OpenSearch cluster
- Configuring SSL/TLS certificates and authentication backends
Afternoon Session: Migration Path, Operations & Best Practices
- Migration Strategies (ELK to OpenSearch):
- Assessing current ES version compatibility (best paths from pre-7.10/7.11 vs. newer versions)
- Snapshot & Restore Method: Using shared repository storage (AWS S3, NFS) for seamless data transfer
- Reindex-from-Remote & Logstash Rolling Migrations: Handling live data cutovers with minimal downtime
- API and client SDK adjustments (updating endpoints, connection strings, and client libraries) - Lifecycle Management & Operational Differences:
- Elasticsearch ILM (Index Lifecycle Management) vs. OpenSearch ISM (Index State Management) syntax and policies
- Rollover, shrinking, downsampling, and index retention strategies - Monitoring, Backup, and Troubleshooting:
- Cluster health APIs, cluster stats, and tracking shard allocation issues
- Common failure scenarios (circuit breaker exceptions, JVM garbage collection pauses, split-brain mitigation)
Q&A and Wrap-up: Open forum for specific company migration roadblocks and architecture reviews
Practical exercises and Hand-On Labs will be a key focus of the course. Participants will gain experience with OpenSearch deployment, configuration, data ingestion, security, migration, monitoring, and troubleshooting through realistic, real-world scenarios.
Requirements
Participants should have:
- Basic knowledge of Linux command-line operations.
- Familiarity with networking concepts (TCP/IP, HTTP/HTTPS, DNS).
- Basic understanding of log management and monitoring concepts.
- General knowledge of containers (Docker) is beneficial but not required.
- Basic experience with Elasticsearch or the ELK Stack
14 Hours
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3200 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations