Skip to main content

Elasticsearch for Logging

Ship and analyze time-series data

If you are looking to learn about Beats, Logstash, Kibana, and other tools from the ecosystem, this Elasticsearch class will teach you how to set up and use Kibana and Timelion, build different types of visualizations, create dashboards, dig in with sub-aggregations, and use Kibana to search through data.

Your trainer is an active Elasticsearch consultant who worked with clients from 20+ different industries and the author of Elasticsearch in Action.

Here are some problems Radu Gheorghe, your Elasticsearch trainer, solved for Sematext clients recently:

  • Improved search relevancy using Learning to Rank
  • Optimized multiple petabyte-scale clusters. Some up to 400 nodes.
  • Designed Elasticsearch index and cluster architecture for dozens of clients
  • Optimized log ingestion pipelines to parse and enrich 100K+ events/second
  • Helped clients reduce production Elasticsearch and ingestion pipeline costs by as much as 10x

A word from Radu Gheorghe

“Attendees come in highly motivated, making the class feel more “alive” than I expected. They constantly look for takeaways to improve their setup, from tweaking a boost to changing the sharding strategy. Their use-cases are very diverse, too, so we end up covering a lot of material.

Radu Gheorghe Sematext Elasticsearch Training Instructor

8-hour online class available upon request

Looking for an extended knowledge-based introduction to Elasticsearch training? You’ve come to the right place.

Request Now

Why attend?

  • Small, interactive, instructor-led classes
  • Lots of hands-on exercises
  • Customized learning experience
  • More flexible – no need to travel
  • Certificate of Completion included

Who should attend?

This Elasticsearch course is designed for technical attendees with basic Elasticsearch experience, as we’ll focus on the tooling around Elasticsearch. A person should be able to index data to Elasticsearch, run queries and aggregations, work with mappings and analysis.

Experience with Linux systems is not a must, but a basic familiarity with running shell commands (e.g., using curl command) will make the course more enjoyable. If you do not have prior Elasticsearch experience, we strongly suggest you consider attending our Intro to Elasticsearch class first.

For running a logging setup in production, with a non-trivial volume of logs, one needs a good understanding of performance, scaling, monitoring and administering the components involved. While we cover these aspects for ETL tools (Logstash, Logagent, etc) here, the equivalent Elasticsearch part is covered in our Elasticsearch Operations course.

What attendees say

Sematext was an ideal training partner for Parse.ly. We had just recently adopted Elasticsearch on a new project, and they gave us two days of solid training that was tailored to our team’s needs. The material was built atop strong foundations and moved quickly into advanced areas around querying, Lucene internals, and cluster performance. It was clear that it was all informed by real-world experience operating these systems at scale.

Andrew Montalenti CTO/Founder – Parse.ly

Course Outline

Basic setup: a faster, distributed grep
  • Kibana installation and index patterns
  • Discover tab and saved searches
  • Logstash installation
  • Logstsh configuration
  • Lab
    • Index apache logs with Logstash
    • Set up Kibana, run and save searches
Making use of structured logging
  • Logstash’s popular plugins
  • Vizualize. Types of visualizations
  • Building dashboards
  • Lab
    • Configure Logstash to parse and enrich Apache logs
    • Search in fields, using ranges and wildcards
    • Build different types of visualizations and set up a dashboard
Advanced visualizations
  • Searching across multiple clusters
  • Timelion charts and sheets
  • Cumulative metrics
  • Working with multiple time series
  • Customizing Timelion charts
  • Dealing with missing data points
  • Removing noise
  • Lab
    • Set up various Timelion charts
Tuning the ingestion pipeline
  • Pipeline patterns
  • Logstash tunables
  • Filebeat installation and configuration
  • Filebeat configuration
  • Filebeat tunables
  • Metricbeat and Filebeat modules
  • Installing and configuring Logagent
  • Parsing files
  • Lab
    • Tune Logstash for throughput
    • Use Kafka as a buffer
    • Ship logs via Filebeat
    • Parse and ship logs via Logagent
Scaling out the pipeline
  • Sending logs directly to Elasticsearch
  • Sending through Logstash
  • Sending through Logagent
  • General decision points and tradeoffs
  • Lab
    • Parse and ship logs via Filebeat and Ingest node
    • Parse and ship logs via Filebeat and Logstash
    • Use Kafka as a buffer between Filebeat and Logstash
    • Send syslog to Logagent via UDP, parse them and ship to Elasticsearch

Main Topics

  • Kibana searches, visualizations, dashboarding, Timelion
  • Logstash configuration: parsing logs, configuring plugins and pipelines
  • Using Filebeat and Metricbeat to push logs and metrics to Elasticsearch
  • Using Logagent for flexible and efficient log parsing
  • Optimizing pipeline designs; using Kafka as a central buffer

Elasticsearch Training

Course key takeaways

After taking this course you will know how to:

  • Set up and use Kibana and Timelion
  • Build different types of visualizations

  • Create dashboards, dig in with sub-aggregations, and use Kibana to search through data.

Things to remember

Participants must use their own computer with OSX, Linux, or Windows, with a recent version of Java installed.

Participants should be comfortable using a terminal/command line. Sematext provides:
  • A digital copy of the training material
  • A VM with all configs, scripts, exercises, etc.

Want to master your Elasticsearch use case faster?

Pick from a wide range of short (2h), use case focused classes to fit your exact needs

  • Online
  • 2-hours
  • Use-case focused
  • Instructor-led

Elasticsearch Fundamentals

Understand how Elasticsearch works and get started with setting it up for either search or log aggregation.

Read more

Kibana and Logstash Fundamentals

Get started with Logstash and Kibana, so you can build an ELK stack: from parsing logs to building dashboards.

Read more

Elasticsearch Scaling 101

Learn about how nodes and shards work, so you can scale your Elasticsearch cluster from PoC to as much as you hardware can hold.

Read more

Elasticsearch Scaling 202

Learn index and cluster architectures that make clusters scale, from time- and size-based indices, to cross-cluster search.

Read more

Elasticsearch Tuning 101

From caches and refreshes to routing, learn about the most important knobs that influence both indexing and search performance.

Read more

Elasticsearch Tuning 202

From hardware choices, to garbage collection, merge policy and thread pool tuning – learn how to squeeze even more performance from your cluster.

Read more

Monitoring Elasticsearch

Bridge the gap between having proper Elasticsearch monitoring in place and understanding how to diagnose and troubleshoot the cluster.

Read more

Administering Elasticsearch

Fully understand Elasticsearch’s management capabilities: from pre-configuring index settings and mappings to how to safely perform upgrades.

Read more

Need On-Site or Remote Training

Get in touch with us

Stay up to date

Get tips, how-tos, and news about Elastic / ELK Stack, Observability, Solr, and Sematext Cloud news and updates.

Sematext Newsletter