Elasticsearch for Logging
Ship and analyze time-series data
If you are looking to learn about Beats, Logstash, Kibana, and other tools from the ecosystem, this Elasticsearch class will teach you how to set up and use Kibana and Timelion, build different types of visualizations, create dashboards, dig in with sub-aggregations, and use Kibana to search through data.
Your trainer is an active Elasticsearch consultant who worked with clients from 20+ different industries and the author of Elasticsearch in Action.
Here are some problems Radu Gheorghe, your Elasticsearch trainer, solved for Sematext clients recently:
A word from Radu Gheorghe
“Attendees come in highly motivated, making the class feel more “alive” than I expected. They constantly look for takeaways to improve their setup, from tweaking a boost to changing the sharding strategy. Their use-cases are very diverse, too, so we end up covering a lot of material.
8-hour online class available upon request
Looking for an extended knowledge-based introduction to Elasticsearch training? You’ve come to the right place.
- Small, interactive, instructor-led classes
- Lots of hands-on exercises
- Customized learning experience
- More flexible – no need to travel
- Certificate of Completion included
Who should attend?
This Elasticsearch course is designed for technical attendees with basic Elasticsearch experience, as we’ll focus on the tooling around Elasticsearch. A person should be able to index data to Elasticsearch, run queries and aggregations, work with mappings and analysis.
Experience with Linux systems is not a must, but a basic familiarity with running shell commands (e.g., using curl command) will make the course more enjoyable. If you do not have prior Elasticsearch experience, we strongly suggest you consider attending our Intro to Elasticsearch class first.
For running a logging setup in production, with a non-trivial volume of logs, one needs a good understanding of performance, scaling, monitoring and administering the components involved. While we cover these aspects for ETL tools (Logstash, Logagent, etc) here, the equivalent Elasticsearch part is covered in our Elasticsearch Operations course.
What attendees say
Sematext was an ideal training partner for Parse.ly. We had just recently adopted Elasticsearch on a new project, and they gave us two days of solid training that was tailored to our team’s needs. The material was built atop strong foundations and moved quickly into advanced areas around querying, Lucene internals, and cluster performance. It was clear that it was all informed by real-world experience operating these systems at scale.
Basic setup: a faster, distributed grep
- Kibana installation and index patterns
- Discover tab and saved searches
- Logstash installation
- Logstsh configuration
- Index apache logs with Logstash
- Set up Kibana, run and save searches
Making use of structured logging
- Logstash’s popular plugins
- Vizualize. Types of visualizations
- Building dashboards
- Configure Logstash to parse and enrich Apache logs
- Search in fields, using ranges and wildcards
- Build different types of visualizations and set up a dashboard
- Searching across multiple clusters
- Timelion charts and sheets
- Cumulative metrics
- Working with multiple time series
- Customizing Timelion charts
- Dealing with missing data points
- Removing noise
- Set up various Timelion charts
Tuning the ingestion pipeline
- Pipeline patterns
- Logstash tunables
- Filebeat installation and configuration
- Filebeat configuration
- Filebeat tunables
- Metricbeat and Filebeat modules
- Installing and configuring Logagent
- Parsing files
- Tune Logstash for throughput
- Use Kafka as a buffer
- Ship logs via Filebeat
- Parse and ship logs via Logagent
Scaling out the pipeline
- Sending logs directly to Elasticsearch
- Sending through Logstash
- Sending through Logagent
- General decision points and tradeoffs
- Parse and ship logs via Filebeat and Ingest node
- Parse and ship logs via Filebeat and Logstash
- Use Kafka as a buffer between Filebeat and Logstash
- Send syslog to Logagent via UDP, parse them and ship to Elasticsearch
- Kibana searches, visualizations, dashboarding, Timelion
- Logstash configuration: parsing logs, configuring plugins and pipelines
- Using Filebeat and Metricbeat to push logs and metrics to Elasticsearch
- Using Logagent for flexible and efficient log parsing
- Optimizing pipeline designs; using Kafka as a central buffer
Course key takeaways
After taking this course you will know how to:
- Set up and use Kibana and Timelion
Build different types of visualizations
- Create dashboards, dig in with sub-aggregations, and use Kibana to search through data.
Things to remember
Participants must use their own computer with OSX, Linux, or Windows, with a recent version of Java installed.Participants should be comfortable using a terminal/command line. Sematext provides:
- A digital copy of the training material
- A VM with all configs, scripts, exercises, etc.
Want to master your Elasticsearch use case faster?
Pick from a wide range of short (2h), use case focused classes to fit your exact needs
Need On-Site or Remote Training
Get in touch with us