ELK: Elasticsearch, Logstash and Kibana for System Administrators
Course Description
Course Overview
This instructor-led live course is aimed at system administrators who want to set up the ELK stack (Elasticsearch, Logstash, Kibana). The course begins with an overview of ELK architecture and functionality, then moves on to deployment and hands-on practice in a live lab. Practical exercises form a significant part of the course, giving participants the opportunity to apply their knowledge in practice while receiving real-time feedback on their progress.
Course Format
- Strong emphasis on live practice
- Most concepts are learned through exercises as well as practical deployment and implementation
Book this course
- Format: Remote
- Language: PL
- Type: Public course with a guaranteed date (both full groups and individuals can join)
- Date: 10.09.2026
- Duration: 2 days (14h)
- Trainer: Marcin Lewandowski
Net price per participant.
Prerequisites
- Experience in system administration
- Knowledge of the Linux command line
- Prior experience with Elasticsearch is required
Target Audience
- System Administrators
Course Outline
Introduction
- Overview of Elastic Stack (ELK)
Elasticsearch
Overview:
- What and Why
- Terminology: Documents, Index, Shards, Node, Cluster, Scaling Up/Out
Operations: Configuration and Deployment
- Configuring Elasticsearch
- Deploying Elasticsearch
- Lab
Node: Discovery, Types, and Cluster State
- Distributed Model and Discovery
- Master, Data, Client, and Tribe Nodes
- Master Election and Minimum Master Nodes
- Cluster State
- Shard Allocation
Backup: Snapshot and Restore
- High Availability vs. Backup
- Repository, Snapshot, and Restore
- Internal Mechanisms
Production Monitoring
- Alerting Best Practices
- JVM
- Query Performance
- Thread Pools
- Troubleshooting
Logstash
- What and Why
- Configuration
- Inputs, Filters, and Outputs
- Installation and Configuration
- Backup and Restore
- Cluster and Availability Nuances
- Best Practices
Kibana
- What and Why
- Configuration Settings
- Time Selection, Search, and Filters
- Kibana Discover, Visualize, and Dashboard Interfaces
- Installation and Configuration
- Backup and Restore
- Cluster and Availability Nuances
- Best Practices
Filebeat
- Logs and Issues
- Filebeat Architecture
- Installation and Configuration
- Backup and Restore
- Cluster and Availability Nuances
- Best Practices
Frequently Asked Questions (FAQ)
Who is the ELK (Elasticsearch, Logstash, Kibana) course intended for, and what are the requirements?
The course is aimed directly at system administrators who are strictly required to have prior experience with Elasticsearch, knowledge of the Linux command line, and general administration experience. Participants who meet these requirements will be able to easily navigate through the advanced architecture of the ELK stack, learning how to deploy, configure, and troubleshoot administrative issues in a production environment.
In what format and when does the ELK stack administration course take place?
The course takes place live online with an instructor on the guaranteed date of September 10, 2026. It lasts 2 days (14 hours in total) and is structured as a public course, meaning both individuals and whole groups can join. The format is highly interactive, facilitating direct contact with the trainer regardless of the participant's location.
What is a public course with a guaranteed date?
A public course with a guaranteed date is a course that will definitely take place on the scheduled date, regardless of the final number of enrolled participants. This allows you to safely reserve your time off, vacation, or business trip at your company with total confidence that the classes will not be canceled. It is an open format, meaning that individual specialists as well as organized groups from different companies can participate.
What exactly will I learn during the course on Elasticsearch, Logstash, Kibana, and Filebeat?
During the course, you will learn how to independently configure, deploy, scale, and monitor the complete ELK stack along with Filebeat agents. You will learn how to manage clusters and shard allocation in Elasticsearch, create log processing pipelines using inputs/filters/outputs in Logstash, build advanced dashboards and visualizations in Kibana, as well as how to manage backups (snapshot/restore) and production environment performance.
Does the course focus on theory or on practical log and cluster management?
The course places a strong emphasis on live practice and implementing concepts through lab exercises. Most of the material—including troubleshooting JVM issues, managing thread pools, configuring high availability, and solving log issues using Filebeat—is delivered through practical tasks where the instructor monitors progress in real time and provides feedback.
What is the price of the ELK course for administrators and can I get funding for it (PSF, KFS, BUR)?
The participation fee is 3100 PLN net per participant, and you can easily obtain funding from programs such as the Subject Financial System (PSF), the National Training Fund (KFS), or the Development Services Database (BUR). This fee covers the full 14 hours of live workshops as well as support in going through the formalities associated with obtaining funding, making it an ideal solution if your company lacks a training budget.

No budget? Get funding!
A program that allows you to quickly and easily obtain funding for employee training.

Public courses
- Knowledge exchange and networking with professionals from various industries.
- Interactive, live-conducted classes — not just theory, but also exercises and discussions.
- Flexible online format — join from anywhere.
Need Help?
Reach out to learn more about our team and the kinds of tailored solutions we can offer your organization.
Get in Touchwroclaw@nobleprog.pl or +48 (22) 103 3718