Curriculum planned

Stage 03 · NoSQL, Search & Application Data

Elasticsearch and OpenSearch

A complete search-platform course covering Elasticsearch and OpenSearch architecture, documents and mappings, text analysis, Query DSL, scoring and relevance, aggregations, ingestion, data streams, shard/segment internals, lifecycle management, snapshots, security, observability, ES|QL/PPL-style analytics, cross-cluster features, vector and hybrid search, RAG/AI search, performance engineering, migrations, and production operations.

31planned chapters
155reserved lesson paths
Intermediate → Advancedlearning level
Plannedcourse state
Coverage baselineCurrent Elastic Stack 9.x and OpenSearch 3.x concepts, including ES|QL, OpenSearch vector/neural/hybrid search, lifecycle automation, security, snapshots, and multi-cluster operations

Course brief

Build and operate search systems by understanding analysis, relevance, shards, segments, lifecycle, resilience, security, and modern vector retrieval—not by treating the engine as a JSON database.

A complete search-platform course covering Elasticsearch and OpenSearch architecture, documents and mappings, text analysis, Query DSL, scoring and relevance, aggregations, ingestion, data streams, shard/segment internals, lifecycle management, snapshots, security, observability, ES|QL/PPL-style analytics, cross-cluster features, vector and hybrid search, RAG/AI search, performance engineering, migrations, and production operations.

This syllabus deliberately separates foundations, modeling, querying, internals, reliability, security, performance, operations, and production design so advanced material is not compressed into generic catch-all chapters.

By the end

You will be able to

  • Design mappings, analyzers, index/data-stream layouts, shard strategies, and ingestion pipelines for search and observability workloads
  • Write, profile, and evaluate lexical, filtered, aggregate, vector, semantic, and hybrid queries with relevance evidence
  • Operate Elasticsearch and OpenSearch clusters with lifecycle policies, snapshots, security, allocation, monitoring, upgrades, and disaster recovery
  • Understand where Elastic and OpenSearch diverge in management, security, query languages, AI/search tooling, and managed-service ecosystems
  • Build production search/RAG architectures with measurable quality, latency, freshness, resilience, capacity, and cost objectives

Complete planned syllabus

31 chapters · 155 lesson paths.

Every lesson path is reserved now but intentionally not linked until its lesson HTML is actually published. The sequence moves from foundations through advanced implementation, architecture, operations, reliability, security, tuning, and a production capstone.

01

Chapter 1

Search Engine Foundations, Elasticsearch vs OpenSearch, Deployment Models, and Lab Setup

5 lessons
01
Inverted-Index Search vs Relational/Document/Vector Databases: Workload Fit and Architectural TradeoffsPlanned lesson · reserved path Chapter01/Lesson1.html
Planned
02
Elasticsearch and OpenSearch Lineage, Licensing/Ecosystem Differences, APIs, and Compatibility ExpectationsPlanned lesson · reserved path Chapter01/Lesson2.html
Planned
03
Self-Managed, Elastic Cloud/Serverless, Amazon OpenSearch Service, and Other Managed Responsibility BoundariesPlanned lesson · reserved path Chapter01/Lesson3.html
Planned
04
Start Local Clusters, Use Kibana/OpenSearch Dashboards Dev Tools or curl, and Inspect Cluster/Node HealthPlanned lesson · reserved path Chapter01/Lesson4.html
Planned
05
Build a Reproducible Lab with Sample Data, TLS/Auth, Persistent Storage, Metrics, and Safe Reset AutomationPlanned lesson · reserved path Chapter01/Lesson5.html
Planned
02

Chapter 2

Documents, Indices, Data Streams, Shards, Replicas, Nodes, and Cluster Architecture

5 lessons
01
JSON Documents, _source, Metadata Fields, IDs, Versions/Sequence Numbers, and Optimistic ConcurrencyPlanned lesson · reserved path Chapter02/Lesson1.html
Planned
02
Indices, Aliases, Data Streams, Backing Indices, Shards, Replicas, and RoutingPlanned lesson · reserved path Chapter02/Lesson2.html
Planned
03
Node Roles, Cluster State, Master/Cluster-Manager Responsibilities, Data Tiers, and Coordinating WorkPlanned lesson · reserved path Chapter02/Lesson3.html
Planned
04
Distributed Write and Search Request Flows: Primary Shard, Replication, Scatter/Gather, and Partial FailuresPlanned lesson · reserved path Chapter02/Lesson4.html
Planned
05
Trace One Document from Index Request Through Refresh to Search Result and Explain Every Distributed StepPlanned lesson · reserved path Chapter02/Lesson5.html
Planned
03

Chapter 3

Mappings and Field Types: keyword, text, Numeric, Date, Geo, Object, Nested, and Runtime Fields

5 lessons
01
Explicit vs Dynamic Mappings, Field Explosion, Mapping Conflicts, and Schema-Governance StrategyPlanned lesson · reserved path Chapter03/Lesson1.html
Planned
02
text vs keyword: Analysis, Exact Matching, Sorting/Aggregation, Multi-Fields, and NormalizersPlanned lesson · reserved path Chapter03/Lesson2.html
Planned
03
Numeric, Date, Boolean, IP, Geo, Range, Dense Vector, Object, Flattened, and Other Specialized TypesPlanned lesson · reserved path Chapter03/Lesson3.html
Planned
04
Object vs nested Modeling, Parent/Child/Join Tradeoffs, Denormalization, and Update CostPlanned lesson · reserved path Chapter03/Lesson4.html
Planned
05
Design a Mapping from Query/Aggregation Requirements and Validate It Before Bulk IngestionPlanned lesson · reserved path Chapter03/Lesson5.html
Planned
04

Chapter 4

Indexing and CRUD: Bulk APIs, Refresh, Concurrency Control, and Idempotent Ingestion

5 lessons
01
Index/Create/Update/Delete Semantics, IDs, Upserts, Scripts, and Partial Document UpdatesPlanned lesson · reserved path Chapter04/Lesson1.html
Planned
02
Bulk Request Format, Batch Sizing, Backpressure, Error Inspection, and Retry ClassificationPlanned lesson · reserved path Chapter04/Lesson2.html
Planned
03
Refresh vs Flush vs Force Merge: Search Visibility, Durability, Segments, and PerformancePlanned lesson · reserved path Chapter04/Lesson3.html
Planned
04
if_seq_no/if_primary_term Concurrency Control, External Versioning Concepts, and Idempotency KeysPlanned lesson · reserved path Chapter04/Lesson4.html
Planned
05
Build a High-Throughput Bulk Loader that Handles Partial Failure Without Silent Data Loss or DuplicationPlanned lesson · reserved path Chapter04/Lesson5.html
Planned
05

Chapter 5

Text Analysis: Character Filters, Tokenizers, Token Filters, Analyzers, and Language Search

5 lessons
01
Index-Time vs Search-Time Analysis and Why Token Streams Define Search SemanticsPlanned lesson · reserved path Chapter05/Lesson1.html
Planned
02
Standard, Keyword, Whitespace, Pattern, N-Gram/Edge-N-Gram, Path, and Language Tokenization PatternsPlanned lesson · reserved path Chapter05/Lesson2.html
Planned
03
Lowercase, Stop, Stemmer, Synonym, Shingle, ASCII Folding, and Normalization TradeoffsPlanned lesson · reserved path Chapter05/Lesson3.html
Planned
04
Custom Analyzers, Multi-Fields, Search Analyzers, Synonym Lifecycle, and Reindexing ImplicationsPlanned lesson · reserved path Chapter05/Lesson4.html
Planned
05
Use Analyze APIs to Debug Unexpected Matching and Build Tests for Tokenization/Normalization ContractsPlanned lesson · reserved path Chapter05/Lesson5.html
Planned
06

Chapter 6

Query DSL Fundamentals: Term-Level, Full-Text, Boolean, Range, Exists, and Filtering

5 lessons
01
match, multi_match, match_phrase, query_string/simple_query_string, and Phrase/Proximity SemanticsPlanned lesson · reserved path Chapter06/Lesson1.html
Planned
02
term/terms, range, exists, prefix/wildcard/regexp, IDs, and Cost AwarenessPlanned lesson · reserved path Chapter06/Lesson2.html
Planned
03
bool must/should/filter/must_not, Minimum Should Match, Filter Context, and CacheabilityPlanned lesson · reserved path Chapter06/Lesson3.html
Planned
04
Nested Queries, Geo Queries, Script Queries, and Avoiding Expensive Query Anti-PatternsPlanned lesson · reserved path Chapter06/Lesson4.html
Planned
05
Construct a Search API from User Intent with Safe Query Templates, Explicit Filters, and Test CasesPlanned lesson · reserved path Chapter06/Lesson5.html
Planned
07

Chapter 7

Relevance Engineering: BM25, Field Weighting, Function Score, Ranking, and Evaluation

5 lessons
01
TF/IDF Intuition, BM25 Parameters, Document Length, Rare Terms, and Why Scores Are Query-RelativePlanned lesson · reserved path Chapter07/Lesson1.html
Planned
02
Field Boosts, DisMax, Tie Breakers, Cross/Best/Most Fields, and Multi-Match StrategyPlanned lesson · reserved path Chapter07/Lesson2.html
Planned
03
Function Score, Decay, Rank Feature, Business Signals, Freshness, and Popularity Without Drowning Text RelevancePlanned lesson · reserved path Chapter07/Lesson3.html
Planned
04
Named Queries, Explain/Profile, Score Debugging, and Avoiding Score Comparisons Across Different Retrieval SourcesPlanned lesson · reserved path Chapter07/Lesson4.html
Planned
05
Build a Relevance Evaluation Set with Queries, Judgments, Metrics, Baselines, and Regression ThresholdsPlanned lesson · reserved path Chapter07/Lesson5.html
Planned
08

Chapter 8

Aggregations: Metrics, Buckets, Pipeline Aggregations, Cardinality, and Analytical Search

5 lessons
01
Metric Aggregations: min/max/avg/sum/stats/percentiles/cardinality and Approximation TradeoffsPlanned lesson · reserved path Chapter08/Lesson1.html
Planned
02
Bucket Aggregations: terms, range, date histogram, filters, composite, significant terms, and GeoPlanned lesson · reserved path Chapter08/Lesson2.html
Planned
03
Nested/Reverse Nested, Filter/Global, Sampler, and Modeling Implications for AnalyticsPlanned lesson · reserved path Chapter08/Lesson3.html
Planned
04
Pipeline Aggregations, Moving Functions, Derivatives, Bucket Scripts, and Time-Series ComputationPlanned lesson · reserved path Chapter08/Lesson4.html
Planned
05
Design a Faceted Analytics Query and Control Accuracy, Memory, Shard Size, and Response ComplexityPlanned lesson · reserved path Chapter08/Lesson5.html
Planned
09

Chapter 9

Dynamic Templates, Index Templates, Component Templates, and Schema Evolution

5 lessons
01
Dynamic Field Detection, Coercion, Date/Numeric Detection, and Failure Modes from Uncontrolled InputPlanned lesson · reserved path Chapter09/Lesson1.html
Planned
02
Dynamic Templates by Path/Name/Type for Stable Mapping ContractsPlanned lesson · reserved path Chapter09/Lesson2.html
Planned
03
Composable Index Templates, Component Templates, Priorities, Simulation, and Environment PromotionPlanned lesson · reserved path Chapter09/Lesson3.html
Planned
04
Changing Mappings Safely: Additive Changes, New Indices, Reindex, Alias Cutover, and RollbackPlanned lesson · reserved path Chapter09/Lesson4.html
Planned
05
Create a Versioned Schema Deployment Workflow with Template Tests and Zero-Downtime ReindexingPlanned lesson · reserved path Chapter09/Lesson5.html
Planned
10

Chapter 10

Data Streams, Time-Series Data, Logs, Metrics, and Append-Heavy Workloads

5 lessons
01
Data Streams, Backing Indices, Write Index, @timestamp, Rollover, and Append-Only DesignPlanned lesson · reserved path Chapter10/Lesson1.html
Planned
02
Time-Series Dimensions/Metrics Concepts, Index Modes, Routing, and Compression/Storage ConsiderationsPlanned lesson · reserved path Chapter10/Lesson2.html
Planned
03
Logs and Metrics Modeling: High Cardinality, Labels, Structured Events, and Field GovernancePlanned lesson · reserved path Chapter10/Lesson3.html
Planned
04
Late/Out-of-Order Events, Updates/Deletes Against Backing Indices, and Operational ConstraintsPlanned lesson · reserved path Chapter10/Lesson4.html
Planned
05
Design a Telemetry Data Stream with Lifecycle, Schema, Routing, Search, Aggregation, and Retention RequirementsPlanned lesson · reserved path Chapter10/Lesson5.html
Planned
11

Chapter 11

Ingest Pipelines, Processors, Enrichment, Failure Handling, and Data Quality

5 lessons
01
Ingest Nodes/Pipelines, Processor Execution, on_failure, Conditional Processing, and SimulationPlanned lesson · reserved path Chapter11/Lesson1.html
Planned
02
Grok/Dissect, Date, Convert, Rename, Set, Remove, Script, GeoIP/User-Agent-Like Enrichment PatternsPlanned lesson · reserved path Chapter11/Lesson2.html
Planned
03
Enrich Policies and Lookup Data: Refresh, Consistency, and Deployment WorkflowsPlanned lesson · reserved path Chapter11/Lesson3.html
Planned
04
Dead-Letter/Failure Indices, Observability, Retry, and Preventing Poison Documents from Blocking PipelinesPlanned lesson · reserved path Chapter11/Lesson4.html
Planned
05
Build and Benchmark an Ingest Pipeline Against Upstream ETL Alternatives and Define Ownership BoundariesPlanned lesson · reserved path Chapter11/Lesson5.html
Planned
12

Chapter 12

Aliases, Rollover, Reindex, Update/Delete by Query, and Zero-Downtime Index Changes

5 lessons
01
Read/Write Aliases, Filters, Routing, is_write_index, and Atomic Alias UpdatesPlanned lesson · reserved path Chapter12/Lesson1.html
Planned
02
Rollover Conditions by Age/Size/Docs and Coordinating with Data Streams/Lifecycle PoliciesPlanned lesson · reserved path Chapter12/Lesson2.html
Planned
03
Reindex from Index/Remote Source, Slicing, Throttling, Conflict Handling, and ValidationPlanned lesson · reserved path Chapter12/Lesson3.html
Planned
04
Update-by-Query/Delete-by-Query, Task APIs, Cancellation, Version Conflicts, and Cluster ImpactPlanned lesson · reserved path Chapter12/Lesson4.html
Planned
05
Execute a Mapping Migration with Dual Read/Write or Alias Cutover, Validation, and Rollback EvidencePlanned lesson · reserved path Chapter12/Lesson5.html
Planned
13

Chapter 13

Shard Sizing, Routing, Allocation, Awareness, and Cluster Topology

5 lessons
01
Primary/Replica Shard Count, Shard Overhead, Dataset Growth, Search Concurrency, and Recovery TimePlanned lesson · reserved path Chapter13/Lesson1.html
Planned
02
Document Routing, Custom Routing, Hotspots, Skew, and Co-Locating QueriesPlanned lesson · reserved path Chapter13/Lesson2.html
Planned
03
Allocation Deciders, Disk Watermarks, Awareness/Forced Awareness, Data Tiers, and Zone FailurePlanned lesson · reserved path Chapter13/Lesson3.html
Planned
04
Shard Rebalancing, Recovery, Throttling, Relocation, and Operational HeadroomPlanned lesson · reserved path Chapter13/Lesson4.html
Planned
05
Model a Capacity/Shard Plan and Simulate Node Loss Without Exceeding Recovery or Latency ObjectivesPlanned lesson · reserved path Chapter13/Lesson5.html
Planned
14

Chapter 14

Lucene Segments, Refresh, Merge, Translog, Flush, and Storage Internals

5 lessons
01
Immutable Segments, Inverted Index/Postings, Stored Fields, Doc Values, Norms, and Term DictionariesPlanned lesson · reserved path Chapter14/Lesson1.html
Planned
02
Refresh Creates Searchable Segments; Flush Commits; Translog Supports Recovery—Separate the ConceptsPlanned lesson · reserved path Chapter14/Lesson2.html
Planned
03
Segment Merging, Deleted Docs, Merge Policy, Force Merge Risks, and Write AmplificationPlanned lesson · reserved path Chapter14/Lesson3.html
Planned
04
Compression, Filesystem Cache, mmap, Storage Latency, and Why Local SSD Often MattersPlanned lesson · reserved path Chapter14/Lesson4.html
Planned
05
Diagnose an Indexing/Storage Problem Using Segment Counts, Merge Pressure, Disk I/O, and Refresh BehaviorPlanned lesson · reserved path Chapter14/Lesson5.html
Planned
15

Chapter 15

Heap, Caches, Circuit Breakers, Thread Pools, Backpressure, and JVM/Runtime Health

5 lessons
01
Heap vs Filesystem Cache, Object Overhead, Compressed OOPs Concepts, and Why More Heap Is Not Always BetterPlanned lesson · reserved path Chapter15/Lesson1.html
Planned
02
Query/Request/Fielddata/Shard Request Caches: Eligibility, Invalidation, and Memory TradeoffsPlanned lesson · reserved path Chapter15/Lesson2.html
Planned
03
Circuit Breakers, In-Flight Requests, Aggregation Memory, Fielddata Hazards, and Failure ProtectionPlanned lesson · reserved path Chapter15/Lesson3.html
Planned
04
Thread Pools, Queues, Rejections, Indexing Pressure, Search Backpressure, and Client-Side ConcurrencyPlanned lesson · reserved path Chapter15/Lesson4.html
Planned
05
Build a Saturation Diagnosis from GC, CPU, Heap, Rejections, Latency, Disk, and Workload EvidencePlanned lesson · reserved path Chapter15/Lesson5.html
Planned
16

Chapter 16

Search Execution, Profiling, Slow Logs, Async/Search-After/PIT, and Pagination

5 lessons
01
Distributed Query/Fetch Phases, Can-Match, Shard Pruning, DFS Concepts, and Coordination CostPlanned lesson · reserved path Chapter16/Lesson1.html
Planned
02
Profile API, Explain, Search Slow Logs, Hot Threads, Tasks, and Distinguishing Query from Fetch CostPlanned lesson · reserved path Chapter16/Lesson2.html
Planned
03
from/size Limits, search_after, Point-in-Time Readers, Stable Sort Keys, and Pagination CorrectnessPlanned lesson · reserved path Chapter16/Lesson3.html
Planned
04
Async Search, Cancellation, Timeouts, Partial Results, and Long-Running Analytical RequestsPlanned lesson · reserved path Chapter16/Lesson4.html
Planned
05
Tune a Slow Search by Changing Query, Mapping, Routing, Shards, Aggregation Strategy, or Pagination—Then MeasurePlanned lesson · reserved path Chapter16/Lesson5.html
Planned
17

Chapter 17

Index Lifecycle: Elastic ILM/Data Tiers and OpenSearch ISM

5 lessons
01
Lifecycle Goals: Rollover, Retention, Tiering, Shrink/Force-Merge-Like Actions, and Cost/Recovery TradeoffsPlanned lesson · reserved path Chapter17/Lesson1.html
Planned
02
Elastic ILM Phases/Actions, Data Tiers, Rollover Aliases/Data Streams, and Explain/TroubleshootingPlanned lesson · reserved path Chapter17/Lesson2.html
Planned
03
OpenSearch Index State Management Policies, States, Transitions, Actions, Templates, and SimulationPlanned lesson · reserved path Chapter17/Lesson3.html
Planned
04
Lifecycle Policy Versioning, Safe Testing, Stuck Actions, Manual Intervention, and Compliance RetentionPlanned lesson · reserved path Chapter17/Lesson4.html
Planned
05
Design Equivalent Retention Strategies in Elastic and OpenSearch and Document Feature/Operational DifferencesPlanned lesson · reserved path Chapter17/Lesson5.html
Planned
18

Chapter 18

Snapshots, Restore, Searchable/Remote Storage Concepts, and Disaster Recovery

5 lessons
01
Snapshot Repository Architecture, Incremental Segment Reuse, Consistency, and Repository Access ControlPlanned lesson · reserved path Chapter18/Lesson1.html
Planned
02
Snapshot Lifecycle/Scheduled Backups, Retention, Verification, and MonitoringPlanned lesson · reserved path Chapter18/Lesson2.html
Planned
03
Restore Full/Partial Indices, Rename-on-Restore, Global State/Security Considerations, and Conflict HandlingPlanned lesson · reserved path Chapter18/Lesson3.html
Planned
04
Cross-Region Repository Strategy, Searchable Snapshot/Remote Store Concepts, and Cost/Latency TradeoffsPlanned lesson · reserved path Chapter18/Lesson4.html
Planned
05
Run a Restore Drill and Measure RPO/RTO, Data Completeness, Security State, Templates, and Application CutoverPlanned lesson · reserved path Chapter18/Lesson5.html
Planned
19

Chapter 19

Elastic Security: TLS, Realms, Users/Roles, API Keys, DLS/FLS, and Audit

5 lessons
01
Secure-by-Default Principles, Node/HTTP TLS, Certificates, Trust, and Enrollment/Bootstrap ConceptsPlanned lesson · reserved path Chapter19/Lesson1.html
Planned
02
Users, Roles, Cluster/Index/Application Privileges, Spaces, and Least-Privilege DesignPlanned lesson · reserved path Chapter19/Lesson2.html
Planned
03
API Keys, Service Accounts/Tokens, Rotation, Expiration, and Machine-to-Machine AuthenticationPlanned lesson · reserved path Chapter19/Lesson3.html
Planned
04
Document/Field-Level Security, Run-As, Audit Logging, and Subscription/Feature AwarenessPlanned lesson · reserved path Chapter19/Lesson4.html
Planned
05
Threat-Model an Elastic Deployment for Anonymous Exposure, Over-Privileged APIs, Snapshot Theft, and Query AbusePlanned lesson · reserved path Chapter19/Lesson5.html
Planned
20

Chapter 20

OpenSearch Security: TLS, Internal Users, Roles, Tenants, Backends, and Fine-Grained Access

5 lessons
01
Security Plugin Architecture, Node/HTTP Certificates, Distinguished Names, and InitializationPlanned lesson · reserved path Chapter20/Lesson1.html
Planned
02
Users, Roles, Role Mappings, Action Groups, Index Permissions, and Cluster PermissionsPlanned lesson · reserved path Chapter20/Lesson2.html
Planned
03
Authentication Backends, LDAP/OIDC/SAML-Like Integrations, Dashboards Multi-Tenancy, and Impersonation ConceptsPlanned lesson · reserved path Chapter20/Lesson3.html
Planned
04
Document/Field-Level Security, Audit Logs, API Keys/Scoped Access Where Available, and Secrets RotationPlanned lesson · reserved path Chapter20/Lesson4.html
Planned
05
Compare an Equivalent Least-Privilege Application Role in OpenSearch vs Elastic and Document Behavioral DifferencesPlanned lesson · reserved path Chapter20/Lesson5.html
Planned
21

Chapter 21

Cluster Operations, Rolling Maintenance, Upgrades, Node Replacement, and Failure Recovery

5 lessons
01
Cluster Health, Unassigned Shards, Allocation Explain, Voting/Master Eligibility, and Quorum SafetyPlanned lesson · reserved path Chapter21/Lesson1.html
Planned
02
Rolling Restart/Upgrade Sequencing, Shard Allocation Control, Synced Recovery Concepts, and ValidationPlanned lesson · reserved path Chapter21/Lesson2.html
Planned
03
Node Replacement, Disk Expansion, Tier Migration, Rebalancing, and DecommissioningPlanned lesson · reserved path Chapter21/Lesson3.html
Planned
04
Version Compatibility, Breaking Changes, Plugin Compatibility, Snapshot Before Upgrade, and Rollback BoundariesPlanned lesson · reserved path Chapter21/Lesson4.html
Planned
05
Execute a Maintenance Game Day with a Node Failure During Upgrade and Prove Recovery ProceduresPlanned lesson · reserved path Chapter21/Lesson5.html
Planned
22

Chapter 22

Remote Clusters, Cross-Cluster Search, Cross-Cluster Replication, and Multi-Region Design

5 lessons
01
Remote Cluster Connectivity, Sniff/Proxy-Like Modes, Security, Latency, and Failure SemanticsPlanned lesson · reserved path Chapter22/Lesson1.html
Planned
02
Cross-Cluster Search Across Indices/Data Streams and Federated Query TradeoffsPlanned lesson · reserved path Chapter22/Lesson2.html
Planned
03
Elastic Cross-Cluster Replication: Leader/Follower, Auto-Follow, Disaster Recovery, and Non-Replicated ConfigurationPlanned lesson · reserved path Chapter22/Lesson3.html
Planned
04
OpenSearch Cross-Cluster Replication/Search Concepts and Managed-Service ConstraintsPlanned lesson · reserved path Chapter22/Lesson4.html
Planned
05
Design Multi-Region Search/DR with Explicit RPO/RTO, Write Ownership, Security, Failover, and Cost TradeoffsPlanned lesson · reserved path Chapter22/Lesson5.html
Planned
23

Chapter 23

Operational Analytics Languages: ES|QL, OpenSearch PPL/SQL, and Query API Boundaries

5 lessons
01
ES|QL Pipeline Syntax, Sources, Filtering, Transformation, Aggregation, Enrichment, and Tabular ResultsPlanned lesson · reserved path Chapter23/Lesson1.html
Planned
02
ES|QL Across Multiple Indices/Clusters and When It Complements vs Replaces Query DSL/AggregationsPlanned lesson · reserved path Chapter23/Lesson2.html
Planned
03
OpenSearch PPL and SQL Interfaces: Pipeline/Relational Mental Models, Supported Operations, and LimitationsPlanned lesson · reserved path Chapter23/Lesson3.html
Planned
04
Dashboards/Notebook/Observability Query Workflows and Security/Resource BoundariesPlanned lesson · reserved path Chapter23/Lesson4.html
Planned
05
Translate One Analytical Requirement Between Query DSL+Aggregations, ES|QL, and PPL and Compare Semantics/CostPlanned lesson · reserved path Chapter23/Lesson5.html
Planned
24

Chapter 24

Observability, Dashboards, Alerts, Tracing Search Workloads, and SLOs

5 lessons
01
Cluster/Node/Index Metrics: JVM, CPU, Disk, Shards, Indexing, Search, Cache, Merge, Refresh, and RecoveryPlanned lesson · reserved path Chapter24/Lesson1.html
Planned
02
Dashboards/Kibana Data Views, Saved Objects, Visualizations, and Environment SeparationPlanned lesson · reserved path Chapter24/Lesson2.html
Planned
03
Alerting/Rules/Monitors, Thresholds vs Anomaly/Rate Conditions, Noise Control, and Incident RoutingPlanned lesson · reserved path Chapter24/Lesson3.html
Planned
04
Search SLOs: Availability, p95/p99 Latency, Freshness, Indexing Lag, Error/Rejection Rate, and Relevance QualityPlanned lesson · reserved path Chapter24/Lesson4.html
Planned
05
Build an Operations Dashboard and Incident Runbook Linking User Symptoms to Cluster and Query EvidencePlanned lesson · reserved path Chapter24/Lesson5.html
Planned
25

Chapter 25

Vector Search Fundamentals: Embeddings, Dense/Sparse Vectors, ANN, HNSW, Quantization, and Filters

5 lessons
01
Embedding Semantics, Dimensions, Distance/Similarity, Normalization, Model Versioning, and Data ContractsPlanned lesson · reserved path Chapter25/Lesson1.html
Planned
02
Exact vs Approximate kNN, HNSW Concepts, ef/m Parameters, Recall/Latency/Memory Tradeoffs, and Ground-Truth TestingPlanned lesson · reserved path Chapter25/Lesson2.html
Planned
03
Elastic dense_vector/kNN Concepts and OpenSearch k-NN/vector Engine OptionsPlanned lesson · reserved path Chapter25/Lesson3.html
Planned
04
Filtering Vector Search, Multi-Vector/Nested Patterns, Quantization/Compression, and Hardware/Memory PlanningPlanned lesson · reserved path Chapter25/Lesson4.html
Planned
05
Benchmark Vector Recall, p99 Latency, Index Build Time, Memory, and Filter Selectivity with Representative QueriesPlanned lesson · reserved path Chapter25/Lesson5.html
Planned
26

Chapter 26

Semantic, Neural, Sparse, and Hybrid Search in Elasticsearch and OpenSearch

5 lessons
01
Semantic Search from Text to Embeddings: Ingest-Time vs Query-Time Model Invocation and Failure BoundariesPlanned lesson · reserved path Chapter26/Lesson1.html
Planned
02
Elastic Semantic/Vector Retrieval and Hybrid Ranking Concepts Across Lexical and Dense/Sparse SignalsPlanned lesson · reserved path Chapter26/Lesson2.html
Planned
03
OpenSearch neural, neural_sparse, k-NN, Ingest/Search Pipelines, and ML Commons Model IntegrationPlanned lesson · reserved path Chapter26/Lesson3.html
Planned
04
Hybrid Score Normalization, Weighted Combination, Reciprocal-Rank-Like Fusion, Re-Ranking, and Search Quality EvaluationPlanned lesson · reserved path Chapter26/Lesson4.html
Planned
05
Build Equivalent Keyword+Semantic Search Pipelines in Both Platforms and Compare Quality, Latency, and Operational ComplexityPlanned lesson · reserved path Chapter26/Lesson5.html
Planned
27

Chapter 27

RAG, AI Search, Inference Pipelines, Agentic Search, and Production Retrieval Architecture

5 lessons
01
RAG Architecture: Chunking, Metadata, Embeddings, Retrieval, Re-Ranking, Context Packing, Citations, and EvaluationPlanned lesson · reserved path Chapter27/Lesson1.html
Planned
02
Managed/External Model Connectors, Inference Endpoints, Secrets, Rate Limits, Batching, and Model LifecyclePlanned lesson · reserved path Chapter27/Lesson2.html
Planned
03
Conversational/Agentic Search Concepts, Query Rewriting, Tooling, Memory, and GuardrailsPlanned lesson · reserved path Chapter27/Lesson3.html
Planned
04
Security for RAG: Tenant Filtering, Document-Level Access, Prompt/Data Injection, Sensitive Fields, and AuditabilityPlanned lesson · reserved path Chapter27/Lesson4.html
Planned
05
Evaluate Retrieval Separately from Generation with Recall@k, NDCG/MRR-Like Metrics, Faithfulness, Latency, and CostPlanned lesson · reserved path Chapter27/Lesson5.html
Planned
28

Chapter 28

Log Analytics, Security Analytics, Search Applications, and Workload-Specific Architecture

5 lessons
01
Application/Product Search: Catalog Modeling, Synonyms, Relevance Signals, Autocomplete, Facets, and Personalization BoundariesPlanned lesson · reserved path Chapter28/Lesson1.html
Planned
02
Log Analytics: ECS/OpenTelemetry-Like Schema Discipline, Pipelines, Data Streams, Retention, and High CardinalityPlanned lesson · reserved path Chapter28/Lesson2.html
Planned
03
Security Analytics: Event Normalization, Detection Queries, Alert Volume, Long Retention, and Investigative SearchPlanned lesson · reserved path Chapter28/Lesson3.html
Planned
04
Observability: Logs/Metrics/Traces Correlation, Service Maps, APM-Like Workflows, and Cost ControlsPlanned lesson · reserved path Chapter28/Lesson4.html
Planned
05
Choose Index/Shard/Lifecycle/Search Strategies per Workload Instead of Running Every Use Case in One Undifferentiated ClusterPlanned lesson · reserved path Chapter28/Lesson5.html
Planned
29

Chapter 29

Migration and Interoperability: Elasticsearch ↔ OpenSearch, Reindexing, Clients, Plugins, and API Drift

5 lessons
01
Assess API, Mapping, Query, Security, Plugin, Snapshot, and Client Compatibility Before MigrationPlanned lesson · reserved path Chapter29/Lesson1.html
Planned
02
Snapshot Compatibility Boundaries vs Remote Reindex/ETL, Full Copy, Dual Write, and Incremental SynchronizationPlanned lesson · reserved path Chapter29/Lesson2.html
Planned
03
Client/SDK and Query-Language Differences, Deprecated APIs, Feature Replacements, and Testing StrategyPlanned lesson · reserved path Chapter29/Lesson3.html
Planned
04
Managed-Service Migration: Networking, IAM, Encryption, Snapshot Repositories, DNS/Endpoint Cutover, and RollbackPlanned lesson · reserved path Chapter29/Lesson4.html
Planned
05
Build a Migration Runbook with Data Validation, Relevance Regression, Performance Baselines, RPO, and Rollback TriggersPlanned lesson · reserved path Chapter29/Lesson5.html
Planned
30

Chapter 30

Performance Engineering and Capacity Planning: Indexing, Search, Shards, Hardware, and Cost

5 lessons
01
Workload Characterization: QPS, Write Rate, Document Size, Fields, Retention, Aggregations, Vector Dimensions, and ConcurrencyPlanned lesson · reserved path Chapter30/Lesson1.html
Planned
02
Indexing Tuning: Bulk Size, Refresh, Replicas, Pipelines, Merge, Translog/Durability, and BackpressurePlanned lesson · reserved path Chapter30/Lesson2.html
Planned
03
Search Tuning: Query Shape, Filters, Caches, Routing, Shard Count, Precomputation, and Aggregation StrategiesPlanned lesson · reserved path Chapter30/Lesson3.html
Planned
04
Hardware/Topology: CPU, Heap, Page Cache, SSD, Network, Data Tiers, Hot/Warm/Cold, and Failure HeadroomPlanned lesson · reserved path Chapter30/Lesson4.html
Planned
05
Run Production-Like Benchmarks with Tail Latency, Relevance, Recovery, Indexing Lag, Saturation, and Cost per WorkloadPlanned lesson · reserved path Chapter30/Lesson5.html
Planned
31

Chapter 31

Production Capstone: Build, Evaluate, Secure, Scale, Recover, and Operate a Search Platform

5 lessons
01
Define Search/Analytics Requirements, Relevance Judgments, Freshness, Retention, Security, SLOs, RPO/RTO, and Cost ConstraintsPlanned lesson · reserved path Chapter31/Lesson1.html
Planned
02
Create Mappings/Analyzers/Templates, Ingest Pipelines, Data Streams/Indices, Lifecycle Policies, and Core Search/Aggregation APIsPlanned lesson · reserved path Chapter31/Lesson2.html
Planned
03
Add Vector/Hybrid/RAG Retrieval with Explicit Quality Benchmarks and Tenant/Security FiltersPlanned lesson · reserved path Chapter31/Lesson3.html
Planned
04
Load-Test, Profile, Secure, Snapshot/Restore, Fail Over, Upgrade, Monitor, and Execute Operational Incident DrillsPlanned lesson · reserved path Chapter31/Lesson4.html
Planned
05
Present Elastic vs OpenSearch Architecture Choices with Evidence, Feature/License/Operations Tradeoffs, and Exit/Migration StrategyPlanned lesson · reserved path Chapter31/Lesson5.html
Planned