Corporate · onsite · online training worldwide
contact@DevOpsSchool.com· +91 99057 40781·
> Data Visualisation & Analytics · DevOpsSchool Trainer

Kibana Trainer

Private corporate batches, live online cohorts and 1-on-1 mentoring in the query and visualisation layer over Elasticsearch — Discover, KQL, Lens, dashboards and alerting — taught by a practitioner who runs it in production.

20 years across DevOps, SRE and Security · 10,000+ engineers trained · Trained teams at JPMorgan Chase, Verizon, Nokia and the World Bank

DeliveryOnline · Onsite · Hybrid
FormatsCorporate · 1-on-1 · Cohort
AgendaCustomisable
Batch size8–30 engineers
Engineers we've trained work at
JPMorgan ChaseBank of AmericaWells FargoVerizonNokiaWorld BankGE HealthcareVMwareOracleQualcommMercedes-BenzAirbusDatadogSplunkDeloitteInfosysWiproCapgemini
# who teaches it

Your Kibana trainer

Rajesh Kumar

Principal DevOps Engineer & Architect

Early-bird MLOpsAIOps practitionerData platform operations20 years in productionPrincipal / architect roles10,000+ engineers trainedM.Tech BITS Pilani25+ certifications

Rajesh teaches Kibana as a query interface first and a chart builder second — because a dashboard is only as good as the KQL and filters underneath it, and a panel that scans a billion documents will fail regardless of how it looks. Sessions cover Discover and field-level investigation, KQL and Lucene syntax including wildcards, ranges, negation with parentheses and null checks, then the full visualisation range from Lens and aggregation-based charts to TSVB and Timelion with offsets and splits. Dashboards, controls and drilldowns, alerting rules and connectors, reporting, Dev Tools, Spaces and role-based access are all taught against a live Elasticsearch cluster.

Twenty years across DevOps, SRE and Security, in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe and others. He has trained engineers at JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus — more than 10,000 people personally. He teaches what he runs, not what he reads.

One practitioner, not a bench

You are booked with a named engineer, and that is who turns up. Marketplaces and larger providers rotate whoever is free, so the person who sold you the agenda is rarely the person teaching it.

The same trainer is available for the next engagement, which matters when a team builds on what it learned last time.

18,000+certified learners
500+corporate batches delivered
50+countries served
100+certification programmes
# faculty

Who delivers Kibana engagements

Your batch is assigned a named trainer before it starts, and that is who teaches it. See the full faculty.

How your Kibana trainer is chosen

Engagements are matched on the tool, not the calendar. For Kibana that means a trainer who has run it in production — the query and visualisation layer over Elasticsearch — Discover, KQL, Lens, dashboards and alerting — rather than whoever is free that week. You are told who is teaching before you commit, and that person is on the discovery call that shapes the agenda.

Where a batch is large enough to need a second trainer, the pairing is declared up front. The lead trainer stays accountable for the syllabus and the assessment either way.

Rajesh Kumar

Principal DevOps Engineer & Architect

India20 yrsLead trainer

Twenty years across DevOps, SRE and Security in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe, IBM/Emptoris, Ness, MindTree and Accenture. He has trained more than 10,000 engineers personally, at organisations including JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus. He teaches what he runs, not what he reads.

Balachandran Anbalagan

IndiaInstructorCoach

Durga Prasad

IndiaInstructorCoach

Gaurav Aggarwal

IndiaInstructorCoach

Harsh Mehta

IndiaInstructorCoach

Kapil Gupta

IndiaInstructorCoach

Kunal Jain

IndiaInstructorCoach

Nikhil Gupta

IndiaInstructorCoach

Pranab Kumar

IndiaInstructorCoach

Rohit Ghatol

IndiaInstructorCoach

Amit Agarwal

IndiaInstructorCoach

Anil Kumar

IndiaInstructorCoach

# how to engage

Four ways to work with this trainer

Private corporate batch

Teams of 8–30

Custom agenda, your timezone, onsite or online, NDA-friendly.

Request a quote

1-on-1 mentoring

Individual engineers

A private instructor and a curriculum built around your goal.

₹99,999

Live & Interactive cohort

Individuals who want peers

Scheduled batch, max 8 to 10 hours of live instruction.

₹34,999

Self-paced video

Self-starters

Full LMS access — 20+ courses and 50+ tools included.

₹833/mo
# private batches

Private Kibana training for your team

A private batch starts with a discovery call. We look at the stack you actually run — the CI system, the cloud, the constraints — and map the agenda onto it, so examples use your topology rather than a generic one.

Delivery is onsite at your premises, live online, or hybrid, scheduled around your release calendar rather than ours. Batches run 8 to 30 engineers.

Every attendee leaves with recordings, slides, lab repositories and a completion certificate. You receive an attendance and assessment report. Invoicing supports PO and GST.

Talk to us about a private Kibana batch

What you provide vs what we bring

  • You: the room or the call, and the engineers
  • Us: trainer, agenda, labs, assessment, certificates
  • Labs: we guide your team through provisioning their own free-tier cloud environment — the skill goes with them
# the technology

What is Kibana?

Kibana is the query and visualisation interface for data held in Elasticsearch. It stores no data of its own: every chart, table, map and dashboard is a query issued against an Elasticsearch index, and every saved object — data view, visualisation, dashboard, alert rule — lives in a hidden Elasticsearch index that Kibana manages. Understanding that relationship is what makes the difference between building dashboards that work and building dashboards that time out.

The day-to-day surfaces are Discover and the visualisation editors. Discover is where investigation happens: pick a data view, set a time range, write a query in KQL or Lucene syntax, add filters, and read raw documents field by field. Kibana Query Language covers the cases people actually need — field matching, wildcards, ranges, boolean operators with parentheses, and existence or null checks — while Lucene syntax and the filter pills remain available for anything it does not express.

On top of that sit the building tools. Lens for drag-and-drop charts, the aggregation-based editors for line graphs, tables, pie and gauge charts and metrics, TSVB and Timelion for time-series work with offsets, splits and expression syntax, Maps for geospatial data, and Canvas for presentation-grade output. Dashboards compose those panels with shared filters, controls and drilldowns. Around them, Kibana provides alerting rules with connectors, reporting, Dev Tools for raw queries, Spaces for separating teams, and role-based access control down to index and field level.

Why this skill matters now

Most organisations that run Elasticsearch have far more people who need to read the data than people who can write a Query DSL request. Kibana is what closes that gap, which is why it is usually the most widely used component of the Elastic Stack and the one whose quality determines whether the whole investment is judged a success.

The skill in demand is not clicking through the chart wizard. It is knowing which visualisation honestly represents the question, writing KQL that narrows a billion documents before the aggregation runs, using filters and controls so one dashboard serves every team rather than spawning forty copies, and building drilldowns that carry context from an overview into raw documents. Those are the habits that make an incident dashboard usable at three in the morning.

There is also a governance dimension that surfaces the moment more than one team shares an instance. Spaces, saved-object management, role-based access down to field level, and exporting dashboards as objects that can be version-controlled are what stop a shared Kibana turning into an unmanaged sprawl nobody trusts.

Kibana training
# outcomes

What your team can do afterwards

Set up Kibana against an Elasticsearch cluster and create data views that expose the right fields with the right formatting
Investigate data in Discover — time ranges, field lists, document inspection, saved searches and column layouts
Write KQL fluently: field matching, wildcards, numeric and date ranges, boolean logic with parentheses, negation and existence checks
Choose the visualisation that answers the question honestly, and build it in Lens or the aggregation-based editors
Build time-series analysis with TSVB and Timelion, including offsets, splits and derived series
Compose dashboards with shared filters, controls, drilldowns and links so one dashboard serves many teams
Create alerting rules with connectors, and schedule reports and exports
Administer a shared Kibana: Spaces, saved-object management, role-based access control and version-controlled dashboards
# curriculum

8 modules. Live demos in a real lab, not slides.

01Kibana setup, data views and the gotchasLive & Interactive5 hrs · 2 assignments · 1 capstone

Getting Kibana connected and understanding what it is doing. Installation and the connection to Elasticsearch, kibana.yml, the saved-objects index, then data views — index patterns, the time field, field types and formatters — and the well-known gotchas that account for most first-week confusion.

Topics: Installing Kibana and connecting it to an Elasticsearch cluster · kibana.yml: the settings that matter · How Kibana stores saved objects, and why that index matters · Data views: index patterns, wildcards and the time field · Field types as Kibana sees them: keyword vs text, and what is aggregatable · Field formatters, custom labels and scripted versus runtime fields · Gotchas: missing time field, unanalysed vs analysed fields, no results for the right reason · Time range, refresh and the timepicker's effect on every query · Advanced settings worth changing on day one

  • Assignments: (1) Create data views for three indices, including one with a wildcard pattern; (2) Diagnose three searches that return nothing, each for a different structural reason
  • Capstone: Set up the Kibana and Elasticsearch lab pair you keep for the rest of the course, with documented data views
02Discover and investigationLive & Interactive5 hrs · 2 assignments · 1 capstone

Where real work starts. Navigating Discover, selecting and reordering fields, reading the field list and its value distribution, expanding documents, surrounding-document context, saved searches, and the workflow of narrowing from millions of events to the handful that explain an incident.

Topics: The Discover interface and the document table · Selecting fields, column order and table density · The field list, top values and quick visualise · Expanding a document: table view and JSON view · Viewing surrounding documents and single-document context · Saved searches and reusing them as dashboard panels · Sorting, sampling and the document limit · Exporting results to CSV · An investigation workflow from symptom to root-cause documents

  • Assignments: (1) Narrow a full index to the ten documents that explain a stated failure; (2) Build three saved searches your team would use weekly
  • Capstone: Document an end-to-end investigation in Discover that someone else could reproduce step by step
03Querying and filteringLive & Interactive5 hrs · 2 assignments · 1 capstone

The language layer under every panel. KQL in depth — matching, wildcards, ranges, boolean operators, parentheses and negation, existence and null checks — then Lucene syntax for what KQL does not express, filter pills including custom DSL filters, and the difference between a query and a filter in how results are cached.

Topics: Basic text queries in KQL: free text vs field-scoped · Field matching, quoting and case behaviour · Boolean operators, NOT and parentheses · Querying numbers and dates with range syntax · Querying with wildcards, and what wildcards cost · Querying for nulls and the existence of a value · Lucene query syntax and when to switch to it · Filter pills: add, edit, negate, disable, pin · Custom DSL filters for anything the UI cannot express · Query vs filter: scoring, caching and performance · Saving queries and sharing them across dashboards

  • Assignments: (1) Answer twelve written questions in KQL, then rewrite three as filters and explain the difference; (2) Build a custom DSL filter for a condition the filter editor cannot express
  • Capstone: Produce a query and filter library for one dataset that the rest of the team reuses
04Visualising dataLive & Interactive5 hrs · 2 assignments · 1 capstone

Turning a query into a chart that tells the truth. The visualisation editors and how the aggregation model maps onto a chart — metrics on one axis, buckets on the other. Line graphs from first creation through options, metrics and saving; then tables, pie charts, gauges and single-metric panels, and the rules for choosing between them.

Topics: The visualisation model: metrics, buckets and how they map to a chart · Creating a line graph and configuring its options · Line graph metrics: count, average, sum, percentile, unique count · Bucket aggregations: date histogram, terms, filters, ranges · Split series and split charts · Saving, reusing and duplicating visualisations · Grids and data tables · Pie and donut charts, and when they mislead · Gauge charts and goal panels · Metric and single-value panels · Lens: drag-and-drop building and switching chart types · Choosing the honest visualisation for a given question

  • Assignments: (1) Build the same question as four different chart types and argue for one; (2) Rebuild a misleading chart so it represents the data honestly
  • Capstone: Produce a visualisation set for one dataset where each chart answers a distinct, stated question
05DashboardsLive & Interactive5 hrs · 2 assignments · 1 capstone

Composing panels into something a team relies on. Creating dashboards, layout and panel sizing, applying filters and queries at dashboard level, controls that let readers slice without editing, drilldowns between dashboards and into Discover, time synchronisation, sharing and embedding, and dashboard performance.

Topics: Creating a new dashboard and adding existing or new panels · Layout, panel sizing and reading order · Dashboard-level query and filter bar; pinned filters · Controls: options lists, range sliders and time slider · Drilldowns: dashboard-to-dashboard and dashboard-to-Discover · URL drilldowns to external systems · Panel-level time ranges and per-panel options · Saving, cloning and organising dashboards · Sharing: links, embed code, snapshots and permalinks · Dashboard performance: panel count, time range and aggregation cost · Designing for on-call versus designing for reporting

  • Assignments: (1) Convert three near-identical dashboards into one with controls; (2) Build a drilldown path from an overview panel to the raw documents behind it
  • Capstone: Deliver an operational dashboard that a new on-call engineer can use without a briefing
06Time-series analysis with TSVB and TimelionLive & Interactive5 hrs · 2 assignments · 1 capstone

The tools built for time. TSVB for time-series visual builder panels with derived series and annotations, then Timelion and its expression language: the syntax, offsets for comparing a period against a prior one, splits for breaking a series by a field, and the arithmetic and transformation functions.

Topics: TSVB: time series, metric, top N, gauge and markdown panel types · TSVB aggregations, series options and annotations · Derived series: derivative, cumulative sum, moving average, math · Introduction to Timelion and its expression syntax · Timelion data sources and the .es() function · Timelion offsets: comparing this week with last week · Timelion split by field and multiple series · Timelion transformation functions: derivative, movingaverage, trend, scale · Styling, labels and conditional formatting in Timelion · Choosing between Lens, TSVB and Timelion for a given question

  • Assignments: (1) Build a week-over-week comparison chart using Timelion offsets; (2) Use a TSVB derived series to show rate of change rather than raw counts
  • Capstone: Deliver a time-series analysis panel set that shows trend, comparison and anomaly for one metric
07Alerting, reporting, Maps and CanvasLive & Interactive5 hrs · 2 assignments · 1 capstone

Getting output out of Kibana. Alerting rules and their evaluation model, connectors to email, Slack, webhook and ticketing systems, rule management and muting; then reporting and scheduled exports, geospatial work in Maps, and Canvas for presentation-grade output built from live queries.

Topics: Kibana alerting: rule types, conditions and evaluation schedule · Threshold rules on index data and on Elasticsearch queries · Actions, connectors and action frequency · Rule management: enabling, muting, snoozing and troubleshooting · Alerting on log and metric thresholds · Reporting: PDF and PNG generation, CSV export · Scheduled reports and the reporting queue · Maps: layers, geo fields, clustering and choropleths · Canvas: elements, expressions and live data in a presentation · Choosing between a dashboard, a report and an alert for a given need

  • Assignments: (1) Build an alert rule with a connector and prove it fires and recovers correctly; (2) Build a Maps layer that shows geographic distribution of a real dataset
  • Capstone: Deliver an alert pack plus a scheduled report for one dataset, each with a documented owner
08Administration, Spaces and Kibana as codeLive & Interactive5 hrs · 2 assignments · 1 capstone

Running Kibana for an organisation rather than a person. Dev Tools for raw queries and diagnostics, saved-object management including export and import, Spaces for separating teams, role-based access control down to index and field level, upgrade considerations, and putting dashboards under version control.

Topics: Dev Tools console: running Query DSL directly and reading responses · Grok debugger, painless lab and the search profiler · Saved objects: browsing, editing, exporting and importing · Resolving broken saved-object references after a data view change · Spaces: creating them and scoping saved objects per team · Role-based access control: Kibana privileges, index privileges, field and document-level security · Users, roles and integration with an identity provider · Stack Management: index management, index lifecycle policies and data views · Monitoring Kibana and Elasticsearch from the Stack Monitoring UI · Dashboards as code: exporting NDJSON and deploying through CI · Upgrade considerations and saved-object migrations

  • Assignments: (1) Export a Space's saved objects, wipe it, and restore from the export; (2) Configure a role that can view one team's dashboards but not another's data
  • Capstone: Deliver a shared Kibana with Spaces, roles and a Git-backed dashboard deployment process

Need this mapped to your stack?

We rebuild the agenda around the tools you actually run.

Request a custom agenda
# hands-on

Labs and capstones your engineers actually build

LAB · DISCOVER

From a billion documents to ten

Work a real incident in Discover: narrow by time, add KQL and filters, inspect field distributions and document context, and end with the documents that explain the failure.

discoverkqlinvestigation
LAB · KQL

Twelve questions, one query bar

Translate twelve written questions into KQL using wildcards, ranges, parentheses, negation and null checks, then convert three to filters and measure the difference.

kqllucenefilters
LAB · CHARTS

Four charts, one truth

Build the same question as a line graph, table, pie chart and gauge, then argue which one is honest and rebuild a misleading chart from an existing dashboard.

visualisationslenschart choice
LAB · DASHBOARDS

One dashboard, every team

Collapse three near-duplicate dashboards into one driven by controls, add drilldowns into Discover, and cut its load time by restructuring the panel queries.

dashboardscontrolsdrilldowns
LAB · TIMELION

This week against last week

Use Timelion offsets, splits and moving averages to build a comparison view, then reproduce the same analysis in TSVB and compare the two approaches.

timeliontsvboffsets
CAPSTONE · SHARED KIBANA

Spaces, roles and dashboards in Git

Stand up a multi-team Kibana with Spaces and field-level access control, export every saved object as NDJSON, and deploy it into a clean instance through CI.

spacesrbacsaved objects
# ecosystem

The tools Kibana sits next to

Elasticsearch
Logstash
Beats
Filebeat
Metricbeat
Elastic APM
OpenSearch Dashboards
Grafana
Kafka
Docker
Kubernetes
Fluentd

Who this is for

  • Operations and support engineers who triage incidents from log dashboards
  • SREs and DevOps engineers building the views their teams rely on during an incident
  • Security analysts investigating events held in Elasticsearch indices
  • Business and data analysts reporting on data they do not own the pipeline for
  • Developers who need to read application logs and traces without a database client
  • Platform owners administering a shared Kibana across multiple teams

Pre-requisites

  • Comfortable in a browser-based analytics tool, and able to read a log line and say what its fields mean
  • Basic understanding of Elasticsearch concepts: index, document, field, time field
  • Familiarity with JSON, since Dev Tools and custom filters use it directly
  • Some query-language exposure — SQL, Lucene or anything similar — is helpful but not required
  • Access to an Elasticsearch and Kibana instance, local or free-tier cloud, with real data in it
# pricing

Straightforward pricing

Every plan includes 1 year of full LMS access — not just this course, the entire DevOpsSchool LMS: 20+ courses, 50+ tools, videos, quizzes, assignments and projects.

Self-paced video

₹833/mo

Billed yearly at ₹9,996

Enroll now

1-on-1 mentorship

₹99,999

Full program, private instructor

Enroll 1-on-1

Corporate / private batch

8–30 engineers · custom agenda · onsite or online · PO and GST invoicing

Get a custom quote

Refunds. If we cancel or postpone a cohort, you get a full refund within 15 days. There is no money-back guarantee otherwise.

Terms. Course material remains licensed to the attendee. Read the terms.

Your data. We don't share it with third parties. Privacy policy.

Every attendee gets a verifiable certificate

  • Issued per attendee on completion
  • Verifiable at devopsschool.com/certificates
  • Hard copy available on request
  • Corporate batches receive an attendance and assessment report
DevOpsSchool

Kibana Training

Certificate of completion

# feedback

What engineers say

4.4 / 5 from 26 reviews on Trustpilot.

★★★★★
Basics explanation was exemplary from Rajesh where he dealt with complicated topics to be simple. Great learning stuff personally for me.
Krishna Mohan Yelleti · Trustpilot
★★★★★
Very detailed explanation and has lots of patience in attending the questionnaire. Thanks again for your wonderful sessions.
Uttam Samudrala · Trustpilot
★★★★★
Good discussion, helped us to understand different tools in SRE.
Prashant Saxena · Trustpilot
★★★★★
Got good lab sessions which kept the new DevOps tool learnings to the point and it helped a lot in my career.
robin son · Trustpilot
★★★★★
I took Terraform training with the tutor named Mithilesh. I requested to tailor the course curriculum for my needs. He did an excellent job of showing me how to write the Terraform script per the instructions provided.
jason smith · Trustpilot
★★★★★
My experience with the AIOps training was positive. The course covered important topics in a structured way, and Rajesh Kumar explained the concepts patiently. I found the practical aspects particularly helpful because they made the technical content easier to understand.
AARTI KUMARI · Trustpilot
# comparison

Why a named practitioner beats a marketplace listing

What mattersYouTube + blogsGeneric online courseFreelance marketplaceDevOpsSchool
Named practitionerNoRarelyVaries per bookingYes — same trainer each time
Production experienceUnknownUnknownUnverified20 years, named employers
Custom agendaNoNoSometimesBuilt from your stack
Onsite deliveryNoNoSometimesYes
Lab environmentNoneSandbox that expiresVariesYour own cloud — skill goes with you
AssessmentNoneQuizRarelyAssignments + capstone per module
Per-attendee certificatesNoSometimesRarelyYes
Corporate invoicingNoLimitedVariesPO and GST
Post-training supportNoneForum, time-limitedNoneLifetime forum access
# questions

Frequently asked

Can the agenda be customised for our stack?
Yes — that is the normal case for a private batch. We start with a discovery call, look at the indices, data views and use cases you actually have, and rebuild the module list around them. Labs then run against your data rather than a sample set.
Do you deliver onsite?
Yes. Private batches run onsite at your premises, live online, or hybrid. You provide the room and the engineers; we bring the trainer, agenda, labs, assessment and certificates.
What lab environment do we need?
Attendees provision their own environment — free-tier AWS, Azure or GCP, or local VMs running Elasticsearch and Kibana — and we walk them through it. We deliberately do not hand out temporary sandboxes, because the environment they build is the one they keep.
How is this different from your Elasticsearch course?
This course is about the query and visualisation experience: Discover, KQL, Lens, TSVB, Timelion, dashboards, alerting and Spaces. The Elasticsearch course is about the engine underneath — mapping, analysis, the Query DSL, aggregations and cluster operations. People who consume the data take this one; people who run the cluster take that one.
Do we need to know Elasticsearch first?
Only the vocabulary — index, document, field, time field. We cover what Kibana needs you to understand about the engine, particularly which field types are aggregatable and why an analysed field behaves differently in a chart. Deeper engine work is the Elasticsearch course.
How long does a private Kibana batch take?
Typically two to three days. Data views, Discover, KQL and core visualisations fit in two; adding dashboards with controls and drilldowns, TSVB and Timelion, alerting, Spaces and access control makes three.
What size are batches?
Private corporate batches run 8 to 30 engineers. Public Live & Interactive cohorts are capped at 10 so everyone gets time with the trainer.
Do attendees get a certificate?
Yes — every attendee receives a completion certificate, verifiable at devopsschool.com/certificates. Corporate batches also receive an attendance and assessment report.
Does this cover OpenSearch Dashboards?
Substantially, yes. Discover, the aggregation-based visualisations, dashboards and Dev Tools are close to identical; we call out where the two have diverged, particularly around Lens, alerting and the newer Elastic-only features.
Our dashboards are slow. Is that addressed?
Directly. Dashboard performance is a query problem, not a rendering problem, so we cover narrowing with KQL and filters before aggregation, panel count, time range defaults, terms cardinality and per-panel time ranges — with before-and-after measurements in the lab.
What is your refund position?
If we cancel or postpone a cohort, you receive a full refund within 15 days. There is no general money-back guarantee, and GST and gateway fees are not refunded.

Still deciding?

Tell us the team, the stack and the timeline. You'll get a straight answer, not a sales sequence.

Talk to an advisor
# ready when you are

Book a Kibana trainer — or ask a question first.

  • No spam, no drip sequence
  • Syllabus in 60 seconds
  • A human reply within one business day

Prefer to call or email?

More ways to reach us on the contact page.

Talk to an advisorRequest a quote