A production-shaped source baseline
Three Elasticsearch data streams, four ingest pipelines, ILM, six Kibana dashboards, Elastic APM, and sixteen instrumented services generating traffic.
ClickHouse Chuỗi Di chuyển
Dựng nguồn Elasticsearch, ghi logs, traces và metrics trực tiếp song song vào ClickHouse Cloud, chứng minh hai hệ thống khớp nhau, rồi dừng Elasticsearch với ClickStack là giao diện observability duy nhất.
Not a reindex. A controlled systems change.
Copying documents is the easy part. The real migration is replacing data streams, mappings, ILM, ingest pipelines, Kibana dashboards, and alert rules without losing the signals operators rely on.
This workshop gives you two live workloads: Filebeat shipping three log formats, and the OpenTelemetry Demo sending traces, metrics, and logs from sixteen microservices through Elastic APM. You inspect the system before designing its replacement.
The cutover is evidence-driven. Two OpenTelemetry Collectors fan the same events into Elasticsearch and ClickHouse Cloud while validation scripts compare counts, schemas, enrichment, and freshness.
Only after the parity gate passes do you remove the Elasticsearch exporters and stop the old stack. HyperDX then becomes the single UI for search, dashboards, traces, metrics, alerts, and AI-assisted investigation.
What you walk away with
A realistic source, an optimized ClickHouse target, and a cutover decision backed by live measurements.
Three Elasticsearch data streams, four ingest pipelines, ILM, six Kibana dashboards, Elastic APM, and sixteen instrumented services generating traffic.
MergeTree sort keys chosen from access patterns, flexible OTel attributes kept in Map, and hot fields promoted to typed materialized columns.
A Null → materialized view → MergeTree path with IP_TRIE dictionaries, materialized enrichment columns, TTL, text indexes, and summary tables.
File and OTLP collectors dual-write every signal to both backends while automated checks compare live counts and verify GeoIP, severity, and parsed fields.
HyperDX sources for logs, traces, and all five metrics tables, plus recreated dashboards, saved searches, alerts, and an AI-assisted chart.
Five query translations, a seven-decision ADR, six advanced SQL exercises, and a scenario-based assessment focused on trade-offs rather than commands.
What replaces what
The route · 4–6 hours hands-on
Build the baseline, make the design decisions, run both systems together, and remove the old backend only when the evidence says it is safe.
Install Docker, the ClickHouse client, curl and jq; choose local or EC2 for the source; create the ClickHouse Cloud account; and verify every artifact.
Start Elasticsearch, Kibana, Filebeat, Elastic APM Server, three log generators, and the OpenTelemetry Demo, then capture a growing-data baseline.
Inspect mappings, data streams, pipelines, lifecycle rules, and query latency; translate five queries; then write the target schema and migration ADR.
Provision ClickHouse, create dictionaries and tables, start dual-write, validate parity, configure HyperDX, test TTL and summaries, migrate alerts, and cut over.
Complete fifteen multiple-choice questions and five open scenarios covering schema, migration planning, debugging, and alerting trade-offs.
Self-paced by default. The source created in module 01 stays live through module 03. Never stop Elasticsearch until both parity scripts pass and the collector cutover configs are ready.
Before you join
Bring a ClickHouse Cloud trial and a machine that can run the source stack. Leave with every Elasticsearch subsystem mapped, three live signals validated in parallel, and a rollback-aware cutover you can explain.