Logging / Search
ELK Stack
A common logging stack built from Elasticsearch, Logstash, and Kibana for collecting, indexing, searching, and visualizing logs.
Problem it solves
Why it exists.
It solves the challenge of finding the story across distributed application and infrastructure logs.
Optimized for
Where it shines.
Centralized log ingestion, full-text search, dashboards, and incident investigation across many services.
Use with care
Where not to use it.
Do not use it as a replacement for metrics or traces, and do not ingest everything without retention, cost, and privacy controls.
Components
What it is made of.
- Beats or shippers
- Logstash
- Elasticsearch
- Kibana
- Index lifecycle policy
Process
How it works.
- Agents collect and forward events
- Logstash parses and enriches records
- Elasticsearch indexes the documents
- Kibana searches and visualizes the result