Skip to content

ELK Stack

What It Is

ELK usually means Elasticsearch, Logstash, and Kibana. It is often extended with Beats.

Component Roles

  • Elasticsearch stores and indexes data
  • Logstash processes and transforms the stream
  • Kibana visualizes and searches

Practice

  • Logging without normalized fields and a retention policy quickly becomes expensive and hard to use.