Skip to content
EduVerse
ELK Stack

ELK Stack

In depth

Monitoring

Also known as: Elastic Stack, Elasticsearch-Logstash-Kibana

Elasticsearch, Logstash and Kibana combined to collect, store and visualise logs.

ELK Stack, explained

Written by EduVerse

What it is

The ELK Stack is a combination of three tools that handle logs together. Logstash collects and reshapes log lines, Elasticsearch stores and indexes them for fast search, and Kibana is the web interface where you search and build charts. Small shippers such as Filebeat often feed the logs in.

Why teams use it

When an app runs on many servers or containers, reading log files one machine at a time is hopeless, and containers may be gone before you look. Central logging puts everything in one searchable place, so you can follow a single request across services and spot patterns in errors.

An example from work

A customer reports that their payment failed around 14:05. In Kibana you filter on that time window and the customer’s order id, and find a timeout from the payment service followed by a retry that never happened. Without central logs you’d be logging into servers one by one.

Our own explanation, not a quote from the book.

In the book

Sentences from The Software Realm, Decoded that mention ELK Stack, exactly as printed.

    1 more passages about ELK Stack in the full book

    Read every conversation where ELK Stack comes up, with the interactive slides and demos.

    See the book

    Where it fits

    Centralised log management and analysis

    Coverage in the book

    In depth

    Covered in depth: multiple pages with explanations, examples and simulations.

    Appears in