2. Purpose
Centralized Log Management
◦ Collect, Parse and Filter using Logstash
◦ Store, Index and Search using Elasticsearch
◦ Visualize using Kibana
Full open source stack
◦ Use for free
◦ Support plan from Elasticsearch company
3. Elasticsearch
Real-time search engine
◦ Based on Apache Solr/Lucene
◦ Pure Java
◦ Document database
◦ Advanced text indexing
◦ Fuzzy search
◦ Replication/Sharding for true scalability
4. Logstash
JRuby Based log processor
Pluggable event pipeline
◦ Input plugins
◦ Filter plugins
◦ Codec plugins
◦ Output plugins
DevOps Comunity
◦ Mix of developers, operations and system administrators
5. Kibana
Browser based dashboard for ElasticSearch
Visualization of query results
◦ Time Charts
◦ Filter any field
◦ Compare subsets
7. Logstash not just for logs
Interpretes different log formats
◦ Syslog messages
◦ Log4j with full details
◦ Apache log files
Other event types too
◦ Ganglia server monitoring events
◦ SNMP events
◦ Windows EventLog
Pre-proces before sending
◦ lumberjack