SlideShare a Scribd company logo
DEEP DIVE INTO ELASTICSEARCH
Establish A Powerful Log Analysis System
With Elastic Stack.
On Premises vs SaaS Elastic Stack
Comparisons.
Tyler
DevOps Engineer
NFQ Asia Company
Agenda
• Intro.
• Overview: Elastic Stack.
• Establish a powerful log analysis system with Elastic Stack.
• Elastic stack options from cloud providers.
• Which one would be fit for us?
• Cost Reflections.
• In conclusion.
About Me
• In tech for 7+ years.
• Technical Project Coordinator @ AVASO Technology Solutions.
• Infrastructure Technical Lead @ Betfair Group PLC.
• DevOps Engineer @ NFQ Asia.
• Member of Vietnam Elasticsearch Community.
• Bash/PowerShell languages.
• A dog parent :D
About NFQ Asia
• Member of NFQ Company.
• 15+ years’ experience in e-business
strategy and software development
• 300+ professionals.
• 4 countries: offices in Lithuania,
Germany, Vietnam, Singapore.
• Founded in Vietnam since 2015.
• Having organized 5 community
events/hackathons in Vietnam.
DATA
Cost
Operations
Features
Platforms
Plugins
Capability
Mapping
Processors
Aggregations
APIs
Monitoring
Security
Encryption
Supports
Backup
Database
Searching
Analytics
ComplexityArchitecture
APIsFlexibility
Availability
Compatibility
Centralization
Elasticsearch is everywhere
What is Elastic Stack?
• Formerly known as ELK Stack.
• ELK - The acronym for three open source
projects: elasticsearch, logstash, and kibana.
• Distributed, scalable, and highly available
(both on premises or SaaS).
• The Elastic Stack is the next evolution of ELK.
• Supports the lightweight Beats data shippers
from ES v2.1.1.
Elasticsearch
• “You know, for Search”
• Free, Open Source.
• Search engine based on Lucene.
• Near real-time searching, analytics and
visualization capabilities.
• Sophisticated Restful API.
Logstash
• Open source data collection engine that unifies
data from disparate sources, normalizes it and
distributes it.
• The ingestion workhorse for elasticsearch and
more.
• Real-time capabilities and pluggable pipeline
architecture.
• Community-extensible and developer-friendly
plugin ecosystem.
Kibana
• Open source analytics and visualization
platform designed to work with elasticsearch.
• Specialized for large volumes of streaming and
real-time data.
• No code, no additional infrastructure required.
• Easily and quickly understandable through
graphic representation.
Beats Platform
• “Data shippers” that are installed on servers
as agents.
• Either elasticsearch directly or through
logstash.
• Library written based on Golang.
• Supports create your own beat for specific
use cases.
ESTABLISH A POWERFUL LOG ANALYSIS
SYSTEM WITH ELASTIC STACK
Rationale
• What is log?
• How do we solve the production issue as usual?
• How much time do you spend investigating the
production issue?
• Where are the archived log?
• Visualization and dashboards?
The Challenge
How do you satisfy the search needs of the application system’s over 2,000 docs
per second while simultaneously providing tactical operational insights that help
both Development Team and Operation Team iteratively improve the customer
experience?
The Simple Log Analysis Diagram
Demonstration
Scalability Rationale
• High availability.
• Petabyte-scale data is written and/or read frequently.
• High scalability.
• Sufficient data allocation.
• Costs.
The Elasticsearch Hot-Warm Architecture
The Elasticsearch Hot-Warm Architecture (cont.)
ON PREMISES VS SaaS ELASTIC STACK
COMPARISONS
WHAT IS AWS ELASTICSEARCH
SERVICE?
• Managed service in AWS Cloud.
• Introduced in Oct 2015.
• Fully managed; Zero admin.
• Highly available and reliable.
• Built-in Kibana support.
• Integrated with other services in AWS ecosystem.
The AWS Integration
What is Elastic Cloud?
• Launched in Oct 2015.
• Provided by Elastic.
• High provisioning and scaling.
• Hosted in the Cloud Providers.
• Service-oriented architecture.
• Containerization using Docker.
• Fully supports custom plugins and API.
Elastic Cloud Architecture
HOW DO I KNOW WHICH ONE IS FIT
WITH ME?
Specifications comparison sheet
Self-managed Elastic Stack AWS Elasticsearch Service Elastic Cloud Enterprise
Pros
More options and features.
Complete control settings and
capacity.
Access to other APIs
Comprehensive ES monitoring
solutions.
Lowest costs.
SaaS.
Simplify the operations via APIs.
Security by IAM.
Automated snapshots*.
Encryption at rest.
Monitoring included*.
Technical supported.
SaaS.
Fully control through APIs.
Technical Supported.
Uptime SLA.
Feature-rich and complete
monitoring product.
Available on Marketplace.
Cons
Self maintenance.
Infrastructure matters.
No technical supported.
X-Pack limit features.
Limited control.
Less capacity and scalability.
Backup once time per day.
No plugins, no logs.
Medium expensive.
Only support I2 series EC2
instances.
Most expensive.
Imperfect for AWS-hosted
solutions.
Deep Dive Into Elasticsearch: Establish A Powerful Log Analysis System With Elastic Stack | On Premises vs SaaS Elastic Stack Comparisons.
Costs Comparison Chart
8,400.38 10,678.56 11,512.51
75,303.17
81,375.17
11,316.98 14,500.26
25,201.1525,201.15
32,035.68 34,537.54
203,318.55
219,712.95
28,319.95
38,295.63
50,402.30
0
50,000
100,000
150,000
200,000
250,000
Elastic Stack (AWS) Elastic Stack (GCP) AWS Elasticsearch Services Elastic Cloud (GCP) Elastic Cloud (AWS)
Cost($)
Service Models
One Year One Year (All Upfront) Three Years Three Years (All Upfront)
*Costs calculated based on 3TB-data cluster in multi-AZ in
Frankfurt region
In Conclusion
• Elasticsearch leverage the power of analysis ability for both Dev/Ops teams.
• Easily operate/maintain the huge cluster of servers and microservices.
• Choose the proper architecture depend on application/system.
• Estimate the budget to meet the requirements.
• Optimize the aggregation to adopt the resources.
• High availability oriented system.
We are hiring…
• Java Senior/Lead Developer
• PHP Senior Developer
• PHP Technical Lead
• Front-end Senior Developer
• Front-end Technical Lead
• Technical Project Manager
Simply send us an email with your enclosed
updated CV to: career@nfq.asia
Contact Me
LinkedIn: linkedin.com/in/tylernguyen91
Email: tai.nguyen@nfq.asia
Telegram: @tylern91

More Related Content

PPTX
Monitor Azure Kubernetes Cluster With Prometheus by Mamta Jha
PPTX
Live Application and Infrastructure Monitoring and Root Cause Log Analysis wi...
PDF
WSO2Con USA 2017: Building an Effective API Architecture
 
PPTX
50 Shades of Data - how, when and why Big,Relational,NoSQL,Elastic,Event,CQRS...
PPTX
Cloudtrek Basics Overview
PDF
IoT and Serverless - AWS - Serverless Summit - Madhusudan Shekar
PDF
The Workshop: Alcanzando una observabilidad unificada con Elastic APM
PDF
Effective AIOps with Open Source Software in a Week
Monitor Azure Kubernetes Cluster With Prometheus by Mamta Jha
Live Application and Infrastructure Monitoring and Root Cause Log Analysis wi...
WSO2Con USA 2017: Building an Effective API Architecture
 
50 Shades of Data - how, when and why Big,Relational,NoSQL,Elastic,Event,CQRS...
Cloudtrek Basics Overview
IoT and Serverless - AWS - Serverless Summit - Madhusudan Shekar
The Workshop: Alcanzando una observabilidad unificada con Elastic APM
Effective AIOps with Open Source Software in a Week

What's hot (20)

PDF
Project Sherpa: How RightScale Went All in on Docker
PPTX
Reducing MTTR and False Escalations: Event Correlation at LinkedIn
PPTX
Opening the Outage Door: Integrating OMS into CIS
PPTX
[Webinar] AWS Monitoring with Site24x7
PDF
Azure Application insights - An Introduction
PPTX
SharePoint best practices
PPTX
Couchbase Connect 2016: Monitoring Production Deployments The Tools – LinkedIn
PPTX
APRICOT 2017: Trafficshifting: Avoiding Disasters & Improving Performance at ...
PDF
RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...
PDF
SignalR 101
PPTX
GAB 2017 - Logic Apps and Azure Functions
PPTX
Monitoring Containerized Application in Alibaba Cloud
PPTX
Couchbase Connect 2016
PDF
Orchestrating Cloud Workloads with RightScale Self-Service
PDF
Mastering Azure Monitor
PDF
David Max SATURN 2018 - Migrating from Oracle to Espresso
PDF
Stateful Interaction In Serverless Architecture With Redis: Pyounguk Cho
PDF
Master thesis
PPTX
Using SaltStack to Auto Triage and Remediate Production Systems
PDF
Serverless for visual journalism at the bbc
Project Sherpa: How RightScale Went All in on Docker
Reducing MTTR and False Escalations: Event Correlation at LinkedIn
Opening the Outage Door: Integrating OMS into CIS
[Webinar] AWS Monitoring with Site24x7
Azure Application insights - An Introduction
SharePoint best practices
Couchbase Connect 2016: Monitoring Production Deployments The Tools – LinkedIn
APRICOT 2017: Trafficshifting: Avoiding Disasters & Improving Performance at ...
RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...
SignalR 101
GAB 2017 - Logic Apps and Azure Functions
Monitoring Containerized Application in Alibaba Cloud
Couchbase Connect 2016
Orchestrating Cloud Workloads with RightScale Self-Service
Mastering Azure Monitor
David Max SATURN 2018 - Migrating from Oracle to Espresso
Stateful Interaction In Serverless Architecture With Redis: Pyounguk Cho
Master thesis
Using SaltStack to Auto Triage and Remediate Production Systems
Serverless for visual journalism at the bbc
Ad

Similar to Deep Dive Into Elasticsearch: Establish A Powerful Log Analysis System With Elastic Stack | On Premises vs SaaS Elastic Stack Comparisons. (20)

PDF
Elastic.co's ELK Stack - Platform Agnostic Immutable Infrastructure & Analys...
PDF
Regina Pison - Elastic - OSL19
PPTX
Elastic Stack Introduction
PPTX
Open source log analytics
PPTX
Elastic Search Capability Presentation.pptx
PPTX
Serhii Matynenko "How to Deal with Logs, Migrating from Monolith Architecture...
PPTX
ELK Solutions Enablement Session - 17th March'2020
PPTX
Intro elasticsearch taswarbhatti
PPTX
Elasticsearch features and ecosystem
PPTX
Log analysis using Logstash,ElasticSearch and Kibana
PPTX
Log analysis using Logstash,ElasticSearch and Kibana - Desert Code Camp 2014
PDF
Roaring with elastic search sangam2018
PPTX
Devteach 2017 Store 2 million of audit a day into elasticsearch
PDF
Log Analytics with AWS
PDF
Elastic{ON} Seminar New York (2017)
PDF
Growing with elastic search
PDF
Eko10 - Security Monitoring for Big Infrastructures without a Million Dollar ...
PPTX
Elastic stack Presentation
PDF
Analyzing your web and application logs with the Amazon Elasticsearch Service...
PDF
Log analysis with the elk stack
Elastic.co's ELK Stack - Platform Agnostic Immutable Infrastructure & Analys...
Regina Pison - Elastic - OSL19
Elastic Stack Introduction
Open source log analytics
Elastic Search Capability Presentation.pptx
Serhii Matynenko "How to Deal with Logs, Migrating from Monolith Architecture...
ELK Solutions Enablement Session - 17th March'2020
Intro elasticsearch taswarbhatti
Elasticsearch features and ecosystem
Log analysis using Logstash,ElasticSearch and Kibana
Log analysis using Logstash,ElasticSearch and Kibana - Desert Code Camp 2014
Roaring with elastic search sangam2018
Devteach 2017 Store 2 million of audit a day into elasticsearch
Log Analytics with AWS
Elastic{ON} Seminar New York (2017)
Growing with elastic search
Eko10 - Security Monitoring for Big Infrastructures without a Million Dollar ...
Elastic stack Presentation
Analyzing your web and application logs with the Amazon Elasticsearch Service...
Log analysis with the elk stack
Ad

Recently uploaded (20)

PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Cloud computing and distributed systems.
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Approach and Philosophy of On baking technology
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
 
PDF
Machine learning based COVID-19 study performance prediction
PPTX
A Presentation on Artificial Intelligence
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
NewMind AI Weekly Chronicles - August'25 Week I
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Cloud computing and distributed systems.
NewMind AI Monthly Chronicles - July 2025
Encapsulation_ Review paper, used for researhc scholars
Unlocking AI with Model Context Protocol (MCP)
Building Integrated photovoltaic BIPV_UPV.pdf
Encapsulation theory and applications.pdf
Approach and Philosophy of On baking technology
MYSQL Presentation for SQL database connectivity
Diabetes mellitus diagnosis method based random forest with bat algorithm
Per capita expenditure prediction using model stacking based on satellite ima...
Understanding_Digital_Forensics_Presentation.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
 
Machine learning based COVID-19 study performance prediction
A Presentation on Artificial Intelligence

Deep Dive Into Elasticsearch: Establish A Powerful Log Analysis System With Elastic Stack | On Premises vs SaaS Elastic Stack Comparisons.

  • 1. DEEP DIVE INTO ELASTICSEARCH Establish A Powerful Log Analysis System With Elastic Stack. On Premises vs SaaS Elastic Stack Comparisons. Tyler DevOps Engineer NFQ Asia Company
  • 2. Agenda • Intro. • Overview: Elastic Stack. • Establish a powerful log analysis system with Elastic Stack. • Elastic stack options from cloud providers. • Which one would be fit for us? • Cost Reflections. • In conclusion.
  • 3. About Me • In tech for 7+ years. • Technical Project Coordinator @ AVASO Technology Solutions. • Infrastructure Technical Lead @ Betfair Group PLC. • DevOps Engineer @ NFQ Asia. • Member of Vietnam Elasticsearch Community. • Bash/PowerShell languages. • A dog parent :D
  • 4. About NFQ Asia • Member of NFQ Company. • 15+ years’ experience in e-business strategy and software development • 300+ professionals. • 4 countries: offices in Lithuania, Germany, Vietnam, Singapore. • Founded in Vietnam since 2015. • Having organized 5 community events/hackathons in Vietnam.
  • 7. What is Elastic Stack? • Formerly known as ELK Stack. • ELK - The acronym for three open source projects: elasticsearch, logstash, and kibana. • Distributed, scalable, and highly available (both on premises or SaaS). • The Elastic Stack is the next evolution of ELK. • Supports the lightweight Beats data shippers from ES v2.1.1.
  • 8. Elasticsearch • “You know, for Search” • Free, Open Source. • Search engine based on Lucene. • Near real-time searching, analytics and visualization capabilities. • Sophisticated Restful API.
  • 9. Logstash • Open source data collection engine that unifies data from disparate sources, normalizes it and distributes it. • The ingestion workhorse for elasticsearch and more. • Real-time capabilities and pluggable pipeline architecture. • Community-extensible and developer-friendly plugin ecosystem.
  • 10. Kibana • Open source analytics and visualization platform designed to work with elasticsearch. • Specialized for large volumes of streaming and real-time data. • No code, no additional infrastructure required. • Easily and quickly understandable through graphic representation.
  • 11. Beats Platform • “Data shippers” that are installed on servers as agents. • Either elasticsearch directly or through logstash. • Library written based on Golang. • Supports create your own beat for specific use cases.
  • 12. ESTABLISH A POWERFUL LOG ANALYSIS SYSTEM WITH ELASTIC STACK
  • 13. Rationale • What is log? • How do we solve the production issue as usual? • How much time do you spend investigating the production issue? • Where are the archived log? • Visualization and dashboards?
  • 14. The Challenge How do you satisfy the search needs of the application system’s over 2,000 docs per second while simultaneously providing tactical operational insights that help both Development Team and Operation Team iteratively improve the customer experience?
  • 15. The Simple Log Analysis Diagram
  • 17. Scalability Rationale • High availability. • Petabyte-scale data is written and/or read frequently. • High scalability. • Sufficient data allocation. • Costs.
  • 19. The Elasticsearch Hot-Warm Architecture (cont.)
  • 20. ON PREMISES VS SaaS ELASTIC STACK COMPARISONS
  • 21. WHAT IS AWS ELASTICSEARCH SERVICE? • Managed service in AWS Cloud. • Introduced in Oct 2015. • Fully managed; Zero admin. • Highly available and reliable. • Built-in Kibana support. • Integrated with other services in AWS ecosystem.
  • 23. What is Elastic Cloud? • Launched in Oct 2015. • Provided by Elastic. • High provisioning and scaling. • Hosted in the Cloud Providers. • Service-oriented architecture. • Containerization using Docker. • Fully supports custom plugins and API.
  • 25. HOW DO I KNOW WHICH ONE IS FIT WITH ME?
  • 26. Specifications comparison sheet Self-managed Elastic Stack AWS Elasticsearch Service Elastic Cloud Enterprise Pros More options and features. Complete control settings and capacity. Access to other APIs Comprehensive ES monitoring solutions. Lowest costs. SaaS. Simplify the operations via APIs. Security by IAM. Automated snapshots*. Encryption at rest. Monitoring included*. Technical supported. SaaS. Fully control through APIs. Technical Supported. Uptime SLA. Feature-rich and complete monitoring product. Available on Marketplace. Cons Self maintenance. Infrastructure matters. No technical supported. X-Pack limit features. Limited control. Less capacity and scalability. Backup once time per day. No plugins, no logs. Medium expensive. Only support I2 series EC2 instances. Most expensive. Imperfect for AWS-hosted solutions.
  • 28. Costs Comparison Chart 8,400.38 10,678.56 11,512.51 75,303.17 81,375.17 11,316.98 14,500.26 25,201.1525,201.15 32,035.68 34,537.54 203,318.55 219,712.95 28,319.95 38,295.63 50,402.30 0 50,000 100,000 150,000 200,000 250,000 Elastic Stack (AWS) Elastic Stack (GCP) AWS Elasticsearch Services Elastic Cloud (GCP) Elastic Cloud (AWS) Cost($) Service Models One Year One Year (All Upfront) Three Years Three Years (All Upfront) *Costs calculated based on 3TB-data cluster in multi-AZ in Frankfurt region
  • 29. In Conclusion • Elasticsearch leverage the power of analysis ability for both Dev/Ops teams. • Easily operate/maintain the huge cluster of servers and microservices. • Choose the proper architecture depend on application/system. • Estimate the budget to meet the requirements. • Optimize the aggregation to adopt the resources. • High availability oriented system.
  • 30. We are hiring… • Java Senior/Lead Developer • PHP Senior Developer • PHP Technical Lead • Front-end Senior Developer • Front-end Technical Lead • Technical Project Manager Simply send us an email with your enclosed updated CV to: career@nfq.asia
  • 31. Contact Me LinkedIn: linkedin.com/in/tylernguyen91 Email: tai.nguyen@nfq.asia Telegram: @tylern91