SlideShare a Scribd company logo
8
Most read
13
Most read
15
Most read
ELK STACK
Master the data
BY EL MAHDI BENZEKRI
PLAN
 Ourproblem
 Old solutions limits
 Other solutions
 ELK Stack overview
 Logstash/Elasticsearch/Kibana
 Demo
Who are we?
Our problem
Lot of
users
Lots of
data
Lots of
systems
Integrated
collection
of logs
Old solutions limits
• Tail & grep impossible with multiple systems
• DBs dont scale and its difficult to extract statistics
• Syslog :
• Only log history
• Not flexible : syslog client to syslog server
ELK Elasticsearch Logstash and Kibana Stack for Log Management
Other solutions
- Biggest tool
- 537 apps
- High cost and
complexity
- Up to
~10000$
SPLUNK
- Easy setup
- Establish
baseline and
notify
- Sensitive data
- Data
transmition
overhead
- Complex
pricing strategy
SUMO LOGIC (SAAS)
ELK Stack
- Open source
- Easy install
- Mature
components
- Complexity of
three different
products
- Diffrent
machines in
production
Logstash
Over 200 plugins and all pluggable and mixable
Unify and democratize data from different sources and
into different destinations
Data collection engine
Logstash loves data
Logstash popular plugins
- Date
- mutate
- Grok
- Multiline
FILTER
- File
- Stdin
- syslog
INPUT
- Elasticsearch
- File
- Mongodb
- Email
- stdout
OUTPUT
Elasticsearch
• Build on top of Apache Lucene(java)
• Developer-Friendly, RESTful API
• High Availability
• Massively Distributed
• Real-Time data and Advanced Analytics(1s from indexing to
searching)
Elasticsearch architecture
Elasticsearch REST API
Kibana
Real time dashboards
Designed to interact with elasticsearch data
Full JS and HTML5 analytics and visualization platform
Search query syntax
• status:active
• title:(quick OR brown)
• title:(quick brown)
• author:"John Smith«
• book.*:(quick brown)
• _missing_:title
• _exists_:title
• qu?ck bro*
• name:/joh?n(ath[oa]n)/
• Fuzziness :
• quikc~ brwn~ foks~
• quikc~1
• Proximity seach:
• "fox quick"~5
• Ranges
• date:[2012-01-01 TO 2012-
12-31]
• count:{10 TO *] = count:>10
• Boosting
• quick^2 fox
• Boolean operators
• quick brown +fox –news
• Avoid
• ((quick AND fox) OR
(brown AND fox) OR
fox) AND NOT news
• *ing
Demo architecture
TOMCAT Logs
Accounts.json
REST API
File input plugin
01110100 01101000 01100001
01101110 01101011 00100000
01111001 01101111 01110101
:D

More Related Content

PPTX
PPTX
ELK Stack
PPTX
Elastic - ELK, Logstash & Kibana
PPTX
Digital Marketing PPT(Presentation) - Digital Marketing Strategies
PPTX
Elastic stack Presentation
PPTX
Elastic Stack Introduction
PDF
ksqlDB - Stream Processing simplified!
PPTX
Robotic Process Automation (RPA)
ELK Stack
Elastic - ELK, Logstash & Kibana
Digital Marketing PPT(Presentation) - Digital Marketing Strategies
Elastic stack Presentation
Elastic Stack Introduction
ksqlDB - Stream Processing simplified!
Robotic Process Automation (RPA)

What's hot (20)

PPTX
Log analysis using elk
PDF
Log analysis with the elk stack
PPTX
The Elastic ELK Stack
PDF
Introducing ELK
PDF
Elasticsearch
PPTX
Centralized log-management-with-elastic-stack
PDF
What Is ELK Stack | ELK Tutorial For Beginners | Elasticsearch Kibana | ELK S...
PPTX
Introduction to ELK
PPTX
Log management with ELK
PDF
Elk - An introduction
PDF
ELK introduction
PDF
Elasticsearch in Netflix
PDF
Introduction to elasticsearch
PPTX
Caching
PDF
Introduction to elasticsearch
PDF
Log analysis with elastic stack
ODP
Deep Dive Into Elasticsearch
PPTX
엘라스틱 서치 세미나
PPTX
Introduction to ELK
PDF
Elasticsearch
Log analysis using elk
Log analysis with the elk stack
The Elastic ELK Stack
Introducing ELK
Elasticsearch
Centralized log-management-with-elastic-stack
What Is ELK Stack | ELK Tutorial For Beginners | Elasticsearch Kibana | ELK S...
Introduction to ELK
Log management with ELK
Elk - An introduction
ELK introduction
Elasticsearch in Netflix
Introduction to elasticsearch
Caching
Introduction to elasticsearch
Log analysis with elastic stack
Deep Dive Into Elasticsearch
엘라스틱 서치 세미나
Introduction to ELK
Elasticsearch
Ad

Similar to ELK Elasticsearch Logstash and Kibana Stack for Log Management (20)

PPTX
Centralized Logging System Using ELK Stack
PDF
COUG_AAbate_Oracle_Database_12c_New_Features
PPTX
Building a Pluggable Analytics Stack with Cassandra (Jim Peregord, Element Co...
PDF
A Journey from Oracle to PostgreSQL
 
PDF
PPTX
An AMIS Overview of Oracle database 12c (12.1)
PDF
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
PPTX
Doing More with Postgres - Yesterday's Vision Becomes Today's Reality
 
PPTX
PPTX
Oracle OpenWorld 2016 Review - Focus on Data, BigData, Streaming Data, Machin...
PPTX
Oracle OpenWo2014 review part 03 three_paa_s_database
PDF
The Central View of your Data with Postgres
 
PDF
The Real Scoop on Migrating from Oracle Databases
 
PPTX
ELK Ruminating on Logs (Zendcon 2016)
PPTX
Big Data Analytics on the Cloud Oracle Applications AWS Redshift & Tableau
PPT
Building Scalable Big Data Infrastructure Using Open Source Software Presenta...
PDF
PLSSUG - Troubleshoot SQL Server performance problems like a Microsoft Engineer
PDF
Alfresco monitoring with Nagios and ELK stack
PPTX
Ibm datastage online training in hyderabad
PDF
A Glass Half Full: Using Programmable Hardware Accelerators in Analytical Dat...
Centralized Logging System Using ELK Stack
COUG_AAbate_Oracle_Database_12c_New_Features
Building a Pluggable Analytics Stack with Cassandra (Jim Peregord, Element Co...
A Journey from Oracle to PostgreSQL
 
An AMIS Overview of Oracle database 12c (12.1)
Centralized Logging Feature in CloudStack using ELK and Grafana - Kiran Chava...
Doing More with Postgres - Yesterday's Vision Becomes Today's Reality
 
Oracle OpenWorld 2016 Review - Focus on Data, BigData, Streaming Data, Machin...
Oracle OpenWo2014 review part 03 three_paa_s_database
The Central View of your Data with Postgres
 
The Real Scoop on Migrating from Oracle Databases
 
ELK Ruminating on Logs (Zendcon 2016)
Big Data Analytics on the Cloud Oracle Applications AWS Redshift & Tableau
Building Scalable Big Data Infrastructure Using Open Source Software Presenta...
PLSSUG - Troubleshoot SQL Server performance problems like a Microsoft Engineer
Alfresco monitoring with Nagios and ELK stack
Ibm datastage online training in hyderabad
A Glass Half Full: Using Programmable Hardware Accelerators in Analytical Dat...
Ad

Recently uploaded (20)

PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PDF
System and Network Administration Chapter 2
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
Understanding Forklifts - TECH EHS Solution
PPTX
Introduction to Artificial Intelligence
PDF
AI in Product Development-omnex systems
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
System and Network Administraation Chapter 3
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
L1 - Introduction to python Backend.pptx
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Which alternative to Crystal Reports is best for small or large businesses.pdf
Operating system designcfffgfgggggggvggggggggg
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
VVF-Customer-Presentation2025-Ver1.9.pptx
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
System and Network Administration Chapter 2
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Understanding Forklifts - TECH EHS Solution
Introduction to Artificial Intelligence
AI in Product Development-omnex systems
How to Choose the Right IT Partner for Your Business in Malaysia
Adobe Illustrator 28.6 Crack My Vision of Vector Design
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
System and Network Administraation Chapter 3
ISO 45001 Occupational Health and Safety Management System
Design an Analysis of Algorithms I-SECS-1021-03
2025 Textile ERP Trends: SAP, Odoo & Oracle
L1 - Introduction to python Backend.pptx
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf

ELK Elasticsearch Logstash and Kibana Stack for Log Management

  • 1. ELK STACK Master the data BY EL MAHDI BENZEKRI
  • 2. PLAN  Ourproblem  Old solutions limits  Other solutions  ELK Stack overview  Logstash/Elasticsearch/Kibana  Demo
  • 4. Our problem Lot of users Lots of data Lots of systems Integrated collection of logs
  • 5. Old solutions limits • Tail & grep impossible with multiple systems • DBs dont scale and its difficult to extract statistics • Syslog : • Only log history • Not flexible : syslog client to syslog server
  • 7. Other solutions - Biggest tool - 537 apps - High cost and complexity - Up to ~10000$ SPLUNK - Easy setup - Establish baseline and notify - Sensitive data - Data transmition overhead - Complex pricing strategy SUMO LOGIC (SAAS)
  • 8. ELK Stack - Open source - Easy install - Mature components - Complexity of three different products - Diffrent machines in production
  • 9. Logstash Over 200 plugins and all pluggable and mixable Unify and democratize data from different sources and into different destinations Data collection engine
  • 11. Logstash popular plugins - Date - mutate - Grok - Multiline FILTER - File - Stdin - syslog INPUT - Elasticsearch - File - Mongodb - Email - stdout OUTPUT
  • 12. Elasticsearch • Build on top of Apache Lucene(java) • Developer-Friendly, RESTful API • High Availability • Massively Distributed • Real-Time data and Advanced Analytics(1s from indexing to searching)
  • 15. Kibana Real time dashboards Designed to interact with elasticsearch data Full JS and HTML5 analytics and visualization platform
  • 16. Search query syntax • status:active • title:(quick OR brown) • title:(quick brown) • author:"John Smith« • book.*:(quick brown) • _missing_:title • _exists_:title • qu?ck bro* • name:/joh?n(ath[oa]n)/ • Fuzziness : • quikc~ brwn~ foks~ • quikc~1 • Proximity seach: • "fox quick"~5 • Ranges • date:[2012-01-01 TO 2012- 12-31] • count:{10 TO *] = count:>10 • Boosting • quick^2 fox • Boolean operators • quick brown +fox –news • Avoid • ((quick AND fox) OR (brown AND fox) OR fox) AND NOT news • *ing
  • 18. 01110100 01101000 01100001 01101110 01101011 00100000 01111001 01101111 01110101 :D