Deploymezs architecture
The following diagram depicts commonly used Elastic Stack deployment architecture:
The diagram depicts three possible architectures:
- Ship the operation metrics directly to Elasticsearch: As seen in the preceding diagram, one will install various types of Beats such as Metricbeat, Filebeat, Packetbeat, and so on, on the edge servers from which they would like to ship the operation metrics/logs. If no further processing of events is required, then the generated events can be shipped directly to the Elasticsearch cluster. Once the data is present in Elasticsearch, it can then be visualized/analyzed using Kibana. In this architecture, the flow of events would be Beats → Elasticsearch → Kibana.
- Ship the operation metrics to Logstash: The operation metrics/logs captured by the Beats and installed on edge servers is sent to Logstash for further processing such as, for instance, parsing the logs or enriching log events. Then the parsed/enriched events are pushed to Elasticsearch...