Elastic Stack
Turn your data into solutions
Elastic Stack is an open source information and event management solution that focuses on centralized collection, processing, analysis, and storage.
The focus here is not only on classic log management, but also in the areas of IT security (audit, SIEM and threat intelligence) and anomaly detection.
Elasticsearch
The Open Source Enterprise search server
Elasticsearch is a distributed search and analytics server, which represents the core of the Elastic Stack. The communication between Elasticsearch and the service consumer is almost exclusively based on JSON via REST interface. This has the advantage that even smaller read and write operations can be tested and developed using CURL, without having to resort to a heavy-weight API.
Scaling
Performance
Logstash
Flexible Log- and Eventmanagement
Logstash is an open source log management solution that specializes in channeling, filtering and distribution of log and event information. It supports a large number of input and output formats and thus integrates into almost any IT environment.
In short, Logstash is the open source solution for managing and analyzing log information and the tool of choice to address the increasing volume of information in an auditable manner. Logstash has a variety of input, filtering and output plug-ins. Thus all events and log messages available in your network can be received, processed and forwarded.
Integration
input { stdin { } } filter { grok { match => { "message" => "%{COMBINEDAPACHELOG}" } } date { match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ] } } output { elasticsearch { hosts => ["localhost:9200"] } stdout { codec => rubydebug } }
Kibana
Your look in the Elastic Stack
Kibana visualizes and analyzes the data stored in Elasticsearch. Sophisticated filtering option allows the construction of dashboards for all data stored in Elasticsearch. Working with Kibana is the real reward for the effort invested in collecting the log and event information in advance. The access to all stored information is very fast and no deeper knowledge of a query language like SQL is necessary. Of course understanding the underlying intersections of the queried data is an advantage in order to get to the goal quickly, but even without it, visual viewing of the data is simply fun.
Beats
Collect, analyze and send
Beats is the platform for building lightweight data collectors for a wide variety of data types.
There are different Beats with a multitude of possibilities for reading in data, from enriching or processing data in advance by processors, through a multitude of modules with prefabricated processing chains for direct submission in Elasticsearch, to ready-made dashboards for a wide variety of products. In addition, there is the possibility of not only sending data to Elasticsearch and Logstash, because the absolute plus is the possibility of enriching the data with additional information in the form of document fields and tags while reading it in before sending it.
Beats not only convince with their integrations, but also with their very small footprint on the system.
Like every member of the Elastic Stack toolbox, Beats are a standard tool for processing information and events of all kinds, codecs and sources. So it is almost impossible to get around tBeats when collecting information with the Elastic Stack or related tools.
Filebeat
Yes, you read that right – Elasticsearch! Because with its large number of modules for a large number of products in a modern infrastructure, Filebeat provides already processed data or processing pipelines for Elasticsearch, as well as index patterns and Kibana dashboards – and of course everything is ECS-compliant. These mechanisms guarantee perfect functioning with, for example, the new Elastic Security Integration for a comprehensive IT security evaluation.
Winlogbeat
Starter Pack
The simple beginning of something big
With our starter packages, we want to make it easier to get started with log management with the Elastic Stack (Elasticsearch, Logstash and Kibana) and offer a cost-effective way of getting to know the open source system without having to make large financial advance payments, such as which is often the case with commercial products.
One of our experienced consultants comes on site for 4 or 7 days, sets up the system directly on site and teaches the basics for further operation. The package is billed at a fixed price and there are no additional costs.
We recommend attending our Elastic Stack training before booking the Elastic Stack Standard Starter Pack. This training is already included in the Elastic Stack Starter Pack Premium.
Elastic Stack Starterpaket Standard
- Joint workshop on log and event management
- Introduction to the Logstash, Elasticsearch, Kibana, and Beats components
- Installation and basic configuration on customer hardware
- Exemplary integration of customer logs and evaluation using Kibana
Elastic Stack Starterpaket Premium
- Elastic Stack Training (4 days for 3 participants – additional participants possible for an extra charge – 6 max.) *
- Joint workshop on log and event management
- Introduction to the components Logstash, Elasticsearch, Kibana and Beats
- Installation and basic configuration on customer hardware
- Exemplary integration of customer logs and evaluation with the help of Kibana
(including rental notebooks, training material and attendee certificates)
Subscriptions
Elastic Enterprise
With us you get all self-managed Elastic Subscriptions so that you can use your on-premise deployments optimally and with all ELK stack features. Simply request and we will create an individual offer for your area.
News
Posts from our Blog
NETWAYS Webinare – Die nächsten Themen
Wie viele vielleicht wissen führen wir auf unserem YouTube-Kanal eine Vielzahl von Webinaren durch. Diese handeln nicht nur von Icinga, sondern beispielsweise auch Elastic und Graylog. Im Laufe der Zeit sind wir von den einzelnen, getrennten Webinaren zu Serien...
Mermaid zum Visualisieren von Graphen
Gerade im Umfeld von Logstash-Pipelines steht man oft vor dem Problem, wie die einzelnen Code Teile zusammenhängen. Dafür hat sich für mich Mermaid bewährt. Was mir an Mermaid besonders gefällt ist, dass man mit einer relativ einfachen Syntax Graphen definieren kann,...
Webinars
Our Webinars for Elastic



Service from the market leader
We are happy to bring you our experience from countless Elastic projects. Whether professional services, training or support for your environment.