ELK Stack
Search engines that scan and process the entire text in a document prior to indexing, are so-called full-text search engines. Lucene, which Elasticsearch and Solr are built on top of, is an example of a full-text search engine.
�
https://www.elastic.co/blog/found-indexing-for-beginners-part2/
Many Users
Elasticsearch
Elasticsearch elements
• Single instance of Lucene on a node
• Can be primary or replica
• Keeps a copy of the index
https://www.elastic.co/blog/found-indexing-for-beginners-part1/
https://www.elastic.co/blog/found-indexing-for-beginners-part3
Terminologies
Installation type
Various data sources
Logstash
Log parsing
Grok
Kibana
http://localhost:5601
access1M.log
client_hostname.csv
Exercise –web log visualization
Given: A dump file contains web log data
https://www.elastic.co/blog/importing-csv-and-log-data-into-elasticsearch-with-file-data-visualizer
https://www.bmc.com/blogs/elasticsearch-load-csv-logstash/