Is anybody here successfully using ELK in a low ram environment with low message flow?
Is anybody here successfully using ELK in a low ram environment with low message flow?
Scalyr provides especially powerful features for log parsing and analysis, as well as integrating system and application metrics, and it's wicked fast -- most searches run in well under 1 second. (Disclosure: I am the founder of Scalyr.)
If you're interested, the respective web sites are easy to find, or drop me a line (my email address is in my profile).
I've helped a bunch of financial and security companies implement and deploy elk as a critical infra component. Generally I'm seeing it used to complement Splunk, Alienvault and other log/network/security monitoring solutions.
Happy to help with any questions about deploying and managing ELK in production.
We're running a similar configuration and I'd like to know the limitations before we'd need to start using a clustered setup.
I assume it would reduce the disk usage as well.
I've got a t2.small server on AWS that's taking in a low/moderate logging from three servers (syslog x3, nginx x3, zero-low traffic redis) and it's usually in the 750MB of RAM with absolutely no notable CPU load.
Granted Kibana/ElasticSearch gets pretty much no traffic other than checking it once or twice a day, just to get a glance at 4xx/5xx errors.
So yeah, you just defined my current use-case down to the letter -- centralized logging, fancy interface for filtering/searching/visualizing said log data.
I haven't tried aggregating a years worth of data into a single search, but for reasonable log troubleshooting everything is going well.