Elasticsearch, Logstash, and Other Data
LISA: Where systems engineering and operations professionals share real-world knowledge about designing, building, and maintaining the critical systems of our interconnected world.
The LISA conference has long served as the annual vendor-neutral meeting place for the wider system administration community. The LISA14 program recognized the overlap and differences between traditional and modern IT operations and engineering, and developed a highly-curated program around 5 key topics: Systems Engineering, Security, Culture, DevOps, and Monitoring/Metrics. The program included 22 half- and full-day training sessions; 10 workshops; and a conference program consisting of 50 invited talks, panels, refereed paper presentations, and mini-tutorials.
Grand Ballroom D
Elasticsearch is a distrbuted and reliable data store that can be used for a variety of purposes. One use of particular interest to system administrators is as a storage engine for Logstash. This tutorial covers how to implement an Elasticsearch cluster and use Logstash and related tools to store and query log data (syslog, web logs, etc).
System administrators who need a tool to aggregate and examine log data across their environment.
Participants will leave the tutorial ready to implement and manage an Elasticsearch cluster, store and analyze their logs and other data with Logstash, and methods for using Elasticsearch with other data.
- An introduction to Elasticsearch
- How to implement and manage a replicated and distributed data store.
- How to use Logstash to store log files (or other time-stamped data)
- Tools for querying and analyzing those logs
- Ways to use and abuse Elasticsearch for other types of data






















