Skip to content
JackSparrow414
Go back

Setting Up ELK and Getting Started

Table of contents

Open Table of contents

Setting Up ELK and Getting Started

Introduction

Defining the Data Format

The basic article structure is:

{
  "title": "Article title—string",
  "author": "Author name—string",
  "article_content": "Article body—string",
  "article_genre": "Article genre—string; multiple values are allowed, so this field is an array",
  "chines": "Whether the article is Chinese—boolean",
  "reading_count": "Article read count—numeric",
  "created": "Article creation time—date",
  "updated": "Article update time—date"
}

Installation and Startup

Find Windows installation instructions on the official sites. Here are the Elasticsearch Windows instructions; consult the documentation for the other two components.

brew tap elastic/tap

brew install elastic/tap/elasticsearch-full

brew install elastic/tap/kibana-full

brew install elastic/tap/logstash-full

Starting Elasticsearch

The default port is 9200.

brew service start elasticsearch

Wait a moment.

Output similar to the following indicates successful startup.

{
  "name" : "duhongbodeMacBook-Pro.local",
  "cluster_name" : "elasticsearch_jacksparrow414",
  "cluster_uuid" : "rp73VaY8RRCgQrl4M5uR9A",
  "version" : {
    "number" : "7.7.1",
    "build_flavor" : "default",
    "build_type" : "tar",
    "build_hash" : "ad56dce891c901a492bb1ee393f12dfff473a423",
    "build_date" : "2020-05-28T16:30:01.040088Z",
    "build_snapshot" : false,
    "lucene_version" : "8.5.1",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

Starting Kibana

Before startup, configure the port and host in kibana.yml, located in /usr/local/etc/kibana. server.port and server.host settings enabled in kibana.yml

brew service start kibana

Visit localhost:5601 in a browser.

Starting Logstash

Configuring first-pipeline.conf

input {
  2     stdin {

        }
  5 }
  6
  7 output {
  8     elasticsearch {
  9         hosts => [ "localhost:9200" ]
 10         user => "elastic"
 11         password => "password"
 12     }
 13 }

Starting Logstash in the Foreground

Enter the Logstash configuration directory:

cd /usr/local/etc/logstash

Not sure where it is? See Logstash directory layout.

Start it with the first-pipeline configuration file:

logstash -f first-pipeline.conf --config.reload.automatic

Use CTRL-D to stop foreground Logstash.

Installing Logstash Plugins

For plugin installation, see the official documentation and Logstash plugin list.

Configuring Basic Security

Without security configuration, Kibana prompts you to configure it when logging in.

Official documentation

For development, the minimal security setup is sufficient.

Configuring Elasticsearch Credentials

Credential configuration documentation elasticsearch-setup-passwords command setting passwords for built-in users

Here, all passwords are set to password.

Configuring Kibana Security

Uncomment the Elasticsearch-related username setting in kibana.yml.

See the official documentation for subsequent steps.

Logging In After Configuration

Visit kibana.localhost:5601 and log in with username elastic and password password.

Logging In to Kibana

After login, open Dev Tools. This graphical panel is convenient for Elasticsearch REST operations and provides completion hints. Management and Dev Tools entries in the Kibana navigation menu

Creating Data in Elasticsearch

Creating an Index

If you know Solr, an Elasticsearch index is roughly like a Solr core: a collection of data with similar structures. Why similar rather than identical? Because the structure within an index can be adjusted dynamically according to type. We will not go deeply into this in an introductory article.

Note: you can write data without creating an index, and Elasticsearch will create one dynamically if absent. Here, however, we create the index first.

First define the index and its data structure in Kibana’s Management -> Dev Tools.

PUT /my-articles
{
  "mappings": {
    "properties": {
       "title": {
          "type": "text"
       },
        "author": {
          "type": "text"
       },
        "article_content": {
          "type": "text"
       },
        "article_genre": {
          "type": "text"
       },
        "chinese": {
          "type": "boolean"
       },
        "reading_count": {
          "type": "integer"
       },
        "created": {
          "type": "date",
          "format": "yyyy-MM-dd HH:mm:ss"
       },
        "updated": {
          "type": "date",
          "format": "yyyy-MM-dd HH:mm:ss"
       }
    }
  },
  "settings": {
    "index": {
       "number_of_shards": 1,
       "number_of_replicas": 1
    }
  },
  "aliases": {

  }
}
  1. Use PUT followed by the index name. Index names must be lowercase. Detailed naming rules

  2. The request body contains mappings for the data structure, settings for shard and replica counts, and aliases. I have not studied aliases yet; I leave features outside the current scenario for later.

  3. Under mappings, properties defines the individual fields and their types, in this format:

    "FIELD_NAME": {
        "type": "FIELD_TYPE"
    }

    The mappings above follow our initial data format: text for strings, boolean for booleans, date for dates, and integer for numbers. More types are in the official field-type documentation.

Inspecting the Created Index

After creating it, the first thing I want to do is inspect its complete structure.

GET /my-articles

Kibana Dev Tools querying an Elasticsearch index and its mappings

Inspecting the Mappings

View only the mappings structure:

GET /my-articles/_mapping

Inspecting a Field’s Type

Inspect the author field’s type:

GET /my-articles/_mapping/field/author

Kibana Dev Tools returning field mappings for an Elasticsearch index

Creating Data

After defining the structure, add data. Indexing documentation

POST /my-articles/_doc
{
  "title": "青玉案·元夕",
  "author": "辛弃疾",
  "article_content":"东风夜放花千树,更吹落、星如雨。宝马雕车香满路。凤箫声动,玉壶光转,一夜鱼龙舞。蛾儿雪柳黄金缕,笑语盈盈暗香去。众里寻他千百度,蓦然回首,那人却在,灯火阑珊处。",
  "article_genre": ["古词","记叙文"],
  "reading_count": 25,
  "chinese": true,
  "created": "2021-06-03 19:27:56",
  "updated": "2021-06-03 19:27:56"
}

You can either specify an ID when creating data or let Elasticsearch generate one. We use the second approach.

Displaying Data in Kibana

Use Discover to view data in Kibana, but first create an index pattern.

Creating Index Patterns

Management->Stack Management->Kibana->Index Patterns Index Patterns page and create button in Kibana Stack Management

Click Create index pattern, select the index just created, and click Next step. Choose created as the time field, then click Create index pattern. Selecting a time field and confirming Index Pattern creation in Kibana

Viewing Data

Select the index pattern and refresh. If no data appears, adjust the time range to include the data. Kibana Discover selecting an index pattern and time range, then refreshing data

By default, only Time and Document are displayed. Kibana Discover displaying records with the default Time and Document columns

Click + on frequently viewed fields to add them as columns. Kibana Discover results after selected fields are added as table columns

Final Notes

This is a basic introduction. My approach is:

Logstash is not yet needed in this scenario, so confirming installation and startup is enough. Later articles will explain it more thoroughly when we use it.

Mind Map

ELK introduction mind map covering installation, APIs, template mappings, and document operations The next article focuses on Elasticsearch query syntax.


Share this post:

Continue this series

Elasticsearch and ELK in Practice

  1. Setting Up ELK and Getting StartedYou are here
  2. Querying Elasticsearch
  3. Practical Elasticsearch: Common Operations, Logstash Integration, Local IP Handling, and ECS Field Mapping
  4. Generating PEM CA Certificates for ELK, Enabling HTTPS, and Connecting with the Elasticsearch Java Client
  5. Using the Elasticsearch Java API
  6. Shipping Tomcat Access Logs from EC2 to ELK with Filebeat and AWS CloudWatch Logs
  7. Shipping Tomcat access_logs from EC2 to Elasticsearch with Filebeat and AWS CloudWatch Logs, with Automated Log Management via ILM
  8. Building Elastic Stack from the Official Documentation: A Three-Node Elasticsearch Cluster, Kibana, Filebeat, Metricbeat, and Migration Without Downtime
  9. A Practical Guide to Elasticsearch in Application Development, with a Real Optimization Case
  10. Automating AWS EC2 Creation, Elasticsearch and Kibana Installation, and OpenTelemetry Monitoring
  11. Replacing Database LIKE Queries with Elasticsearch: Approaches and Implementation Details

Comments

Questions, corrections, and experiences are welcome. Sign in with GitHub to comment; both language versions share this discussion.

Comments are available on the live site only.