Elastic (ELK)
Elasticsearch and the stack — Beats, Logstash, Kibana, and Elastic APM
The Elastic stack pairs Elasticsearch with Beats or Logstash for ingest and Kibana for exploration. Because Elasticsearch is a full-text search engine first and a metrics store second, the trade-offs differ sharply from Prometheus or Loki: indexing everything makes arbitrary search fast and makes storage expensive. Interview questions concentrate on that cost. Expect to be asked about shard sizing and why too many small shards hurts more than a few large ones, about index lifecycle management moving data through hot, warm, cold and frozen tiers, and about mapping explosions caused by dynamic field creation on unstructured logs. Ingest pipelines versus Logstash filters is a common design question — the answer usually turns on whether you need the buffering and richer transformation Logstash offers, or whether a lightweight Beat plus an ingest pipeline is enough.
Elasticsearch & the Elastic Stack
Understand the distributed search engine at the core of the ELK stack.
Beats, Logstash & Ingestion
Collect, parse, and enrich data on its way into Elasticsearch.
Kibana — Discover, Visualize & Query
Explore, visualize, and build dashboards over Elasticsearch data.
Elastic Observability & APM
Use the Elastic Stack as a full observability platform for logs, metrics, and traces.