Elastic Stack Monitoring

The Elastic Stack (formerly known as ELK stack) is a very powerful tool for any kind of Search, Monitoring or Security Use Case. Therefore using the stack to monitor itself is a low hanging fruit. The recommended setup is to use the separate Self Monitoring cluster for this purpose.

Elastic comes with a lot of inbuilt monitoring capabilities. The Elastic Agent as well as the Beats do have integrations / modules to collect the necessary data. By using the Elastic Cloud the self monitoring can be activated for any cluster.

Nevertheless using the inbuilt monitoring app can be very helpful. But if a user has already a separate cluster to monitor the production cluster it makes sense to use all available capabilities also for that. Thats the reason we have Elasticsearch Monitoring dashboards as an extension to the normal behavior like this one.

This Elastic Stack Monitoring Dashboard includes the following components:

  1. Create 2 index patterns / data views
  2. Create 1 transform
  3. Create Dashboard from ndjson file

Source: https://github.com/jeffvestal/elastic-stack-monitoring-dashboard

Tested versions 8.x
ECS compliant Yes

You must log in to submit a review.

Related downloads

RUM extension dashboard

This dashboard provide deeper insight into the real user monitoring data collected by Elastic RUM.

Vega Scatterplot Kibana visualization

A scatterplot visualization made with Vega Lite for Kibana

Vega Compound Gauge

This is a compund gauge visualization made with Vega. Its very helpful for visualization of percentage values.

Threat detection Kibana dashboard

Kibana dashboard example visualizing the results of the Elastic SIEM detection engine

Elastic Stack Monitoring Dashboard

Kibana dashboards that is showing the monitoring data collected by Elastics in built monitoring capabilities.

Sigma Elastic SIEM rules for web server logs

A collection of rules based on the Sigma detection rules for web server looks, e.g. apache, nginx or IIS.

These downloads could be also interesting for you

Watch to detect large shards

This watch is getting data from the Elasticsearch shards API directly and checking for large shards.

ACSC Advisory IOCs detection rules

ACSC Advisory IOCs detection rules for Elastic SIEM

Office display canvas example

Kibana canvas example showing an office screen with weather, news and stock information

Cloudflare Kibana dashboards

Cloudflare dashboards and ingest pipelines to visualize cloudflare logs

Plex ingest node pipeline

A plex ingest node pipeline to parse logs from Plex for Elasticsearch

Watch for changes in IOWaits

A watch which alerts if the time spent by a hosts CPU in IOWait, has increased by more than than N% in the last Y mins.