# ElasticSearch for non-fulltext logs

**URL:** <https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134>\
**Category:** Elasticsearch\
**Created:** [December 20, 2012, 11:27am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134 "2012-12-20T11:27:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [December 20, 2012, 11:27am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/1 "2012-12-20T11:27:54Z")

</div>

I am stuck between using elasticsearch and cassandra for log data. Most of  
the log data that I will have is not full text search based, most of it is  
aggrated data and information about the logs them self. The reason that I  
am looking at something like full text serach over something like mongodb  
is at my day job we use mongodb and it has been a love heat sort of setup,  
I dont want to have to deal with all the node types I like the simplicity  
of sharded nothing systems. What I dont know is if elasticsearch is going  
to be okay that most of the data is not full text search like, i may input  
some raw logs for real time log stuff but it would only live for a set  
period of time.

--

---

<div class="post-metadata">

**Author:** ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)\
**Post date:** [December 21, 2012, 4:20am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/2 "2012-12-21T04:20:09Z")

</div>

Hi,

Elasticsearch is a good choice for this. Lots of people are using ES for  
log indexing. Most of the time they search on 1 or more indexed fields.  
If you will need to simply retrieve big block of logs, optionally doing  
some processing of it, then Cassandra (Or HBase!) are good choices. If you  
think you'll need to look up logs by anything other than some primary key,  
then ES is a better choice.

## Otis

Solr & Elasticsearch Consulting

> **[Sematext | IT System Monitoring Tools for DevOps](https://sematext.com/)**
>
> IT system monitoring and management tools for DevOps who need 24x7 live visibility into their infrastructure.

On Thursday, December 20, 2012 6:27:54 AM UTC-5, Wojons Tech wrote:

> I am stuck between using elasticsearch and cassandra for log data. Most of  
> the log data that I will have is not full text search based, most of it is  
> aggrated data and information about the logs them self. The reason that I  
> am looking at something like full text serach over something like mongodb  
> is at my day job we use mongodb and it has been a love heat sort of setup,  
> I dont want to have to deal with all the node types I like the simplicity  
> of sharded nothing systems. What I dont know is if elasticsearch is going  
> to be okay that most of the data is not full text search like, i may input  
> some raw logs for real time log stuff but it would only live for a set  
> period of time.

--

---

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [December 21, 2012, 5:06am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/3 "2012-12-21T05:06:22Z")

</div>

Otis,

Thank you, would you also belive that if i use it to store metrics on the  
data that it is also a good choice?

On Thursday, December 20, 2012 8:20:09 PM UTC-8, Otis Gospodnetic wrote:

> Hi,
> 
> Elasticsearch is a good choice for this. Lots of people are using ES for  
> log indexing. Most of the time they search on 1 or more indexed fields.  
> If you will need to simply retrieve big block of logs, optionally doing  
> some processing of it, then Cassandra (Or HBase!) are good choices. If you  
> think you'll need to look up logs by anything other than some primary key,  
> then ES is a better choice.
> 
> ## Otis
> 
> Solr & Elasticsearch Consulting  
> [http://sematext.com/](http://sematext.com/)
> 
> On Thursday, December 20, 2012 6:27:54 AM UTC-5, Wojons Tech wrote:
> 
> > I am stuck between using elasticsearch and cassandra for log data. Most  
> > of the log data that I will have is not full text search based, most of it  
> > is aggrated data and information about the logs them self. The reason that  
> > I am looking at something like full text serach over something like mongodb  
> > is at my day job we use mongodb and it has been a love heat sort of setup,  
> > I dont want to have to deal with all the node types I like the simplicity  
> > of sharded nothing systems. What I dont know is if elasticsearch is going  
> > to be okay that most of the data is not full text search like, i may input  
> > some raw logs for real time log stuff but it would only live for a set  
> > period of time.

--

---

<div class="post-metadata">

**Author:** ![karmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karmi/32/44951_2.png) [@karmi](https://discuss.elastic.co/u/karmi)\
**Post date:** [December 21, 2012, 11:11am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/4 "2012-12-21T11:11:30Z")

</div>

> What I dont know is if elasticsearch is going to be okay that most of the  
> data is not full text search like, i may input some raw logs for real time  
> log stuff but it would only live for a set period of time.

That is a pretty nice use case for Elasticsearch, one for which it is  
suited very well. Look at the [http://logstash.net](http://logstash.net) and [http://kibana.org](http://kibana.org)  
to get inspiration and play around.

Karel

--

---

<div class="post-metadata">

**Author:** ![Robin\_Verlangen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_verlangen/32/1542_2.png) [@Robin\_Verlangen](https://discuss.elastic.co/u/Robin_Verlangen)\
**Post date:** [December 21, 2012, 11:17am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/5 "2012-12-21T11:17:48Z")

</div>

I would like to add to that, that I'm also working on such a project. It's  
entirely managed, so no management/knowledge needed. If you need any  
details, or would like to discuss some methods we use, feel free to contact  
me.

Best regards,

Robin Verlangen  
_Software engineer_  
\*  
\*  
W [http://www.robinverlangen.nl](http://www.robinverlangen.nl)  
E robin@us2.nl

[http://goo.gl/Lt7BC](http://goo.gl/Lt7BC)

Disclaimer: The information contained in this message and attachments is  
intended solely for the attention and use of the named addressee and may be  
confidential. If you are not the intended recipient, you are reminded that  
the information remains the property of the sender. You must not use,  
disclose, distribute, copy, print or rely on this e-mail. If you have  
received this message in error, please contact the sender immediately and  
irrevocably delete this message and any copies.

On Fri, Dec 21, 2012 at 12:11 PM, Karel Minařík [karel.minarik@gmail.com](mailto:karel.minarik@gmail.com)wrote:

> What I dont know is if elasticsearch is going to be okay that most of the
> 
> > data is not full text search like, i may input some raw logs for real time  
> > log stuff but it would only live for a set period of time.
> 
> That is a pretty nice use case for Elasticsearch, one for which it is  
> suited very well. Look at the [http://logstash.net](http://logstash.net) and [http://kibana.org](http://kibana.org)  
> to get inspiration and play around.
> 
> Karel
> 
> --

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:58am UTC](https://discuss.elastic.co/t/elasticsearch-for-non-fulltext-logs/10134/6 "2017-07-06T02:58:48Z")

</div>


