# ELK Architecture Questions

**URL:** <https://discuss.elastic.co/t/elk-architecture-questions/46831>\
**Category:** Elasticsearch\
**Created:** [April 8, 2016, 4:17pm UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831 "2016-04-08T16:17:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fsa317](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fsa317](https://discuss.elastic.co/u/fsa317)\
**Post date:** [April 8, 2016, 4:17pm UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831/1 "2016-04-08T16:17:55Z")

</div>

Hi, I'm relatively new to ELK and have some specific questions about the overall architecture.

In a typical ELK stack by the time log data is in ES does it need to be in a specific schema so that it can be read by Kibana?

The reason I ask is I have a very specific architecture where I want to insert log data from log4j directly into ElasticSearch without LogStash. I also want the data once it is in ES to be viewed by Kibana OR by a custom application that would read from ES directly. What I haven't been able to understand is whether or not there is in essence a required schema in ES.

Any tips to help me clarify these questions are appreciated.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 9, 2016, 7:07am UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831/2 "2016-04-09T07:07:49Z")

</div>

> [@fsa317](#):
>
> In a typical ELK stack by the time log data is in ES does it need to be in a specific schema so that it can be read by Kibana?

Preferably yes, but KB will still work.

Look into templates - [Index templates | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#indices-templates)

---

<div class="post-metadata">

**Author:** ![fsa317](https://avatars.discourse-cdn.com/v4/letter/f/a88e4f/32.png) [@fsa317](https://discuss.elastic.co/u/fsa317)\
**Post date:** [April 11, 2016, 11:48am UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831/3 "2016-04-11T11:48:27Z")

</div>

Thanks, are there pre-defined templates for use with Kibana or generally when using ES to store log data?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 11, 2016, 9:04pm UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831/4 "2016-04-11T21:04:15Z")

</div>

You can look at the Logstash one - [https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:00pm UTC](https://discuss.elastic.co/t/elk-architecture-questions/46831/5 "2017-07-05T23:00:35Z")

</div>


