# MongoDB vs Elasticsearch?

**URL:** <https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478>\
**Category:** Elasticsearch\
**Created:** [May 4, 2017, 3:24am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478 "2017-05-04T03:24:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![LmYjQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmyjq/32/97480_2.png) [@LmYjQ](https://discuss.elastic.co/u/LmYjQ)\
**Post date:** [May 4, 2017, 3:24am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478/1 "2017-05-04T03:24:02Z")

</div>

Hi, everyone.  
I'm considering doing log analysis with td-agent and ELK. I have seen in the [td-agent](https://www.fluentd.org/dataoutputs): . It says, mongodb is commonly for app log, and elastic-search+kibana is commonly for text-log.  
I'm new to both mongo and ELK, could you give me general idea of the pros and cons for mongo vs ES?  
especially the **disadvantage of ELK for app log analysis**.  
Thank you in advance.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 4, 2017, 3:49am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478/2 "2017-05-04T03:49:15Z")

</div>

I followed the link you had there. I think the only perceivable difference between "app" logs and so-called "text" logs is how they've been inserted into Elasticsearch. If you do no tokenization of any kind, then yes, it will be a text search. However, using log parsers like Logstash (or even Treasure Data's fluentd), then your "text" logs _become_ structured logs, which allows them to be stored "schema-less," which makes them no different from the so-called "app" logs.

This is the _default_ behavior of the Elastic stack (we don't call it ELK any more because there are more parts than just Elasticsearch, Logstash, and Kibana). Use Beats and/or Logstash to ingest logs and tokenize them. Elasticsearch even has what's known as an Ingest Node now, and can do some limited parsing and tokenizing of logs itself. As such, Elasticsearch is on equal footing with the other "schema-less backends" while still maintaining all of the benefits of a full-text search engine.

Disadvantage? I don't see one.

---

<div class="post-metadata">

**Author:** ![LmYjQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lmyjq/32/97480_2.png) [@LmYjQ](https://discuss.elastic.co/u/LmYjQ)\
**Post date:** [May 4, 2017, 3:57am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478/3 "2017-05-04T03:57:50Z")

</div>

Thank you Aaron. [quote="theuntergeek, post:2, topic:84478"]  
As such, Elasticsearch is on equal footing with the other "schema-less backends" while still maintaining all of the benefits of a full-text search engine.  
[/quote]  
That's what I'm thinking about. Tokenize or not.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 4, 2017, 3:58am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478/4 "2017-05-04T03:58:33Z")

</div>

Always tokenize if you can. Logstash or ingest node are terrific choices for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2017, 4:00am UTC](https://discuss.elastic.co/t/mongodb-vs-elasticsearch/84478/5 "2017-06-01T04:00:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
