# New to ELK Stack on AWS?

**URL:** https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164
**Category:** Elasticsearch
**Created:** [March 13, 2019, 2:11pm UTC](https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164 "2019-03-13T14:11:45Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![lar](https://avatars.discourse-cdn.com/v4/letter/l/47e85d/32.png) [@lar](https://discuss.elastic.co/u/lar)
#### Post date: [March 13, 2019, 2:11pm UTC](https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164/1 "2019-03-13T14:11:45Z")

</div>

I am using ELK stack on AWS (not the AWS Manages Service ES), like Installing ELK stack on EC2 to collect all infrastructure logs and application logs. I have few questions:

1 - What is being used for Data shipping from Instances/Applications to Logstash ?  
2 - How many AZ subnets/Security groups are there ?  
3 - How many AZs are used ?  
4 - Is a ELB used, if Yes betwwen which ELK stack instances.  
5 - How are the infrastructure logs collected ?  
6 - How is ELK stack monitored ?  
7 - Where are the logs stored ?  
8 - What is used with Curotor to clean up old indexes ?  
9 - What is user for Kibana Auth. ? built in X-Pack ?  
10 - How is cloudwatch/cloudtrail/S3/SNS are used in ELK stack ?

---

<div class="post-metadata">

### Author: ![lar](https://avatars.discourse-cdn.com/v4/letter/l/47e85d/32.png) [@lar](https://discuss.elastic.co/u/lar)
#### Post date: [March 22, 2019, 4:30pm UTC](https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164/2 "2019-03-22T16:30:30Z")

</div>

Any one

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 22, 2019, 5:20pm UTC](https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164/3 "2019-03-22T17:20:49Z")

</div>

Going to try to answer but I don't think I can answer everything.

> 1 - What is being used for Data shipping from Instances/Applications to Logstash ?

I'd look at filebeat.

> 2 - How many AZ subnets/Security groups are there ?

No idea.

> 3 - How many AZs are used ?

No idea.

> 4 - Is a ELB used, if Yes betwwen which ELK stack instances.

No idea.

> 5 - How are the infrastructure logs collected ?

Filebeat?

> 6 - How is ELK stack monitored ?

Each application (Elasticsearch, Logstash, Beats, Kibana) can send its monitoring data to a ElasticStack monitoring cluster which can be the same you deployed.

> 7 - Where are the logs stored ?

Locally on disk.

> 8 - What is used with Curotor to clean up old indexes ?

Not sure I understand the question.

> 9 - What is user for Kibana Auth. ? built in X-Pack ?

You need to set it yourself. Security documentation says it all.

> 10 - How is cloudwatch/cloudtrail/S3/SNS are used in ELK stack ?

No idea.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 19, 2019, 5:20pm UTC](https://discuss.elastic.co/t/new-to-elk-stack-on-aws/172164/4 "2019-04-19T17:20:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
