Skip to main content

Overview

Elastic (Elasticsearch) is a distributed search and analytics engine commonly used to store, search, and visualize log data, often as part of the Elastic Stack (ELK). Control Plane can ship org logs to Elasticsearch using one of three connection types:
  1. AWS Elasticsearch - an Elasticsearch domain hosted on AWS.
  2. Elastic Cloud - a deployment hosted on Elastic Cloud.
  3. Generic Elasticsearch - any other reachable Elasticsearch endpoint.
Only one connection type can be configured at a time. Follow the steps below to configure log shipping to Elastic.

Step 1 - Credential Procurement

The credentials required depend on the connection type:

Step 2 - Configure External Logging

External logging can be configured by using either the UI Console or CLI.

Enable Logging using the UI Console

  1. From the Control Plane Console UI, click on Org in the left menu.
  2. Click External Logs in the middle context menu.
  3. Select Elastic, choose the connection type (AWS, Elastic Cloud, or Generic), and fill out the required fields.
  4. Select the secret created to authenticate to Elastic. Refer to the credential procurement section to obtain and configure the necessary credentials.
  5. Click Save.
  6. After the configuration is complete, log entries will be available at Elastic within a few minutes.

Enable Logging using the CLI

The external logging configuration can be created / updated using the CLI’s cpln org patch ORG_NAME -f FILE.yaml command. Below is an example of an Org manifest (in YAML) for each connection type. Edit and save the YAML as a file and use it as an input to the CLI’s cpln org patch ORG_NAME -f FILE.yaml command. Refer to the credential procurement section to obtain and configure the necessary credentials.
Only one of aws, elasticCloud, or generic can be set at a time.

AWS Elasticsearch

  • Substitute: ORG_NAME, AWS_SECRET, HOST_NAME, INDEX, TYPE, and REGION.
YAML
  • host - Required. Must be a valid AWS Elasticsearch hostname, ending in es.amazonaws.com.
  • port - Defaults to 443.
  • index - Required.
  • type - Required.
  • region - Required.
  • credentials - Required. Must reference an AWS secret.

Elastic Cloud

  • Substitute: ORG_NAME, USERPASS_SECRET, CLOUD_ID, INDEX, and TYPE.
YAML
  • cloudId - Required. The deployment’s Cloud ID, found on the Elastic Cloud deployment overview page.
  • index - Required.
  • type - Required.
  • credentials - Required. Must reference a Username & Password secret.

Generic Elasticsearch

  • Substitute: ORG_NAME, USERPASS_SECRET, HOST_NAME, INDEX, and TYPE.
YAML
  • host - Required.
  • port - Defaults to 443.
  • path - Optional. Must start with a /.
  • index - Required.
  • type - Required.
  • credentials - Required. Must reference a Username & Password secret.