Logs from different applications rarely arrive in the same format. Logstash receives event records, extracts useful fields, changes or enriches them and sends the results to a destination such as Elasticsearch. A team might use it to turn free-form messages into consistent records that can be searched by service, customer or error type. Its processing rules and handling of interrupted delivery matter as much as keeping the Logstash process running.
Current guidance
The recovered article recommends a release per pipeline, but current Logstash supports multiple independently configured pipelines; deployment boundaries should follow isolation and operational needs. ECK can orchestrate supported Logstash versions, while pipeline definitions, plugin versions and credentials remain application configuration. Review grok patterns, date parsing, enrichment and index routing rather than treating a successful deployment as proof that transformations still match.
Persistent queues are disabled by default. When enabled, they buffer events on local disk and attempt at-least-once delivery after restart; this can include duplicates. Elastic documents important limits: queue files are not replicated, permanent disk loss is not covered, and inputs without acknowledgement cannot obtain the same protection as Beats or HTTP. An abnormal shutdown before a checkpoint is committed can also lose queued events. Size storage across all pipelines and preserve queued data during Pod replacement.
Exercise representative valid and malformed events, an unavailable output and subsequent recovery. Check dead-letter handling where supported, backpressure, duplicate behavior and the final Elasticsearch mapping. Drain or deliberately recover old queues before removing their volumes. A Kubernetes configuration rollback does not reconstruct events already transformed or dropped, so retain test fixtures and record which pipeline version produced the destination data.
Historical upstream link check · 2026-10-09
The recorded upstream address redirects to https://www.elastic.co/logstash and returned HTTP 200 on 2026-10-09. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
Logstash is an open source, server-side data processing pipeline that ingests data from a multitude of sources simultaneously transforms it, and then sends it to your favorite “stash.”
Best Practices
Release and tune this chart once per Logstash pipeline
To achieve multiple pipelines with this chart, current best practice is to maintain one pipeline per chart release. In this way, the configuration is simplified and pipelines are more isolated from one another.
Default Pipeline: Beats Input -> Elasticsearch Output
Current best practice for ELK logging is to ship logs from hosts using Filebeat to logstash where persistent queues are enabled. Filebeat supports structured (e.g. JSON) and unstructured (e.g. log lines) log shipment.
Load Beats-generated index template into Elasticsearch
To best utilize the combination of Beats, Logstash and Elasticsearch, load Beats-generated index templates into Elasticsearch as described here.
On a remote-to-Kubernetes Linux instance, you might run the following command to load that instance’s Beats-generated index template into Elasticsearch (Elasticsearch hostname will vary).
As data travels from source to store, Logstash filters parse each event, identify named fields to build the structure, and transform them to converge on a common format for easier, accelerated analysis and business value.
Logstash dynamically transforms and prepares your data regardless of format or complexity:
- Derive structure from unstructured data with grok
- Decipher geo-coordinates from IP addresses
- Anonymize PII data, exclude sensitive fields completely
- Ease overall processing independent of the data source, format, or schema.
Centrally Manage Deployments With a Single UI
Take the helm of your Logstash deployments with the Pipeline Management UI, which makes orchestrating and managing your pipelines a breeze. The management controls also integrate seamlessly with the built-in security features to prevent any unintended rewiring.
Sources & further reading
Spotted something that needs another look?
Help improve this page →