Back to articles
Technology Insight

Building a Centralized Logging System (ELK Stack) on VPS for 10+ Server Monitoring: Optimized Configuration for Low Resources

May 18, 2026

Introduction: The Critical Need for Centralized Logging

In today's distributed infrastructure landscape, managing logs across multiple servers has become increasingly complex. When operating 10 or more servers, manually checking individual log files becomes impractical and inefficient. A centralized logging system provides a unified view of your entire infrastructure, enabling faster troubleshooting, security monitoring, and performance analysis. The ELK Stack (Elasticsearch, Logstash, Kibana) has emerged as the industry standard for log aggregation and visualization, but its resource requirements can be daunting for organizations with limited infrastructure budgets.

This guide demonstrates how to deploy a fully functional ELK Stack on a single VPS (Virtual Private Server) with optimized configurations specifically designed for low-resource environments. By following these recommendations, you can monitor 10+ servers effectively while maintaining system stability and performance.

Architecture Overview: ELK Stack Components

The ELK Stack consists of three core components that work together to collect, process, store, and visualize log data:

  • Elasticsearch: A distributed search and analytics engine that stores and indexes log data. It provides powerful query capabilities and horizontal scalability.
  • Logstash: A server-side data processing pipeline that ingests data from multiple sources, transforms it, and sends it to Elasticsearch.
  • Kibana: A visualization layer that provides dashboards and interfaces for exploring and analyzing log data stored in Elasticsearch.

For resource-constrained environments, we'll implement a modified architecture where Logstash agents (Filebeat) run on each monitored server, sending logs directly to Elasticsearch to reduce the processing load on the central VPS.

VPS Requirements and Selection Criteria

Choosing the right VPS is crucial for balancing performance and cost. For monitoring 10+ servers, we recommend the following minimum specifications:

  • CPU: 4 vCPUs (minimum 2 for light loads)
  • RAM: 8 GB (with 4 GB dedicated to Elasticsearch heap)
  • Storage: 50 GB SSD (with additional space for log retention)
  • Network: 1 Gbps connection with sufficient bandwidth for log traffic

When selecting a VPS provider, consider factors beyond raw specifications. Look for providers offering consistent I/O performance, reliable networking, and predictable billing. Many cloud providers now offer "burstable" instances that can handle occasional spikes in log volume without requiring expensive dedicated resources year-round.

Step-by-Step Installation Process

1. System Preparation and Optimization

Before installing the ELK components, optimize your VPS operating system for better performance:

  1. Update system packages: sudo apt update && sudo apt upgrade -y
  2. Increase system limits for Elasticsearch: Edit /etc/security/limits.conf to set nofile to 65536 and nproc to 4096
  3. Configure swapiness: Set vm.swappiness=1 in /etc/sysctl.conf to reduce swapping
  4. Disable transparent huge pages for Elasticsearch: Add to /etc/rc.local

2. Elasticsearch Installation and Configuration

Install Elasticsearch with optimized settings for low-resource environments:

wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update && sudo apt-get install elasticsearch

Configure /etc/elasticsearch/elasticsearch.yml with these critical optimizations:

  • Set cluster name: cluster.name: production-logging
  • Configure node as single-node cluster: discovery.type: single-node
  • Limit heap size: ES_JAVA_OPTS="-Xms2g -Xmx2g" (adjust based on available RAM)
  • Enable compression for network traffic: http.compression: true

3. Logstash Configuration for Efficient Processing

While we'll use Filebeat on client servers for most logs, Logstash on the VPS can handle additional processing. Configure /etc/logstash/logstash.yml:

  • Set pipeline workers: pipeline.workers: 2 (reduces CPU usage)
  • Configure batch size: pipeline.batch.size: 125 (optimizes memory usage)
  • Enable monitoring: xpack.monitoring.enabled: true

4. Kibana Setup for Visualization

Install Kibana and configure it to connect to your Elasticsearch instance:

sudo apt-get install kibana
sudo systemctl enable kibana
sudo systemctl start kibana

Configure /etc/kibana/kibana.yml with server host set to localhost and appropriate security settings. For low-resource environments, disable unused plugins to reduce memory consumption.

Client-Side Configuration: Filebeat on Monitored Servers

Instead of running Logstash on each monitored server (which would consume significant resources), deploy Filebeat as a lightweight log shipper. Install Filebeat on each of your 10+ servers:

curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.17.0-amd64.deb
sudo dpkg -i filebeat-7.17.0-amd64.deb

Configure /etc/filebeat/filebeat.yml to send logs directly to your Elasticsearch VPS:

  • Define log paths for system logs, application logs, and custom logs
  • Configure output to Elasticsearch with compression enabled
  • Set up modules for common services (nginx, mysql, system)
  • Enable backpressure-sensitive settings to prevent overwhelming the VPS

Performance Optimization Strategies

Elasticsearch Index Management

Proper index management is critical for maintaining performance in resource-constrained environments:

  • Implement index lifecycle management (ILM) to automatically roll over indices
  • Configure index templates with optimal shard counts (1 primary, 0 replicas for single-node)
  • Set up curator to delete old indices based on retention policies
  • Use index compression with the best_compression codec

Memory and CPU Optimization

Monitor and adjust resource usage regularly:

  1. Use the Elasticsearch _nodes/stats API to monitor heap usage
  2. Configure circuit breakers to prevent out-of-memory errors
  3. Adjust refresh intervals to reduce I/O: index.refresh_interval: 30s
  4. Disable fielddata for text fields that don't require aggregation

Network and I/O Optimization

Optimize data transfer between components:

  • Enable gzip compression for all HTTP traffic
  • Configure Filebeat to use bulk API with appropriate batch sizes
  • Use network policies to limit connections and prevent denial of service
  • Monitor network bandwidth and adjust log sampling if necessary

Security Considerations

Even in resource-constrained environments, security cannot be compromised:

  • Enable Elasticsearch security features with basic authentication
  • Configure TLS/SSL for all communications between components
  • Implement IP whitelisting for Elasticsearch API access
  • Use role-based access control in Kibana to limit user permissions
  • Regularly update all components to patch security vulnerabilities

Monitoring Your Monitoring System

Implement monitoring for the ELK Stack itself to ensure it remains healthy:

  • Set up Elasticsearch monitoring through Kibana Stack Monitoring
  • Configure alerts for critical conditions (disk space, memory usage, node status)
  • Monitor queue sizes in Logstash and Filebeat to detect bottlenecks
  • Track ingestion rates and search performance over time

Scaling Considerations

As your infrastructure grows beyond 10 servers, consider these scaling strategies:

  1. Vertical Scaling: Upgrade your VPS resources (RAM, CPU, storage) as needed
  2. Horizontal Scaling: Add additional Elasticsearch nodes to form a cluster
  3. Data Tiering: Move older indices to cheaper storage while keeping recent data on SSD
  4. Log Sampling: Reduce volume by sampling less critical logs

Cost Optimization Techniques

Maintain an efficient logging system while controlling costs:

  • Implement log retention policies aligned with compliance requirements
  • Use index compression to reduce storage requirements
  • Consider cold storage for archival logs (older than 30 days)
  • Monitor and eliminate duplicate or unnecessary log sources
  • Schedule resource-intensive operations (reindexing, backups) during off-peak hours

Conclusion: Achieving Enterprise-Grade Monitoring on a Budget

Building a centralized logging system for 10+ servers on a single VPS is not only possible but practical with proper configuration and optimization. The ELK Stack, when tuned for resource efficiency, provides powerful log aggregation and visualization capabilities without requiring expensive infrastructure. By following the guidelines in this article, you can implement a monitoring solution that scales with your needs while remaining cost-effective.

Remember that successful log management is an ongoing process. Regularly review your configurations, monitor system performance, and adjust settings as your logging needs evolve. With careful planning and optimization, your ELK Stack deployment will provide invaluable insights into your infrastructure while maintaining stability and performance.

Pro Tip: Start with conservative resource allocations and monitor closely for the first week. It's easier to add resources than to recover from an overwhelmed system. Document all configuration changes and establish a regular maintenance schedule for your logging infrastructure.