Back to articles
Technology Insight

Centralized Logging Management (ELK Stack)

May 6, 2026
Centralized Logging Management with ELK Stack on VPS

Centralized Logging Management with ELK Stack: Aggregating Logs from Multiple VPS

When operating multiple VPS servers simultaneously, viewing logs scattered across individual machines is difficult, time-consuming, and easy to miss incidents. Centralized Logging helps collect all logs (access logs, error logs, system logs, audit logs…) from many servers to a central server. The ELK Stack (Elasticsearch + Logstash + Kibana) is currently the most powerful and popular solution. This article provides a detailed guide on implementing a professional centralized logging system in 2026.

1. Why Do You Need Centralized Logging?

Scattered logs make debugging, monitoring, and attack detection difficult. A centralized system offers:

  • Fast Search: Query logs from dozens of VPS in just a few seconds.
  • Real-time Alerts: Detect errors, brute-force attempts, or suspicious access.
  • Deep Analysis: Create dashboards, reports, and trend analysis.
  • Audit & Compliance: Easily meet security and regulatory requirements.

// Interface simulating Log Event
interface LogEvent {
  timestamp: Date;
  host: string;
  service: string;
  level: "info" | "warning" | "error" | "critical";
  message: string;
  ip?: string;
  userAgent?: string;
}

class CentralLogger {
  private logs: LogEvent[] = [];

  ingestLog(event: LogEvent) {
    this.logs.push(event);
    if (event.level === "critical" || event.message.includes("Failed password")) {
      console.error(`[ALERT] Critical issue from ${event.host}: ${event.message}`);
    }
  }

  search(query: string): LogEvent[] {
    console.log(`[ELK] Searching logs with keyword: ${query}`);
    return this.logs.filter(log => log.message.includes(query));
  }
}
 

2. Overview of ELK Stack

The ELK Stack consists of:

  • Elasticsearch: Distributed search and data storage engine.
  • Logstash / Filebeat: Log collection and processing from VPS servers.
  • Kibana: Web interface for visualization, querying, and creating alerts.

3. Architecture and VPS Requirements

Component Recommended CPU / RAM Storage
Elasticsearch 4-8 cores / 16-32GB NVMe 200GB+
Logstash + Kibana 2-4 cores / 8GB NVMe 100GB
Filebeat (shipper) Lightweight (runs on each VPS) Negligible

4. Installing Elasticsearch


// Elasticsearch configuration example (elasticsearch.yml)
const esConfig = `
cluster.name: production-elk
node.name: elk-master
network.host: 0.0.0.0
http.port: 9200
discovery.type: single-node
xpack.security.enabled: true
`;

console.log("[Elasticsearch] Cluster configured successfully");
 

5. Deploying Filebeat on Client VPS


// Filebeat configuration (filebeat.yml)
const filebeatConfig = `
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log
    - /var/log/nginx/access.log
    - /var/log/auth.log

output.elasticsearch:
  hosts: ["http://elk-central.example.com:9200"]
  username: "elastic"
  password: "your_strong_password"
`;

console.log("[Filebeat] Log shipping from VPS to ELK Server configured");
 

6. Using Kibana for Visualization and Alerts

Kibana allows you to create beautiful dashboards, flexible queries, and set up alerts via email or Slack.


// Alert management logic in Kibana (simulated)
interface AlertRule {
  name: string;
  query: string;
  threshold: number;
  severity: string;
}

const alertRules: AlertRule[] = [
  { name: "Brute Force Detection", query: "Failed password", threshold: 10, severity: "High" },
  { name: "High Error Rate", query: "level:error", threshold: 50, severity: "Medium" },
  { name: "Unauthorized Access", query: "401 OR 403", threshold: 20, severity: "High" }
];

function checkAlerts() {
  console.log(`[Kibana] Checking ${alertRules.length} alert rules...`);
  alertRules.forEach(rule => {
    console.log(`[ALERT] Rule "${rule.name}" - Severity: ${rule.severity}`);
  });
}

checkAlerts();
 

7. Best Practices for Running ELK Stack

  • Use Filebeat instead of Logstash on clients to save resources.
  • Enable X-Pack Security and HTTPS for Elasticsearch.
  • Set up Index Lifecycle Management (ILM) to automatically delete old logs.
  • Monitor cluster health with Metricbeat.
  • Regularly backup Elasticsearch snapshots.
  • Restrict Kibana access using roles.

8. Conclusion: Centralized Logging Deployment Checklist

Before putting the system into production, verify the following:

  1. Have you installed and secured Elasticsearch + Kibana?
  2. Has Filebeat been deployed on all VPS servers?
  3. Have important logs (nginx, auth, application) been shipped?
  4. Have you created necessary dashboards and alert rules?
  5. Do you have a log retention and backup policy?
  6. Can the system scale when log volume increases?

Implementing the ELK Stack gives you full control over logs from multiple VPS, enables early incident detection, and greatly improves debugging efficiency. It is an essential foundation for modern production systems in 2026.

Hope this detailed guide helps you successfully build a powerful Centralized Logging system!