Centralized Logging with EFK
A production-grade centralized logging platform with Elasticsearch, Fluent Bit and Kibana, deployed with the ECK operator, including why EFK beats ELK on small clusters, lifecycle policies, and backup you've restored.
What you'll be able to do
- Deploy Elasticsearch with ECK and size it correctly
- Build Fluent Bit pipelines that parse and route reliably
- Build a Kibana on-call dashboard with alerting
- Run snapshots, SLM and restore drills
Before you start
Kubernetes Administration Level 1.
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Modules
- 01EFK architectureWhat runs where, what stores what, how data movesRead →
- 02Elasticsearch fundamentalsShards, replicas, mappings, heapRead →
- 03ECK operator on KubernetesInstall, topology, upgradesRead →
- 04Log collection: Fluent Bit vs FluentdWhy EFK and not ELKRead →
- 05Parsing & routingMultiline, enrichment, Kubernetes metadataRead →
- 06Kibana & KQLData views, saved searchesRead →
- 07Kibana on-call dashboardFrom empty Kibana to alertsRead →
- 08Lifecycle & backupILM, SLM, snapshots, searchable snapshotsRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 24 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
Back-pressure, buffers and the pipeline that drops quietly.
Watermarks, shards and recovery.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.