
In this blog post, we will show you how to set up a basic ELK stack for Log Management on AlmaLinux 10. The ELK Stack is a popular open-source solution used for log management, monitoring, and data analysis. It consists of three main components: Elasticsearch, Logstash, and Kibana. Logstash collects and processes log data from various sources, such as servers, applications, and network devices, before sending it to Elasticsearch. Elasticsearch stores and indexes the data, enabling fast and efficient searches across large volumes of logs. Kibana provides an interactive web interface that lets users visualize log data with dashboards, charts, and graphs, making it easier to identify trends, troubleshoot issues, and monitor system performance. Together, the ELK Stack helps organizations centralize logs, improve operational visibility, detect security threats, and resolve problems quickly, making it an essential tool for modern IT infrastructure and log management.
A basic ELK stack on AlmaLinux 10 is straightforward to set up and will take around 15 minutes. Let’s get started!
Table of Contents
Prerequisites
- A server running AlmaLinux 10 OS
- User privileges: root or non-root user with sudo privileges
Step 1. Update your system
Before installing anything on the server, it is a good practice to update the system packages to their latest available versions. To do that, execute the following command in your terminal on AlmaLinux 10:
dnf update -y && dnf upgrade -y
Step 2. Install Java
Java is needed for the ELK Stack because Elasticsearch is built on Java, and the Java Runtime Environment (JRE) is required to run it efficiently and reliably. To install Java, execute the following command:
dnf install java-21-openjdk -y
To check the installed Java version, execute the following command:
java -version
You should receive output similar to this:
[root@test ~]# java -version
openjdk version "26.0.1" 2026-04-21
OpenJDK Runtime Environment (Red_Hat-26.0.1.0.8-1) (build 26.0.1+8)
OpenJDK 64-Bit Server VM (Red_Hat-26.0.1.0.8-1) (build 26.0.1+8, mixed mode, sharing)
Step 3. Install Elasticsearch
Now, to install Elasticsearch so we can set up log management on AlmaLinux 10, first we need to add the GPG key:
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
To create the Elasticsearch repository, execute the following command:
nano /etc/yum.repos.d/elasticsearch.repo
And paste the following lines of code:
[elasticsearch]
name=Elastic repository
baseurl=https://artifacts.elastic.co/packages/8.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
Save the file and close it. Then update the system:
dnf update -y
Once the system is updated, you can install Elasticsearch with the command below:
dnf install elasticsearch -y
Once installed, start and enable the Elasticsearch service:
systemctl start elasticsearch && systemctl enable elasticsearch
To check the status of the service, execute the command below:
systemctl status elasticsearch
You will get output similar to this:
[root@test ~]# systemctl status elasticsearch
● elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:16:16 CDT; 1min 24s ago
Invocation: 2cf50ece709942aaaf7e1b0341cd15cd
Docs: https://www.elastic.co
Main PID: 37076 (java)
Tasks: 99 (limit: 10644)
Memory: 1.1G (peak: 1.2G, swap: 192.8M, swap peak: 192.8M)
CPU: 45.689s
CGroup: /system.slice/elasticsearch.service
Step 4. Install Kibana
To install Kibana, execute the command below:
dnf install kibana -y
Once installed, start and enable the Kibana service:
systemctl start kibana && systemctl enable kibana
To check the status of the service, execute the command below:
systemctl status kibana
You will get output similar to this:
[root@test ~]# systemctl status kibana
● kibana.service - Kibana
Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:35:50 CDT; 6s ago
Invocation: e9615e679062496ca76b8449c8a90ccf
Docs: https://www.elastic.co
Main PID: 73503 (node)
Tasks: 11 (limit: 10644)
Memory: 240.9M (peak: 245.2M)
CPU: 5.777s
CGroup: /system.slice/kibana.service
└─73503 /usr/share/kibana/bin/../node/glibc-217/bin/node /usr/share/kibana/bin/../src/cli/kibana/dist
Step 5. Install Logstash
To install Logstash, execute the command below:
dnf install logstash -y
Once installed, start and enable the Logstash service:
systemctl start logstash && systemctl enable logstash
To check the status of the service, execute the command below:
systemctl status logstash
You will get output similar to this:
[root@test ~]# systemctl status logstash
● logstash.service - logstash
Loaded: loaded (/usr/lib/systemd/system/logstash.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:24:47 CDT; 6s ago
Invocation: 6e502b0f2a474a3d8103ba885b8ef01c
Main PID: 38152 (java)
Tasks: 15 (limit: 10644)
Memory: 457.3M (peak: 457.6M)
CPU: 11.659s
CGroup: /system.slice/logstash.service
In the next steps, we will configure Elasticsearch, Logstash, and Kibana to work together.
Step 6. Configure Elasticsearch
To configure Elasticsearch. Open the following file:
nano /etc/elasticsearch/elasticsearch.yml
And modify the following lines to look like this:
cluster.name: elk-cluster
node.name: node-1
network.host: 0.0.0.0
http.port: 9200
discovery.type: single-node
xpack.security.enabled: false
Once done, restart the Elasticsearch service:
systemctl restart elasticsearch
To check if everything is OK, run the following command:
curl http://localhost:9200
You should receive output similar to this:
[root@test ~]# curl http://localhost:9200
{
"name" : "node-1",
"cluster_name" : "elk-cluster",
"cluster_uuid" : "kiZUBK1yRCOt9vPtqlgD-w",
"version" : {
"number" : "8.19.18",
"build_flavor" : "default",
"build_type" : "rpm",
"build_hash" : "e8ac685d1710aae2c9fc9ca61e2956ab9424d5f8",
"build_date" : "2026-06-26T10:09:47.981719133Z",
"build_snapshot" : false,
"lucene_version" : "9.12.2",
"minimum_wire_compatibility_version" : "7.17.0",
"minimum_index_compatibility_version" : "7.0.0"
},
"tagline" : "You Know, for Search"
}
Step 7. Configure Kibana
To configure Kibana, open the following file:
nano /etc/kibana/kibana.yml
Modify the following lines to look like this:
server.port: 5601
server.host: "0.0.0.0"
elasticsearch.hosts:
- "http://localhost:9200"
Save the file, close it, and restart the Kibana service:
systemctl restart kibana
Step 8. Configure Logstash
To configure Logstash, you need to create the following file:
nano /etc/logstash/conf.d/beats.conf
Paste the following lines of code:
input {
beats {
port => 5044
}
}
filter {
}
output {
elasticsearch {
hosts => ["http://localhost:9200"]
index => "logs-%{+YYYY.MM.dd}"
}
stdout {
codec => rubydebug
}
}
Save the file and close it. To test the connection, execute the command below:
/usr/share/logstash/bin/logstash --config.test_and_exit -f /etc/logstash/conf.d/beats.conf
You should get the following output:
Configuration OK
[INFO ] 2026-07-18 21:43:45.094 [LogStash::Runner] runner - Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash
This means that the configuration is OK.
Step 9. Install and Configure Filebeat
Filebeat is important in an ELK setup because it efficiently collects log files from servers and applications and securely forwards them to Logstash or Elasticsearch for centralized processing, storage, and analysis. Filebeat is part of the Elastic Beats family, not the original ELK Stack. However, in modern deployments, Filebeat is commonly used alongside ELK because it is lightweight, efficient, and better suited to collecting and forwarding logs than Logstash reading log files directly.
To install Filebeat, execute the following command:
dnf install filebeat -y
Once installed, start and enable the Filebeat service:
systemctl start filebeat && systemctl enable filebeat
To check the status of the service, execute the command below:
systemctl status filebeat
You will get output similar to this:
root@test ~]# systemctl status filebeat
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:44:47 CDT; 6s ago
Invocation: 33fbfaa916914ef09b3de896834d9fe6
Docs: https://www.elastic.co/beats/filebeat
Main PID: 81805 (filebeat)
Tasks: 6 (limit: 10644)
Memory: 141.1M (peak: 141.3M)
CPU: 230ms
CGroup: /system.slice/filebeat.service
To configure Filebeat, open the following file:
nano /etc/filebeat/filebeat.yml
And modify the following lines of code to look like this:
filebeat.inputs:
- type: filestream
enabled: true
paths:
- /var/log/*.log
- /var/log/messages
- /var/log/secure
#output.elasticsearch:
output.logstash:
hosts: ["localhost:5044"]
setup.kibana:
host: "localhost:5601"
Save the file and close it.
Enable the system module:
filebeat modules enable system
You should get the following output:
[root@test ~]# filebeat modules enable system
Enabled system
Restart the Filebeat service:
systemctl restart filebeat
To see if the previous configuration works with the log file, check the status of the Filebeat service:
systemctl status filebeat
If everything is OK with the service’s output, you will see a message indicating that Filebeat sends log files to Logstash or directly to Elasticsearch.
root@test ~]# systemctl status filebeat
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:58:14 CDT; 1s ago
Invocation: 66901e86e08446c99181da0a84f75386
Docs: https://www.elastic.co/beats/filebeat
Main PID: 83070 (filebeat)
Tasks: 6 (limit: 10644)
Memory: 47.5M (peak: 47.8M)
CPU: 162ms
CGroup: /system.slice/filebeat.service
└─83070 /usr/share/filebeat/bin/filebeat --environment systemd -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat --path.config /etc/filebeat --path.data /var/>
Jul 17 18:58:14 test.vps systemd[1]: Started filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch..
How does the workflow work?
In the configured ELK stack, Filebeat continuously monitors log files (such as /var/log/messages and /var/log/secure) on the AlmaLinux server. When new log entries are detected, Filebeat forwards them to Logstash over TCP port 5044. Logstash acts as the processing layer, where logs can be filtered, parsed, enriched, or transformed before being sent to Elasticsearch on port 9200. Elasticsearch indexes and stores the logs, making them searchable and efficient to query. Finally, Kibana connects to Elasticsearch on port 5601, providing a web interface where users can search, filter, visualize, and analyze log data in real time through dashboards and the Discover view.
Conclusion
That’s it. You successfully installed the ELK Stack on AlmaLinux 10.
Of course, you do not have to install it yourself if you have difficulty and are not familiar with Linux. All you have to do is sign up for one of our NVMe VPS plans and submit a support ticket. Our admins are available 24/7 and will help you with any aspect of installing ELK Stack.
If you liked this post about setting up a basic ELK stack for log management on AlmaLinux 10, please share it with your friends or leave a reply below. Thanks.
