How to Set Up Basic ELK Stack (or Lightweight Alternative) for Log Management on AlmaLinux 10

How to Set Up Basic ELK Stack (or Lightweight Alternative) for Log Management on AlmaLinux 10

In this blog post, we will show you how to set up a basic ELK stack for Log Management on AlmaLinux 10. The ELK Stack is a popular open-source solution used for log management, monitoring, and data analysis. It consists of three main components: Elasticsearch, Logstash, and Kibana. Logstash collects and processes log data from various sources, such as servers, applications, and network devices, before sending it to Elasticsearch. Elasticsearch stores and indexes the data, enabling fast and efficient searches across large volumes of logs. Kibana provides an interactive web interface that lets users visualize log data with dashboards, charts, and graphs, making it easier to identify trends, troubleshoot issues, and monitor system performance. Together, the ELK Stack helps organizations centralize logs, improve operational visibility, detect security threats, and resolve problems quickly, making it an essential tool for modern IT infrastructure and log management.

A basic ELK stack on AlmaLinux 10 is straightforward to set up and will take around 15 minutes. Let’s get started!

Prerequisites

Step 1. Update your system

Before installing anything on the server, it is a good practice to update the system packages to their latest available versions. To do that, execute the following command in your terminal on AlmaLinux 10:

dnf update -y && dnf upgrade -y

Step 2. Install Java

Java is needed for the ELK Stack because Elasticsearch is built on Java, and the Java Runtime Environment (JRE) is required to run it efficiently and reliably. To install Java, execute the following command:

dnf install java-21-openjdk -y

To check the installed Java version, execute the following command:

java -version

You should receive output similar to this:

[root@test ~]# java -version
openjdk version "26.0.1" 2026-04-21
OpenJDK Runtime Environment (Red_Hat-26.0.1.0.8-1) (build 26.0.1+8)
OpenJDK 64-Bit Server VM (Red_Hat-26.0.1.0.8-1) (build 26.0.1+8, mixed mode, sharing)

Step 3. Install Elasticsearch

Now, to install Elasticsearch so we can set up log management on AlmaLinux 10, first we need to add the GPG key:

rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch

To create the Elasticsearch repository, execute the following command:

nano /etc/yum.repos.d/elasticsearch.repo

And paste the following lines of code:

[elasticsearch]
name=Elastic repository
baseurl=https://artifacts.elastic.co/packages/8.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md

Save the file and close it. Then update the system:

dnf update -y

Once the system is updated, you can install Elasticsearch with the command below:

dnf install elasticsearch -y

Once installed, start and enable the Elasticsearch service:

systemctl start elasticsearch && systemctl enable elasticsearch

To check the status of the service, execute the command below:

systemctl status elasticsearch

You will get output similar to this:

[root@test ~]# systemctl status elasticsearch
● elasticsearch.service - Elasticsearch
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:16:16 CDT; 1min 24s ago
Invocation: 2cf50ece709942aaaf7e1b0341cd15cd
Docs: https://www.elastic.co
Main PID: 37076 (java)
Tasks: 99 (limit: 10644)
Memory: 1.1G (peak: 1.2G, swap: 192.8M, swap peak: 192.8M)
CPU: 45.689s
CGroup: /system.slice/elasticsearch.service

Step 4. Install Kibana

To install Kibana, execute the command below:

dnf install kibana -y

Once installed, start and enable the Kibana service:

systemctl start kibana && systemctl enable kibana

To check the status of the service, execute the command below:

systemctl status kibana

You will get output similar to this:

[root@test ~]# systemctl status kibana
● kibana.service - Kibana
Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:35:50 CDT; 6s ago
Invocation: e9615e679062496ca76b8449c8a90ccf
Docs: https://www.elastic.co
Main PID: 73503 (node)
Tasks: 11 (limit: 10644)
Memory: 240.9M (peak: 245.2M)
CPU: 5.777s
CGroup: /system.slice/kibana.service
└─73503 /usr/share/kibana/bin/../node/glibc-217/bin/node /usr/share/kibana/bin/../src/cli/kibana/dist

Step 5. Install Logstash

To install Logstash, execute the command below:

 dnf install logstash -y

Once installed, start and enable the Logstash service:

systemctl start logstash && systemctl enable logstash

To check the status of the service, execute the command below:

systemctl status logstash

You will get output similar to this:

[root@test ~]# systemctl status logstash
● logstash.service - logstash
Loaded: loaded (/usr/lib/systemd/system/logstash.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:24:47 CDT; 6s ago
Invocation: 6e502b0f2a474a3d8103ba885b8ef01c
Main PID: 38152 (java)
Tasks: 15 (limit: 10644)
Memory: 457.3M (peak: 457.6M)
CPU: 11.659s
CGroup: /system.slice/logstash.service

In the next steps, we will configure Elasticsearch, Logstash, and Kibana to work together.

Step 6. Configure Elasticsearch

To configure Elasticsearch. Open the following file:

nano /etc/elasticsearch/elasticsearch.yml

And modify the following lines to look like this:

cluster.name: elk-cluster

node.name: node-1

network.host: 0.0.0.0

http.port: 9200

discovery.type: single-node

xpack.security.enabled: false

Once done, restart the Elasticsearch service:

systemctl restart elasticsearch

To check if everything is OK, run the following command:

curl http://localhost:9200

You should receive output similar to this:

[root@test ~]# curl http://localhost:9200
{
"name" : "node-1",
"cluster_name" : "elk-cluster",
"cluster_uuid" : "kiZUBK1yRCOt9vPtqlgD-w",
"version" : {
"number" : "8.19.18",
"build_flavor" : "default",
"build_type" : "rpm",
"build_hash" : "e8ac685d1710aae2c9fc9ca61e2956ab9424d5f8",
"build_date" : "2026-06-26T10:09:47.981719133Z",
"build_snapshot" : false,
"lucene_version" : "9.12.2",
"minimum_wire_compatibility_version" : "7.17.0",
"minimum_index_compatibility_version" : "7.0.0"
},
"tagline" : "You Know, for Search"
}

Step 7. Configure Kibana

To configure Kibana, open the following file:

nano /etc/kibana/kibana.yml

Modify the following lines to look like this:

server.port: 5601

server.host: "0.0.0.0"

elasticsearch.hosts:
- "http://localhost:9200"

Save the file, close it, and restart the Kibana service:

systemctl restart kibana

Step 8. Configure Logstash

To configure Logstash, you need to create the following file:

nano /etc/logstash/conf.d/beats.conf

Paste the following lines of code:

input {
beats {
port => 5044
}
}

filter {

}

output {

elasticsearch {
hosts => ["http://localhost:9200"]
index => "logs-%{+YYYY.MM.dd}"
}

stdout {
codec => rubydebug
}
}

Save the file and close it. To test the connection, execute the command below:

/usr/share/logstash/bin/logstash --config.test_and_exit -f /etc/logstash/conf.d/beats.conf

You should get the following output:

Configuration OK
[INFO ] 2026-07-18 21:43:45.094 [LogStash::Runner] runner - Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash

This means that the configuration is OK.

Step 9. Install and Configure Filebeat

Filebeat is important in an ELK setup because it efficiently collects log files from servers and applications and securely forwards them to Logstash or Elasticsearch for centralized processing, storage, and analysis. Filebeat is part of the Elastic Beats family, not the original ELK Stack. However, in modern deployments, Filebeat is commonly used alongside ELK because it is lightweight, efficient, and better suited to collecting and forwarding logs than Logstash reading log files directly.

To install Filebeat, execute the following command:

dnf install filebeat -y

Once installed, start and enable the Filebeat service:

systemctl start filebeat && systemctl enable filebeat

To check the status of the service, execute the command below:

systemctl status filebeat

You will get output similar to this:

root@test ~]# systemctl status filebeat
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:44:47 CDT; 6s ago
Invocation: 33fbfaa916914ef09b3de896834d9fe6
Docs: https://www.elastic.co/beats/filebeat
Main PID: 81805 (filebeat)
Tasks: 6 (limit: 10644)
Memory: 141.1M (peak: 141.3M)
CPU: 230ms
CGroup: /system.slice/filebeat.service

To configure Filebeat, open the following file:

nano /etc/filebeat/filebeat.yml

And modify the following lines of code to look like this:

filebeat.inputs:

- type: filestream

enabled: true

paths:
- /var/log/*.log
- /var/log/messages
- /var/log/secure

#output.elasticsearch:

output.logstash:
hosts: ["localhost:5044"]

setup.kibana:
host: "localhost:5601"

Save the file and close it.

Enable the system module:

filebeat modules enable system

You should get the following output:

Need a fast and easy fix?
✔ Unlimited Managed Support
✔ Supports Your Software
✔ 2 CPU Cores
✔ 2 GB RAM
✔ 50 GB PCIe4 NVMe Disk
✔ 1854 GeekBench Score
✔ Unmetered Data Transfer
NVME 2 VPS

Now just $43 .99
/mo

GET YOUR VPS
[root@test ~]#  filebeat modules enable system
Enabled system

Restart the Filebeat service:

systemctl restart filebeat

To see if the previous configuration works with the log file, check the status of the Filebeat service:

systemctl status filebeat

If everything is OK with the service’s output, you will see a message indicating that Filebeat sends log files to Logstash or directly to Elasticsearch.

root@test ~]# systemctl status filebeat
● filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch.
Loaded: loaded (/usr/lib/systemd/system/filebeat.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-07-17 18:58:14 CDT; 1s ago
Invocation: 66901e86e08446c99181da0a84f75386
Docs: https://www.elastic.co/beats/filebeat
Main PID: 83070 (filebeat)
Tasks: 6 (limit: 10644)
Memory: 47.5M (peak: 47.8M)
CPU: 162ms
CGroup: /system.slice/filebeat.service
└─83070 /usr/share/filebeat/bin/filebeat --environment systemd -c /etc/filebeat/filebeat.yml --path.home /usr/share/filebeat --path.config /etc/filebeat --path.data /var/>

Jul 17 18:58:14 test.vps systemd[1]: Started filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch..

How does the workflow work?

In the configured ELK stack, Filebeat continuously monitors log files (such as /var/log/messages and /var/log/secure) on the AlmaLinux server. When new log entries are detected, Filebeat forwards them to Logstash over TCP port 5044. Logstash acts as the processing layer, where logs can be filtered, parsed, enriched, or transformed before being sent to Elasticsearch on port 9200. Elasticsearch indexes and stores the logs, making them searchable and efficient to query. Finally, Kibana connects to Elasticsearch on port 5601, providing a web interface where users can search, filter, visualize, and analyze log data in real time through dashboards and the Discover view.

Conclusion

That’s it. You successfully installed the ELK Stack on AlmaLinux 10.

Of course, you do not have to install it yourself if you have difficulty and are not familiar with Linux. All you have to do is sign up for one of our NVMe VPS plans and submit a support ticket. Our admins are available 24/7 and will help you with any aspect of installing ELK Stack.

If you liked this post about setting up a basic ELK stack for log management on AlmaLinux 10, please share it with your friends or leave a reply below. Thanks.

Leave a Comment