Quiz Entry - updated: 2026.09.17
Which tools belong to which job in a logging stack?
Collectors gather on the device, parsers normalise, a transport moves the data, an indexed store keeps it, and an analysis front-end queries it — most "log products" are really bundles of several of these roles.
| Job | Typical tools |
|---|---|
| Collectors (on the end device) | rsyslog, Fluentd, Filebeat, Winlogbeat, NXLog |
| Formats encountered | plain text, JSON, XML, vendor formats (Check Point, Windows EVTX) |
| Normalisation (parsing and structuring) | Logstash, Fluentd, Vector |
| Transport | syslog, HTTPS/API, MQTT, Kafka, vendor protocols (Beats) |
| Storage / DBMS | ELK stack (Elasticsearch, Logstash, Kibana), Splunk, Graylog, Loki |
| Analysis and visualisation | Kibana, OpenSearch Dashboards, Grafana, Splunk |
Two things are worth noticing. First, several tools appear in more than one row — Fluentd both collects and normalises, Splunk both stores and analyses — which is why stack diagrams rarely map one tool to one box. Second, the formats row is the reason the normalisation row exists: Windows writes EVTX, a firewall writes its own syntax, an app writes JSON, and none of them agree on what to call a source IP address.
Go deeper:
Grafana Loki documentation — a log store that indexes labels instead of full text, the main design alternative to Elasticsearch.
Fluent Bit manual — the lightweight collector: inputs, parsers, filters and outputs, i.e. the whole stack in one small agent.