LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

Which tools belong to which job in a logging stack?

Collectors gather on the device, parsers normalise, a transport moves the data, an indexed store keeps it, and an analysis front-end queries it — most "log products" are really bundles of several of these roles.

Job Typical tools
Collectors (on the end device) rsyslog, Fluentd, Filebeat, Winlogbeat, NXLog
Formats encountered plain text, JSON, XML, vendor formats (Check Point, Windows EVTX)
Normalisation (parsing and structuring) Logstash, Fluentd, Vector
Transport syslog, HTTPS/API, MQTT, Kafka, vendor protocols (Beats)
Storage / DBMS ELK stack (Elasticsearch, Logstash, Kibana), Splunk, Graylog, Loki
Analysis and visualisation Kibana, OpenSearch Dashboards, Grafana, Splunk

Two things are worth noticing. First, several tools appear in more than one row — Fluentd both collects and normalises, Splunk both stores and analyses — which is why stack diagrams rarely map one tool to one box. Second, the formats row is the reason the normalisation row exists: Windows writes EVTX, a firewall writes its own syntax, an app writes JSON, and none of them agree on what to call a source IP address.

Go deeper:

  • tool Grafana Loki documentation — a log store that indexes labels instead of full text, the main design alternative to Elasticsearch.
  • tool Fluent Bit manual — the lightweight collector: inputs, parsers, filters and outputs, i.e. the whole stack in one small agent.

From Quiz: ITIA / IT Infrastructure Monitoring: Logging, Monitoring and Observability | Updated: Sep 17, 2026