Overview
Authenticated JSON logs, persistent storage, and Kibana search on Railway.
Run Elasticsearch, Logstash, and Kibana in the same Railway environment. Send application events to private Logstash intake, then search them in Kibana.
Start here
- Quickstart: deploy and verify your first event.
- Sending data: use the Node.js, Python, or Go examples.
- Live demo: explore synthetic logs in an existing dashboard.
What is included
Official Elastic images pinned by version and digest. Authenticated JSON intake with a restricted Elasticsearch writer. Persistent Elasticsearch data, a Logstash queue, and a dead letter queue. Stable Kibana encryption keys and log lifecycle configuration for new volumes.
Operating boundaries
Only Kibana is public. Service traffic uses unencrypted HTTP on Railway's private network. Producers must run in the same project and environment. Application logs must be sent explicitly; Railway platform logs are not collected automatically.
This is a single-node stack. Volumes provide persistence, not high availability or backups. An intake success means accepted, not indexed. Confirm delivery through Kibana Discover.
Before production
Review cost, configuration, and upgrade recovery. Plan backups, monitor disk use and queue occupancy, and avoid sending passwords, tokens, or personal data.
Custom template source is MIT licensed. Elastic images retain their upstream licenses. See the template's LICENSE and NOTICE.md.