ELK Stack · Docs

Quickstart

Deploy the stack and confirm an event in Discover.

One-click deploy

Deploy on Railway

Open the template and keep its defaults. Railway generates the credentials and configures the service references. Review Configuration and Cost, then confirm your deployment in Railway.

Wait for Elasticsearch, Logstash and Kibana to become healthy. Open Kibana’s public HTTPS domain on port 5601. Keep Elasticsearch and Logstash private. If a service fails, inspect its logs using Troubleshooting.

Optional manual Railway setup

Create services named Elasticsearch, Logstash, and Kibana in the same project, environment, and region. Connect each service to its corresponding repository directory. Each directory includes a Dockerfile and railway.json.

Service rootVolume mountHealthcheckPORT variable
/elasticsearch/usr/share/elasticsearch/data/ready8081
/logstash/usr/share/logstash/data/_node/pipelines/main9600
/kibanaNone/ready8082

Copy the reference expressions from Configuration. Generate credentials in your password manager and enter them directly in Railway Variables. Keep the original credentials and encryption keys stable.

Deploy Elasticsearch first, then Logstash and Kibana. Generate an HTTPS domain for Kibana targeting UI port 5601, not readiness port 8082. Leave Elasticsearch and Logstash private.

Connect your application

In a producer service in the same Railway environment, set:

LOGSTASH_URL=http://${{Logstash.RAILWAY_PRIVATE_DOMAIN}}:8080
LOGSTASH_PASSWORD=${{Logstash.INPUT_PASSWORD}}

The private URL is not reachable from your laptop. Send an event from the producer service:

curl --fail-with-body --user "shipper:$LOGSTASH_PASSWORD" \
  -H 'Content-Type: application/json' "$LOGSTASH_URL" \
  -d '{"message":"hello from Railway","service":"my-app","level":"info"}'

Confirm indexing

Open Kibana's HTTPS domain. Log in as elastic with the original Elasticsearch ELASTIC_PASSWORD from Railway Variables.

Open Analytics → Discover → Create a data view. Set the index pattern to elk-logs and time field to @timestamp. Search message : "hello from Railway" and widen the time range if needed.

Finding the original event confirms indexing. Use a limited viewer account for routine access, as described in the template's OPERATIONS.md.

On this page