Shay Banon | Founder & CEO
Aaron Katz | CRO
Janesh Moorjani | CFO
Elastic Overview
Elastic Stack
Updates and Roadmap
Alex Francoeur
Ingest
Ingest
Ingest
Ingest
Ingest
Elastic Common Schema
@timestamp
http.request.method
host.hostname
source.ip
geo.location
Ingest Node:
Enrichment Processor
source.ip => is_known_botnet?
geo.location => city/region/country
Adding Data
• What technology? (eg. Nginx)
• What to monitor? (eg. logs, metrics, packets)
• Where is it? (eg. paths to logfiles)
Integrations Manager
• Beats config
• Ingest node config
• Index template
• First index
• Index alias
• Index lifecycle management
policy
• Snapshot lifecycle
management policy
• Index patterns
• Kibana dashboards
• Canvas workpads
• Machine learning jobs
• Alerts
Automatically Setup
• Beats config
• Ingest node config
• Index template
• First index
• Index alias
• Index lifecycle management
policy
• Snapshot lifecycle
management policy
• Index patterns
• Kibana dashboards
• Canvas workpads
• Machine learning jobs
• Alerts
Automatically Setup
Filebeat
Metricbeat
Packetbeat
WinLogBeat
Heartbeat
Journalbeat
Beats Agent
Beats Config
• Single config language
• Installs required Beats
• Upgrades Beats
• Upgrades itself
Beats Agent
Fleet
• Centralized Config Deployment

• Centralized Beats Monitoring

• Centralized Upgrade
Management
Data Management
Frozen
Indices
Heap File system cache
Disk
Heap File system cache
Disk
Index Lifecycle
Management
Hot Nodes
1
2
3
Cold NodesWarm Nodes
1
2
3
1
2
3
Hot Nodes Cold NodesWarm Nodes
1
2
3
1 2 3
Hot Nodes Cold NodesWarm Nodes
231
2
3
Hot Nodes Cold NodesWarm Nodes
1
1
Hot Nodes Cold NodesWarm Nodes
1
2
3
1
Hot Nodes Cold NodesWarm Nodes
1
2
3
Hot Nodes Cold NodesWarm Nodes
1
2
3
Hot Nodes Cold NodesWarm Nodes
1
2
3
(coming soon to X-Pack)
Snapshot Lifecycle
Management
• Periodic scheduled backups
• Retention polices for automatic deletion
Snapshot Management
Data Transforms
Clickstream Data
Page views per minute?
Clickstream Data
99th percentile latency?
Clickstream Data
Most frequent URLs?
Clickstream Data
How long was session 1?
Clickstream Data
How long was session 1?
Clickstream Data
Average session length?
Clickstream Data
Average session length?
Session Data
Average number of pages per session?
Session Data
Most frequent exit page per session?
Session Data
Session Data
How frequently do users visit the site?
Session Data
How frequently do users visit the site?
User Data
• Pivot
• Pattern Matching
Data Transformation
Advanced ML
Analytics
• Outlier detection
• Supervised model training for regression & classification
• Ingest Prediction Processor
Advanced ML Analytics
Search
Performance
improvements
Query Before After Improvement
Fuzzy 46 qps
Phrase 4 qps
Bool AND 9.3 qps
Bool OR 3.3 qps
Term 33 qps
Query Before After Improvement
Fuzzy 46 qps 59 qps 28%
Phrase 4 qps 7 qps 87%
Bool AND 9.3 qps 23.5 qps 247%
Bool OR 3.3 qps 9.8 qps 292%
Term 33 qps 1,160 qps 3,700%
Magic WAND
"query" : "elasticsearch and lucene"
max_score(and) == 1
max_score(lucene) == 5
max_score(elasticsearch) == 3
Weak-AND
Min top-10 score and (1)
elasticsearch
(3)
lucene
(5)
<=1 ✓ ✓ ✓
> 1 and <= 4 ✗ ✓ ✓
> 4 and <= 9 ✗ ✗ ✓
> 9 ✗ ✗ ✗
Weak-AND
Weak-AND
Weak-AND
"aggs": { ... }
"track_total_hits": true
"hits": {
"total": 123456789,
"hits": [ ... ]
}
"hits": {
"total": {
"value": 10000,
"relation": "gte"
},
"hits": [ ... ]
}
Weak-AND
Search as you type
index_prefixes:

qu, qui, quic, quick
br, bro, brow, brown
fo, fox, foxe, foxes

index_phrases:
the_quick

quick_brown

brown_fox

fox_jumped

jumped_over
over_the
the_lazy
lazy_dog
match_phrase_prefix: “quick brown f*”
Advanced Scoring
rank_feature:
Advanced Scoring
• Star Ratings
• PageRank
• Popularity
score = BM25(Text) + PageRank
rank_feature:
Advanced Scoring
• Star Ratings
• PageRank
• Popularity
score = BM25(Text) + Saturation(PageRank)
rank_feature:
Advanced Scoring
• Star Ratings
• PageRank
• Popularity
distance_feature:
rank_feature:
Advanced Scoring
• Date
• Geopoint
• Numeric
• Star Ratings
• PageRank
• Popularity
script_score: • Custom scoring, including vectors
distance_feature: • Date
• Geopoint
• Numeric
rank_feature:
Advanced Scoring
• Star Ratings
• PageRank
• Popularity
Work
with
WAND
script_score: • Custom scoring, including vectors
distance_feature:
rank_feature:
Advanced Scoring
• Star Ratings
• PageRank
• Popularity
• Date
• Geopoint
• Numeric
Result Pinning
Geoshapes
• v2.3: 1 dim, for numbers and dates
• v5.0: 2 dim, for geopoints
• v5.2: 2 dim, for number & date ranges
• v6.7: 7 dim, for geoshapes
BKD Trees
BKD Geoshapes
• Accurate to 1cm, vs 50m
• Index is 60% smaller
• Indexing 60% faster
• Queries 50% faster
• Plus BKD GeoPoints 80% faster indexing
BKD Geoshapes
Distributed Layer
Zen
minimum_master_nodes: 2
minimum_master_nodes: 2
minimum_master_nodes: 2
minimum_master_nodes: 1
minimum_master_nodes: 1
cluster.initial_master_nodes
Cross Cluster Search
New York London Tokyo
v5.6 v6.7 v7.x
Three Major Versions
Cross Cluster Replication
New York London Tokyo
ldn_sales ldn_sales
New York London Tokyo
tk_salesny_sales
New York London Tokyo
tk_salesny_sales
ldn_sales ldn_sales
Kibana
Security
PKI
SAML Kerberos
OpenID
Lens
New Platform
Custom
Workflows
Stable Plugin
APIs
Typescript
Shared
Services
Task Manager/Alerting
SIEM
Stack Monitoring Machine Learning
Observability
112
Templated Alerts
when [CPU] > [90%]
then alert
[alerts@me.com]
Chart-based Alerts
function my_alert()
{…}
Custom Alerts
Guides
News Feed
Thank you

Elastic Stack roadmap deep dive