Kubernetes and Cloud Native Associate (KCNA)Cloud Native ObservabilityMedium
An incident response team receives an alert about high error rates in a critical microservice. To quickly understand the context of these errors, they need to correlate the alert with detailed log messages associated with the failing requests. Which component of the observability stack is primarily responsible for storing and indexing these detailed log messages to enable efficient searching and analysis?
- AGrafana
- BPrometheus
- CAlertmanager
- DElasticsearch
Show answer & explanationAnswer & explanation
Correct answer: D. Elasticsearch
Elasticsearch is a distributed, RESTful search and analytics engine that can store and index large volumes of data, including log messages. It provides powerful search capabilities, making it ideal for correlating alerts with specific log entries and performing detailed log analysis.
Why the other options are wrong
- A. Grafana is a visualization tool, not a data store for logs.
- B. Prometheus stores time-series metrics, not detailed log messages.
- C. Alertmanager handles routing and de-duplication of alerts, not log storage.
Elasticsearch
A distributed, open-source search and analytics engine built on Apache Lucene, commonly used for log and event data storage and analysis.
- Part of the 'E' in the ELK stack (Elasticsearch, Logstash, Kibana).
- Provides powerful full-text search, near real-time analytics, and schema-free JSON document storage.
- Scalable horizontally to handle large volumes of data.
- Often used as a backend for log management systems.
Memory trick: Elasticsearch stores and searches logs with ease.