The ELK Stack (now branded "Elastic Stack") is the most popular open-source log pipeline:
- Elasticsearch — distributed search/storage engine.
- Logstash — log shipping/parsing pipeline.
- Kibana — visualisation, search and SIEM UI.
- Beats (Filebeat, Winlogbeat, Packetbeat) — lightweight shippers.
- Elastic SIEM — detection rules, timeline, cases.
For a CySA+ analyst it is the budget alternative to Splunk and the core of many SOAR-friendly open SOC stacks (Wazuh, Security Onion).