Build a distributed logging stack (ELK / Loki)

About Build a distributed logging stack (ELK / Loki)

Ship lines off N hosts, choose what to index, age data through tiers, retain or delete on schedule, and survive a chatty service — built one decision at a time.

Difficulty
intermediate
Time
about 80 minutes
Stages
9
Topic
Observability: Metrics, Logs & Traces

How this problem is worked

Nine stages, from what the thing is for to how it compares with the real implementations. Each asks one question, and the simulator runs the architecture you draw against the requirements you wrote.

  1. 01Purpose & invariantsWhat is this for, and what must always be true of it?
  2. 02Workload characterizationWho writes, who reads, and in what shapes?
  3. 03Data model & on-disk formatWhat does the data look like at rest?
  4. 04Core algorithmsHow do the write path and the read path actually work?
  5. 05Distribution & replicationHow does this scale out and survive losing a machine?
  6. 06Consistency & correctnessUnder concurrency and failure, what is guaranteed?
  7. 07Failure modes & recoveryWhat actually happens when each part fails?
  8. 08Operational characteristicsCan a human run this at three in the morning?
  9. 09Trade-offs & comparisonWhere does this sit against the alternatives?

Primary sources for this problem

  • Grafana Labs — 'Loki: Like Prometheus, but for logs' (announcement, 2018)
  • Elastic — Data tiers and Index Lifecycle Management (elastic.co/guide)
  • Grafana — Loki labels and cardinality best practices (grafana.com/docs/loki)
  • Fluent Bit — Backpressure and storage configuration (docs.fluentbit.io)
  • Filebeat — Internal queue tuning (elastic.co/guide/en/beats)
  • Promtail — Positions, WAL, and the checkpoint-before-send gotcha (grafana.com/docs/loki)
  • OpenTelemetry — Sampling strategies (head vs tail) (opentelemetry.io)
  • Designing Data-Intensive Applications, Kleppmann — Ch 3 (storage), Ch 11 (stream processing)

Browse the full problem catalog, or see what the simulator does and does not model.