Logstash

Logstash is the open-source data processing pipeline maintained by Elastic, a publicly traded company (NYSE: ESTC) founded in 2012 by Shay Banon, Simon Willnauer, Steven Schuurman, and Uri Boness.

Reviewed by 7wData

On this page

Profile

Logstash is an open-source data processing pipeline that collects, transforms, and routes logs and events from multiple sources to storage or analytics platforms.

Logstash is the open-source data processing pipeline maintained by Elastic, a publicly traded company (NYSE: ESTC) founded in 2012 by Shay Banon, Simon Willnauer, Steven Schuurman, and Uri Boness. Jordan Sissel, the original creator of Logstash, joined Elastic's ecosystem alongside Kibana (developed by Rashid Khan) to form what became the ELK Stack. Elastic acquired Logstash in August 2013 and has integrated it as a foundational component of the broader Elastic Stack.

Logstash ingests data from multiple sources—logs, events, metrics, and traces—transforms it through over 200 configurable plugins, and routes it to downstream systems including Elasticsearch, files, or third-party services. The software is written in a blend of Java (49.7%) and Ruby (45.2%), enabling multithreaded data processing with extensive filtering capabilities. As of fiscal 2025, Elastic reported $1.483 billion in revenue, up 17% year-over-year, with Elastic Cloud revenue reaching $688 million.

The company employs approximately 5,067 people globally. Logstash is used by over 7,270 companies worldwide, with strong adoption across software development, big data, and cloud services sectors. Major named users include Netflix, which operates nearly 800 Elasticsearch nodes for logging; Accenture; Fujitsu; Tripwire; and Medium.

In 2025, Elastic introduced Streams, an agentic AI-powered solution that automates log parsing and field extraction, reducing manual SRE overhead. The observability layer, which relies on Logstash for data ingestion, earned Elastic recognition as a Leader in both the 2025 Gartner Magic Quadrant and IDC MarketScape for observability platforms. Recent releases, including Logstash 9.4.2 (May 2026), upgraded JRuby to version 10 and now require Java 21, reflecting ongoing modernization. The competitive landscape includes Fluentd (stronger on extensibility) and Vector (better resource efficiency for cloud-native workloads), though Logstash remains the go-to choice for complex enterprise log enrichment and transformation pipelines integrated with Elasticsearch.

Track Logstash and 240+ vendors.

335k+ subscribers read the daily AI & data note. One email, both newsletters. Unsubscribe anytime.

Who buys this

  • Enterprise IT and DevOps teams building centralized logging and observability across complex infrastructure
  • Financial services and healthcare organizations requiring compliant log processing and retention
  • Cloud-native SaaS companies and software platforms managing high-volume application and infrastructure logs
  • Large technology companies operating distributed systems needing real-time data ingestion and alerting

Publicly disclosed clients

  • Netflix
  • Accenture
  • Fujitsu
  • Tripwire
  • Medium
  • GitHub
  • Nikkei

Strengths and what to watch

Strengths

  • Largest plugin ecosystem (200+) with seamless native integration to Elasticsearch and Kibana
  • Proven at scale across Fortune 500 companies and enterprises managing petabytes of log data daily
  • Active development and regular releases with Java 21 modernization and new recovery features for production stability

Watch for

  • Resource overhead compared to newer Rust-based alternatives like Vector; Logstash requires 500MB–2GB RAM vs Vector's 100–200MB
  • Competing displacement pressure from cloud-managed observability platforms and lightweight edge collectors (Fluent Bit, Vector) reducing on-premise Logstash deployments
  • JRuby/Java dependency constraints for organizations seeking minimal operational overhead; recent Java 21 requirement breaks legacy environments

Recent moves

Key Information

Industry
Logging & Monitoring
Founded
2012

Frequently Asked Questions

What is Logstash?

Logstash is an open-source data processing pipeline that collects, transforms, and routes logs, events, and metrics from multiple sources to storage systems like Elasticsearch. Maintained by Elastic, it features over 200 plugins for data enrichment and integration with analytics platforms.

Is Logstash part of the ELK Stack?

Yes. Logstash, created by Jordan Sissel, is the data processing component of the ELK Stack, alongside Elasticsearch and Kibana. Elastic acquired Logstash in August 2013 and integrated it as a foundational component of the Elastic Stack for data ingestion and transformation.

How much memory does Logstash require?

Logstash typically requires 500MB to 2GB of RAM depending on configuration and workload complexity. Lighter alternatives like Vector use only 100–200MB, making them attractive for resource-constrained cloud environments. However, Logstash's broader plugin ecosystem makes it preferable for complex enterprise log enrichment and transformation pipelines.

How does Logstash compare to Vector?

Logstash excels in complex enterprise log enrichment with 200+ plugins and native Elasticsearch integration, but requires 500MB–2GB RAM. Vector prioritizes resource efficiency (100–200MB) and cloud-native deployments. For petabyte-scale Fortune 500 operations, Logstash's proven enterprise track record wins; for edge collectors, Vector's lighter footprint prevails.

What companies use Logstash?

Over 7,270 companies use Logstash globally, including Netflix (which operates nearly 800 Elasticsearch nodes), Accenture, Fujitsu, GitHub, Medium, and Tripwire. It's widely adopted across software development, big data, cloud services, financial services, and healthcare sectors, reflecting its strength in enterprise observability.

What's new in Logstash?

Logstash 9.4.2 (May 2026) upgraded JRuby to version 10 and now requires Java 21. Elastic also launched Streams, an AI-powered solution automating log parsing and field extraction to reduce SRE overhead. Elastic was recognized as an observability Leader in the 2025 Gartner Magic Quadrant.

How Logstash compares

Direct head-to-head against 3 competitors. Picked by 7wData.

This company

Logstash

Positioning
Logstash is an open-source data processing pipeline that collects, transforms, and routes logs and events from multiple sources to storage or analytics platforms.
Customer segments
Enterprise IT and DevOps teams building centralized logging and observability across complex infrastructure
Strengths
Largest plugin ecosystem (200+) with seamless native integration to Elasticsearch and Kibana
Watch for
Resource overhead compared to newer Rust-based alternatives like Vector; Logstash requires 500MB–2GB RAM vs Vector's 100–200MB
Recent moves
Logstash 9.4.2 released with JRuby 10 upgrade and Java 21 requirement

Fluent Bit

Positioning
CNCF-graduated lightweight agent for logs, metrics, and traces; preferred edge collector for Kubernetes and cloud-native infrastructure.
Customer segments
DevOps and platform engineering teams in Kubernetes-first organizations; embedded systems and IoT deployments needing minimal resource overhead.
Strengths
Processes up to 40x more log volume per CPU than Fluentd; 15 billion cumulative downloads; benchmarked under 1MB memory on edge nodes.
Watch for
Limited transformation depth; complex log enrichment requires a separate aggregation tier, adding architectural overhead buyers consistently cite as friction.
Recent moves
CNCF published official Fluentd-to-Fluent Bit migration guide, October 2025, formalizing community consolidation around Fluent Bit as the primary project.

Vector

Positioning
Rust-based OSS data pipeline for logs and metrics; open-source foundation for Datadog Observability Pipelines commercial product.
Customer segments
SRE and platform teams at mid-to-large tech companies; Datadog customers seeking pre-ingestion cost reduction via log filtering.
Strengths
Written in Rust; 100-200MB RAM at runtime versus Logstash's 500MB-2GB; largest known user processes 500TB of observability data daily.
Watch for
Increasingly steered toward Datadog's commercial ecosystem; teams not on Datadog report feature prioritization favors Datadog sinks over neutral routing destinations.
Recent moves
Vector deprecated azure_monitor_logs sink in 2025, launching new Azure Logs Ingestion API sink ahead of Microsoft's September 2026 API retirement.

Cribl

Positioning
Vendor-neutral enterprise data pipeline for log routing, cost reduction, and schema normalization across SIEM and observability destinations.
Customer segments
Enterprise security and observability teams with multi-vendor stacks; Fortune 500 IT ops and SOC teams managing ingestion costs.
Strengths
Vendor-neutral routing reduces ingestion costs by filtering before data reaches Splunk, Datadog, or Elasticsearch; purpose-built for enterprise compliance and cost control.
Watch for
$3.5B valuation on $300M ARR; IPO positioning may drive pricing changes customers cite as a risk to long-term contract predictability.
Recent moves
Cribl launched Copilot Editor, June 2025, adding AI-powered pipeline building that translates raw logs into standard schemas without manual configuration.

Sources

  1. github.com — Logstash repository, maintainer, current version (9.4.2), active development metrics, codebase composition
  2. www.elastic.co — Elastic company founding (2012), founders (Shay Banon, Simon Willnauer, Steven Schuurman, Uri Boness), Logstash integration history
  3. www.crunchbase.com — Elastic funding history, Series A ($10M, 2012), Series B ($24M, 2013), Series C ($70M, 2014), IPO details (October 4, 2018)
  4. www.elastic.co — Current Logstash version, installation methods, licensing, Java 21 requirement
  5. www.elastic.co — Named customers including GitHub, Nikkei, Gigamon, CADDi, Tavily, Corvian, Brotherhood Mutual, City of Sacramento, Region Midtjylland, and others
  6. finance.yahoo.com — Elastic fiscal 2025 financial results: $1.483 billion revenue (+17% YoY), Elastic Cloud $688M (+26% YoY), employee count 5,067
  7. ir.elastic.co — Elastic Streams announcement (October 27, 2025), AI-powered log parsing and field extraction features
  8. www.elastic.co — Elastic named Leader in 2025 Gartner Magic Quadrant for Observability Platforms (July 7, 2025), second consecutive year
  9. enlyft.com — Logstash adoption metrics: 7,270+ companies using Logstash globally, top industries (Software Development, Big Data, Cloud Services), geographic distribution
  10. betterstack.com — Logstash competitive positioning vs Fluentd and Vector, resource usage (500MB-2GB RAM), plugin ecosystem size (200+), use case differentiation