Skip to content

Choose a data onboarding path

The managed platform uses OpenTelemetry as the standard observability data model.

For observability workloads:

  • OpenTelemetry provides the common telemetry model for logs, metrics, and traces;
  • Elastic Agent provides the standard collection and telemetry gateway layer;
  • Fleet provides centralized management of Elastic Agents, policies, and integrations;
  • Elasticsearch stores and analyzes the resulting telemetry;
  • Kibana provides visualization, investigation, and observability workflows.

Azure data-ingestion architecture showing applications, servers, Kubernetes, Azure services, and application data sources sending telemetry through Elastic Agent and supported integrations to managed Elasticsearch and Kibana.

OpenTelemetry-first observability

For new observability workloads, prefer OpenTelemetry conventions and OpenTelemetry-native telemetry wherever supported.

The goal is to provide a consistent representation of telemetry from:

  • applications;
  • servers and virtual machines;
  • Kubernetes;
  • Azure services;
  • databases and middleware;
  • network and security systems;
  • custom sources.

Elastic integrations that produce ECS-compatible events remain supported, but new observability designs should move toward OpenTelemetry semantic conventions and OTel-native data streams where available.

Choose by workload

Data source Recommended onboarding path
Application logs, metrics, and traces Elastic Agent with OpenTelemetry integrations
Servers and virtual machines Elastic Agent with OpenTelemetry integrations
Kubernetes Elastic Agent with OpenTelemetry integrations
Azure services Elastic Agent with OpenTelemetry integrations
Network and appliance telemetry Elastic Agent integrations, normalized for the observability pipeline
Existing Logstash pipelines Logstash where required for existing pipelines
Application search documents Elasticsearch API
Existing Elasticsearch deployment Migration or reindex process

Observability data

For logs, metrics, and traces, use Elastic Agent with OpenTelemetry integrations as the preferred architecture.

Elastic Agent can collect or receive telemetry from applications, infrastructure, Kubernetes, Azure services, and supported integrations. Fleet centrally manages the agents and their policies.

The resulting observability data should follow OpenTelemetry conventions where supported.

See Manage Elastic Agents with Fleet, then continue with onboard observability data.

OpenTelemetry data streams

OpenTelemetry-native telemetry is stored using signal-specific data streams. Typical patterns include:

Signal Data stream pattern
Logs logs-*.otel-*
Metrics metrics-*.otel-*
Traces traces-*.otel-*

ECS-compatible streams can continue to exist for integrations and existing workloads that require them.

Search and application data

Application search data is different from observability telemetry.

Search documents, knowledge content, vector data, and application records are typically sent directly to Elasticsearch using the Elasticsearch API. These documents do not need to be represented as OpenTelemetry telemetry.

Continue with onboard search data.

Existing pipelines

Existing Logstash and ECS-based pipelines can continue to operate when required.

For new observability onboarding, prefer the OpenTelemetry-first architecture unless there is a specific compatibility requirement.

Use the deployment endpoints

Use only the Elasticsearch, Fleet, and other endpoints provided for your deployment.

The source system must be able to:

  • resolve the endpoint hostname;
  • reach the endpoint over the configured network path;
  • trust the TLS certificate;
  • authenticate using an approved credential.

Do not use administrator credentials for normal data ingestion.

Start small

Before onboarding the full production workload:

  1. configure one representative source;
  2. verify that Elastic Agent is receiving or collecting the telemetry;
  3. confirm logs, metrics, or traces are represented correctly;
  4. verify the expected OpenTelemetry attributes and resource metadata;
  5. confirm the data appears in the expected Elasticsearch data streams;
  6. validate the data in Kibana;
  7. then expand onboarding to additional sources.

Need help choosing?

Use:

  • AI chat: https://copilot.ivedha.cloud
  • Support portal: https://support.ivedha.com/

For the next step, choose either: