elk-stack

elk-stack is a cursor rule for Cursor from sanjeed5/awesome-cursor-rules-mdc. It costs 2,476 tokens per session, scanned A, original, CC0-1.0.

A set of guidelines for the ELK stack: Elasticsearch, Logstash, and Kibana, tools used to collect, search, and view application logs. It focuses on structured JSON logging and centralized observability.

In plain words
What is it for?
Use it when designing application logging for containers, sending logs to Elasticsearch, or investigating systems through Kibana dashboards and searches.
Why use it?
It helps turn scattered, inconsistent logs into searchable records that are easier to filter and investigate. This makes diagnosing application failures and operational problems more systematic.

Cursor rule for Cursor

Written for Cursor: a Cursor rule (.mdc).

Good fit Use it when designing application logging for containers, sending logs to Elasticsearch, or investigating systems through Kibana dashboards and searches.

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/sanjeed5/awesome-cursor-rules-mdc/elk-stack
About the project

awesome-cursor-rules-mdc is a generator that creates Cursor MDC rule files from structured library information, using semantic search and language models to gather and organize guidance. Developers use it to produce reusable rules for libraries in Cursor, and the catalogue includes 200 of those rules.

sanjeed5/awesome-cursor-rules-mdc · 3,571 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/sanjeed5/awesome-cursor-rules-mdc

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for elk-stack

README.md
[![agentmods](https://agentmods.dev/badge/rules/sanjeed5/awesome-cursor-rules-mdc/elk-stack.svg)](https://agentmods.dev/rules/sanjeed5/awesome-cursor-rules-mdc/elk-stack)
Your own site
<a href="https://agentmods.dev/rules/sanjeed5/awesome-cursor-rules-mdc/elk-stack"><img src="https://agentmods.dev/badge/rules/sanjeed5/awesome-cursor-rules-mdc/elk-stack.svg" alt="Measured on agentmods" height="20"></a>
Per session 2,476 This file is loaded in full into every session.
When invoked 2,476 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.02476 $0.02476
Opus 5 $0.01238 $0.01238
Sonnet 5 $0.00495 $0.00495
Haiku 4.5 $0.00248 $0.00248

Measured 4d ago against content hash 44d1060491b4, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

elk-stack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

rules-mdc/elk-stack.mdc · 279 lines

How it starts

The opening of the file, as written. The whole thing — 279 lines — stays where its author put it; the contents beside it link to each section on GitHub.

elk-stack Best Practices

The ELK (Elasticsearch-Logstash-Kibana) stack is our standard for centralized logging and observability. Adhering to these guidelines ensures our logs are consistent, actionable, and efficient, enabling rapid troubleshooting and deep insights.

Code Organization and Structure

1. Standardize on Structured Logging

Always emit logs as structured JSON to stdout. This is the only acceptable method for application logging. Avoid writing to local files.

Rationale: stdout is the standard stream for containerized applications, easily captured by Elastic Agent or Filebeat. Structured JSON ensures logs are machine-readable and parsable without complex regex, making them immediately queryable in Elasticsearch.

✅ GOOD: Python with structlog

# app/logging_config.py
import sys
import structlog
import os

def configure_logging():
    # Define canonical fields and processors
    shared_processors = [
        structlog.stdlib.add_logger_name,
        structlog.stdlib.add_log_level,
        structlog.processors.TimeStamper(fmt="iso"),
        structlog.processors.StackInfoRenderer(),
        structlog.processors.format_exc_info,
        structlog.processors.merge_extra_context,
        # Enforce canonical fields: service_name, trace_id, span_id
        lambda logger, method_name, event_dict: event_dict.update(
            service_name=os.getenv("SERVICE_NAME", "unknown-service"),
            trace_id=os.getenv("X_B3_TRACEID", "no-trace-id"), # Example for B3 propagation
            span_id=os.getenv("X_B3_SPANID", "no-span-id"),
        ),
    ]

    if os.getenv("APP_ENV", "development") == "production":
        # Production: JSON output for log aggregators
        processors = shared_processors + [
            structlog.processors.dict_tracebacks, # Structured tracebacks
            structlog.processors.JSONRenderer(),
        ]
    else:
        # Development: Pretty printing for local readability
        processors = shared_processors + [
            structlog.dev.ConsoleRenderer(),
        ]

    structlog.configure(
        processors=processors,
        logger_factory=structlog.stdlib.LoggerFactory(),
        wrapper_class=structlog.stdlib.BoundLogger,
        cache_logger_on_first_use=True,
    )

    # Optionally, redirect standard Python logging to structlog
    # import logging
    # logging.basicConfig(handlers=[structlog.stdlib.ProcessorFormatter.wrap_for_formatter], level=os.getenv("LOG_LEVEL", "INFO").upper())
    # structlog.stdlib.ProcessorFormatter.remove_processors_from_logger(logging.getLogger())

# In your application entry point:
# from app.logging_config import configure_logging
# configure_logging()
# log = structlog.get_logger(__name__)

Read the full file on GitHub · 279 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 279 lines · 2,476 tokens per session scan A 44d1060491b4

Subscribe to this mod's changes

elk-stack is a cursor rule published in the GitHub repository sanjeed5/awesome-cursor-rules-mdc (3,571 stars, last pushed 3mo ago), licensed CC0-1.0. It adds 2,476 tokens to every session, about $0.0124 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.