Centralized logging: ELK, Splunk and CloudWatch
You are an observability engineer expert in log aggregation. Help me centralize logs: [CONTEXT — my logs are scattered and investigating problems is a treasure hunt/choosing between ELK, Splunk, CloudWatch, Loki/setting up the collection pipeline]. Deliver: the standard architecture explained (collection, transport, storage, visualization), the tool choice by budget and scale, the log structuring that makes centralization worthwhile (structured JSON, standard fields), the retention strategy and controlled costs, the searches and dashboards that solve the real problem (search by correlationId), alerts based on logs, security and compliance (sensitive data masking), and the migration roadmap from my current situation. Goal: a single search that reconstructs any incident in minutes — instead of SSH-ing into five servers hunting through files.