In the operation,maintenance and security of IT,improving the log is an important means to help technicians quickly locate problems,analyze the causes of failures and optimize the system.In projects with large business volume and high concurrency,the ELK of a single node will cause problems such as data loss and slow query.This paper proposes the solution of using Elasticsearch cluster and multi-node logstash to optimize the log performance of medium and large systems.