Tink vs Elasticsearch Exporter

elasticsearch_exporter is Prometheus's usual Elasticsearch scrape: a :9114 /metrics endpoint of cluster health and index gauges. That is not a mechanic. Tink installs in one command, watches the Linux server, explains what is wrong, and helps you fix it.

elasticsearch_exporter exposes elasticsearch_* gauges. Tink answers “why is this VPS sick?”

Accidental sysadmins land on elasticsearch_exporter because every ELK + Prometheus diagram starts with a cluster-health scrape. Then the disk fills, nginx dies, and Grafana is quiet — nothing scraped, so nothing fired.

Tink is the other job: detect the issue on the machine, say why it happened in plain English, propose the command, and run it only after you approve. Keep elasticsearch_exporter if you already operate Prometheus and need Elasticsearch gauges. Use Tink if you run Linux servers and want a mechanic.

FeatureTinkElasticsearch Exporter
Setup time30 seconds (one curl | sh command)Hours — exporter user, ES_URI, --es.uri, :9114, prometheus.yml scrape job, dashboards, and Alertmanager
What you getWorking monitoring, diagnosis, and approved fixesAn Elasticsearch scrape target. Host disk, nginx, Postgres, and certs stay your problem until PromQL fires and you SSH in
PricingFree (Scout) / $9 / $29 per machine per monthFree software (Apache 2.0). You still pay for Prometheus, Grafana, Alertmanager, and the engineer who writes the rules
Hidden costsNone — fully managedA cluster credential, --es.all / --es.indices cardinality, and a second tool to tell you the box is sick
Monitoring approachAgent on the server — CPU, disk, services, logs, certs, portselasticsearch_cluster_health_* and elasticsearch_indices_* gauges. elasticsearch_exporter does not watch host disk or a quiet cert unless you added another exporter
ConfigurationNone after install — heuristics and AIES_URI, --es.uri, --es.all, scrape intervals, and which PromQL actually pages you
Plain-English diagnosisYes — AI explains root cause, impact, and fixYou graph elasticsearch_cluster_health_status in Grafana, then SSH in to change the box
Fix executionProposes and executes approved commands with an audit trailExport only — elasticsearch_exporter cannot restart Elasticsearch or free disk
AlertingBuilt-in across 8 channelsNot an Elasticsearch Exporter job — Prometheus rules and Alertmanager have to fire
Predictive alertsYes — disk fills in ~6 days, memory and CPU trendsNot an exporter job — a cluster-health scrape does not forecast a quiet volume
SSH brute-force detectionBuilt-in — parses auth.log every scanOnly if you ship auth.log elsewhere, parse it, write a query, and wire an alert downstream
Machine offline detectionAgent presence monitoring with multi-channel alertsSilence if elasticsearch_exporter dies — unless you built an up{job="elasticsearch"} deadman check
Public status pageShareable URL with 90-day historyNone — elasticsearch_exporter has no customer-facing status page
Weekly fleet digestAutomated Monday digest + daily brief when issues are openNone — an Elasticsearch scrape target is not a plain-English fleet narrative
On-call trackingBuilt-in /oncall command + incident acknowledgmentNot included — wire Alertmanager into PagerDuty or another incident tool
Conversation interfaceTelegram, WhatsApp, web dashboard, CLIcurl :9114/metrics and Grafana. No mechanic you text when heap filled and the cluster flipped yellow
Learning curveNone — works after installSteep — ES_URI, index collectors, PromQL, scrape configs, and which rule actually pages
Best forFreelancers, small teams, accidental sysadmins (1-50 Linux servers)Teams that already run Prometheus and need Elasticsearch scrapes, not a sick-VPS mechanic

When Elasticsearch Exporter is the right choice

Keep elasticsearch_exporter when you already want that exact job:

  • Prometheus Elasticsearch scrapes — you need elasticsearch_cluster_health_status in PromQL, not a mechanic.
  • Per-index and JVM heap gauges — cluster status, shard counts, and heap matter more than host nginx, certs, and SSH on a quiet VPS.
  • An existing Prometheus + Grafana stack — elasticsearch_exporter already ships, dashboards already graph, and someone owns Alertmanager.
  • Hosts that only export — you already run elasticsearch_exporter next to Elasticsearch, not a sick-box SSH loop.

The real cost of “just run elasticsearch_exporter”

A search-cluster exporter is in every ELK + Prometheus diagram. A working ops loop for five Linux boxes is not:

  • An exported yellow-cluster metric still means you SSH in and change the box by hand
  • Host disk, nginx, certs, and SSH brute-force never appear unless you scraped those signals and Alertmanager paged
  • Index-collector cardinality, ES_URI credentials, and PromQL punish the hours you spend debugging targets
  • A single VPS with a dead elasticsearch_exporter still needs a mechanic, not another scrape job

For a 5-server team, Tink Mechanic at $45/month is cheaper than elasticsearch_exporter plus the engineer who keeps Prometheus scrape alive, and every scan includes a diagnosis a quiet /metrics endpoint will not type.

No prometheus.yml homework. No silent host. One command install.

Start Mechanic

Also compare: Tink vs Elastic · Tink vs Prometheus · Tink vs Node Exporter