As DFIR investigations grow in complexity, logs have quickly become some of the most fruitful data sources. But logs aren't small. In today's investigations, how can the forensic practitioner quickly turn large amounts of data into actionable knowledge? In this presentation, we'll learn how to incorporate the ELK stack within our forensic toolkit, allowing practitioners to quickly index, analyze, enrich, and visualize even the largest log sets. Watch out haystack - the needle just got bigger.