SME Track: AIOps & Alerting
Presenter: Specialist (DSR) — AIOps
Date: 2026-11-11
SLB × Elastic Workshop Program
Reduce alert volume through rule tuning, deduplication, and suppression.
These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.
The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.
Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.
Use → to see why each feature matters for SLB.
Signal without the noise
Alert storms, duplicate pages, and rules that never get tuned — on-call learns to ignore the channel.
Threshold, anomaly, and SLO-based rules with grouping, suppression, and AI-assisted triage in one alerts UI.
User-facing reliability, not just green dashboards
CPU graphs look fine while customers see errors — no shared error budget or burn-rate language with product teams.
SLOs define availability/latency targets from real traces and metrics, with burn alerts before users flood support.
Natural language over your live telemetry
Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.
Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.
Your lab uses Elastic Observability Serverless for a zero-ops learning environment.
The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.
Instruqt track: slb-sme-aiops-alerting