AIOps 01 — Alert Fatigue & Noise Reduction

SME Track: AIOps & Alerting

Presenter: Specialist (DSR) — AIOps

Date: 2026-11-11

SLB × Elastic Workshop Program

Overview

Reduce alert volume through rule tuning, deduplication, and suppression.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • Understanding why alert fatigue happens in Elastic
  • Rule tuning — thresholds and conditions
  • Alert deduplication, suppression, and exceptions
  • Day-to-day alert triage and diagnosis workflows

Why these features?

🔔Observability AlertsSignal without the noise
SLOsUser-facing reliability, not just green dashboards
AI AssistantNatural language over your live telemetry

Use → to see why each feature matters for SLB.

Why Observability Alerts?

Signal without the noise

Without it

Alert storms, duplicate pages, and rules that never get tuned — on-call learns to ignore the channel.

With Observability Alerts

Threshold, anomaly, and SLO-based rules with grouping, suppression, and AI-assisted triage in one alerts UI.

  • Tune rules to SLB services instead of one-size-fits-all thresholds
  • Deduplicate and acknowledge with context for handoffs
  • Feed Workflows for automated first response
Rule
Alert
Triage

Why SLOs?

User-facing reliability, not just green dashboards

Without it

CPU graphs look fine while customers see errors — no shared error budget or burn-rate language with product teams.

With SLOs

SLOs define availability/latency targets from real traces and metrics, with burn alerts before users flood support.

  • Align SRE and product on measurable reliability
  • Prioritize fixes when error budget is draining
  • Native in Observability on every deployment — no custom PromQL recording rules required
SLI signal
SLO target
Burn alert

Why AI Assistant?

Natural language over your live telemetry

Without it

Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.

With AI Assistant

Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.

  • Onboard new engineers without memorizing query syntax
  • Explain spikes and error patterns during live incidents
  • Draft queries you can save, share, and reuse
Question
AI Assistant
Evidence

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-sme-aiops-alerting

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides