SME Track: AIOps & Alerting
Presenter: Specialist (DSR) — AIOps
Date: 2026-11-18
SLB × Elastic Workshop Program
AI-assisted investigation and automated remediation workflows.
These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.
The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.
Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.
Use → to see why each feature matters for SLB.
Natural language over your live telemetry
Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.
Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.
Repeatable AI workflows with guardrails
Ad-hoc ChatGPT sessions with no access to SLB data, no audit trail, and inconsistent answers per engineer.
Build agents that use observability context, tools, and retrieval — tuned prompts your team can trust and share.
Logs, metrics, and traces in one place
Three tabs, three tools, manual correlation — "which deploy caused this spike?" takes too long.
APM, Logs Explorer, and Metrics views link the same service context — pivot from error log to trace to CPU in clicks.
Automate alert response safely
Manual Slack pings, ticket copy-paste, and runbook hunts — alerts fire but nothing moves until a human acts.
Workflows chain connectors (Slack, PagerDuty, webhooks) with approval steps when alerts or SLOs breach.
Your lab uses Elastic Observability Serverless for a zero-ops learning environment.
The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.
Instruqt track: slb-sme-aiops-alerting