AIOps 02 — AI-Assisted Investigation & Automated Response

SME Track: AIOps & Alerting

Presenter: Specialist (DSR) — AIOps

Date: 2026-11-18

SLB × Elastic Workshop Program

Overview

AI-assisted investigation and automated remediation workflows.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • Intelligent alert investigation with AI Assistant for Observability
  • Root cause analysis — correlating logs, metrics, traces
  • Log pattern analysis and anomaly detection
  • Automated remediation workflows with Elastic Workflows

Why these features?

AI AssistantNatural language over your live telemetry
🤖Agent BuilderRepeatable AI workflows with guardrails
Unified ObservabilityLogs, metrics, and traces in one place
WorkflowsAutomate alert response safely

Use → to see why each feature matters for SLB.

Why AI Assistant?

Natural language over your live telemetry

Without it

Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.

With AI Assistant

Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.

  • Onboard new engineers without memorizing query syntax
  • Explain spikes and error patterns during live incidents
  • Draft queries you can save, share, and reuse
Question
AI Assistant
Evidence

Why Agent Builder?

Repeatable AI workflows with guardrails

Without it

Ad-hoc ChatGPT sessions with no access to SLB data, no audit trail, and inconsistent answers per engineer.

With Agent Builder

Build agents that use observability context, tools, and retrieval — tuned prompts your team can trust and share.

  • Standardize "investigate service X" and "summarize deploy" playbooks
  • Connect tools (ES|QL, alerts, docs) instead of copy-paste context
  • Govern who can publish agents — architecture-friendly AI ops
Agent
Tools + data
Action

Why Unified Observability?

Logs, metrics, and traces in one place

Without it

Three tabs, three tools, manual correlation — "which deploy caused this spike?" takes too long.

With Unified Observability

APM, Logs Explorer, and Metrics views link the same service context — pivot from error log to trace to CPU in clicks.

  • Shorter MTTR when signals share service.name and trace.id
  • Deploy validation: check all three pillars after a release
  • One Observability overview for leadership and SRE review
Logs
Metrics
Traces

Why Workflows?

Automate alert response safely

Without it

Manual Slack pings, ticket copy-paste, and runbook hunts — alerts fire but nothing moves until a human acts.

With Workflows

Workflows chain connectors (Slack, PagerDuty, webhooks) with approval steps when alerts or SLOs breach.

  • Notify the right channel with context automatically
  • Add human-in-the-loop before remediation scripts run
  • Reduce toil without bypassing change control
Alert
Workflow
Notify / act

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-sme-aiops-alerting

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides