SME Track: AIOps & Alerting
Presenter: Specialist (DSR) — AIOps
Date: 2026-11-25
SLB × Elastic Workshop Program
Build and test automated remediation workflows triggered from observability alerts.
These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.
The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.
Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.
Use → to see why each feature matters for SLB.
Automate alert response safely
Manual Slack pings, ticket copy-paste, and runbook hunts — alerts fire but nothing moves until a human acts.
Workflows chain connectors (Slack, PagerDuty, webhooks) with approval steps when alerts or SLOs breach.
Signal without the noise
Alert storms, duplicate pages, and rules that never get tuned — on-call learns to ignore the channel.
Threshold, anomaly, and SLO-based rules with grouping, suppression, and AI-assisted triage in one alerts UI.
User-facing reliability, not just green dashboards
CPU graphs look fine while customers see errors — no shared error budget or burn-rate language with product teams.
SLOs define availability/latency targets from real traces and metrics, with burn alerts before users flood support.
Your lab uses Elastic Observability Serverless for a zero-ops learning environment.
The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.
Instruqt track: slb-sme-aiops-alerting