Arch 01 — Architecture & Migration Strategy

SME Track: Architects

Presenter: Specialist (DSR)

Date: 2026-08-26

SLB × Elastic Workshop Program

Overview

Target-state ingestion design and coexistence planning during migration.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • Streams and OTel target-state (Serverless, ECH, or on-prem)
  • Coexistence planning during migration (Grafana + Elastic side by side)
  • Multi-team project access and API keys

Why these features?

Observability everywhereSame value on Serverless, ECH, and self-managed
📡Managed OTel ingestionSend OTLP once — Elastic handles the rest
Elastic StreamsManaged routing and processing for telemetry
🔐API keys & accessSecure multi-team automation on any deployment

Use → to see why each feature matters for SLB.

Why Observability everywhere?

Same value on Serverless, ECH, and self-managed

Without it

Teams treat deployment choice as a feature fork — assuming Serverless skills won't transfer to ECH or on-prem, or that only one model fits SLB.

With Observability everywhere

Serverless, Elastic Cloud Hosted, and self-managed share the same Observability UX. Labs use Serverless to skip cluster toil; you apply the same ES|QL, Streams, and AI workflows wherever Elastic runs.

  • Serverless: Elastic manages scaling, upgrades, ILM, and Fleet overhead
  • ECH / on-prem: same capabilities when you need full infrastructure control
  • Choose deployment for ops burden — not for observability feature access
Your deployment
Same Kibana
Same skills

Why Managed OTel ingestion?

Send OTLP once — Elastic handles the rest

Without it

Multiple exporters, bespoke endpoints, and glue code to normalize Prometheus, Loki, and Jaeger into one query model.

With Managed OTel ingestion

Point OpenTelemetry collectors at Elastic OTLP endpoints — unified logs, metrics, and traces in any deployment model.

  • One semantic model (OTel) across services and hosts
  • Side-by-side migration: Grafana today, Elastic Streams tomorrow
  • Less custom integration code to maintain
OTel SDK
Managed OTLP
Unified store

Why Elastic Streams?

Managed routing and processing for telemetry

Without it

Custom ingest pipelines, index templates, and rollover policies per team — fragile, hard to govern, and different on every cluster.

With Elastic Streams

Streams define how logs, metrics, and traces are routed, processed, and retained — on Serverless, ECH, and self-managed, with a unified UI.

  • Reduce DIY pipeline + ILM work with declarative stream rules
  • Consistent ownership and naming across SLB domains
  • On self-managed/ECH you may still use ILM — Streams simplify routing either way
Ingest
Streams
Search & alerts

Why API keys & access?

Secure multi-team automation on any deployment

Without it

Shared credentials, over-privileged scripts, and no clear ownership per integration.

With API keys & access

Scoped API keys and role patterns — project keys on Serverless, deployment keys on ECH, native users on self-managed.

  • Automate dashboards and CI checks without shared passwords
  • Audit who can query vs who can configure Streams
  • Architect-friendly boundary between teams on one project
Team
API key
Scoped access

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-sme-architects

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides