BI 02 — ES|QL for Analysts

SME Track: BI & Data Analysts

Presenter: Pramod Saripalli

Date: 2026-09-30

SLB × Elastic Workshop Program

Overview

ES|QL query patterns, aggregations, and time-series analysis for analysts.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • Simple query patterns and aggregations
  • Time-based analysis
  • Correlating observability data with cost and utilization context

Why these features?

ES|QLOne query language for logs, metrics, and traces
AI AssistantNatural language over your live telemetry
Unified ObservabilityLogs, metrics, and traces in one place

Use → to see why each feature matters for SLB.

Why ES|QL?

One query language for logs, metrics, and traces

Without it

Different syntax per signal — PromQL for metrics, LogQL for logs, trace UI only — context switching slows incidents.

With ES|QL

ES|QL pipes data through filters, stats, and joins across observability datasets in Logs Explorer and Dev Tools.

  • Faster investigations with reusable query patterns
  • Same syntax in Logs Explorer on Serverless, ECH, and self-managed
  • AI Assistant can draft and explain ES|QL for your team
FROM logs-*
STATS / WHERE
Answer

Why AI Assistant?

Natural language over your live telemetry

Without it

Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.

With AI Assistant

Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.

  • Onboard new engineers without memorizing query syntax
  • Explain spikes and error patterns during live incidents
  • Draft queries you can save, share, and reuse
Question
AI Assistant
Evidence

Why Unified Observability?

Logs, metrics, and traces in one place

Without it

Three tabs, three tools, manual correlation — "which deploy caused this spike?" takes too long.

With Unified Observability

APM, Logs Explorer, and Metrics views link the same service context — pivot from error log to trace to CPU in clicks.

  • Shorter MTTR when signals share service.name and trace.id
  • Deploy validation: check all three pillars after a release
  • One Observability overview for leadership and SRE review
Logs
Metrics
Traces

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-sme-bi-analysts

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides