SME Track: All Teams
Presenter: Roberto Pantoja
Date: 2026-11-04
SLB × Elastic Workshop Program
Cross-team session reviewing adoption progress and next steps.
These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.
The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.
Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.
Use → to see why each feature matters for SLB.
Same value on Serverless, ECH, and self-managed
Teams treat deployment choice as a feature fork — assuming Serverless skills won't transfer to ECH or on-prem, or that only one model fits SLB.
Serverless, Elastic Cloud Hosted, and self-managed share the same Observability UX. Labs use Serverless to skip cluster toil; you apply the same ES|QL, Streams, and AI workflows wherever Elastic runs.
Managed routing and processing for telemetry
Custom ingest pipelines, index templates, and rollover policies per team — fragile, hard to govern, and different on every cluster.
Streams define how logs, metrics, and traces are routed, processed, and retained — on Serverless, ECH, and self-managed, with a unified UI.
One query language for logs, metrics, and traces
Different syntax per signal — PromQL for metrics, LogQL for logs, trace UI only — context switching slows incidents.
ES|QL pipes data through filters, stats, and joins across observability datasets in Logs Explorer and Dev Tools.
User-facing reliability, not just green dashboards
CPU graphs look fine while customers see errors — no shared error budget or burn-rate language with product teams.
SLOs define availability/latency targets from real traces and metrics, with burn alerts before users flood support.
Natural language over your live telemetry
Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.
Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.
Automate alert response safely
Manual Slack pings, ticket copy-paste, and runbook hunts — alerts fire but nothing moves until a human acts.
Workflows chain connectors (Slack, PagerDuty, webhooks) with approval steps when alerts or SLOs breach.
Your lab uses Elastic Observability Serverless for a zero-ops learning environment.
The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.
Instruqt track: slb-sme-all-teams