Shared Foundations
Presenter: Enrique
Date: 2026-07-29
SLB × Elastic Workshop Program
Practical examples of data ingestion, querying with ES|QL, and using Kibana dashboards — with a focus on what Grafana users need to know.
These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.
The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.
Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.
Use → to see why each feature matters for SLB.
One query language for logs, metrics, and traces
Different syntax per signal — PromQL for metrics, LogQL for logs, trace UI only — context switching slows incidents.
ES|QL pipes data through filters, stats, and joins across observability datasets in Logs Explorer and Dev Tools.
Managed routing and processing for telemetry
Custom ingest pipelines, index templates, and rollover policies per team — fragile, hard to govern, and different on every cluster.
Streams define how logs, metrics, and traces are routed, processed, and retained — on Serverless, ECH, and self-managed, with a unified UI.
Send OTLP once — Elastic handles the rest
Multiple exporters, bespoke endpoints, and glue code to normalize Prometheus, Loki, and Jaeger into one query model.
Point OpenTelemetry collectors at Elastic OTLP endpoints — unified logs, metrics, and traces in any deployment model.
Grafana-style views, Elastic-native drilldowns
Static panels that break when fields change — no path from chart to raw events without switching tools.
Lens builds visualizations drag-and-drop; dashboards link to Discover, APM, and ES|QL for drilldown.
Natural language over your live telemetry
Every investigator rebuilds the same ES|QL, scrolls dashboards, and writes runbook prose from scratch.
Ask questions in plain language — get ES|QL, summaries, and correlated logs/traces grounded in your project data.
Your lab uses Elastic Observability Serverless for a zero-ops learning environment.
The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.
Instruqt track: slb-shared-foundations