F-04 — Looking Forward with Elastic

Shared Foundations

Presenter: Specialist (DSR)

Date: 2026-08-05

SLB × Elastic Workshop Program

Overview

First look at Elastic 9.x and what it means for SLB SRE.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • What's new in Elastic 9.x
  • What to expect during the migration
  • Key features relevant to SLB SRE
  • Roadmap highlights

Why these features?

Observability everywhereSame value on Serverless, ECH, and self-managed
🤖Agent BuilderRepeatable AI workflows with guardrails
WorkflowsAutomate alert response safely
Elastic StreamsManaged routing and processing for telemetry

Use → to see why each feature matters for SLB.

Why Observability everywhere?

Same value on Serverless, ECH, and self-managed

Without it

Teams treat deployment choice as a feature fork — assuming Serverless skills won't transfer to ECH or on-prem, or that only one model fits SLB.

With Observability everywhere

Serverless, Elastic Cloud Hosted, and self-managed share the same Observability UX. Labs use Serverless to skip cluster toil; you apply the same ES|QL, Streams, and AI workflows wherever Elastic runs.

  • Serverless: Elastic manages scaling, upgrades, ILM, and Fleet overhead
  • ECH / on-prem: same capabilities when you need full infrastructure control
  • Choose deployment for ops burden — not for observability feature access
Your deployment
Same Kibana
Same skills

Why Agent Builder?

Repeatable AI workflows with guardrails

Without it

Ad-hoc ChatGPT sessions with no access to SLB data, no audit trail, and inconsistent answers per engineer.

With Agent Builder

Build agents that use observability context, tools, and retrieval — tuned prompts your team can trust and share.

  • Standardize "investigate service X" and "summarize deploy" playbooks
  • Connect tools (ES|QL, alerts, docs) instead of copy-paste context
  • Govern who can publish agents — architecture-friendly AI ops
Agent
Tools + data
Action

Why Workflows?

Automate alert response safely

Without it

Manual Slack pings, ticket copy-paste, and runbook hunts — alerts fire but nothing moves until a human acts.

With Workflows

Workflows chain connectors (Slack, PagerDuty, webhooks) with approval steps when alerts or SLOs breach.

  • Notify the right channel with context automatically
  • Add human-in-the-loop before remediation scripts run
  • Reduce toil without bypassing change control
Alert
Workflow
Notify / act

Why Elastic Streams?

Managed routing and processing for telemetry

Without it

Custom ingest pipelines, index templates, and rollover policies per team — fragile, hard to govern, and different on every cluster.

With Elastic Streams

Streams define how logs, metrics, and traces are routed, processed, and retained — on Serverless, ECH, and self-managed, with a unified UI.

  • Reduce DIY pipeline + ILM work with declarative stream rules
  • Consistent ownership and naming across SLB domains
  • On self-managed/ECH you may still use ILM — Streams simplify routing either way
Ingest
Streams
Search & alerts

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-shared-foundations

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides