Docs
  • Release notes
  • Troubleshoot
  • Reference
  1. Docs /
  2. Solutions and use cases /
  3. Observability solution /
  4. Get started

OpenTelemetry use cases

Explore specific use cases for the Elastic OpenTelemetry:

  • Kubernetes observability
  • LLM observability
  • Upstream OpenTelemetry Collector (self-managed Elastic Stack)
Previous
Docker
Next
Kubernetes observability
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
  • Elastic fundamentals
  • Solutions and use cases
  • Manage data
  • Explore and analyze
  • Deploy and manage
  • Manage your Cloud account
  • Troubleshoot
  • Release notes
  • Reference
  • Extend and contribute
  • Contribute to the docs
  • Search use case
    • Get started
      • Quickstarts
        • Index and search basics
        • Keyword search with Python
        • Semantic search
    • Ingest for search use cases
      • Ingest pipelines for search use cases
    • Search approaches
      • Full-text search
        • How full-text search works
        • Text analysis during search
        • Search relevance optimizations
          • Mixing exact search with stemming
          • Getting consistent scoring
          • Incorporating static relevance signals into the score
        • Search with synonyms
          • Create or update synonyms set API examples
      • Vector search
        • Use cases
        • Semantic search for text
          • Semantic search with semantic_text
          • Semantic search with the inference API
          • Semantic search with ELSER (ingest pipelines)
          • Using Cohere with Elasticsearch
          • Tutorial: Manual dense and sparse workflows
          • Using OpenAI compatible models
        • Multimodal search
          • Tutorial: Build multimodal search
        • Dense vector
          • kNN search in Elasticsearch
          • Bring your own dense vectors
          • Optimize vector storage for semantic search
          • GPU vector indexing
        • Sparse vector search in Elasticsearch
      • Hybrid search
        • Hybrid search with semantic_text
      • Ranking and reranking
        • Semantic reranking
        • Learning To Rank (LTR)
          • Deploy and manage LTR models
          • Search using LTR
    • Build search queries
      • The _search API
      • The async-search API
      • ES|QL for search
      • Retrievers
      • Search templates
    • RAG
    • Add search to your app
      • Client libraries
      • Search UI
    • APIs and tools
  • Elasticsearch solution
    • Get started
      • AI onboarding
      • Find connection details
    • Agent Builder
    • Playground (deprecated)
      • Optimize model context
      • View and modify queries
      • Troubleshooting
    • Query rules UI
    • Search Applications
      • Search API and templates
      • Security
      • Search Application client guide
  • Observability solution
    • Get started
      • Elastic Observability quickstarts
        • Quickstart: Monitor hosts with OpenTelemetry
        • Quickstart: Monitor your application performance
        • Quickstart: Unified Kubernetes Observability with Elastic OpenTelemetry
        • Quickstart: Send OTLP data to Elastic Serverless or Elastic Cloud Hosted
        • Quickstart: Create a Synthetic Monitor
        • Quickstart: Monitor hosts with Elastic Agent
        • Quickstart: Monitor your Kubernetes cluster with Elastic Agent
        • Quickstart: Collect data with AWS Firehose
      • OpenTelemetry quickstarts
        • Ingest custom metrics with Elastic OpenTelemetry
        • Self-managed
          • Kubernetes
          • Hosts / VMs
          • Docker
        • Elastic Cloud Serverless
          • Kubernetes
          • Hosts and VMs
          • Docker
        • Elastic Cloud Hosted
          • Kubernetes
          • Hosts and VMs
          • Docker
      • OpenTelemetry use cases
        • Kubernetes observability
          • Prerequisites and compatibility
          • Components description
          • Deployment
          • Instrumenting Applications
          • Upgrade
          • Customization
        • LLM observability
        • Upstream OpenTelemetry Collector
      • Other Observability tutorials
        • Tutorial: Monitor a Java application
      • Logs Essentials
    • Applications and services
      • Application performance monitoring (APM)
        • Get started with traces and APM
        • Application data types
          • Spans
          • Transactions
            • Transaction sampling
          • Traces
          • Errors
          • Metrics
          • Metadata
        • Collect application data
          • OpenTelemetry
            • Contrib OpenTelemetry Collectors and language SDKs
            • Collect metrics
            • Create APM agent key for EDOT SDKs
            • Centrally configure EDOT SDKs
            • Limitations
            • Attributes and labels
            • Data stream routing
          • APM agents
            • Centrally configure APM agents
            • Real User Monitoring (RUM)
            • Create and upload source maps (RUM)
          • Kubernetes
          • AWS Lambda Functions
          • Jaeger (deprecated)
        • View and analyze data
          • Overviews
            • Services
            • Traces UI
            • Dependencies
            • Service Map
            • Service overview
            • Mobile service overview
          • Drill down into data
            • Transactions UI
            • Trace sample timeline
            • Errors UI
            • Metrics UI
            • Infrastructure
            • Logs
          • Explore traces in Discover
          • Filter and search data
            • Filters
            • Advanced queries
            • Cross-cluster search
          • Interpret data
            • Find transaction latency and failure correlations
            • Track deployments with annotations
            • Explore mobile sessions with Discover
            • Observe Lambda functions
          • Integrate with machine learning
          • APM Agent explorer
        • Act on data
          • Create rules and alerts
          • Create custom links
        • Use APM securely
          • Secure data
            • Control access to APM data
            • Built-in data filters
            • Custom filters
            • Delete sensitive data
          • Secure communication with APM agents
            • APM agent TLS communication
            • API keys
            • Secret token
            • Anonymous authentication
          • Secure communication with the Elastic Stack
            • Use feature roles
            • Grant access using API keys
          • Secure access to the Applications UI
            • Create an APM reader user
            • Create an annotation user
            • Create an API user
            • Create a central config user
            • Create a storage explorer user
        • Manage storage
          • Storage Explorer
          • Data streams
          • Index lifecycle management
          • View the Elasticsearch index template
          • Parse data using ingest pipelines
          • Storage and sizing guide
          • Reduce storage
          • Explore data in Elasticsearch
        • Work with APM Server
          • Set up
            • Fleet-managed APM Server
            • APM Server binary
          • Configure
            • General configuration options
            • Anonymous authentication
            • APM agent authorization
            • Configure APM Agent Central Configuration
            • Instrumentation
            • Kibana endpoint
            • Logging
            • Output
              • Elastic Cloud Hosted
              • Elasticsearch
              • Logstash
              • Kafka
              • Redis
              • Console
            • Project paths
            • Real User Monitoring (RUM)
            • SSL/TLS settings
              • SSL/TLS output settings
              • SSL/TLS input settings
            • Tail-based sampling
            • Use environment variables in the configuration
            • Advanced setup
              • Installation layout
              • Secrets keystore
              • Command reference
              • Tune data ingestion
              • High Availability
              • APM Server and systemd
          • Monitor
            • Fleet-managed
            • APM Server binary
              • Use internal collection
              • Use Metricbeat collection
              • Use local collection
        • APM APIs
          • APM UI API
          • APM Server API
            • APM Server information API
            • Elastic APM events intake API
            • Elastic APM agent configuration API
            • OpenTelemetry intake API
            • Jaeger event intake
          • Managed intake service event API
        • Upgrade
          • APM agent compatibility
          • Upgrade to version 9.0
            • Self-installation standalone
            • Self-installation APM integration
            • Elastic Cloud standalone
            • Elastic Cloud APM integration
          • Switch to the Elastic APM integration
            • Switch a self-installation
            • Switch an Elastic Cloud cluster
      • Synthetic monitoring
        • Get started
          • Use a Synthetics project
          • Use the Synthetics UI
        • Scripting browser monitors
          • Write a synthetic test
          • Configure individual monitors
          • Use the Synthetics Recorder
        • Configure lightweight monitors
        • Manage monitors
        • Work with params and secrets
        • Analyze monitor data
        • Monitor resources on private networks
        • Use the CLI
        • Configure a Synthetics project
        • Multi-factor Authentication
        • Kerberos authentication
        • Configure Synthetics settings
        • Grant users access to secured resources
          • Setup role
          • Writer role
          • Reader role
        • Manage data retention
        • Use Synthetics with network security
        • Migrate from the Elastic Synthetics integration
        • Scale and architect a deployment
        • Synthetics support matrix
        • Synthetics Encryption and Security
      • Real user monitoring
        • OpenTelemetry for Real User Monitoring (RUM)
      • LLM and agentic AI observability
      • Uptime monitoring (deprecated)
        • Get started
        • Analyze
          • View monitor status
          • Analyze monitors
          • Inspect uptime duration anomalies
        • Configure settings
      • Visualize OpenTelemetry data
    • CI/CD
    • Cloud
      • AWS
        • Ingestion options
        • Monitor AWS with Elastic Agent
          • EC2
          • Kinesis data streams
          • S3
          • SQS
        • Monitor AWS with Beats
        • Monitor AWS with Amazon Data Firehose
          • VPC Flow Logs
          • CloudTrail logs
          • Network Firewall logs
          • WAF logs
          • CloudWatch logs
        • Monitor AWS with Elastic Serverless Forwarder
      • Azure
        • Monitor Microsoft Azure with Elastic Agent
        • Monitor Microsoft Azure with Beats
        • Ingest multi-tenant Azure Event Hub logs with Filebeat
        • Monitor Microsoft Azure with the Azure Native Service
        • Monitor Microsoft Azure OpenAI
      • GCP
        • GCP Dataflow templates
    • Infrastructure and hosts
      • Analyze infrastructure and host metrics
        • Get started with system metrics
        • View infrastructure metrics by resource type
        • Explore metrics data with Discover in Kibana
        • Explore infrastructure metrics over time (deprecated)
        • Analyze and compare hosts
        • Detect metric anomalies
        • Configure settings
      • Universal Profiling
        • Get started
        • Manage data storage
          • Index lifecycle management
          • Configure probabilistic profiling
        • Advanced configuration
          • Tag data for querying
          • Add symbols for native frames
          • Use a proxy
          • Override kernel version check
          • Environment variables to configure the Universal Profiling Agent
          • Configuration file of the Universal Profiling Agent
        • Upgrade
        • Self-hosted infrastructure
        • Install the backend
          • Step 1: Update the stack
          • Step 2: Enable Universal Profiling in Kibana
          • Step 3: Set up Universal Profiling in Kibana
          • Step 4: Run the backend applications
          • Step 5: Next steps
        • Operate the backend
      • Network Topology
        • Tutorial: Monitor your network devices with the Network Topology plugin
        • Network Topology field reference
      • Tutorial: Observe your Kubernetes deployments
      • Tutorial: Observe your nginx instances
        • Understanding "no results found" message
      • Collect NGINX data with OpenTelemetry integrations (Fleet-managed)
      • Collect NGINX data with OpenTelemetry integrations (standalone)
    • Logs
      • Get started with system logs
      • Send any log file using Elastic Agent
      • Send any log file using OTel Collector
      • Send application log data
        • Plaintext application logs
        • ECS formatted application logs
        • APM agent log sending
      • Parse and route logs using ingest pipelines
      • Filter and aggregate logs
      • Explore logs
        • Explore logs in Discover
        • Categorize log entries
        • Inspect log anomalies
      • Run a pattern analysis on log data
      • Configure log data sources
      • Configure log data retention
      • Add a service name to logs
      • Logs index template reference
        • Default logs index template
    • Streams
      • Get data in
      • Organize data
      • Process documents
      • Configure data lifecycle
      • Manage data quality
      • Map fields
      • Configure advanced settings
      • Knowledge Indicators
      • Wired streams field naming
      • Streamlang
        • Append processor
        • Concat processor
        • Convert processor
        • Date processor
        • Dissect processor
        • Drop document processor
        • Enrich processor
        • Grok processor
        • Join processor
        • JSON extract processor
        • Lowercase processor
        • Math processor
        • Network direction processor
        • Redact processor
        • Registered domain processor
        • Remove processor
        • Rename processor
        • Replace processor
        • Set processor
        • Sort processor
        • Split processor
        • Trim processor
        • Uppercase processor
        • URI parts processor
        • User agent processor
        • Manual pipeline configuration
    • Incident management
      • Alerting
        • Create and manage rules
          • Anomaly detection
          • APM anomaly
          • Custom threshold
          • Degraded docs
          • Elasticsearch query
          • Error count threshold
          • Failed transaction rate threshold
          • Failed docs
          • Inventory
          • Latency threshold
          • Log threshold
          • Metric threshold
          • Monitor Status
          • TLS certificate
          • Uptime duration anomaly
          • SLO burn rate
        • Aggregation options
          • Rate aggregation
        • View and manage alerts
          • SLO burn rate breaches
          • Threshold breaches
      • Cases
      • Service-level objectives (SLOs)
        • Configure SLO access
        • Create an SLO
        • Create a composite SLO
        • View and manage SLOs
        • Configure SLOs settings
    • Data set quality
    • AI for Observability
      • Agent Builder for Observability
      • AI Assistant
      • Automatic Import
      • Large language model performance matrix for Observability
    • Cross-project search
    • Serverless feature tiers
    • APIs
  • Security solution
    • Get started
      • Elastic Security quickstarts
        • Detect and respond to threats with SIEM
        • Protect your hosts with endpoint security
        • Secure your cloud assets with cloud security posture management
      • Elastic Security requirements
      • Elastic Security UI
      • Ingest data to Elastic Security
        • Enable threat intelligence integrations
        • Automatic migration
        • Automatic Import
        • Content connectors
      • Spaces and Elastic Security
        • Spaces and Elastic Defend FAQ
      • Data views and Elastic Security
      • Create runtime fields in Elastic Security
      • SIEM Readiness
    • ES|QL for security
      • Tutorial: Threat hunting with ES|QL
    • AI for security
      • Elastic AI SOC Engine
        • Triage alerts
        • Upgrade from EASE to Elastic Security
      • Agent Builder for Elastic Security
        • Agents, skills, and tools
        • Security use cases
      • AI Assistant for Security
        • AI Assistant Knowledge Base
        • Use AI Assistant's Knowledge Base to improve response quality
      • Attack Discovery
        • Grant feature access
        • Run Attack Discovery
          • Run from Attacks view
            • Configure Attack Discovery settings
            • Manual runs
            • Scheduled runs
            • Troubleshoot with AI
          • Run from a workflow
          • Run from Agent Builder
          • Run from Attack Discovery page
        • Triage Attack Discovery findings
        • Manage saved discoveries
          • Manage from Attacks view
          • Manage from Attack Discovery page
      • Large language model performance matrix for Elastic Security
      • AI use cases
        • Triage alerts
        • Identify, investigate, and document threats
        • Generate, customize, and learn about ES|QL queries
      • Value report
    • Security MCP App
    • Detections and alerts
      • Before you begin
        • Turn on detections
        • Detections privileges
        • Detection rule concepts
        • Advanced data source configuration
          • Cross-cluster search and detection rules
          • Cross-project search and detection rules
          • Using logsdb index mode with Elastic Security
      • MITRE ATT&CK coverage
        • Remap to MITRE ATT&CK v19
      • Prebuilt rules
        • Prebuilt rule components
        • Install prebuilt rules
        • Update prebuilt rules
        • Prebuilt rules in air-gapped environments
        • Customize prebuilt rules
      • Author rules
        • Choose the right rule type
          • About building block rules
        • Rule type guides
          • ES|QL rules
          • Custom query rules
          • Event correlation (EQL) rules
          • Indicator match rules
          • Threshold rules
          • Machine learning rules
          • New terms rules
        • Using the UI
        • Using the API
        • Common rule settings
        • Set rule data sources
        • Write investigation guides
        • Validate and test rules
      • Manage detection rules
        • View rule changes history
      • Monitor rule executions
        • Fill rule execution gaps
      • Reduce noise and false positives
        • Tune detection rules
        • Rule exceptions
          • Create and manage value lists
          • Add and manage exceptions
          • Create and manage shared exception lists
        • Suppress detection alerts
      • Manage detection alerts
        • Visualize detection alerts
        • View detection alert details
        • Query alert indices
    • Configure endpoint protection with Elastic Defend
      • Elastic Defend requirements
      • Install Elastic Defend
        • Enable access on macOS
        • Deploy on macOS with MDM
        • Prevent Elastic Agent uninstallation
      • Elastic Defend feature privileges
      • Configure an integration policy for Elastic Defend
        • Configure updates for protection artifacts
        • Turn off diagnostic data for Elastic Defend
        • Configure self-healing rollback for Windows endpoints
        • Configure Linux file system monitoring
        • Configure data volume
        • Create an Elastic Defend policy using API
      • Configure offline endpoints and air-gapped environments
      • Remote output and cross-cluster search
      • Uninstall Elastic Agent
    • Manage Elastic Defend
      • Endpoints
      • Policies
      • Elastic Endpoint exceptions
      • Trusted applications
      • Trusted devices
      • Event filters
      • Host isolation exceptions
      • Blocklist
      • Exception types and syntax
      • Optimize Elastic Defend
      • Event capture and Elastic Defend
      • Endpoint protection rules
      • Automatic troubleshooting
      • Allowlist Elastic Endpoint in third-party antivirus apps
      • Elastic Endpoint self-protection features
    • Endpoint response actions
      • Automated response actions
      • Isolate a host
      • Response actions history
      • Script library
      • Third-party response actions
      • Configure third-party response actions
    • Cloud Security
      • Security posture management overview
      • Enable cloud security features in Serverless
      • Cloud security posture management
        • Get started with CSPM for AWS
        • Get started with CSPM for GCP
        • Get started with CSPM for Azure
        • CSPM privilege requirements
        • CSPM Findings
        • CSPM benchmarks
        • Cloud Security Posture dashboard
        • Frequently asked questions (FAQ)
      • Kubernetes security posture management
        • Get started with KSPM
        • KSPM Findings
        • KSPM benchmarks
        • Cloud Security Posture dashboard
        • Frequently asked questions (FAQ)
      • Cloud Asset Discovery
        • Set up Cloud Asset Discovery for AWS
        • Set up Cloud Asset Discovery for GCP
        • Set up Cloud Asset Discovery for Azure
      • Cloud native vulnerability management
        • Get started with CNVM
        • CNVM privilege requirements
        • CNVM Findings
        • CNVM dashboard
        • Frequently asked questions (FAQ)
      • Cloud workload protection for VMs
        • Capture environment variables
      • Cloud workload protection for Kubernetes
        • Get started with Defend for Containers for Kubernetes
        • Container workload protection policies
        • Kubernetes dashboard
    • Ingest third-party security data
      • AWS Config
      • AWS Inspector
      • AWS Security Hub
      • AWS Security Hub CSPM
      • CNCF Falco
      • Google Security Command Center
      • Microsoft Defender for Cloud
      • Microsoft Defender for Endpoint
      • Microsoft Defender XDR
      • Prisma Cloud
      • Qualys VMDR
      • Rapid7 InsightVM
      • Tenable VM
      • Wiz
    • Investigation tools
      • Explore Security data in Discover
      • Timeline
        • Timeline templates
      • Visual event analyzer
      • Session View
      • Osquery
        • Osquery manager integration
        • Osquery FAQ
        • Add Osquery Response Actions
        • Run Osquery from investigation guides
        • Run Osquery from alerts
        • Examine Osquery results
        • Use placeholder fields in Osquery queries
      • Notes
      • Indicators of compromise
      • Cases
    • Dashboards
      • Overview dashboard
      • Detection & Response dashboard
      • Cloud Security Posture dashboard
      • Kubernetes dashboard
      • Entity Analytics dashboard
      • Data Quality dashboard
      • Cloud Native Vulnerability Management Dashboard
      • Detection rule monitoring dashboard
      • Endpoint Detection and Response dashboard
    • Entity analytics
      • Entity analytics requirements
      • Entity store
        • Entity relationships
      • Entity risk scoring
        • Turn on risk scoring
        • Asset criticality
        • View and analyze risk score data
      • Manage entities
        • Watchlists
        • Entity resolution
        • Privileged user monitoring
          • Privileged user monitoring requirements
          • Set up privileged user monitoring
          • Monitor privileged user activities
      • Advanced behavioral detections
        • Machine learning job and rule requirements
        • Anomaly detection
        • Optimizing anomaly results
        • Behavioral detection use cases
      • Investigate entities
        • Monitor entity risk
        • View entity details
      • Explore
        • Hosts page
        • Network page
          • Configure network map data
          • Configure the DNS histogram
        • Users page
    • Serverless feature tiers
    • APIs
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.