Observability Labs
Explore Elastic Observability Labs for expert-led resources and hands-on learning. Enhance your skills and optimize your observability strategy with Elastic.

Cut log storage costs with two Elasticsearch data tiers instead of four
Elastic benchmarked one day of logs on SSD with everything older moved to frozen searchable snapshots, and it came out 16x cheaper than keeping all of it hot. The ILM policy and the cost model are both in the post.

Temporal Cloud observability in Elastic: 50+ metrics, zero collectors

Not every log deserves 90 days: per-stream retention in Elastic Streams

Cross-project search for Elastic Observability: one query across every linked project

No log file too small: How Elastic Agent tracks files below the 1 KiB threshold
Blog
Developer insights and practical observability articles from our experts to inspire and empower your monitoring stack

Telemetry Policy: change OpenTelemetry sampling and log levels at runtime, no restart
Telemetry Policy says what you want to happen and leaves each component to work out how. Change an OpenTelemetry Java agent's trace sampling to 1% and the JVM keeps serving traffic.

Monitor Supabase in Elastic: dashboards, alert templates, SLO templates, and zero agents
When your Supabase API goes slow, it could be the node, Postgres, the pooler or PostgREST. Elastic tells you which one and shows you the logs from whichever it was.

Native OTLP metrics ingestion on Elastic Cloud Hosted
Send an exponential OpenTelemetry histogram and Elasticsearch keeps the scale and buckets you sent. All four type and temporality combinations work now, and your SDK and Collector config stay exactly as they are.
.jpg)
Collecting rootless Podman logs with Elastic Agent: the CRI parser, user-scoped paths, and the Podman socket
Rootless Podman containers write their logs in CRI format. This Fleet policy reads them and attaches container.* fields, with the match_source_index value that rootless paths need.

AI root cause analysis in Elastic Agent Builder that cites its evidence
The new release failed at 27.2%, the old one at 28.2%, so the deploy was never the cause; the agent worked that out in 72 seconds and handed back a trace ID for the failure that was.

Drain Vercel into Elastic: serverless observability with nothing to install
A drain and an API key put Vercel logs, traces, and Speed Insights into Elastic Cloud, where you can follow a slow request from the edge to the Lambda function behind it.

How one ES|QL query builds a metric chart for every metric in Elasticsearch
METRICS_INFO reports what metrics are in your data and how to aggregate each one, so Kibana Discover can chart counters, gauges and histograms correctly with no configuration and no field names to look up.

LLM tracing in Elastic APM: prompts, responses, and token counts in the span view
In a twenty-call agentic trace, you can see which span is using the most tokens and read the prompt that caused it. Both live in Elastic APM, so there is no second tool to run.

Your AI agent needs an alibi: Observability and audit trails for Agent Builder in Elastic
Elastic 9.5 traces every Agent Builder run as OpenTelemetry spans in your own cluster, so tool calls and token counts are queryable with ES|QL. One workflow step adds the approval record, in a data stream the pipeline cannot rewrite.

From a 582ms latency spike to the team that owns it, using Kibana Discover
Getting there takes a data view, some filter pills, a KQL query and a switch to Lucene query syntax, but the part that actually names the team is one ES|QL LOOKUP JOIN against a service catalog index.

From recommendation to remediation in 4 stages: human-in-the-loop automation with Elastic Workflows
An approval gate that pauses incident response automation before the action and gives the reviewer enough evidence to decide in seconds. Whatever happens next, approved or declined, lands in one auditable record.

From alert to root cause in 3 minutes: automated root cause analysis with Elastic Agent Builder
Automated root cause analysis only works if the agent compares the incident window against the last healthy one. Skip that step and you get a summariser. The read-only skill, the scoped role and the Elastic Workflow are all here.

AI agent observability for Microsoft Foundry: two env vars, no collector
Set up LLM tracing once and every model call, tool execution and handoff from your Foundry agent arrives in Kibana as one queryable trace, with token counts on each span and code for Agent Framework, LangGraph and Node.js.

Sleep through the 3am page: automated incident response with Elastic on Red Hat OpenShift
Elastic Observability handles three routine incidents on its own: it scales, restarts or rolls back the workload, then confirms the service recovered, all with the reasoning model inside your own cluster.

OpenTelemetry Java extensions: customize traces without forking the agent
One JAR, loaded at startup by the OpenTelemetry Java agent, lets you filter health checks, rename spans, add resource attributes, and control sampling with no application code changes.