Elastic Observability Labs
This field guide walks through the ingest architectures I27;ve seen work in production, the data quality checks that decide whether your dashboards actually work, and the ECS mapping that makes mainframe data usable to the platform.
Featured






Stop finding out about your Claude bill on invoice day: Anthropic API monitoring is now in Elastic
Track Anthropic API spend and rate limit headroom across every workspace, model, and service tier, so cost surprises and throttling stop being production-time discoveries.

Use Elasticsearch as a Drop-In Prometheus Backend for Grafana
Use Elasticsearch as a Prometheus backend for Grafana dashboards, autocomplete, Metrics Drilldown, and alerting without changing PromQL workflows.

From alert to root cause in seconds: AI-powered observability with Elastic Agent Builder and Workflows
Elastic Agent Builder and Workflows replace dashboard hunting: one question surfaces the root cause, correlates metrics across weeks, and calculates business impact; then the workflow files the ticket.

3 signals, 2 env vars, 0 collectors: OpenTelemetry with Python and Elastic27;s Managed OTLP Endpoint
Instrument a Flask API with OpenTelemetry and ship traces, metrics, and logs to Elastic Cloud using just 2 environment variables, no collector needed.

Contextual AI: Stop pinging the SRE: three MCP tools that turn Elastic Agent Builder into your team27;s runbook
Build three MCP tools in Elastic Agent Builder that read endpoint health, recent deploys and SLO burn rate directly in your editor. Encode your platform team27;s runbook once; every developer gets self-serve production context without pinging an SRE.

SNMP Topology Data in Kibana: Collection to Canvas
The Network Topology plugin for Kibana provides a ready-to-deploy Logstash pipeline, a structured schema, and a topology view that shows what27;s connected to what.

Configure downsampling directly in Elastic Streams, no more JSON editing needed
Configure downsampling in Elastic Streams alongside retention and tiers, with a live preview and validation. No more editing ILM or lifecycle JSON.

Self-Driving Observability: From Stacktraces to Profiling-Derived Metrics
Profiling-derived metrics turn raw stacktraces into time-series KPIs, unlock continuous profiling for every user and lay the foundation for an observability system that detects, investigates, and acts on its own.

Don27;t leave metrics on the table: query them with the ES|QL TS command
Recalibrate your mental model for time series queries: learn why FROM can produce inaccurate results for metrics, how TS fixes that, and when to use each command.

Bringing Fire to Elasticsearch: Adding Native Prometheus API Support
Query Elasticsearch directly from Prometheus-compatible clients via native PromQL, discovery, and metadata endpoints. Send data to Elasticsearch with Prometheus Remote Write.

From averages to any percentile: Elasticsearch ships native exponential histogram support in ES|QL
Query any percentile at any time. Elasticsearch natively stores OTel exponential histograms and lets you analyze distributions in ES|QL without fixed buckets or lossy conversions.

ES|QL queries for debugging LLM latency, cost and GPU saturation
Learn how to investigate LLM latency, token cost and GPU saturation using ES|QL against OpenTelemetry traces and get a root cause, not just a symptom.
