-

Elastic Observability Gives SREs a Head Start on Kubernetes Incident Investigations

New Kubernetes investigation workflows and agent skills analyze logs, metrics, anomalies, and cluster events, surfacing root causes and next steps automatically.

SAN FRANCISCO--(BUSINESS WIRE)--Elastic (NYSE: ESTC), the Search AI Company, today introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires. By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended next steps have been surfaced.

For teams running Kubernetes at scale, the gap between alert and answer costs time, compounds outages, and wears down on-call engineers. Elastic closes that gap by starting the investigation automatically, before anyone is paged.

Elastic Observability builds on Kubernetes dashboards, prebuilt alert templates, and ML-powered anomaly detection to deliver two ways to accelerate from alert to resolution: an agentic investigation workflow that runs diagnostics automatically when alerts fire, and a Kubernetes MCP App with skills that brings the same investigation capabilities into the AI tools and IDEs engineers already use — Claude, Cursor, VS Code, and any MCP-compatible client.

The Elastic Observability MCP App lets SREs investigate Kubernetes environments conversationally, with AI agents querying live data from Elasticsearch and surfacing fully interactive views directly in the tool: cluster health rollups, service dependency graphs, anomaly detail with actual versus typical values, blast radius analysis for node failures, and persistent alert rule management.

Elasticsearch stores all Kubernetes logs and metrics at scale with 2.5x better storage efficiency than other observability vendors, ensuring engineers have access to the full operational context needed to investigate incidents. Whether the agentic workflow delivers a confirmed root cause or a structured starting point for continued investigation, SREs never start from scratch.

“Engineers who get paged at 3 a.m. don’t want to start a new investigation from scratch, they want answers," said Bahaaldine Azarmi, general manager, Observability at Elastic. "With this release, Elastic kicks off the investigation the moment an alert fires, so teams reach resolution faster and with more confidence. And because it runs inside the tools engineers already use, there's no context switch and no new interface to learn.”

Availability

The Elastic Kubernetes integration, including dashboards, alert templates, and ML anomaly detection, is available across Elastic Cloud Hosted, Serverless, and self-managed deployments. The Kubernetes investigation workflow and Elastic Observability MCP App are available in technical preview.

To get started, visit elastic.co or read the Elastic blogs.

About Elastic

Elastic (NYSE: ESTC), the Search AI Company, integrates its deep expertise in search technology with artificial intelligence to help everyone transform all of their data into answers, actions, and outcomes. Elastic's Search AI Platform — the foundation for its search, observability, and security solutions — is used by thousands of companies, including more than 50% of the Fortune 500. Learn more at elastic.co.

Elastic and associated marks are trademarks or registered trademarks of elasticsearch B.V. and its subsidiaries. All other company and product names may be trademarks of their respective owners.

Contacts

Media Contact
Elastic PR
PR-team@elastic.co

Elastic N.V.

NYSE:ESTC

Release Versions

Contacts

Media Contact
Elastic PR
PR-team@elastic.co

More News From Elastic N.V.

Elastic Brings OpenAI GPT Cyber Models Into Elastic Security to Help Defenders Investigate and Remediate Threats Faster

SAN FRANCISCO--(BUSINESS WIRE)--Elastic (NYSE: ESTC) today announced plans to bring OpenAI GPT cyber models into Elastic Security. By integrating these models directly into Elastic Security workflows, Elastic aims to give security teams specialized cyber reasoning capabilities for alert triage, investigation, detection engineering and remediation, without requiring customers to deploy and manage separate model infrastructure. Security operations teams face a persistent mismatch between alert vo...

Elastic Announces Internet Availability of Proxy Materials for its 2026 Annual General Meeting of Shareholders

SAN FRANCISCO--(BUSINESS WIRE)--Elastic (NYSE: ESTC) announced the internet availability of proxy materials for its 2026 Annual General Meeting of shareholders to be held on October 15, 2026, at 5:00 PM, Central European Summer Time. The Elastic annual report on Form 10-K for the fiscal year ended April 30, 2026, and proxy statement for its 2026 Annual General Meeting of shareholders have been filed with the U.S. Securities and Exchange Commission (SEC) and may be viewed on the Elastic website...

Elastic Nominates Julia Liuson to Board of Directors

SAN FRANCISCO--(BUSINESS WIRE)--Elastic (NYSE: ESTC) today announced that it has nominated Julia Liuson to its Board of Directors. Liuson is a veteran technology executive with more than three decades of experience spanning software engineering, AI, developer platforms and enterprise technology. She most recently served as President of Microsoft’s Developer Division, where she led technology and business strategy for Microsoft’s developer tools and Azure developer platform. Her portfolio also i...
Back to Newsroom