Skip to content

Add companion notebook for Alerts as data: investigating alert storms with ES|QL - #594

Open
Delacrobix wants to merge 2 commits into
elastic:mainfrom
Delacrobix:alerts-as-data-log-derived-signals-v2
Open

Add companion notebook for Alerts as data: investigating alert storms with ES|QL#594
Delacrobix wants to merge 2 commits into
elastic:mainfrom
Delacrobix:alerts-as-data-log-derived-signals-v2

Conversation

@Delacrobix

@Delacrobix Delacrobix commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Companion notebook for the Observability Labs article Alerts as data: investigating alert storms with ES|QL.

It builds the payments lab, replays two incidents with the gateway rule retuned in between, runs the three ES|QL investigation queries against .alerts-*, and registers the Alert Historian agent and its three tools. Runs for about 25 minutes because the rules evaluate once a minute; the last cell deletes everything it created. Includes .env.example and the OTel Collector configuration under supporting-blog-content/observability-labs/alerts-as-data-log-derived-signals-v2/.

Related article PR: https://github.com/elastic/observability-labs/pull/987

Builds the payments lab, replays two incidents, runs the three ES|QL
investigation queries, and registers the Alert Historian agent.
@gitnotebooks

gitnotebooks Bot commented Sep 7, 2026

Copy link
Copy Markdown

Found 1 changed notebook. Review the changes at https://app.gitnotebooks.com/elastic/elastic-labs/pull/594

@Delacrobix Delacrobix changed the title Add companion notebook: Alerts as data: investigating alert storms with ES|QL Add companion notebook for Alerts as data: investigating alert storms with ES|QL Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant