COMUNICAT Elastic Press

Elastic Observability Gives SREs a Head Start on Kubernetes Incident Investigations

What happened
Based on Elastic Press · Jun 08, 2026

Elastic introduces automated Kubernetes investigation workflows and MCP-based observability skills to accelerate incident resolution for SREs by identifying root causes before alerts are acknowledged.

Key points
·
New Kubernetes investigation workflows and agent skills analyze logs, metrics, anomalies, and cluster events, surfacing root causes and next steps automatically.
·
SAN FRANCISCO--(BUSINESS WIRE)-- Elastic (NYSE: ESTC), the Search AI Company, today introduced an agentic Kubernetes investigation workflow and MCP-based observability skills that diagnose incidents the moment an alert fires.
·
By the time an SRE opens the alert, the root cause has already been identified, evidence has been assembled, and recommended next steps have been surfaced.
·
For teams running Kubernetes at scale, the gap between alert and answer costs time, compounds outages, and wears down on-call engineers.
Key numbers
·
5x better storage efficiency than other vendors, ensuring engineers have comprehensive operational context.

Elastic has launched agentic Kubernetes investigation workflows and MCP-based observability skills that automatically diagnose incidents when alerts trigger. The system identifies root causes, compiles evidence, and suggests next steps before SREs are notified, reducing the time between alert and resolution. This addresses the operational cost of delays in large-scale Kubernetes environments, where outages can compound while engineers investigate manually.

The new capabilities integrate with existing tools like Claude, Cursor, VS Code, and MCP-compatible clients, allowing SREs to investigate Kubernetes environments conversationally. Engineers can query live data from Elasticsearch and view interactive details such as cluster health, service dependencies, anomalies, and blast radius analysis directly within their IDEs. Persistent alert rule management is also supported, streamlining ongoing monitoring.

Elastic Observability stores Kubernetes logs and metrics with 2.5x better storage efficiency than other vendors, ensuring engineers have comprehensive operational context. The agentic workflow either confirms a root cause or provides a structured starting point, eliminating the need to begin investigations from scratch. This reduces cognitive load during critical incidents, particularly during off-hours.

The Kubernetes integration, including dashboards, alert templates, and ML anomaly detection, is available across Elastic Cloud Hosted, Serverless, and self-managed deployments. The investigation workflow and MCP App are currently in technical preview, with access available via elastic.co or Elastic’s blogs. Elastic’s Search AI Platform underpins these solutions, supporting thousands of enterprise customers.

Original source → Deals on Clipraptor.com →