Session

From Alert to Answer: Accelerating Anomaly Investigation with OpenSearch Agent Skills

Anomaly detection is the easy part. An alert fires at 2AM — now what?

The real cost isn't detection lag, it's investigation lag: the 20 minutes an on-call SRE spends correlating logs, cross-referencing metrics, and forming hypotheses before knowing where to look. OpenSearch's anomaly detection plugin surfaces the signal well. It has no opinion on what you do next.

This talk explores how agent skills in OpenSearch's ML framework can collapse that investigation window. Instead of a human triaging an alert, an agent picks up where the detector left off: querying correlated log indices, identifying co-occurring error patterns, cross-referencing recent deploys, and surfacing ranked probable causes — autonomously, before the SRE opens a dashboard.

We'll walk through the architecture of a plan-execute-reflect agent wired to an anomaly detection workflow, the tool design decisions that make agents useful vs. noisy in on-call contexts, and the failure modes that will humble you in production.

You'll leave with a clear pattern for connecting OpenSearch's anomaly detection and agent skills layers, and an honest assessment of where human judgment still wins.

Brian Graf

Sr. Developer Advocate - NetApp Instaclustr

Provo, Utah, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top