CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%
CyberArk redesigned its technical support pipeline using AWS Fargate, PyIceberg and Amazon Bedrock (Claude 3.7 Sonnet) to auto-generate grok patterns for parsing diverse vendor log formats into Iceberg tables, and built autonomous AI agents that query Athena and CyberArk's knowledge base to perform root-cause analysis from natural-language questions. The system cut case resolution time by up to 95% (complex cases from up to 15 days to 2-4 hours), let engineers handle up to 4x more cases per day (from 2-3 to 8-12), and made logs queryable within minutes instead of hours or days.
Overview
CyberArk redesigned its technical support pipeline using AWS Fargate, PyIceberg and Amazon Bedrock (Claude 3.7 Sonnet) to auto-generate grok patterns for parsing diverse vendor log formats into Iceberg tables, and built autonomous AI agents that query Athena and CyberArk's knowledge base to perform root-cause analysis from natural-language questions. The system cut case resolution time by up to 95% (complex cases from up to 15 days to 2-4 hours), let engineers handle up to 4x more cases per day (from 2-3 to 8-12), and made logs queryable within minutes instead of hours or days.
This entry has 13 published fields tied to exact passages in an immutable source capture.
Inspect the highlighted sourceThe challenge
When a support engineer received a new case, the biggest bottleneck was preparing data: customer logs arrived in different formats from multiple vendors requiring manual integration and correlation, AWS Glue crawlers ran as asynchronous batch jobs introducing delays of minutes to hours, and investigations required engineers to manually query data, correlate events and search documentation, taking hours or days.
The solution
CyberArk built single-stage serverless log processing where AWS Fargate with PyIceberg directly creates Iceberg tables from raw logs, used Amazon Bedrock (Claude 3.7 Sonnet) to automatically generate and validate grok patterns for parsing diverse log formats, stored validated patterns in DynamoDB for reuse, and deployed autonomous AI agents that query Athena and CyberArk's knowledge base to perform flow identification, root-cause determination and solution recommendation from natural-language questions.
Reported business value
CyberArk achieved up to a 95% reduction in case resolution time, with simple cases dropping from 4-6 hours to 15-30 minutes and complex cases from up to 15 days to 2-4 hours; support engineers now handle 8-12 cases per day versus 2-3 before, up to 4x more customers helped per engineer, and logs became queryable within minutes instead of hours or days.
Sources
Open any source and check the claim yourself — that is the point of the register.
This record was researched and written with AI assistance, and its claims were checked against the sources above. (EU AI Act art. 50 transparency notice.)
Other cybersecurity entries in the register.
Barracuda Networks Protects With AI
Barracuda Networks unified customer and product telemetry data using Databricks and AI to power BarracudaONE, an AI-powered platform delivering real-time threat detection and automated response by combining signals across attack vectors, securing hundreds of thousands of businesses worldwide.
WithSecure Built Luminen, an AI Cybersecurity Assistant, on Amazon Bedrock
Cybersecurity company WithSecure built Luminen, a generative AI assistant on Amazon Bedrock, to help organizations detect and respond to security events faster, minimizing damage and reducing downtime. WithSecure provides cybersecurity solutions for mid-market companies, prioritizing privacy, data sovereignty, and regulatory compliance in the European Union. Luminen integrates with WithSecure Elements and includes a Security Awareness Assistant that analyzes complex data tables to provide a 7-day security status overview, and an Investigation Assistant that analyzes technical data on identified security issues to build a narrative. Development began in December 2023, a public beta released in May 2024, and Luminen launched in September 2024. WithSecure also uses Amazon Neptune to build knowledge graphs storing relationships between security events.
Logically forecasts narrative risk for government and enterprise with a conversational AI agent on Databricks
Threat intelligence company Logically built a conversational AI agent using Databricks Agent Bricks Custom Agents, AI Search, Delta Lake and LangGraph to make narrative-risk intelligence accessible to non-technical users, processing over 10 million social media messages daily and going from concept to production-ready agent in under two weeks.
Palo Alto Networks advances cybersecurity with the Databricks Data + AI Platform
Palo Alto Networks adopted the Databricks Data + AI Platform, including Unity Catalog, Delta Lake and Spark Declarative Pipelines, to unify fragmented data across its Prisma Cloud modules, achieving 3x faster iterations on AI/ML features, a 20% reduction in COGS, 3x decrease in engineering development time, and 40% less time on data preparation.
Was this helpful?
Your feedback helps us improve our use case database
