← Back to CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%

Source proof for CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%

Source-bound proof

Verified source excerpts for every supported field

Each colour maps a published value to the exact source passage used to support it. Only bounded excerpts are public; administrators can inspect the complete captured source.

13 fields supported

Title

CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%

derived · high
…re This post is co-written with Moshiko Ben Abu, Software Engineer at CyberArk. CyberArk achieved up to 95% reduction in case resolution time using Amazon Bedrock and Apache Iceberg . This improvement addresses a challenge in technical support workflow: when a…

Description

CyberArk redesigned its technical support pipeline using AWS Fargate, PyIceberg and Amazon Bedrock (Claude 3.7 Sonnet) to auto-generate grok patterns for parsing diverse vendor log formats into Iceberg tables, and built autonomous AI agents that query Athena and CyberArk's knowledge base to perform root-cause analysis from natural-language questions. The system cut case resolution time by up to 95% (complex cases from up to 15 days to 2-4 hours), let engineers handle up to 4x more cases per day (from 2-3 to 8-12), and made logs queryable within minutes instead of hours or days.

derived · high
…fficiencies through three key innovations: Single stage serverless processing : AWS Fargate with PyIceberg directly creates Iceberg tables from raw logs in one pass, removing intermediate processing steps and crawler dependencies entirely. AI p…
…y took up to 15 days are now completed in 2 to 4 hours. Engineer productivity : Support engineers now handle 8 to 12 cases per day, compared to just 2 to 3 cases before. This means each engineer is helping up to 4x more customers. Data availability…

Company

CyberArk

classification · high
…t can take days, slowing resolution and reducing overall engineer productivity. CyberArk is a global leader in identity security. Centered on intelligent privilege controls, it provides comprehensive security…

Industry

Cybersecurity

classification · high
…t can take days, slowing resolution and reducing overall engineer productivity. CyberArk is a global leader in identity security. Centered on intelligent privilege controls, it provides comprehensive security…

Problem

When a support engineer received a new case, the biggest bottleneck was preparing data: customer logs arrived in different formats from multiple vendors requiring manual integration and correlation, AWS Glue crawlers ran as asynchronous batch jobs introducing delays of minutes to hours, and investigations required engineers to manually query data, correlate events and search documentation, taking hours or days.

derived · high
…his dependency became the most complex and time-consuming part of the pipeline. Crawlers ran as asynchronous batch jobs rather than in real time, often introducing delays of minutes to hours before support engineers could query the data. But the inefficiency went deeper than just architectural complexity. CyberArk s…

Solution

CyberArk built single-stage serverless log processing where AWS Fargate with PyIceberg directly creates Iceberg tables from raw logs, used Amazon Bedrock (Claude 3.7 Sonnet) to automatically generate and validate grok patterns for parsing diverse log formats, stored validated patterns in DynamoDB for reuse, and deployed autonomous AI agents that query Athena and CyberArk's knowledge base to perform flow identification, root-cause determination and solution recommendation from natural-language questions.

derived · high
…cess into a fully automated workflow. Autonomous investigation with AI Agents : AI Agents autonomously perform complete root cause analysis by querying log data, analyzing product knowledge bases, identifying event flows, and recommending solutions, transforming hours of manual investigation into minutes of automated intellige…

Business value

CyberArk achieved up to a 95% reduction in case resolution time, with simple cases dropping from 4-6 hours to 15-30 minutes and complex cases from up to 15 days to 2-4 hours; support engineers now handle 8-12 cases per day versus 2-3 before, up to 4x more customers helped per engineer, and logs became queryable within minutes instead of hours or days.

derived · high
…berArk achieved up to 95% reduction in time from case assignment to resolution. Simple cases that used to take 4 to 6 hours now take just 15 to 30 minutes. Complex cases that previously took up to 15 days are now completed in 2 to 4 ho…

Technology

Amazon Bedrock, Apache Iceberg, AWS Fargate, PyIceberg, Amazon Athena, AWS Glue, Amazon DynamoDB, Claude 3.7 Sonnet

classification · high
…taining customer data or using it for model training, maintaining data privacy. This entire process invokes Claude 3.7 Sonnet model from Amazon Bedrock and is orchestrated by AWS Fargate tasks with retry logic for reliability. The…

AI capabilities

Agentic AI, Generative AI

classification · high
…cess into a fully automated workflow. Autonomous investigation with AI Agents : AI Agents autonomously perform complete root cause analysis by querying log data, analyzing product knowledge bases, identifying event flow…

Use case type

Autonomous systems

classification · high
…cess into a fully automated workflow. Autonomous investigation with AI Agents : AI Agents autonomously perform complete root cause analysis by querying log data, analyzing product knowledge bases, identifying event flows, and recommending solutions, transforming hours of manual investigation into minutes of automated intellige…

Headline outcome

derived · high
…re This post is co-written with Moshiko Ben Abu, Software Engineer at CyberArk. CyberArk achieved up to 95% reduction in case resolution time using Amazon Bedrock and Apache Iceberg . This improvement addresses a challenge in technical support workflow: when a…

Deployment model

cloud

classification · high
…ips between related events, and make everything queryable in minutes, not days. The architecture had to be serverless to handle unpredictable support volumes, secure enough to protect customer Personally Identifiable Information (PII), a…

Deployment options

cloud

classification · high
…ips between related events, and make everything queryable in minutes, not days. The architecture had to be serverless to handle unpredictable support volumes, secure enough to protect customer Personally Identifiable Information (PII), a…
Capture details
Captured
11 Sept 2026, 06:08 UTC
Extractor
fetch-strip@1
Snapshot hash
220ede5f676f1345f3b54f2c8a190c40eb11a62d2f3e45b144d239e9116673b6