How Trellix Cut Log Parsing Time from Days to Minutes with LangGraph

Trellix, a global cybersecurity firm serving 40,000+ enterprise customers, built Sidekick — an internal agentic platform powered by LangGraph and LangSmith — to automate log parsing and security integration development. What previously took engineers 2–3 days per request now takes minutes, and plugin development that spanned multiple days now completes in a single afternoon.

Impact

Days → minutes

Log parsing time

Multiple days → ~1 afternoon

Plugin development time

Challenge

Trellix engineers spent 2–3 days per customer request manually parsing unfamiliar log formats and developing cybersecurity integrations, creating significant backlogs and slowing resolution times across the support organization.

Solution

Trellix built Sidekick, an internal agentic platform using LangGraph for modular workflow orchestration with human-in-the-loop controls, and LangSmith for observability and systematic agent performance evaluation before production deployment.

Tools & Technologies

Get the full story.

Sign up to read complete case studies, access detailed metrics, and unlock all use cases.

Full Story

Trellix protects more than 40,000 organizations worldwide with AI-native threat detection and extended detection and response (XDR) capabilities. Behind those customer-facing capabilities, Trellix's own engineering teams faced a growing operational burden: thousands of incoming customer requests for cybersecurity integrations and log parsing services, each requiring an engineer to manually interpret log formats, write parsing code, and manage back-and-forth communications. Each request consumed 2–3 days of engineering time and built a backlog that frustrated both customers and internal teams.

The company's response was Sidekick, an internal agentic platform designed to automate the most repetitive parts of this workflow. The challenge in building agentic systems, however, is not just getting them to work — it's getting them to work reliably enough to deploy, explain to stakeholders, and iterate on with confidence. Trellix needed a framework that supported modular design, human oversight during development and testing, and structured observability once in production.

LangGraph provided the orchestration layer. Its map-reduce patterns and Send API enabled Sidekick to be composed as a set of discrete, reusable modules rather than a fragile monolithic agent. Crucially, LangGraph's human-in-the-loop features allowed engineers to pause agent execution, review decisions, approve or modify actions, and restart workflows — a capability that proved essential for building trust in the system before full deployment. LangGraph Studio's visual graph interface made the agent's internal logic transparent to non-technical stakeholders, helping executives understand that Sidekick operated as a carefully engineered program rather than an opaque black box.

LangSmith served as the observability backbone. The team used its dataset management and experiment tracking features to compare different agent architectures systematically, monitoring metrics like recursion rates and document retrieval frequency. Structured trace data replaced raw AWS CloudWatch logs as the primary debugging interface, dramatically reducing time-to-insight when investigating failures.

The results were immediate and measurable. Log parsing that previously required 2–3 days of manual engineering work now completes in minutes. Cybersecurity plugin development that spanned multiple days now takes approximately one afternoon. The reduction in backlog pressure has improved customer response times and freed the engineering team to focus on higher-complexity work. Trellix plans to expand Sidekick's capabilities to external partners and extend automation across additional engineering workflows in the near term.

Similar Cases

C
Cogent
97% faster
vulnerability resolution speed

Cogent built an AI-powered cybersecurity platform with Claude as the reasoning layer, reducing critical vulnerability exposure from days/weeks to minutes — a 97% reduction — while reclaiming 40+ hours monthly from manual reporting.

CybersecurityCAClaude API
CR
C.H. Robinson
~5,500
orders automated daily

C.H. Robinson, one of the world's largest logistics providers managing 37 million shipments annually, built AI agents using LangChain and LangGraph to automate email-based shipment orders end-to-end. The platform now processes approximately 5,500 orders per day automatically, saving more than 600 hours of manual email processing work daily.

Logistics & TransportationLLangChainLLangGraph
M
monday.com
8.7x faster
evaluation speed improvement

monday Service implemented an eval-driven development framework using LangSmith and LangGraph to build and monitor customer-facing AI service agents, achieving 8.7x faster evaluation cycles for IT, HR, and Legal support workflows.

Enterprise SoftwareLLangSmithLLangGraph
K
Klarna
80%
reduction in average customer query resolution time

Klarna is a global fintech company serving over 85 million active users with payment and shopping solutions, processing 2.5 million transactions daily across more than 45 markets. Facing mounting pressure to scale customer support across global markets without proportional headcount increases, Klarna deployed an AI assistant built on LangGraph and refined with LangSmith that now handles the work equivalent of 700 full-time staff. The result is 80% faster customer query resolution and 70% automation of repetitive support tasks.

Financial ServicesLLangGraphLLangSmith
S
Stairwell
40,000+ characters
security data processed per claude request

Stairwell, a cybersecurity company, integrated Claude into its Maleval threat detection platform to summarize complex security findings for analysts. Claude's large context window allows it to process 40,000+ character API responses in a single pass, converting dense technical data into clear, actionable insights with minimal prompt engineering.

TechnologyCybersecurityCClaude