How UOL Uses Elastic AI to Cut Security Incident Resolution Time by 80%

UOL Group is Brazil’s largest digital media, technology, and payments platform, serving eight out of ten Brazilian internet users monthly across more than 200 applications and thousands of cloud and on-premises resources. After migrating from Splunk to Elastic Security and deploying Elastic AI Assistant and Attack Discovery with Amazon Bedrock integration, UOL reduced security incident resolution time by 80% — from days to minutes — and cut false positive alert volume in half.

Impact

80%

Incident resolution time reduction

50%

False positive reduction

200+

Applications monitored

Challenge

UOL’s security analysts worked across two or three disconnected platforms to investigate a single incident, spending hours or days manually pulling logs, correlating data, and building dashboards before they could diagnose and resolve threats.

Solution

UOL deployed Elastic Security, Elastic AI Assistant, and Elastic Attack Discovery integrated with Amazon Bedrock, consolidating observability and security on a single platform with AI-driven natural language alert investigation, automated threat triage, and generative AI root cause analysis.

Tools & Technologies

What Leaders Say

With Elastic, the time needed to fix actual security events has been reduced by 80%, and false positives are down 50%.

Alcides Zanarotti Junior, CTO, UOL

We went from responding to incidents in days to resolving them in minutes. Our analysts no longer juggle two or three different systems because everything they need is finally in one place.

Bruna Donatti, Blue Team Coordinator, UOL

Before Elastic with Amazon Bedrock, it would take days or hours to grab a log, search for the issue, put it on a dashboard and start analyzing. It now takes just minutes.

Alcides Zanarotti Junior, CTO, UOL
Get the full context.

Sign up to read complete case studies, access detailed metrics, and unlock all use cases.

Full Story

UOL Group sits at the center of the Brazilian internet. Eight out of ten Brazilian internet users visit UOL each month to read news, stream sports and entertainment, and access email and financial services. Managing that infrastructure means keeping 200-plus applications and thousands of containers, cloud resources, and on-premises servers running reliably — some of those systems have been in production for over two decades. The scale and heterogeneity of the environment made security operations particularly demanding.

For years, UOL’s security and observability workflows ran on separate platforms. Analysts moved between two or three systems to investigate a single alert, manually pulling logs, searching for patterns, and building dashboards before they could even begin analysis. A complex incident could consume hours or days. False positives were a chronic drain on analyst time, and the friction between disparate tools created blind spots and slowed response.

UOL migrated from Splunk to Elastic Security and consolidated observability and security onto a single Elastic cluster. On top of that foundation, the team deployed Elastic AI Assistant — which allows analysts to investigate alerts, generate queries, and respond to incidents using natural language — and Elastic Attack Discovery, an AI-powered triage layer that surfaces and prioritizes real threats while filtering noise. UOL also integrated Attack Discovery with Amazon Bedrock, leveraging large language models to power AI features across the platform.

The operational shift was immediate. What previously took hours or days — pulling a log, searching for the issue, correlating it across systems, building a dashboard — now takes minutes. “We went from responding to incidents in days to resolving them in minutes,” said Bruna Donatti, UOL’s Blue Team Coordinator. Incident resolution time dropped 80%. False positive volume fell 50%, freeing analysts to focus on real threats. And because observability and security now share a single platform, cross-team collaboration between operations, DevOps, and development teams improved significantly.

The cultural shift has been as notable as the technical one. Teams that were initially reluctant to change now compete to onboard into the platform. UOL’s security team transitioned from delivering set features to building team-specific rules and alerts based on internal customer requests — a more responsive and intelligence-driven security model. For Brazil’s largest digital platform, AI-powered security is now embedded in how the organization operates, not just layered on top of it.

Similar Cases

O
Omnicom
90%
compute infrastructure cost reduction

Omnicom is one of the world’s largest marketing communications networks, with 75,000 employees serving over 5,000 clients across 70+ countries. The company migrated nine global data centers to AWS and built an AI-powered platform on Amazon Bedrock and Amazon SageMaker to deliver hyper-personalized campaigns at scale. The migration cut compute infrastructure costs by 90% while enabling real-time processing of 400 billion daily marketing events.

Media & EntertainmentASAmazon SageMakerABAmazon Bedrock
M
MrBeast
1M+
players who engaged with ai agent

MrBeast and Salesforce built an AI-powered interactive puzzle challenge for Super Bowl 2026, engaging over 1 million players through a Slackbot agent that helped fans organize clues and test theories in real time. The entire enterprise-grade platform — capable of handling 1.5 million simultaneous users — was built in 42 days using Agentforce, Experience Cloud, and MuleSoft, with zero data retained from players.

Media & EntertainmentSASalesforce AgentforceMMuleSoft
TW
The Washington Post
100%
invoice tax accuracy coverage

The Washington Post is a technology-forward media company combining world-class journalism with digital innovation. Facing an unmanageable volume of vendor invoices with inconsistent tax formats, The Post deployed an AI Agent powered by proprietary large language models through Automation Anywhere’s Agentic Process Automation platform. The result: 100% of invoices are now validated for tax accuracy, tax overpayments have been eliminated entirely, and the Finance team captured $1 million in automation value within year one.

Media & EntertainmentAAAutomation Anywhere
CE
Class Editori
One of Italy’s first AI agents in the media landscape
mfgpt launch milestone

Class Editori, a leading Italian media company specializing in finance, fashion, and lifestyle with 40 years of content archives, partnered with Softlab to build MFGPT on Google Cloud — one of Italy’s first generative AI agents in the media industry. The system unified four decades of journalistic archives and real-time financial data into BigQuery, powered by Gemini and Vertex AI, converting trial users into paid subscribers and securing B2B enterprise agreements with major financial institutions.

Media & EntertainmentFFirestoreGCGoogle Cloud Run
TM
The Metropolitan Museum of Art

The Metropolitan Museum of Art partnered with OpenAI to create a conversational AI experience called "Chat with Natalie" for its Sleeping Beauties fashion exhibition, letting visitors interact with a historically accurate AI portrayal of a 1930s New York socialite whose wedding dress is on display.

Media & EntertainmentCChatGPTCCCustom Chat Experience
L
Luminate
334%
increase in daily data processing speed

Luminate powers the Billboard music charts and provides data intelligence across music, film, and television for major record labels, studios, and talent agencies. After migrating from on-premises Spark and SQL Server to Snowflake, the company achieved 334% faster daily data processing across more than 3.5 terabytes of daily input. Market reports that previously took a full month now run overnight, and Luminate can for the first time deliver cross-industry insights correlating music and TV consumption.

Media & EntertainmentSSnowflakeSCSnowflake Cortex AI
BI
Beast Industries
1 million+
players who relied on slackbot’s guidance

Beast Industries is the creator-led conglomerate behind MrBeast, one of the world’s most-followed YouTube channels with hundreds of millions of subscribers. For Super Bowl 2026, Beast Industries partnered with Salesforce to build a first-of-its-kind AI-powered puzzle hunt that ran for a month, supporting over 1 million active players and 1.5 million simultaneous users at peak. An agentic Slackbot — built on Salesforce’s Trust Layer — guided players through clue discovery without revealing answers, blocking 64,000 prompt injection attacks in the process.

Media & EntertainmentSASalesforce Agentforce
T
TRY
30%
reduction in time spent on routine tasks

TRY, Norway's largest creative agency group with 400+ professionals, deployed Claude Enterprise as an enterprise-wide AI platform across creative, strategy, and technical teams. The implementation drove a 30% reduction in time spent on routine tasks and a 40% acceleration in proposal development. Over 50 use cases have been deployed across the organization's six business units.

TechnologyMedia & EntertainmentCEClaude Enterprise