How UOL Uses Elastic AI to Cut Security Incident Resolution Time by 80%

UOL Group is Brazil’s largest digital media, technology, and payments platform, serving eight out of ten Brazilian internet users monthly across more than 200 applications and thousands of cloud and on-premises resources. After migrating from Splunk to Elastic Security and deploying Elastic AI Assistant and Attack Discovery with Amazon Bedrock integration, UOL reduced security incident resolution time by 80% — from days to minutes — and cut false positive alert volume in half.

Impact

80%

Incident resolution time reduction

50%

False positive reduction

200+

Applications monitored

Challenge

UOL’s security analysts worked across two or three disconnected platforms to investigate a single incident, spending hours or days manually pulling logs, correlating data, and building dashboards before they could diagnose and resolve threats.

Solution

UOL deployed Elastic Security, Elastic AI Assistant, and Elastic Attack Discovery integrated with Amazon Bedrock, consolidating observability and security on a single platform with AI-driven natural language alert investigation, automated threat triage, and generative AI root cause analysis.

Tools & Technologies

What Leaders Say

With Elastic, the time needed to fix actual security events has been reduced by 80%, and false positives are down 50%.

Alcides Zanarotti Junior, CTO, UOL

We went from responding to incidents in days to resolving them in minutes. Our analysts no longer juggle two or three different systems because everything they need is finally in one place.

Bruna Donatti, Blue Team Coordinator, UOL

Before Elastic with Amazon Bedrock, it would take days or hours to grab a log, search for the issue, put it on a dashboard and start analyzing. It now takes just minutes.

Alcides Zanarotti Junior, CTO, UOL
Get the full story.

Sign up to read complete case studies, access detailed metrics, and unlock all use cases.

Full Story

UOL Group sits at the center of the Brazilian internet. Eight out of ten Brazilian internet users visit UOL each month to read news, stream sports and entertainment, and access email and financial services. Managing that infrastructure means keeping 200-plus applications and thousands of containers, cloud resources, and on-premises servers running reliably — some of those systems have been in production for over two decades. The scale and heterogeneity of the environment made security operations particularly demanding.

For years, UOL’s security and observability workflows ran on separate platforms. Analysts moved between two or three systems to investigate a single alert, manually pulling logs, searching for patterns, and building dashboards before they could even begin analysis. A complex incident could consume hours or days. False positives were a chronic drain on analyst time, and the friction between disparate tools created blind spots and slowed response.

UOL migrated from Splunk to Elastic Security and consolidated observability and security onto a single Elastic cluster. On top of that foundation, the team deployed Elastic AI Assistant — which allows analysts to investigate alerts, generate queries, and respond to incidents using natural language — and Elastic Attack Discovery, an AI-powered triage layer that surfaces and prioritizes real threats while filtering noise. UOL also integrated Attack Discovery with Amazon Bedrock, leveraging large language models to power AI features across the platform.

The operational shift was immediate. What previously took hours or days — pulling a log, searching for the issue, correlating it across systems, building a dashboard — now takes minutes. “We went from responding to incidents in days to resolving them in minutes,” said Bruna Donatti, UOL’s Blue Team Coordinator. Incident resolution time dropped 80%. False positive volume fell 50%, freeing analysts to focus on real threats. And because observability and security now share a single platform, cross-team collaboration between operations, DevOps, and development teams improved significantly.

The cultural shift has been as notable as the technical one. Teams that were initially reluctant to change now compete to onboard into the platform. UOL’s security team transitioned from delivering set features to building team-specific rules and alerts based on internal customer requests — a more responsive and intelligence-driven security model. For Brazil’s largest digital platform, AI-powered security is now embedded in how the organization operates, not just layered on top of it.

Similar Cases

M
MrBeast
1M+
players who engaged with ai agent

MrBeast and Salesforce built an AI-powered interactive puzzle challenge for Super Bowl 2026, engaging over 1 million players through a Slackbot agent that helped fans organize clues and test theories in real time. The entire enterprise-grade platform — capable of handling 1.5 million simultaneous users — was built in 42 days using Agentforce, Experience Cloud, and MuleSoft, with zero data retained from players.

Media & EntertainmentSASalesforce AgentforceMMuleSoft
L
Luminate
334%
increase in daily data processing speed

Luminate powers the Billboard music charts and provides data intelligence across music, film, and television for major record labels, studios, and talent agencies. After migrating from on-premises Spark and SQL Server to Snowflake, the company achieved 334% faster daily data processing across more than 3.5 terabytes of daily input. Market reports that previously took a full month now run overnight, and Luminate can for the first time deliver cross-industry insights correlating music and TV consumption.

Media & EntertainmentSSnowflakeSCSnowflake Cortex AI
CA
Comcast Advertising
10–30%
reduction in data product development time

Comcast Advertising connects brands to nearly 125 million U.S. households through multiscreen TV campaigns spanning traditional and streaming platforms. The company’s data science team used Databricks Apps to transform complex predictive models into interactive forecasting dashboards accessible directly by sales and marketing teams. Development cycles shortened by 10–30%, with campaign managers gaining the ability to run what-if scenarios in real time without data science support.

Media & EntertainmentDADatabricks AppsDDatabricks
TW
The Washington Post
100%
invoice tax accuracy coverage

The Washington Post is a technology-forward media company combining world-class journalism with digital innovation. Facing an unmanageable volume of vendor invoices with inconsistent tax formats, The Post deployed an AI Agent powered by proprietary large language models through Automation Anywhere’s Agentic Process Automation platform. The result: 100% of invoices are now validated for tax accuracy, tax overpayments have been eliminated entirely, and the Finance team captured $1 million in automation value within year one.

Media & EntertainmentAAAutomation Anywhere
T(
THG (The Hut Group)
60%
reduction in mean time to respond (mttr)

THG (formerly The Hut Group) is a UK-based ecommerce retail company with revenues exceeding £2 billion, selling its own-brand and third-party cosmetics, dietary supplements, and luxury goods online while also providing ecommerce infrastructure to third parties through its Ingenuity division. Facing a rapidly expanding threat surface as it grew through acquisitions and added SaaS platforms, THG deployed Elastic Security as its unified SIEM, using machine learning capabilities to surface novel attack vectors and automation to eliminate manual triage overhead. The outcome: mean time to respond to security events dropped by 60%, first-line triage burden fell from 90% to 50% of analyst time, and physical storage costs declined by 60% through intelligent data tiering.

RetailESElastic Security
TA
Texas A&M University System
99%
incident resolution time reduction

The Texas A&M University System is one of the largest higher education systems in the United States, encompassing 11 universities, 8 state agencies, and a statewide emergency management network that collectively educates over 153,000 students while defending against state-sponsored hackers and cybercriminals. Faced with a massive threat surface spanning 25,000 endpoints, the system’s cybersecurity team deployed Elastic Security for Endpoint, using its machine learning capabilities and automation layer to unify data from hundreds of sources into a single interface. The result: incident resolution time dropped from months to two hours—a 99% reduction—while automated documentation saved over 100 analyst hours per month.

EducationESElastic Security
V
Vectorize.io
~2 hours
time to deploy ai solution for new client

Vectorize.io is a US-based software company that builds agentic and generative AI infrastructure, helping organizations in law, insurance, and finance make vast volumes of unstructured data usable by large language models. By integrating Elastic’s hybrid search and Elastic Cloud Serverless with Amazon Bedrock, Vectorize deploys production-ready AI solutions for clients in hours rather than weeks. One client whose developer community grew by a million users in a year relied on Vectorize’s real-time learning agent—built on Elasticsearch—to answer support queries and instantly index new answers for future use.

Software and TechnologyABAmazon BedrockEElasticsearch
N
N26
70%
task automation in targeted processes

N26 deployed Claude via AWS Bedrock across 15+ internal use cases in its first year, automating up to 70% of tasks in targeted customer service processes and cutting manual processing by 50% across 24 European markets. New AI implementations now go from ideation to evaluation in 1–2 weeks.

Financial ServicesABAmazon BedrockCEClaude Enterprise