Evidence: Low35/100

CyberArk: AI agents with Amazon Bedrock to automate customer support log parsing and investigation

CyberArk redesigned support operations to ingest heterogeneous customer logs, automatically generate parsing patterns, create queryable Iceberg tables, and let AI agents answer natural-language investigation questions. The system uses Amazon Bedrock on AWS Fargate with Amazon S3, AWS Glue Data Catalog, Amazon Athena, Apache Iceberg, AWS Glue automatic table optimization, and Amazon DynamoDB to remove manual log preparation and accelerate root-cause analysis.

Organization
CyberArk
Industry
Tech & Comms
Published
February 2026

Reported outcomes

−95%

case resolution timeTime & speed

8-12%cases per engineer per day

Strategic outcomes

Speed & agilityLogs became queryable within minutes of uploadOther strategic outcomeNew log formats and schema changes require zero manual interventionScale & capacitySupport operations can scale without proportional engineering growthCustomer experience & trustCustomers receive faster issue resolution
Why do we believe this?Outcome claims, sources, and evidence checks

Normalized claim

Case resolution time: 95% decrease

AWS Big Data BlogFeb 18, 2026Blog postExplicit claimLow evidence strength

up to 95% reduction in time from case assignment to resolution

Normalized claim

Cases per engineer per day: 8-12% increase

AWS Big Data BlogFeb 18, 2026Blog postInferred claimLow evidence strength

Support engineers now handle 8 to 12 cases per day, compared to just 2 to 3 cases before

Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
Customer
CyberArk
Provider
AWS
Maturity
Unknown
Linked source
AWS Big Data Blog

No explicit deployment-stage evidence found.

Customer identity supportedSource describes one deploymentMaturity evidence evaluated

Primary read

Use case focus

Showing 2 of 2

  • 1Customer support automation
  • 2Workflow automation
  • Support engineers spent hours to days manually preparing multi-vendor logs before investigations could begin.
  • New log formats and schema changes required days of parser integration work and crawlers introduced query delays.
  • CyberArk uploads log ZIP files to Amazon S3, processes them on AWS Fargate, uses Amazon Bedrock Claude 3.7 Sonnet to generate and validate grok patterns, and writes data to Apache Iceberg tables queryable in Athena.
  • AI agents query Athena and CyberArk's knowledge base to perform event correlation, root-cause analysis, and remediation recommendations with human escalation and feedback loops.
  • Logs onboarding time dropped from days to minutes.
  • Time from case assignment to resolution fell by up to 95%, with simple cases reduced from 4-6 hours to 15-30 minutes and complex cases from up to 15 days to 2-4 hours.
  • Support engineers now handle 8-12 cases per day versus 2-3 before, up to 4x more cases per engineer.
Architecture

Support engineers upload customer log ZIP files to Amazon S3. AWS Fargate processes the logs, uses Amazon Bedrock Claude 3.7 Sonnet to generate and validate grok patterns from sampled entries, and writes parsed data to Apache Iceberg tables with metadata from AWS Glue Data Catalog. Amazon Athena queries the Iceberg tables. AWS Glue automatic table optimization handles maintenance, and Amazon DynamoDB stores known grok patterns. AI agents answer natural-language support questions by querying Athena and CyberArk's knowledge base, with human escalation and feedback loops for unresolved cases.

Sources & evidence1
Evidence: Low35/100Evidence strength
  • Customer explicitly identified
  • Quantified outcome available
  • Technical implementation details available
Type: Blog PostPublished: Feb 18, 2026Publisher: AWSEvidence: VendorConfidence: Medium

AI-generated summary. Verify important details with the linked sources before relying on this case.

Explore related AI use cases

Was this useful?

Community

Comments

No published comments yet.