← All case studies

Elastic × Vrije Universiteit Brussel

Elastic x Vrije Universiteit Brussel, three engineers securing a university at scale

3 engineers managing 64 billion events across 300+ servers

Scattered logs and manual hunting to a single source of truth

Members read free

Unlock the full breakdown

Enter your email to open every case study in the library: the full screenshot, why it works, and the one thing worth stealing. One email unlocks all of them.

Free. No spam. Unsubscribe anytime.

Why it works

The case study earns New Capability as its primary tag because the before-state was not merely slow centralized logging but the complete absence of it: logs lived locally on individual servers with no way to search or correlate across them. The rogue DHCP server anecdote is well chosen because it makes the before-and-after concrete rather than abstract. There is a genuine pull toward Clarity given the core win is visibility, but the team went from zero security operations capability to a functioning SIEM, which crosses the line into net-new rather than simply seeing what was already measured.

Steal this

The before-and-after comparison table at the bottom of the case study maps each operational pain point to its specific resolution, giving readers a structured proof of value that is faster to scan than narrative paragraphs.

Full screenshot of Elastic x Vrije Universiteit Brussel, three engineers securing a university at scale Click to enlarge ↗
View the original on elastic.co ↗

This is editorial commentary and curation. The case study, screenshot, and all metrics are Elastic's published work; we link to the source and lead with our analysis.

  • Vendor Elastic
  • Customer Vrije Universiteit Brussel
  • Industry Nonprofit
  • Trigger NIS2 and CyFUN compliance requirements made centralized security monitoring a regulatory obligation
  • Format Written narrative
  • Structure Challenge-Solution-Results
  • Medium Web page