Elastic × Vrije Universiteit Brussel
3 engineers managing 64 billion events across 300+ servers
Scattered logs and manual hunting to a single source of truth
Members read free
Enter your email to open every case study in the library: the full screenshot, why it works, and the one thing worth stealing. One email unlocks all of them.
Free. No spam. Unsubscribe anytime.
You're in — enjoy the library.
The case study earns New Capability as its primary tag because the before-state was not merely slow centralized logging but the complete absence of it: logs lived locally on individual servers with no way to search or correlate across them. The rogue DHCP server anecdote is well chosen because it makes the before-and-after concrete rather than abstract. There is a genuine pull toward Clarity given the core win is visibility, but the team went from zero security operations capability to a functioning SIEM, which crosses the line into net-new rather than simply seeing what was already measured.
The before-and-after comparison table at the bottom of the case study maps each operational pain point to its specific resolution, giving readers a structured proof of value that is faster to scan than narrative paragraphs.
Click to enlarge ↗ This is editorial commentary and curation. The case study, screenshot, and all metrics are Elastic's published work; we link to the source and lead with our analysis.