Case study
Log Ingestion Automation for Cloud Security
How SquareShift automated Elasticsearch log ingestion for a cloud security firm, unifying identity and threat-detection feeds under ECS-compliant, fully automated cluster deployment.
A security team's own log pipeline shouldn't be the least automated part of its stack — Ansible-driven cluster deployment turns that pipeline into infrastructure, not a manual chore.
Platform & Software Engineering Practice Lead, SquareShift
A US-based cybersecurity firm specializing in cloud security, secure access, and network protection.
Its platform supports enterprises in managing threats and log data at massive scale.
- Automated cluster deployment — Multi-node Elasticsearch clusters stood up without manual steps.
- ECS-compliant ingestion — ZIA and Okta logs unified under one schema.
- Secure by default — CA-signed Fleet configurations for every node.
How SquareShift delivered it.
The challenge
A cybersecurity firm needed to bring ZIA (Zscaler Internet Access) and Okta identity logs into a common schema, but manual, multi-step cluster deployment was slowing every rollout down. Mapping multiple security feeds to ECS added further overhead, and managing backups and authentication at scale was still a manual process.
The client needed secure, automated log ingestion pipelines — not another one-off script, but a repeatable way to stand up and secure clusters as the platform grew.
What we delivered
SquareShift automated multi-node Elasticsearch cluster deployment end to end using Ansible, removing the manual steps that had slowed previous rollouts. The team built ECS-compliant pipelines for Okta logs and integrated the NSS feed and Amazon S3 for secure ingestion.
Every cluster now ships with CA-signed Fleet configurations and SSL set up automatically as part of the same automation, alongside consistent backup routines.
The payoff
Cluster deployment is now fully automated through Ansible instead of manual, multi-step setup, and ZIA and Okta logs flow through ECS-compliant pipelines into a common schema.
Security ingestion is consistently CA-signed and backed by robust backup routines, giving the client a repeatable pattern it can apply as it onboards new log sources and scales further.
Where this work sits
