Case study

Scalable Log Management with Elastic CCR

How SquareShift built a 16-node Elasticsearch cluster with bi-directional cross-cluster replication for a German automotive manufacturer's global log management.

Book a session
100GBLog data ingested daily, across multiple applications
18TB retention capacity spanning hot, warm, and cold tiers
16Nodes in the Elasticsearch cluster built for global log management

A German luxury automotive manufacturer with a strong focus on digital innovation.

Beyond vehicle production, it runs an extensive suite of connected services and digital platforms that require secure, scalable log management for global operations and compliance.

Impact

Log data ingested daily, across multiple applications. TB retention capacity spanning hot, warm, and cold tiers. Nodes in the Elasticsearch cluster built for global log management.

Key services
ClCloud Modernization
PePlatform & Software Engineering
Industry

Automotive

Key technologies / platforms

Elasticsearch · Kibana · Cross-Cluster Replication (CCR) · Index Lifecycle Management (ILM) · Role-Based Access Control (RBAC)

The engagement

How SquareShift delivered it.

The challenge

A German luxury automotive manufacturer runs an extensive suite of connected services and digital platforms beyond vehicle production, and needed secure, scalable log management to support global operations and compliance. Multiple independent log solutions had left the client with poor availability and scalability.

Growing data volumes demanded structured ingestion and efficient storage — the existing setup couldn’t keep up with either the scale or the high-availability bar the business needed.

What we delivered

SquareShift deployed Elasticsearch clusters with bi-directional cross-cluster replication, sized to ingest 100GB of log data a day from multiple applications while retaining 18TB across hot, warm, and cold tiers. The 16-node architecture was built to support both production and non-production environments.

The team implemented ingest pipelines, retention policies, and secure, role-based Kibana dashboards, giving the client one governed way to manage access across its now-unified log platform.

The payoff

The client now runs a 16-node Elasticsearch cluster with bi-directional replication, ingesting 100GB of data a day and retaining 18TB across tiered storage — a single, high-availability platform in place of multiple disconnected log solutions.

Secure, role-based Kibana dashboards give teams governed access to the data they need, and the replication architecture keeps the client’s global operations and compliance requirements covered without a single point of failure.

Bi-directional replication earns its complexity when compliance needs two independent, always-current copies of the same data — not just a nightly backup that's already stale by morning.

Cloud Modernization Practice Lead, SquareShift