Case study

ELK Stack Upgrade: RHEL 7 to RHEL 8

How a global investment management firm upgraded its 16-node ELK Stack environment from RHEL 7 to RHEL 8.

Book a session
16Elasticsearch, Kibana, Fleet, and Logstash nodes upgraded to RHEL 8
Shard allocation, LDAP, and alerting issues resolved during the upgrade
Licensing cost recommendations and sizing analysis delivered alongside the upgrade

A global investment management firm offering retirement services, advisory solutions, and financial insights to individuals and institutions worldwide.

Its production ELK environment runs across 16 nodes, and needed to move from RHEL 7 to RHEL 8 for continued operational support.

Impact

Elasticsearch, Kibana, Fleet, and Logstash nodes upgraded to RHEL 8. Shard allocation, LDAP, and alerting issues resolved during the upgrade. Licensing cost recommendations and sizing analysis delivered alongside the upgrade.

Key services
ClCloud Modernization
PePlatform & Software Engineering
Industry

Financial Services

Key technologies / platforms

RHEL (Red Hat Enterprise Linux) · Elasticsearch · Kibana · Logstash · Fleet · Amazon Linux

The engagement

How SquareShift delivered it.

The challenge

A global investment management firm’s production ELK environment — 10 Elasticsearch nodes, 2 Kibana, 2 Fleet, and 2 Logstash, all on RHEL 7 — needed an OS upgrade, and the firm had to decide between Amazon Linux and RHEL 8 before touching a single node.

With cross-cluster replication running DR-first and rolling upgrades required across every tier, the coordination problem was as real as the OS choice itself — a heterogeneous environment that had to be upgraded node by node, not all at once.

What we delivered

SquareShift helped the firm settle on RHEL 8 for operational consistency, then executed tiered node upgrades in sequence — hot, then cold, then warm, then frozen — coordinating the rolling process across production and DR clusters and managing the DR-first migration and CCR resumption along the way.

Along the way, SquareShift resolved shard allocation, LDAP, and alerting issues surfaced by the upgrade, and delivered licensing cost recommendations and sizing analysis so the firm could plan its Elastic footprint going forward, not just complete the OS move.

The payoff

All 16 nodes across the ELK environment now run on RHEL 8, upgraded tier by tier with replication and DR intact throughout.

Shard allocation, LDAP, and alerting problems that surfaced during the move are resolved, and the firm has a licensing and sizing analysis in hand to guide its next capacity decision.

Migrating DR first and resuming replication after felt slower than upgrading production directly — until it meant every node upgrade after that was already validated.

Cloud Modernization Practice Lead, SquareShift