wallpaper
3 min

Cutting Elasticsearch log-storage costs with Scality RING - automotive case study

MIchael Anderle
Michael Anderle

Executive summary

Eywo moved a major automaker's long-term Elasticsearch log retention off expensive SAN block storage onto an on-premises, S3-compatible Scality RING cluster cutting cost per gigabyte while keeping historical logs instantly searchable through Elasticsearch searchable snapshots.

About client

A major automotive manufacturer generating massive daily streams of telemetry and operational logs.

The challenge

Storing multi-terabyte log data long-term on traditional SAN block storage hit hard limits:

  • High TCO: SAN block storage was financially unsustainable for long-term, multi-terabyte retention.
  • Rigid scaling: expanding traditional storage required disruptive upgrades and lengthy procurement.
  • Data isolation: standard cold archives rendered logs inaccessible for real-time security analysis and compliance audits.

The solution

Eywo designed and implemented a software-defined Scality RING cluster inside the client's secure on-premises environment:

  • Architectural design: sizing the cluster to handle high-throughput log ingestion and parallel query demand.
  • Implementation & integration: deploying the Scality nodes, validating high availability to eliminate single points of failure, and connecting the cluster natively to Elasticsearch.
  • Operational support: ongoing proactive and reactive 24/7 support.

The architecture unlocks Elasticsearch searchable snapshots: older logs are automatically offloaded to cheaper cold or frozen tiers on Scality RING while remaining fully searchable on demand.

Results

  • Significant cost savings: moving long-term logs from premium SAN to dense object storage sharply reduced cost per gigabyte.
  • Seamless scale-out: capacity expands linearly by adding standard x86 servers, with zero downtime.
  • Instant data access: no manual restore of archived logs — historical data stays instantly queryable for security teams.

Lessons learned

  • True, 100% S3 API compliance on-premises is critical so cloud-native tools like Elasticsearch work flawlessly without custom workarounds.
  • A scale-out object-storage foundation removes the operational anxiety of unpredictable data spikes and grows smoothly alongside the business.

Eywo designs and implements observability, ITSM, and infrastructure solutions for enterprise clients across regulated industries. If you're planning a similar project, get in touch.


Let's talk