Cloud Analytics

Alight Solutions Achieves 55 Percent Cost Reduction and Operational Efficiency Through Migration to Amazon OpenSearch Service

Alight Solutions, a global leader in cloud-based human capital technology and services, has successfully completed a large-scale migration of its logging infrastructure from a self-managed Elastic Stack to Amazon OpenSearch Service. This strategic transition has resulted in a 55 percent reduction in monthly infrastructure and licensing costs while reclaiming approximately 2,000 engineering hours annually. By modernizing its log aggregation architecture, Alight now manages over 1 billion log records per day with significantly higher reliability, particularly during peak periods such as Annual Enrollment, where ingestion rates can soar to 100,000 records per second.

As an integrated provider of benefits administration, healthcare navigation, and employee experience solutions, Alight Solutions serves hundreds of enterprise customers and millions of individual users worldwide. The company’s digital ecosystem, Alight Worklife, relies on a complex containerized microservices architecture. To maintain the health and security of this environment, the engineering team requires robust, real-time visibility into system behavior. However, the legacy logging system—a self-managed Elasticsearch 7.x deployment established in 2018—had become a bottleneck for innovation and a significant source of operational risk.

The Growing Burden of Legacy Infrastructure

The decision to migrate was driven by compounding technical and financial pressures. By late 2023, Alight’s self-managed Elastic Stack had grown to 15 Elasticsearch nodes utilizing 168 TB of Amazon Elastic Block Store (EBS) storage. While functional, the environment required an Elastic Platinum subscription to access necessary enterprise features. Between infrastructure costs and licensing fees, Alight was spending upwards of $100,000 per month across its various environments.

Beyond the financial cost, the operational toll was immense. The engineering team estimated that approximately 2,000 hours per year—equivalent to one full-time employee—were dedicated solely to "keeping the lights on." Tasks included manual security vulnerability patching, cluster resizing, and managing Logstash backpressure issues. These operational demands were so intensive that they consumed the entire operational budget, leaving no room for the team to implement advanced observability features like anomaly detection or automated alerting.

Technical instability also played a role in the push for change. In the two years leading up to the migration, Alight experienced two major P1 incidents directly linked to Logstash backpressure. During these events, the ingestion pipeline failed to handle spikes in log volume, leading to data loss and visibility gaps during critical troubleshooting windows. With Elasticsearch 7.x approaching its end-of-support life cycle, the Alight leadership team recognized that a fundamental shift was necessary to support the company’s long-term growth and stability.

Strategic Evaluation and Selection of Amazon OpenSearch Service

In evaluating potential replacements, Alight considered several managed service providers. The primary goal was to find a solution that could handle massive scale while reducing the "undifferentiated heavy lifting" of server management. The team ultimately selected Amazon OpenSearch Service based on five critical factors: cost-efficiency, scalability, security integration, ecosystem compatibility, and managed maintenance.

Amazon OpenSearch Service, a community-driven, open-source search and analytics suite, offered a seamless transition for Alight’s existing workflows. As a managed service, it automates common tasks such as hardware provisioning, software patching, failure recovery, and backups. This allowed Alight to move away from the rigid Elastic Platinum licensing model toward a more flexible, usage-based cost structure.

A pivotal component of the new architecture was the adoption of Amazon OpenSearch Ingestion (OSIS), a fully managed data collector that delivers real-time log data to OpenSearch domains. By utilizing OSIS in conjunction with AWS FireLens and Fluent Bit, Alight could eliminate the need for self-managed Logstash instances, thereby removing the primary source of previous system failures.

A Phased Migration Chronology

The migration process was executed over a seven-month period, beginning in February 2025 and concluding in August 2025. Alight adopted a disciplined, phased approach to ensure zero downtime for its mission-critical applications.

The initial phase involved the creation of standardized Infrastructure as Code (IaC) modules using Terraform. This allowed the team to templatize the deployment of OSIS pipelines and OpenSearch domains. By automating the onboarding process, the time required to integrate a new application into the logging system was reduced from a range of 80–120 hours down to just 4–8 hours—a 95 percent improvement in speed.

To mitigate risk, Alight first migrated two smaller applications to the production OpenSearch environment. This served as a proof-of-concept to validate operational processes and security configurations. Once these were stable, the team moved to the second phase: a parallel-run strategy for high-volume applications, including the flagship Alight Worklife system. During this stage, logs were simultaneously written to both the legacy Elasticsearch cluster and the new OpenSearch Service. This enabled the team to fine-tune cluster sizing, verify query performance, and ensure data integrity before the final cutover.

How Alight Solutions achieved 55% cost savings with Amazon OpenSearch Service | Amazon Web Services

The final phase addressed historical data. Alight migrated the most recent 30 days of live data from Elasticsearch into OpenSearch just prior to decommissioning the old nodes. For older data, the team implemented a full archive strategy using Amazon S3, allowing users to reload historical logs into OpenSearch on demand.

Technical Architecture and Security Integration

The resulting architecture is a sophisticated, cross-account model designed for maximum isolation and security. Log data originates in various "Application Accounts" where Amazon ECS and EC2 workloads reside. These logs are captured by Fluent Bit (via FireLens) and forwarded to a centralized "Logging Account" containing the Amazon OpenSearch Ingestion pipelines and the OpenSearch Service domains.

To solve the persistent issue of log loss during high-traffic events, Alight integrated Amazon Elastic File System (EFS) to provide persistent filesystem buffering for the Fluent Bit sidecar. This ensures that if the ingestion pipeline experiences transient latency, logs are stored safely on disk rather than being dropped from memory.

Security was a paramount concern given the sensitive nature of human capital data. Alight implemented a least-privilege model using AWS IAM roles to govern traffic between accounts. User access to OpenSearch Dashboards is managed through AWS IAM Identity Center, synchronized with Alight’s enterprise Identity Provider via System for Cross-domain Identity Management (SCIM). This setup allows employees to use Single Sign-On (SSO) for log analysis, following the same entitlement and approval workflows used for the AWS Management Console.

The production environment is powered by 18 im4gn.2xlarge.search instances, which leverage AWS Graviton2 processors to provide superior price-performance for data-intensive workloads. The storage strategy utilizes a tiered approach: 25 TB of high-performance "hot" storage for immediate analysis and 180 TB of "UltraWarm" storage for cost-effective retention of older data.

Quantifiable Results and Organizational Impact

The migration has delivered transformative results for Alight Solutions. The immediate 55 percent reduction in monthly costs is expected to climb to 65 percent once the final legacy clusters are fully decommissioned. This is particularly impressive given that Alight is now managing more applications on the new platform than it did on the old one.

Operationally, the engineering team has been liberated from the cycle of manual patching and emergency incident response. Since the full deployment of the OpenSearch-based architecture, Alight has recorded zero P1 incidents related to the logging subsystem. The 2,000 hours of recovered time are now being redirected toward high-value initiatives that improve the end-user experience for Alight’s clients.

"Alight’s mission-critical applications are built on hundreds of interdependent microservices, so effective application logging is critical for analyzing system behaviors, performance tuning, and troubleshooting," said Mark Larson, Enterprise Architect at Alight Solutions. "The ability to reconfigure, resize, and upgrade OpenSearch domains with a few clicks and zero downtime is a game changer for us."

Future Outlook: Innovation Beyond Log Aggregation

With a stable and cost-effective foundation in place, Alight is looking toward the future of observability. The company plans to leverage the advanced features of OpenSearch Service that were previously out of reach due to operational constraints.

Upcoming initiatives include the implementation of anomaly detection and AI-powered log analytics to proactively identify system issues before they affect users. Alight also intends to explore "Zero-ETL" integrations with Amazon S3 and Amazon Aurora to streamline data movement. Furthermore, the company is evaluating a move to Graviton3-based instances (m7g) to further optimize performance and continue its trajectory of cost-efficiency.

The success of this migration serves as a blueprint for other large enterprises burdened by legacy, self-managed data stacks. By partnering with AWS and embracing managed services, Alight Solutions has demonstrated that it is possible to achieve massive scale and high reliability while simultaneously reducing costs and fostering a culture of continuous innovation.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button