About Sumo Logic
Sumo Logic is a cloud-native security and observability analytics company that helps security operations teams ingest, analyze, and act on security and machine data at scale across modern cloud environments. With strong capabilities in cloud-first SIEM, threat detection, and compliance, Sumo Logic is a trusted security analytics platform for high-growth and enterprise organizations managing dynamic cloud infrastructures. Teams looking to integrate with Sumo Logic or build a Sumo Logic integration can use Synqly to route normalized security event and log data into Sumo Logic's analytics engine through standardized ingestion pipelines.
To learn more about this integration, check out the Sumo Logic technical docs.
About the Sumo Logic Cloud SIEM Integration
Sumo Logic Cloud SIEM is Sumo Logic’s cloud-native security information and event management platform, providing automated threat detection, investigation, and response capabilities optimized for cloud-first and hybrid environments. As Synqly’s SIEM provider, Sumo Logic Cloud SIEM enables security teams to route normalized security event data from Synqly-connected tools into Sumo Logic’s detection and analytics engine through a standardized connector. Integrate with Sumo Logic Cloud SIEM to centralize security telemetry from across your stack into Sumo Logic’s platform, enabling cloud-scale threat detection and security operations workflows.
Integration Use Cases
Get Investigation
Retrieves an investigation by ID.
Patch Investigation
Updates an investigation by ID.
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Investigations
Queries investigations
Query Log Providers
Queries available log providers in the source SIEM