Sumo Logic
AI-powered cloud SIEM and log analytics platform for intelligent security operations, threat detection, and infrastructure monitoring.
At a Glance
About Sumo Logic
Sumo Logic is a cloud-native security and observability platform that combines AI-driven log analytics, Cloud SIEM, and multi-agent AI (Dojo AI) to help DevOps and SecOps teams monitor, troubleshoot, and defend their environments. The platform ingests data from cloud and on-premises systems, correlates threats using machine learning, and automates incident response workflows. With 450+ integrations and Flex Licensing, teams can ingest unlimited data and pay only for what they analyze.
Key Features:
- Cloud SIEM — Automatically triages alerts, correlates threats using 900+ out-of-the-box rules, and maps detections to MITRE ATT&CK for faster incident investigation.
- Dojo AI (Multi-Agent Platform) — Specialized AI agents including a SOC Analyst Agent, Query Agent, Summary Agent, and Knowledge Agent that automate triage, generate queries from natural language, and condense signals into actionable summaries.
- Logs for Security — Provides anomaly detection, entity normalization, risk assessment, automated remediation, and cloud security posture monitoring powered by AI/ML models.
- Monitoring and Troubleshooting — Collects log, metrics, and trace data from cloud and on-premises systems with ML-powered root cause analysis (RCA) to slash MTTR.
- Flex Licensing — Usage-based pricing model where log ingest is free and costs are based on scan volume, enabling unlimited data ingestion without budget waste.
- 450+ Integrations — Pre-built apps and integrations for AWS, Azure, GCP, Kubernetes, OpenTelemetry, Slack, PagerDuty, ServiceNow, and more.
- Cloud SOAR — Automated playbooks, progressive automation, case management, and War Room for end-to-end security orchestration and response.
- Compliance & Certifications — SOC 2 Type II, FedRAMP Moderate, ISO 27001, HIPAA, PCI DSS 3.2, GDPR, and CCPA certified.
- UEBA & Threat Intelligence — Behavioral analytics models and premium threat intelligence feeds (including CrowdStrike and Intel471) to enrich investigations and prioritize threats.
To get started, sign up for a 30-day free trial (no credit card required), connect your data sources using the OpenTelemetry collector or one of 450+ integrations, and explore pre-built dashboards for immediate visibility into your security and operational data.
Community Discussions
Be the first to start a conversation about Sumo Logic
Share your experience with Sumo Logic, ask questions, or help others learn from your insights.
Pricing
30-Day Free Trial
Full platform access for 30 days with pre-built dashboards. No credit card required.
- Full platform access
- Pre-built dashboards
- Access to self-service plans
- No credit card required
Essentials
Ideal for small-to-medium-sized DevOps and SecOps teams requiring ad-hoc investigation and troubleshooting.
- Logs for Security (anomaly detection, entity normalization, risk assessment)
- Automated remediation
- Cloud Security Posture Monitoring
- AWS CloudTrail and Amazon GuardDuty threat benchmarking
- Up to 50,000 metrics/day
- Up to 5GB tracing/day
- Up to 365 days log retention
- 300/500 real-time alerting monitors
- Standard support (8x5)
- Sumo Credit – Tiers licensing
- Continuous log ingest
- Unlimited log capacity
- PCI, SOC2 Type 2, CSA, ISO, HIPAA certifications
- 400+ apps and integrations
- AI-driven alerting
- Customizable dashboards
- Single sign-on with SAML
Enterprise Suite
Ideal for maturing security teams looking for real-time threat detection, investigation, and response with Cloud SIEM and Cloud SOAR.
- Everything in Essentials
- Cloud SIEM with 900+ out-of-the-box rules
- Entity Timeline and Entity Relationship Graph
- Insight Global Confidence Scores
- MITRE ATT&CK Coverage Explorer
- UEBA behavioral models
- Premium threat intelligence (CrowdStrike, Intel471)
- Cloud SOAR with full playbook catalog
- Progressive automation
- Case Manager
- Supervised Active Intelligence
- War Room
- Unlimited metrics and tracing capacity
- Customer-defined log retention
- 1000/500 real-time alerting monitors
- Enterprise support (P1 24/7)
- Complex multi-org support
- Sumo Credit Flex licensing
- SIEM log ingest packaging
- Dojo AI (SOC Analyst Agent, Query Agent, Summary Agent, Knowledge Agent)
Capabilities
Key Features
- Cloud SIEM with 900+ out-of-the-box rules
- Dojo AI multi-agent platform (SOC Analyst, Query, Summary, Knowledge agents)
- AI-driven anomaly detection and alerting
- MITRE ATT&CK coverage explorer
- UEBA behavioral analytics
- Premium threat intelligence (CrowdStrike, Intel471)
- Cloud SOAR with automated playbooks
- Flex Licensing (usage-based, ingest-free model)
- Log analytics and search with LogReduce, LogCompare, LogExplain
- Infrastructure and Kubernetes monitoring
- Application observability with distributed tracing (OpenTelemetry)
- Real User Monitoring (RUM)
- 450+ integrations (AWS, Azure, GCP, Slack, PagerDuty, ServiceNow)
- Compliance dashboards (PCI, SOC2, HIPAA)
- Multi-org enterprise support
- Customizable dashboards
- Predictive analytics and outlier detection
- Single sign-on (SAML)
- Management APIs and Terraform support
