Redwood City, CA, USA
2010
  |  By Adam White
You already know the feeling. An alert fires, and you’re the one digging through logs to figure out if it matters. A query takes three tries to get right. A tool demo looked great, but you still cannot picture it running against your own environment. Before dedicating too much of your over-committed schedule to a proof of concept, you want to know one thing: does this actually work the way they say it does?
  |  By Margaret Selid
More security and operations work now happens inside an AI client instead of a dedicated console. That shift creates a gap for any platform that isn’t part of the conversation. Every time an analyst needs to triage an insight or check a log, they have to leave the AI client and go open a different tool. Sumo Logic closes that gap with a Model Context Protocol (MCP) server.
  |  By Oren Shevach
MFA fatigue campaigns work on a simple bet: eventually, someone taps “approve” just to make the notifications stop. It paid off. The attacker was in. The first move was quiet — deactivate SMS authentication, a small settings change easy to miss on a busy queue, and exactly the kind of thing that buys room to work without tripping an alarm. Then came the real work: AWS credentials pulled from one system, SSH keys from another, and a slow and methodical pull of internal source code.
  |  By Tamara Bailey
Commercial airlines run some of the world’s most complex technology environments. Every day, they balance decades-old aircraft systems with modern cloud platforms, connected devices, global payment networks, and strict regulatory requirements, all while ensuring flights depart safely and on time. For security teams, that means protecting an enormous attack surface without disrupting operations.
  |  By Margaret Selid
You’re collecting more telemetry than ever, but chances are it hasn’t made your job easier. Fragmented data, disconnected tools, and manual investigations mean more noise, slower response times, and higher operational costs. The promise of AI is that it will solve it, but in most cases, you just end up trading noise for expensive hallucinations. Point an LLM at raw, unorganized log storage, and you get an assistant that burns through credits to produce generic, unreliable answers.
  |  By David Girvin
Phishing used to be the easy alert. Bad grammar. A link to “Amazon.com.” A sender address off by one character. Analysts joked about it. You almost felt bad for the attacker. That era is over. AI killed it.
  |  By Janet Alexander
So, you want to be a cybersecurity analyst. With the rise in high-profile data breaches, privacy concerns and rapid technological advancements, there’s a greater demand for cybersecurity analysts now. And the demand for cybersecurity analysts is only expected to grow. But before you get too far into pursuing this job, let’s look into the basics of this profession. Below, we answer the most frequently asked questions about becoming a cybersecurity analyst.
  |  By Michelle Beastall
For nearly a decade, the security industry has used machine learning to solve detection. By feeding it enough logs and determining abnormal behaviors, it found the threats that rules-based systems miss. This delivered sharper anomaly detection, fewer false positives, and UEBA is now essential. In fact, threat detection and analytics account for close to 44% of total SIEM spend, the single largest use case by far. Using machine learning for detection was only the start.
  |  By Tamara Bailey
The banking industry stands at a critical intersection of technology, security, and customer experience. As financial institutions navigate massive data volumes and increasingly sophisticated threats, they’re also trying to survive the digital transformation that’s made customer expectations higher than ever and trust more fragile than before.
  |  By Christopher Beier
Artificial intelligence is rapidly reshaping how security operations centers (SOCs) function. Many organizations are now evaluating AI-native architectures to reduce workload and accelerate investigations. A new architectural narrative is emerging. A growing set of AI-native security vendors are proposing centralizing telemetry in a warehouse and deploying AI agents to replace the operational role of the SIEM. They want to centralize telemetry, apply AI, and automate the SOC.
  |  By Sumo Logic, Inc.
Join Jeremy Powell, CISO of Sumo Logic, to learn how AI-powered agents are reshaping modern security operations. Discover the key principles, governance, and best practices for building an agentic security program that enhances analyst productivity, accelerates threat response, and strengthens organizational resilience.
  |  By Sumo Logic, Inc.
On this episode of Masters of Data, we tackle breaking into cybersecurity. David shares his journey from welder to AppSec manager, proving that career pivots are tough but doable. We explore entry points like SOC analyst, GRC, and application security roles, noting that penetration testing gigs are fiercely competitive. AI is reshaping the landscape, making technical skills more accessible while amplifying the need for critical thinking. Networking beats degrees. Side projects and hands-on certifications matter more than credentials.
  |  By Sumo Logic, Inc.
Mobot is Sumo Logic's conversational interface designed to streamline investigations for SOC analysts and observability users. Ask a question in plain English and get a full SOC analyst-style investigation without writing a query. Inside an Insight, Mobot pulls context like the C2IP, ransomware hash, host, and exfiltration data automatically. A six-word question, "anyone else hit by the campaign?", triggers a full investigation across every mailbox and endpoint tied to that attack, with a link to the raw query behind every answer.
  |  By Sumo Logic, Inc.
Sumo Logic's SOC Analyst Agent automatically triages every insight within the SIEM, replacing the manual work that used to fall to a tier-one analyst. Using Sumo Logic's own SOC as customer zero, we found that 100% of tier-one alerts are triaged end-to-end by the agent, resulting in a 89% reduction in median time to triage, from 28 minutes to 3 minutes. In this demo, you’ll see.
  |  By Sumo Logic, Inc.
On this episode of Masters of Data, we take you inside the Dojo AI demo we're bringing to the show floor at Black Hat. We walk through the SOC Analyst Agent, Mobot, and MCP back to back. SOC Analyst Agent triages every tier one alert down to the one that actually matters, and Mobot picks up from there, running the investigation in plain English to track down other phishing victims and lateral movement. We also show how MCP pulls that same insight into Claude or Slack. SOC leads tired of alert fatigue and analyst burnout will want the numbers here: 100% of tier one alerts triaged automatically, and 25 hours a week back per person.
  |  By Sumo Logic, Inc.
On this episode of Masters of Data, we revisit the predictions Adam White, Zoe Hawkins, and David Girvin made at the end of last year, checking our own scorecard halfway through 2026. The hits: agents running amok and deleting databases, MCP becoming the backbone for tracking what agents actually do, growing security gaps around personal data, and a collective rejection of low-quality AI content. The misses: we underestimated how fast companies would cut staff for AI, then quietly start rehiring once the agents couldn't cover the work, and we're still arguing about whether token burn is a cost problem or a coming attack vector.
  |  By Sumo Logic, Inc.
Weekly office hours with David Girvin. Check out recent feature releases and updates, watch a quick live demo, and ask any questions with live Q&A.
  |  By Sumo Logic, Inc.
On this episode of Masters of Data, we dig into one of data's most contested formats: the dashboard. We explore why so many dashboards get built and never opened, tracing the shift from in-person SOC culture (big screens, shared visibility, immediate feedback) to the remote-work era of folders full of charts no one reviews. The conversation covers North Star metrics, the tension between practitioner and leadership dashboards, and the uniquely tricky problem of security metrics that can look green while a threat actor has quiet dwell time in your environment.
  |  By Sumo Logic, Inc.
EU organizations in finance, healthcare, telco, and government face a real tension: keep the business running or satisfy an ever-growing stack of data regulations. Most end up choosing one over the other. Sumo Logic and AWS just changed that. At Infosecurity Europe 2026, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, sat down with Sean Martin from ITSPmagazine to break down Sumo Logic's integration with the AWS European Sovereign Cloud — and what it means for security and operations teams operating in the EU. In this interview, Bill covers.
  |  By Sumo Logic, Inc.
On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.
  |  By Sumo Logic
Security information and event management (SIEM) solutions have been around since 2000, and they were developed with the goal of helping organizations in the early detection of targeted attacks and data breaches.
  |  By Sumo Logic
SIEM stands for Security Information and Event Management and these solutions have been around since 2000. They were developed with the goal of helping organizations in the early detection of targeted attacks and data breaches.
  |  By Sumo Logic
In this paper we will discuss some of the general philosophies and perspectives that will assist anyone who wants to securely leverage the benefits the cloud by using its strengths to overcome issues that have traditionally been labeled as weaknesses.
  |  By Sumo Logic
This white paper describes the technologies and processes used by Sumo Logic to secure customer data, and provides background on the company's deeply ingrained security culture.
  |  By Sumo Logic
This white paper is intended to support stakeholders movement of applications to the cloud, and provide some fundamental approaches to adopt in order to better protect every layer of the AWS infrastructure.

Empowering the People Who Power Modern Business. A Cloud-native Machine Data Analytics Platform for DevSecOps.

Sumo Logic is a secure, cloud-native, machine data analytics service, delivering real-time, continuous intelligence from structured, semi-structured and unstructured data across the entire application lifecycle and stack.

Build, run and secure your AWS, Azure, Google Cloud Platform or Hybrid applications with Sumo Logic, a cloud-native, machine data analytics service for log management and time series metrics.

  • Optimize Continuous Delivery: Accelerate development, testing, & deployment of your application.
  • Monitor & Troubleshoot in Real Time: Enable DevOps to proactively identify and fix performance issues.
  • Secure Your Platform: Detect, investigate and respond to security issues instantly.
  • Simplify Compliance Management: Ensure compliance with HIPAA, PCI, GDPR and much more.

One platform for real-time, Continuous Intelligence.