Sumo Logic

sumologic.com
Observability & Monitoring
Few Days

Cloud log management, monitoring, SIEM tools

How to Replace Sumo Logic

Overview

Sumo Logic is an AI-powered cloud monitoring and security platform that enables organizations to collect, analyze, and act on log data from cloud and on-premises systems. It provides real-time threat detection, incident investigation, and automated response capabilities through its unified SaaS platform powered by machine learning and generative AI.

Features

73 features across 11 categories

AI(12)

AI-driven AlertingAI

AutoML-powered anomaly detection to reduce false positives in real-time alerting

Anomaly DetectionAIPremium

AI models to detect suspicious and anomalous deviations from baseline behaviors

Dojo AIAIPremium

Multi-agent AI platform powered by specialized agents that identify, triage, and resolve issues faster

Global Intelligence Service AppsAI

Collection of apps leveraging machine learning to create advanced operational and security insights benchmarked against population of Sumo Logic customers

Insight Global Confidence ScoresAIPremium

Level of confidence predicted by Sumo Logic's Global Intelligence ML model that the Insight is actionable

Knowledge AgentAIPremium

Instant AI answers to platform questions

Mobot Conversational InterfaceAIPremium

Unified conversational interface that connects users to specialized AI agents

Progressive AutomationAIPremium

Machine learning-driven SOAR that learns repeatable patterns, distinguishes between real and false threats, and offers recommended courses of action

Query AgentAIPremium

Turns natural language requests into queries, simplifying data exploration

SOC Analyst AgentAIPremium

Automates alert triage to identify threats and speed response (beta)

Summary AgentAIPremium

Condenses Insight signals into summaries, reducing noise and highlighting context

Supervised Active IntelligenceAIPremium

Combination of multiple Machine Learning capabilities working together to ensure smooth and uninterrupted SecOps workflow

Also in: monday.com, Notion, Airtable

Administration(2)

Ingest Budgets

Control the daily volume of log data sent to Sumo Logic by assigning ingest budgets that define daily log capacity limits

Scheduled Alert Muting

Pause alert notifications from monitors according to a schedule you define

Also in: Notion, Airtable, Smartsheet

Analytics(15)

Advanced Span Analytics

Aggregate distributed trace data and derive advanced analytics using Sumo Logic Query Language

Alert Response

Provides contextual insights about triggered alerts to minimize investigation and resolution time

Automated Log-level DetectionAI

Quickly identify anomalies and drill down into high-severity logs in the log search histogram

Entity NormalizationPremium

Ingested data fields organized into a schema for further queries and advanced analytics

Entity Relationship GraphPremium

View information about an Entity in an Insight and all other connected (related) entities or systems

Entity TimelinePremium

View information about entity activity before, during, and after Signals and Insights involving the entity

Geo IP Lookups

Automatically visualize IP addresses in dashboards by geolocation

Insight Rules EnginePremium

Transparent rules engine applied to incoming logs to surface Signals and Insights with 900+ out-of-the-box rules

Insight TrainerPremium

Dashboard offering suggestions for making adjustments to rules, such as writing rule tuning expressions and changing severities

Log Search and Visualizations

Use Sumo Logic's Query Language and Dashboarding Framework to parse, aggregate and visualize insights from raw log data

LogReduce, LogCompare, and LogExplain

Patented operators designed to quickly assess activity patterns and surface behavioral insights to accelerate troubleshooting

Lookup Tables

Enrich log data ingested by Sumo Logic in real time with in-memory lookup tables

Metrics Predict OperatorsAI

Predict future time series metrics values using linear and auto-regressive models for resource and capacity planning

Predictive Analytics and Outlier DetectionAI

Forecast trends and identify anomalous activity in real time with advanced query operators

Software Development Optimization

Manage software delivery performance against industry-standard DORA metrics

Also in: Hugging Face, Notion, Smartsheet

Automation(4)

Automated Playbooks

Build and execute automated playbooks tied to alerts with Sumo Logic's Automation Service

Automated RemediationAIPremium

Automatically take action to address security flaws using pre-defined workflows

Automation ServicePremium

Set up actions that run automatically when certain conditions are met for Insight enrichment, notifications, and containment actions

PlaybooksPremium

Predefined set of actions and conditional statements that run in automated workflow to respond to event or incident type

Also in: monday.com, Notion, Airtable

Compliance(3)

Compliance and Audit Logging

Monitor and audit Sumo Logic usage to meet regulatory and compliance requirements

PCI Compliance

Meet PCI DSS compliance requirements with automated controls and reporting

PCI Compliance Apps and Dashboards

Apps designed to help teams meet evolving PCI requirements and maintain audit compliance

Also in: Insider CDP, Airtable, 1Password

Integration(6)

Alerting Integrations

Route contextualized alerts to 3rd party tools including Slack, PagerDuty, ServiceNow to streamline investigations

Log Search API

Integrate Sumo Logic's Log Search capabilities into workflows and 3rd party tools via API for complex use cases

Management APIs

Administor Sumo Logic and manage users via API and/or with IaC tooling like Terraform

OTel Data Onboarding

Easily set up and configure native OTel data ingest and install relevant content to quickly derive insights

OTel for K8s Logs and Events

Enable k8s OTel collection with Sumo Logic's Helm Chart

Sumo Logic Apps

Access to 400+ apps and integrations designed to turn data into insights

Also in: monday.com, Notion, Airtable

Monitoring(5)

AWS CloudTrail and Amazon GuardDuty Threat BenchmarkingPremium

Real-time dashboards and searches evaluating organization against statistical baseline for performance and risk indicators

Cloud Log Management

Streamlined collection, storage, and analysis of logs as a single source of truth in unified SaaS platform

Infrastructure Monitoring

Monitor infrastructure performance and health across cloud and on-premises systems

Live Tail for Streaming Logs

View real-time feed of log events associated with a Source or Collector for development and troubleshooting

Monitoring and Troubleshooting

Collect log data from cloud and on-premises systems to proactively analyze and resolve issues before they affect applications

Observability(8)

APM and Distributed Tracing

Native support for collection of OpenTelemetry with pre-built analytics to monitor and respond to user-impacting performance issues

Application Observability

Full-stack observability with MELT telemetry to ensure application reliability

Kubernetes Observability

Out-of-the-box analytics visualize k8s hierarchical relationships to simplify troubleshooting across clusters

Metrics-based SLOs

Power SLIs and SLOs using metrics

Multi-Cloud Observability

Deep observability for multi-cloud organizations across AWS, Azure, GCP with pre-built integrations

Real User Monitoring (RUM)

Monitor real-user interactions across applications with pre-built visualizations and alerts powered by OpenTelemetry

Reliability Management (SLIs/SLOs)

Simple setup and monitoring of critical user journeys, error budgets and more using pre-built SLO dashboards

Service Maps

Easily understand relationships of complex service interactions across applications to simplify troubleshooting

Also in: Zuplo, Istio, Linkerd

Pricing(1)

Flex Licensing

Pay only for the data being used so you can ingest everything without budget waste

Reporting(3)

Customizable Dashboards

Tailor, extend, or create dashboards to align with specific monitoring, analytics, and reporting needs

Enterprise Audit and Logging Dashboards

Out-of-the-box dashboards that visualize Sumo Logic audit logs to give teams quick insight into user activities and events

Historical and Live Streaming Dashboards

Visualize historical and real-time data to derive contextualized, actionable analytics

Security(14)

Case ManagerPremium

Tools for managing and documenting security cases, including evidence collection, analysis, and reporting

Cloud Security Posture MonitoringPremium

Continuously view the overall state of cybersecurity readiness of your cloud environment

Cloud SIEMAIPremium

Speed up incident investigations by automatically triaging alerts and correlating threats through log analytics

Cloud SOARAIPremium

Security Orchestration, Automation and Response for automated incident response workflows

CrowdStrike Threat Intelligence

Identify indicators of compromise (IOCs) in log data by comparing against CrowdStrike IOC feed

Logs for SecurityAIPremium

Security platform that provides protection, compliance, and AI-driven guided search to help resolve incidents faster

MITRE ATT&CK Coverage ExplorerPremium

Shows MITRE ATT&CK adversary tactics, techniques, and procedures from Enterprise Matrix covered by rules in system

Premium Threat IntelligencePremium

Includes CrowdStrike, Intel471, and other native threat intel feeds to add context to SIEM rules

Risk AssessmentAIPremium

Quantifying the possibility of major impacts on business-critical processes due to cybersecurity threats

Security Data LakePremium

Centralized repository for security logs and data enabling advanced analytics

Single Sign-On with SAML

Support for federated identity access management and single sign-on

Threat DetectionAIPremium

Detect security threats faster with AI-powered analysis of logs and security data

UEBA Behavioral ModelsAIPremium

Suite of UEBA-specific rules designed to detect various classifications of anomalous activities compared against normal baselines

War Room ConfigurationsPremium

Configurations for war room management in security operations

Pricing

Essentials

Free Trial Available
  • Onboard in minutes
  • Start investigating and troubleshooting fast
  • AI-driven alerting to reduce alert fatigue
  • Automatically detects anomalies reducing false positives
  • ML-powered RCA to slash MTTR
  • Identify incident source with telemetry data
  • Hundreds of integrations
  • Up to 300 log monitors
  • Up to 500 metric monitors
  • Up to 365 days log retention
  • Up to 50,000 metrics per day
  • Up to 5GB trace data per day

Enterprise Suite

Popular
Contact Sales
  • Discover threats faster with cloud-native SIEM
  • High-fidelity entity-centric detection
  • Threats mapped to MITRE ATT&CK
  • UEBA-driven coverage
  • Investigate incidents quickly with threat intelligence
  • Full visibility into logs and advanced analytics
  • Strengthen security posture with premium threat intelligence feeds
  • Enrich investigations with external context
  • 24/7 support
  • Automation service with complex multi-org support
  • Up to 1000 log monitors
  • Unlimited user access
  • Unthrottled performance
  • Unlimited metrics per day
  • Unlimited trace data per day
  • Unlimited log retention

Cost Calculator

Pricing data not available for Sumo Logic. Check their website for current pricing.

Build vs Buy

Should you build a Sumo Logic alternative or buy the subscription? Estimate based on 73 features.

Buy Sumo Logic

Better Value
Monthly costContact Sales
3-year totalVaries
Time to deployDays

Build Your Own

Development cost$60,000
Maintenance$900/mo
3-year total$92,400
Dev time~5 months

Buying Sumo Logic saves ~$92,400 over 3 years vs building.

Estimates based on 73 features and a BuildScore of 4/5. Actual costs vary.

Integrations

11 known integrations