Skip to main content

Netskope WebTx (Apps)

icon

We're excited to introduce the new Netskope WebTx app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Netskope WebTx source to collect the web transaction logs from the Netskope WebTx platform. It provides security and IT teams the visibility and insights into web transactions, helping organizations monitor, analyze, and secure their web traffic. Learn more.

Sumo Collection Source (Collection)

icon

We're excited to announce the release of our new cloud-to-cloud source for Sumo Collection. This source aims to collect the list of collectors and their sources using Sumo Logic Collector API and Source API and send them to Sumo Logic for streamlined analysis. Learn more.

Content Management for Organizations - Beta (Manage)

icon

We are excited to announce a new Content Management tab that allows MSSP administrators the ability to conveniently push updates to multiple child organizations at once. Learn more.

note

This feature is in Beta. To participate, contact your Sumo Logic account executive or our Support Team.

Content Management tab

New UI Becomes the Default Experience at Sign-in (User Interface)

icon

We’re excited to announce the next milestone in our transition to the New UI. Starting today, the New UI will become the default experience when you sign in to Sumo Logic.

The Classic UI will be retired in 2025. The exact date will be communicated closer to the transition. To ensure you have access to the latest features, performance improvements, and innovations, we encourage you to start using the New UI as soon as possible.

What’s changing?

  • New UI by default. You will automatically log into the New UI when signing in.
  • Temporary opt-out. If your org was created before this change, you can switch back to the Classic UI, and future logins will remember your preference.
  • New orgs use only the new UI. If your org was created after this change, the Classic UI will not be available.
  • MSSP exception. If your org was created through a parent org, you can still switch to the Classic UI.

Improvements since initial release

Here's what's changed since the last rollout.

  • Faster navigation and performance. Improved menu loading, collapsible and resizable subnavigation, and persistent menu state across tabs.
  • More intuitive workflows. Open/duplicate log searches, drill into Favorites folders, and set a preference to open menu items in new tabs.
  • New features and enhancements. Improved keyboard navigation and UI refinements.
  • Bug fixes. Improved org switcher, Library search fixes, and other minor UI updates.

Learn more.

New in Copilot - Dynamic Titles, Alert Troubleshooting, and Pinned Suggestions (Copilot)

icon

We've introduced three new features to improve your Copilot experience:

Dynamic Conversation Titles

Copilot now automatically updates conversation titles based on your query, making it easier to track and revisit past investigations. You can also customize it by clicking the pencil icon next to the title.

  • Better organization. Conversations now have meaningful names for easy navigation.
  • Faster troubleshooting. Quickly find and resume previous investigations.
  • More control. Rename conversations to match your workflow.

"Open in Copilot" for Alerts

We've added an Open in Copilot button to the Alert Response page, allowing you to troubleshoot alerts directly in Copilot. This preserves the alert context, making it seamless to investigate and resolve issues.

  • Faster root cause analysis. Jump into Copilot instantly from an alert.
  • Context-aware troubleshooting. Maintain alert details while searching logs.

Suggestion Pinning

Now you can pin Copilot suggestions for easy reference. Just hover over a suggestion and click the pin icon to save it within your conversation.

  • Quick access. Keep important suggestions handy for ongoing investigations.
  • Improved workflow. No need to scroll back to find key recommendations.

Learn more.

Threat Intelligence (Security)

icon

We’re excited to introduce Sumo Logic Threat Intelligence, a powerful feature set that enables Cloud SIEM administrators to seamlessly import indicators of Compromise (IoC) files and feeds directly into Sumo Logic to aid in security analysis. IoCs are individual data points about threats that are gathered from external sources about various entities such as host names, file hashes, IP addresses, and other known targets for compromise.

Once indicators are ingested and appear on the Threat Intelligence tab, Cloud SIEM analysts can use the hasThreatMatch function in Cloud SIEM rules to analyze incoming records for matches to the threat intelligence indicators.

Sumo Logic Threat Intelligence will help you stay ahead of emerging threats and enhance your security posture.

note

Only Cloud SIEM administrators can add threat intelligence indicators to the datastore.

Learn more.

Threat Intelligence tab

Apps, Solutions, and Collection Integrations - February Release

icon

New release

We’re excited to announce the release of the new Azure Container Instance app and three OpenTelemetry Remote Management source templates for Sumo Logic.

  • Azure Container Instance app. Azure Container Instances is a fully managed serverless container service that enables you to deploy and manage containers in Azure without the need for virtual machines. This integration allows you to analyse logs and metrics pertaining to Azure Container Instances. Learn more.

  • OpenTelemetry Remote Management. Released MySQL, PostgreSQL, and ElasticSearch OpenTelemetry Remote Management source templates.

Enhancements

Automox (Apps)

icon

We're excited to introduce the new Automox app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Automox source to collect audit and event logs from the Automox platform. It provides security and IT teams with visibility into endpoint management and security. By using this app, teams can improve their security monitoring, streamline endpoint management, and strengthen operational resilience. Learn more.

CyberArk Audit Source (Collection)

icon

We're excited to announce the release of our new cloud-to-cloud source for CyberArk Audit. This source aims to collect the audit events from the CyberArk platform using the CyberArk SIEM integrations API and send them to Sumo Logic for streamlined analysis. Learn more.

New Option to Explore the App Catalog During Onboarding (Apps)

icon

We've updated the onboarding experience to give you the option to bypass data collection setup and explore the App Catalog instead.

A new Go to App Catalog option now appears in the left-hand menu on the data setup page, allowing you to browse integrations and pre-built dashboards before configuring data ingestion. This change makes it easier to explore Sumo Logic’s capabilities without committing to a full setup.

To learn more, check out our quickstart and signup guides.

Single Sign-on for Child Organizations (Manage)

icon

Enabling SSO for child organizations makes moving between organizations under your authority much more seamless and convenient. We are excited to announce that single sign-on (SSO) is now automatically enabled when you create child organizations, allowing you to sign in to child organizations without having to provide separate credentials. Learn more.

Dragos (Apps)

icon

We're excited to introduce the new Dragos app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Dragos source that collects collect vulnerabilities, notifications, addresses, zones, and assets logs from the Dragos platform. This app helps security analysts to minimize cybersecurity risks, improve operational resilience, and safeguard critical infrastructure from evolving cyber threats. Learn more.

Sysdig Secure Source (Collection)

icon

We're excited to announce the release of our new cloud-to-cloud source for Sysdig Secure. This source aims to collect the scan results from the scanner using Sysdig API and send them to Sumo Logic for streamlined analysis. Learn more.

Trust Login (Apps)

icon

We're excited to introduce the new Trust Login app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Trust Login source that collects report logs from the Trust Login platform, enabling security analysts to monitor authentication events and user activities, and respond to potential security threats across your organization. Learn more.

Code42 Incydr (Apps)

icon

We're excited to introduce the new Code42 Incydr app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Code42 Incydr source that collects audits, file events, and user sessions data from the Code42 Incydr platform. This app helps security analysts monitor, detect, and respond to potential data threats across an organization. Learn more.

JumpCloud Directory Insights (Apps)

icon

We're excited to introduce the new JumpCloud Directory Insights app for Sumo Logic. This app provides a comprehensive visibility into authentication events, user activities, and security-related actions within your JumpCloud-managed environment. The pre-configured dashboards can help you to track failed login attempts, privileged access changes, and account lockouts in real-time to improve security and ensure organizational policy compliance. Learn more.

Apps, Solutions, and Collection Integrations - January Release

icon

New release

We’re excited to announce the release of the new Azure Virtual Network app and 11 new OpenTelemetry Remote Management source templates for Sumo Logic.

  • Azure Virtual Network. Azure Virtual Network is a service that provides the fundamental building block for your private network in Azure, enabling many types of Azure resources to securely communicate with one other, using the internet, and on-premises networks. This integration helps in monitoring the outgoing and incoming traffic flows, dropped packets, bandwidth consumption, verifying network isolation, and compliance. Learn more.
  • OpenTelemetry Remote Management. Released Apache, Docker, Kafka, Linux, Local File, Mac, Nginx, RabbitMQ, Redis, Syslog, and Windows OpenTelemetry Remote Management source templates.

AWS Observability v2.11.0

This section details the new features and updates in AWS Observability for upgrading your Terraform script or CloudFormation template to version v2.11.0.

  • New Features:
    • Amazon RDS app. Added support to analyze and monitor RDS Oracle CloudWatch and CloudTrail logs.
    • Amazon Load Balancer apps. Added support to analyze and monitor Cloudtrail audit event logs for Application Load Balancer, Classic Load Balancer, and Network Load Balancer.
    • Added out-of-the-box monitors for RDS Oracle DB, Application Load Balancer, Classic Load Balancer, and Network Load Balancer. Solution now supports 78 out-of-box monitors.
    • Added support to collect custom metrics namespaces.
    • Added support to subscribe cloudWatch log groups based on AWS tags to Sumo Logic.
    • Added support to filter AWS CloudWatch metrics based on AWS tags.
  • Updates:
    • Updated cloudformation helper function with Lambda Runtime to python v3.13.
    • Updated SAM Lambda runtime to python v3.13 with latest library updates.
    • Updated Telemetry Lambda Runtime to python v3.13 with latest library updates.

To learn more, refer the AWS Observability changelog.

Enhancements

Bug Fixes

  • Kubernetes Control Plane. Added the quantization_interval filter variable.

Introducing Sumo Logic Organizations for Flex Customers (Manage)

icon

We are excited to announce that we are now supporting Sumo Logic's Organizations ("Sumo Orgs") feature for Sumo Logic Flex customers. With this release, Flex customers can effectively group, provision, manage, and monitor the credit usage across multiple organizations, providing greater visibility and control over account structures. Learn more.

VMware Workspace ONE (Apps)

icon

We're excited to introduce the new VMware Workspace ONE app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud VMware Workspace ONE source that collects audit logs data from the VMware Workspace ONE platform. This app helps security analysts monitor device compliance, encryption, and overall security status, offering a powerful solution for effective risk analysis, policy enforcement, and device security. Learn more.

Time-Phased Scan Budgets (Manage)

icon

We're excited to introduce the time-phased scan budgets for advanced usage management, which helps you to set Daily, Weekly, or Monthly budgets for individual user or a single shared budget for an entire group. Learn more.

Access Keys Enhancements (Manage)

icon

We're excited to announce enhancements to how you create and manage access keys.

Personal Access Keys

The My Access Keys section has been moved out of Preferences to its own tab and renamed Personal Access Keys.

Personal access keys

To open the Personal Access Keys tab:

  • Classic UI. In the main Sumo Logic menu, select your username and then Preferences > Personal Access Keys.
  • New UI. In the top menu select your username, and then under Preferences select Personal Access Keys. You can also click the Go To... menu at the top of the screen and select Personal Access Keys.

Scopes

You can now create permission scopes for access keys. Scopes limit the API endpoints an access key can be used to call. This allows you to specify only the permissions the access key needs to accomplish a specific task, making the key more secure.

Learn more.

Custom scopes example

New SaaS and Cloud Apps Release (Apps)

icon
  • Symantec Endpoint Security Service. We're excited to introduce the new Symantec Endpoint Security Service app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Symantec Endpoint Security source that collects incident and event logs data from the Symantec Endpoint Security platform. This app provides real-time insights into the log data that allows you to monitor and manage endpoint security in real time, enhancing quick responses to threats. Learn more.

  • Jamf. We're excited to introduce the new Jamf app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Jamf source that collects inventory data from the Jamf platform. This app helps security analysts with critical insights into their organization's Jamf environment. Learn more.

Remote Management for OpenTelemetry Collector (Collection)

icon

The Sumo Logic Distribution for OpenTelemetry Collector now supports remote management, enabling you to configure and manage data collection directly from the Sumo Logic UI. With this feature, you can:

  • Simplify configuration. Set up and manage data collection for multiple collectors without server access.
  • Streamline workflows. Use tags to group collectors and apply centralized data source templates, reducing redundancy and manual effort.
  • Enhance automation. Automatically monitor new servers by tagging them during setup.
  • Accelerate time to value. Start collecting data in minutes with an intuitive UI and no need to manage configuration files.

This release provides a faster, more efficient way to manage large-scale data collection, supporting scalable and automated operations. Learn more.

Trend Micro Vision One (Apps)

icon

We're excited to introduce the new Trend Micro Vision One app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Trend Micro Vision One source that collects alert logs data from the Trend Micro Vision One platform. This app helps you can gain real-time visibility into security events and incidents within your organization's infrastructure, allowing them to detect and react to potential threats quickly. Learn more.

2021 Archive

icon

This is an archive of the 2021 Sumo Logic Service Release Notes.

Looking for older release notes?

Release notes from 2016-2020 have been archived. If you need access to earlier versions, contact Support.

Status
Legal
Privacy Statement
Terms of Use

Copyright © 2025 by Sumo Logic, Inc.