{
 "categories": [
  "observability",
  "enterprise"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-10-02",
   "fact": "homepage",
   "note": "Sumo Logic presents the product as a SaaS log-analytics platform that also includes application observability, infrastructure monitoring, and SIEM.",
   "source": "https://www.sumologic.com/platform/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "license",
   "note": "The platform FAQ describes credit-based Flex licensing and a free trial that requires registration. It does not describe a permanent free tier.",
   "source": "https://www.sumologic.com/platform/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.api.exists",
   "note": "Sumo Logic documents REST APIs with deployment-specific endpoints, including https://api.sumologic.com/api/ for US1.",
   "source": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.api.kinds",
   "note": "The authentication guide says the APIs follow REST patterns and that the interactive docs use the OpenAPI specification unless otherwise stated.",
   "source": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.api.auth[0]",
   "note": "API clients authenticate with an access ID and access key, either as curl -u or as a Base64 HTTP Basic Authorization header. The key inherits the creating user's role.",
   "source": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.api.auth[1]",
   "note": "The US1 API reference documents OAuth bearer tokens from client-credentials or authorization-code grants, in addition to HTTP Basic access keys.",
   "source": "https://api.sumologic.com/docs/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.api.coverage",
   "note": "The OpenAPI reference includes users, roles, monitors, dashboards, folders, partitions, field extraction, SLOs, traces, and other admin groups. Its welcome text says Collector and Search Job APIs are documented separately.",
   "source": "https://api.sumologic.com/docs/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.data_access.export",
   "note": "The Search Job API returns log messages and aggregation records to third-party scripts. It is outside the OpenAPI spec and is available to the listed Enterprise and trial account levels.",
   "source": "https://www.sumologic.com/help/docs/api/search-job/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.data_access.import",
   "note": "The API reference documents JSON create and update operations for platform resources such as dashboards, monitors, folders, and users.",
   "source": "https://api.sumologic.com/docs/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.mcp.first_party",
   "note": "Sumo Logic documents a vendor-hosted MCP server per deployment, with US1 at https://mcp.sumologic.com/mcp. Zurich and AWS European Sovereign Cloud are not supported.",
   "source": "https://www.sumologic.com/help/docs/api/mcp-server/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.mcp.verdict",
   "note": "The help page is Sumo Logic's own MCP guide. Tools include alerts, dashboards, Cloud SIEM insights and rules, log search, and discovery. Auth is OAuth 2.0, with CIMD recommended and disabled until an administrator enables it.",
   "source": "https://www.sumologic.com/help/docs/api/mcp-server/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "sumologic.com/llms.txt is a first-party plain-text index of platform and documentation links for agents, and it points at an AI-instructions page.",
   "source": "https://www.sumologic.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "verdict.scores.api",
   "note": "The management API is broad, documented, and authenticated with access keys or OAuth. A 4-request-per-second limit, the separate Enterprise-gated Search Job API, and Collector APIs outside the OpenAPI spec keep it at 8.",
   "source": "https://api.sumologic.com/docs/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "verdict.scores.mcp",
   "note": "The official MCP server is useful for investigation. Bulk extraction is excluded, the shared 4-per-second limit applies, CIMD is off by default, and two deployments are unsupported, so the score is 7.",
   "source": "https://www.sumologic.com/help/docs/api/mcp-server/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as the current Sumo Logic MCP server guide.",
   "source": "https://www.sumologic.com/help/docs/api/mcp-server/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current API authentication, endpoint, and rate-limit guide.",
   "source": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/",
   "tier": "declared"
  },
  {
   "date": "2026-10-02",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current US1 OpenAPI reference.",
   "source": "https://api.sumologic.com/docs/",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-10-02",
  "volatility": "high",
  "watch": [
   {
    "type": "mcp",
    "url": "https://www.sumologic.com/help/docs/api/mcp-server/"
   },
   {
    "type": "docs",
    "url": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/"
   },
   {
    "type": "docs",
    "url": "https://api.sumologic.com/docs/"
   }
  ]
 },
 "homepage": "https://www.sumologic.com/platform/",
 "id": "sumo-logic",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "access-key",
    "oauth2"
   ],
   "coverage": "partial",
   "docs": "https://www.sumologic.com/help/docs/api/about-apis/getting-started/",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": [
    "json"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Log and security automation belongs on the REST API or the hosted MCP server.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Sumo Logic",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "datadog",
   "splunk",
   "honeycomb",
   "microsoft-sentinel"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Sumo Logic",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 7,
   "overall": 8,
   "rpa": null
  },
  "summary": "Sumo Logic is automatable today through its REST API. This record is Sumo Logic log analytics and Cloud SIEM. It is not Splunk, Datadog, Elastic, Google Security Operations, Microsoft Sentinel, IBM QRadar, or Honeycomb. API hosts are deployment-specific. The US1 reference is https://api.sumologic.com/docs/ and the US1 API root is https://api.sumologic.com/api/. Authentication is an access ID and access key sent as HTTP Basic, or an OAuth 2.0 bearer token from a client-credentials or authorization-code grant. The OpenAPI reference covers users, roles, monitors, dashboards, folders, partitions, field extraction, SLOs, traces, and related administration. Collector Management and the Search Job API are documented outside that specification. Search Job, which scripts use to retrieve log results, is limited to listed Enterprise and trial account levels and authenticates with an access key. Every API call shares a limit of 4 requests per second per user and 10 concurrent requests per access key. Sumo Logic also hosts an MCP server per commercial deployment, including https://mcp.sumologic.com/mcp for US1 and a FedRAMP host. Zurich and the AWS European Sovereign Cloud are excluded. MCP auth is OAuth 2.0. CIMD is recommended and stays off until an administrator enables it. Tools cover alerts, dashboards, Cloud SIEM insights and rules, one log-search call, and discovery of fields, extraction rules, and partitions. Unscoped log searches longer than 30 minutes are rejected. Sumo Logic says not to use MCP for bulk extraction, model training, or high-volume queries, and to use the Search Job API for bulk log retrieval. Cloud SIEM tools can appear for a role that lacks the license and then fail on call. Access is on by default and can be disabled in Feature Management. https://www.sumologic.com/llms.txt is a first-party documentation index for agents. Computer-use viability is unassessed. The API scores 8. MCP scores 7.\n"
 }
}