Logging all operational and security events in our enterprise environment. We use Sumo Logic to monitor all the applications that we run in the Amazon AWS cloud; we use Sumo Logic to monitor the security posture of our AWS IaaS with CloudTrail, VPC flow, S3 audit, GuardDuty, and EKS services.
Contracting Automation Engineer at Craigslist
Out of the box applications were very useful for us. We also use the Threat Intelligence integration for our security monitoring.
What is our primary use case?
How has it helped my organization?
Sumo Logic is a single place to retrieve intelligence without worrying about architecture and performance.
What is most valuable?
The out of the box applications were very useful for us. We also use the Threat Intelligence integration for our security monitoring.
What needs improvement?
Automation is open to user's implementation, in my case, we used to use API to correlate and orchestrate events from Sumo Logic with other platforms, and now we are using an automation platform to centralize the various integrations.
Buyer's Guide
Sumo Logic Security
February 2025

Learn what your peers think about Sumo Logic Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
More than five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Engineering Manager at Braintree
It provides easy visibility and shareable queries
Pros and Cons
- "It provides easy visibility. I also like the shareable queries because we share a lot across groups."
- "There needs to be improvement on imported data which can be used within Sumo Logic to do more advanced queries."
What is our primary use case?
We use it to keep our information database.
How has it helped my organization?
It provides easy visibility. I also like the shareable queries because we share a lot across groups.
What is most valuable?
Being able to join logs together across many services and servers.
What needs improvement?
There needs to be improvement on imported data which can be used within Sumo Logic to do more advanced queries.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
We haven't had issues with it since I have been working with it.
What do I think about the scalability of the solution?
The scalability fits our needs. It seems very fast and works well.
How is customer service and technical support?
We just reach out via email if we need assistance.
What's my experience with pricing, setup cost, and licensing?
I don't pay the bill. I've heard the AWS Marketplace pricing is high, but I like the value.
Which other solutions did I evaluate?
It was already in place when I joined the company, and we are not currently looking at any alternatives.
What other advice do I have?
Reach out, see if you can get a demo on your data, and see how it fits your needs.
It works with all our main applications, so the integration with those products is pretty seamless from my standpoint.
We use the AWS version.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Sumo Logic Security
February 2025

Learn what your peers think about Sumo Logic Security. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Infrastructure Engineer at a wholesaler/distributor with 1,001-5,000 employees
We can ingest logs and make reports out of them. It is a good tool which can help us monitor any issues.
Pros and Cons
- "We can ingest logs and make reports out of them. It is a good tool which can help us monitor any issues."
- "It gives us a bird's eye view of what's happening from our connection's point of view."
- "I would like to see improvement in the user experience when configuring things, ingesting logs, and creating ports."
- "The initial setup is the most stressful, like learning how to use it."
What is our primary use case?
It is primarily for storing logs, then making reports out of the logs and also alert. If something goes up or down, or reaches a threshold, then we are on alert for that.
How has it helped my organization?
We push logs through Sumo Logic. The prime example is logs from our firewall. We have been pushing logs through Sumo Logic. Then, from there, we were able to generate reports which shows us security risks. In a way, it gives us a bird's eye view of what's happening from our connection's point of view.
What is most valuable?
We can ingest logs and make reports out of them. It is a good tool which can help us monitor any issues.
What needs improvement?
I would like to see improvement in the user experience when configuring things, ingesting logs, and creating ports.
Going forward, I would like more templates for reports, especially for common vendors, firewalls, and routers. That would be fantastic.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability is good. I have never had any issues with it.
What do I think about the scalability of the solution?
The scalability is good. You can get as much as you want.
Our environment is very small. However, we are beginning to ramp up by pushing logs through Sumo Logic, as we progress with our cloud migration.
How is customer service and technical support?
The technical support is fantastic.
How was the initial setup?
The initial setup is the most stressful, like learning how to use it. Once you get hang of it, it should be all right.
I have had minimal experience of using Sumo Logic with the cloud. However, I think it's a matter of providing user credentials on your AWS account. I know they have different apps for AWS which you can easily use.
What other advice do I have?
It satisfied what we required of it, but there's still room for improvement in terms of adding applications. Also, there is a little more improvement needed in terms of guiding users on the start up process.
Look at your functionalities, features, and how appropriate the solution is with what you need. Sumo Logic does give a lot of monitoring ability, even ingesting logs and integrating dashboard reports. You can do reports and alarms, which will aid whomever in the management of their infrastructure.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Sumo Logic Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM) Log Management Security Orchestration Automation and Response (SOAR)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
Securonix Next-Gen SIEM
Google Chronicle Suite
USM Anywhere
Sentinel
ArcSight Enterprise Security Manager (ESM)
Buyer's Guide
Download our free Sumo Logic Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?