Mobot is Sumo Logic’s conversational interface designed to streamline investigations for SOC analysts and observability users. Ask a question in plain English and get a full SOC analyst-style investigation without writing a query.
Inside an Insight, Mobot pulls context like the C2IP, ransomware hash, host, and exfiltration data automatically. A six-word question, “anyone else hit by the campaign?”, triggers a full investigation across every mailbox and endpoint tied to that attack, with a link to the raw query behind every answer.
In this demo, you’ll see:
- How Mobot pulls insight context automatically
- How one question investigates an entire campaign across mailboxes and endpoints
- How to verify any answer by clicking into the raw query