---
title: "Sumo Logic MCP server: bringing SIEM and log data into Claude and other AI clients"
page_name: "Sumo Logic MCP server: bringing SIEM and log data into Claude and other AI clients"
type: "blog"
slug: "sumo-logic-mcp-server-ai-clients"
published_at: "2026-09-16"
modified_at: "2026-09-16"
url: "https://www.sumologic.com/blog/sumo-logic-mcp-server-ai-clients"
canonical: "https://www.sumologic.com/blog/sumo-logic-mcp-server-ai-clients"
markdown_url: "https://www.sumologic.com/blog/sumo-logic-mcp-server-ai-clients.md"
lang: "en"
excerpt: "Sumo Logic's MCP server connects SIEM and Log Analytics data to Claude Code and other AI clients, so analysts can search logs and triage insights without leaving their workflow."
taxonomy_blog_category:
  - "AI"
  - "SecOps &amp; Security"
  - "SIEM"
---

[ All blogs ](https://www.sumologic.com/blog "blog")[AI](https://www.sumologic.com/blog/ai), [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security), [SIEM](https://www.sumologic.com/blog/siem)

# Sumo Logic MCP server: bringing SIEM and log data into Claude and other AI clients

[Margaret Selid](#blog-author-block-361)

September 16, 2026

3 min read 

[AI](https://www.sumologic.com/blog/ai), [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security), [SIEM](https://www.sumologic.com/blog/siem)

##### Table of contents

 

 

 

More security and operations work now happens inside an AI client instead of a dedicated console. That shift creates a gap for any platform that isn’t part of the conversation. Every time an analyst needs to triage an insight or check a log, they have to leave the AI client and go open a different tool.

Sumo Logic closes that gap with a [Model Context Protocol (MCP) server](https://www.sumologic.com/help/docs/api/mcp-server/). It connects [Sumo Logic’s SIEM](https://www.sumologic.com/solutions/siem) and [Log Analytics](https://www.sumologic.com/guides/log-analytics) capabilities directly to [Claude Code](https://www.sumologic.com/help/docs/integrations/saas-cloud/claude-compliance/), [GitHub Copilot](https://www.sumologic.com/help/docs/integrations/saas-cloud/github-copilot/), and other MCP-compatible AI clients, so SOC analysts, [DevOps](https://www.sumologic.com/glossary/devops), and SRE teams can search logs, investigate insights, and manage alerts and dashboards from inside the AI client they already use.

Here’s what that actually looks like, and how it works.

## What the Sumo Logic MCP server does

[MCP](https://www.sumologic.com/glossary/model-context-protocol-mcp) is an open standard for connecting AI clients to external tools and data sources. Instead of building a one-off integration for every AI product your team adopts, MCP gives you one governed connection point.

Sumo Logic’s MCP server exposes a defined set of tools that any MCP-compatible client can call: alert search, dashboard management, SIEM insights and detection rules, log search, and data discovery. Connect Claude Code (or another supported client) to that server, and you can ask it to pull an alert, triage a SIEM insight, or run a log search in plain language, then act on the results, all in the same session.

This solves a real workflow gap. Analysts spending more of their day inside an AI client still had to break context and open the Sumo Logic UI every time they needed to triage an insight or search logs. Teams that tried to close that gap with custom integrations usually did it without the audit trails and access controls security and compliance teams require. The MCP server removes both problems. There’s no custom connector to build and every action still runs through Sumo Logic’s existing authentication, authorization, and role-based permissions.

## What you can actually do with it

The MCP server groups its tools into a few categories:

- **SIEM.** Get and filter insights, pull the signals and entities behind an insight, update insight status or assignee, and create or review detection rules.
- **Log search.** Run a log search over a time range and get back aggregated records or raw messages.
- **Alerts.** Search and retrieve alerts by status, severity, or monitor.
- **Dashboards.** Create, retrieve, and update dashboards.
- **Discovery.** List custom fields, field extraction rules, and partitions to help scope a search.

In practice, that supports multi-step investigations in a single conversation: pull an open SIEM insight, review its signals and involved entities, then run a log search on one of those entities to find the raw events behind it, all without leaving Claude.

## How the connection is governed

Every MCP action runs as a named user constrained by that user’s existing Sumo Logic role and permissions, not by an all-access service account. Authentication runs on OAuth 2.0, with client ID metadata documents (CIMD) as the recommended setup for supported clients. Customer data is never used to train AI models, and all MCP interactions are logged for compliance and security review. Agents connected through MCP run in your own environment, not inside Sumo Logic’s infrastructure.

Administrators control MCP server access separately from other AI features. It’s on by default at the organization level, and can be toggled independently of [Mobot](https://www.sumologic.com/blog/mobot-your-log-analysis-partner) and the [SOC Analyst Agent](https://www.sumologic.com/blog/soc-analyst-agent-for-soc-team) under Feature Management.

## What MCP is for, and what it isn’t for

Sumo Logic scopes the MCP server for conversational, agent-driven work such as multi-step investigations, triage, and agent-to-agent workflows where a person is in the loop. It isn’t meant for bulk data extraction or high-volume automated queries. Those still belong on the standard Search Job API. MCP requests are cost-amplifying by nature, since one conversational request can trigger several tool calls, so this distinction matters most for Flex pricing customers watching scan costs.

[See how to set up the Sumo Logic MCP server.](https://www.sumologic.com/help/docs/api/mcp-server/)

### FAQs

 Does Sumo Logic have a Claude integration?+Yes. The MCP server connects to Claude Code and other MCP-compatible AI clients, giving them governed access to Sumo Logic’s SIEM and Log Analytics data.

 Which Sumo Logic products work through MCP?+SIEM (insights and detection rules) and Log Analytics (log search, alerts, dashboards, discovery).

 Is the MCP connection secure?+Access runs through OAuth 2.0, respects each user’s existing Sumo Logic permissions, and every interaction is logged for audit and compliance review. Customer data isn’t used for model training.

 Does this replace Mobot?+No. Mobot is Sumo Logic’s own built-in set of agents inside the product. The MCP server is for connecting *external* AI clients, like Claude Code, to Sumo Logic data instead.

 Where do I find setup instructions?+Full setup steps, deployment URLs, and the complete tool reference are in the[ Sumo Logic MCP Server documentation](https://www.sumologic.com/help/docs/api/mcp-server/).

 

### Article Tags

- [AI](https://www.sumologic.com/blog/ai)
- [SecOps &amp; Security](https://www.sumologic.com/blog/secops-security)
- [SIEM](https://www.sumologic.com/blog/siem)

Margaret Selid

Principal Product Marketing Manager

Margaret is an experienced product marketing leader with a passion for distilling complex technology and ideas into compelling stories. Before joining Sumo Logic, she worked in supply chain technology launching visibility products, after several years promoting cities for economic investment.

[](https://www.sumologic.com/feed "RSS Feed")[](https://twitter.com/intent/tweet?text=Sumo%20Logic%20MCP%20server%3A%20bringing%20SIEM%20and%20log%20data%20into%20Claude%20and%20other%20AI%20clients&url=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsumo-logic-mcp-server-ai-clients "X")[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsumo-logic-mcp-server-ai-clients "Facebook")[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.sumologic.com%2Fblog%2Fsumo-logic-mcp-server-ai-clients "Linkedin")

[Previous blog

How to extract structured fields from unstructured logs](https://www.sumologic.com/blog/how-to-extract-structured-fields-from-unstructured-logs)

People who read this also enjoyed

[  

How to extract structured fields from unstructured logs

September 8, 2026

 

 ](https://www.sumologic.com/blog/how-to-extract-structured-fields-from-unstructured-logs)[  

How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes

September 3, 2026

 

 ](https://www.sumologic.com/blog/soc-analyst-agent-cuts-investigation-time)[  

The six pillars of AI-ready telemetry

September 2, 2026

 

 ](https://www.sumologic.com/blog/six-pillars-ai-ready-telemetry)[  

Mobot levels up: Build incident response playbooks with natural language

August 27, 2026

 ](https://www.sumologic.com/blog/mobot-incident-response-playbooks)

[AI Instructions](https://www.sumologic.com/ai-instructions.md)
