Endless alerts, Focused answers.

Security operations

AI for observability

Built on Dojo AI

Why Sumo Logic?

FAQ

Sumo Logic’s AI agents help security teams detect, investigate, and respond faster.
 They connect fragmented signals, generate story-driven insights, and propose next steps — so analysts can focus on what matters.
Bullets / mini-cards:

  • Summary Agent – Condenses fragmented alerts into actionable narratives.
  • Query Agent – Translates natural language into precise queries.
  • SOC Analyst Agent (coming soon) – Provides AI-assisted triage and reasoning to classify, summarize, and prioritize insights.
  • Knowledge Agent – Answers product questions instantly, using all available documentation.
Actionable security narratives
sumo logic query agent anim lg

For DevOps and SRE teams, AI transforms logs into guided responses. It detects anomalies, correlates issues, and summarizes complex investigations — reducing toil and mean time to recovery.

Every AI capability at Sumo Logic is powered by Dojo AI, our multi-agent reasoning system designed for trust, accuracy, and adaptability.
 It connects specialized agents to interpret data, test hypotheses, and provide transparent guidance — whether you’re securing cloud workloads or improving app performance.

dashboard SOC and SRE machine learning powered analytics 1
“In particular, Sumo Logic’s powerful query functions serve as a competitive function, providing insightful results, like identifying similar errors or software versions with frequent issues.

Youngjip Kim

EVP, Head of AI Team

35 TB
average daily log ingest volume
icon
icon
icon
icon
icon
icon

Sumo Logic Dojo AI is a multi-agent AI platform built to power intelligent security operations and incident response. It is designed to act autonomously while continuously adapting to evolving threats.

The Query Agent helps users rapidly translate natural language requests submitted via Mobot into precise Sumo Logic queries, simplifying the exploration, analysis, and extraction of insights from complex datasets. By understanding context and user intent, it lowers the learning curve for new users while boosting efficiency for experienced analysts.

The Summary Agent creates AI-generated summaries of signals within an Insight, reducing noise and highlighting key context. Analysts get a clear explanation of how an Insight was triggered, making it easier to assess scope, prioritize response, and share a consistent narrative without reviewing raw logs or events.

Mobot is the unified conversational interface of Sumo Logic Dojo AI that connects users to specialized agents, turning natural language requests into actionable insights quickly and intuitively.

Yes. Mobot can leverage the Query Agent to search across and extract key information from unstructured logs, helping ensure critical insights aren’t missed during investigations.

Yes. Mobot retains conversation and search history so users can resume investigations with full context and continuity.

No. Customer data is never used to train AI models.

All Sumo Logic AI capabilities are designed to serve customer-specific outcomes within their own environment. Mobot uses a Large Language Model (LLM) via Amazon Bedrock, which processes data securely and does not retain or use customer information for training or other external purposes.

Traditional machine learning (ML) features, such as AI-driven alerts, generate models specific to each customer’s environment and are never shared or made public.

For more information, see the security and compliance page of our help docs.

Yes. Dojo AI assists analysts with routine tasks and recommendations, but humans review, validate, and guide actions to ensure accuracy, compliance, and trust.

No.

All new AI capabilities undergo legal, compliance, and application security reviews prior to release. Reviews occur with every major update that introduces new analytics or processes previously unused data.

Yes. Dojo AI leverages foundation models securely hosted through Amazon Bedrock.

Yes. Capabilities like Mobot and the SOC Analyst Agent process customer telemetry to perform investigations, run queries, and generate findings. All processing occurs securely within your platform context, and customer data is never used to train generalized AI models. Administrators can turn off Dojo AI capabilities at any time through Feature Management or by submitting a support ticket.

Customers that previously opted out of Sumo Logic AI capabilities will not get access to these or future AI capabilities until they explicitly opt back in.

Sumo Logic AI capabilities follow strict legal, compliance, and security standards to ensure data minimization and fit-for-purpose processing.

  • Customer data is never used to train AI models, shared externally, or used to improve global models.
  • Data remains within the customer’s environment and is processed only to deliver results back to that customer.
  • Sumo Logic applies strong safeguards and filtering to ensure sensitive data is handled securely and appropriately at all times.

Customers can opt out of capabilities that process customer data, including the SOC Analyst Agent and Mobot, at any time from Feature Management or by submitting a support ticket.

No. Customer data is never used to train AI models.

All Sumo Logic AI capabilities are designed to serve customer-specific outcomes within their own environment. Mobot uses a large language model (LLM) via Amazon Bedrock, which processes data securely and does not retain or use customer information for training or other external purposes.

Traditional ML features, such as AI-driven alerts, generate models specific to each customer’s environment and are never shared or made public.

For more information, see trust.sumologic.com.

No additional third parties have any access. Dojo AI leverages foundation models securely hosted through Amazon Bedrock. When customer data is processed using Amazon Bedrock:

  • Customer inputs and outputs are treated as Customer Content under AWS terms.
  • AWS does not use Customer Content to train models or improve Amazon Bedrock.
  • AWS may access Customer Content only as necessary to provide the service or comply with law.
  • Third-party model providers do not have access to customer inputs or outputs.
  • Customer inputs and outputs are not shared with model providers and are not used to train external models.

Customer data processed through Dojo AI remains within Sumo Logic’s secure environment and is used only to deliver results for that customer. It is not used shared with model providers.

Dojo AI and classical ML features store data only temporarily to optimize performance:

  • AI-driven alerts use a rolling 60-day data window, retraining weekly and expiring the oldest data automatically.
  • Mobot may temporarily retain conversation history in a rolling window to improve conversational context and response accuracy.

All stored data follows Sumo Logic’s data retention and deletion policies, ensuring customer information is never retained longer than necessary.

Sumo Logic is currently reviewing AI compliance within a rapidly evolving framework, in particular ISO 42001, designed to help organizations implement AI responsibly.

Sumo Logic AI capabilities operate within our existing industry-recognized security and compliance framework, including FedRAMP Moderate, SOC 2 Type 2, HIPAA, PCI DSS 4.0.1, and ISO 27001:2022. These attestations govern the confidentiality, integrity, and protection of customer data.

Availability of specific AI capabilities may vary by deployment region (including FED) based on compliance boundary requirements.

The current GA versions of Mobot (including Query Agent and Knowledge Agent) and Summary Agent are available in the FED deployment.

The SOC Analyst Agent and certain newer Dojo AI capabilities are not currently available in FED. These capabilities depend on underlying model configurations that do not yet meet the requirements of our FED compliance boundary.

We are actively evaluating future availability of these capabilities in FED as underlying model support and compliance requirements evolve.

The generative AI model is licensed and securely hosted via Amazon Bedrock, meaning it is not directly accessible by Sumo Logic, customers, or third parties.

All new AI capabilities and features undergo comprehensive legal, compliance, and application security reviews before release to ensure data protection, privacy, and regulatory alignment.

Recurring reviews are also conducted with every major update, particularly when a capability introduces new analytics or processes previously unused data types, to maintain ongoing trust and compliance.

AI features are on by default. We offer two methods for opting out.

In-product self opt-out: Beginning August 2026, platform administrators can opt out of all AI features directly within the product settings under Feature Management. Disabling AI at the admin level automatically exempts your tenant from any future AI feature rollouts.

Via your account team or support: You can opt out of specific AI features or all AI features by contacting your Sumo Logic account team or opening a support ticket. If you choose to opt out of all AI features, your tenant will automatically be exempted from future AI feature releases.

For a complete overview of everything included in Sumo Logic’s AI portfolio, click here.

Frame 1073715737