--- slug: /search/mobot title: Sumo Logic Mobot sidebar_label: Mobot ✨ description: Troubleshoot logs, create monitors and dashboards, and learn the platform using plain-language questions with Mobot, Sumo Logic's AI assistant. keywords: - mobot - dojo ai - ai assistant - agent - log analysis - log troubleshooting - unstructured logs - soc analyst canonical: https://www.sumologic.com/help/docs/search/mobot/ --- import useBaseUrl from '@docusaurus/useBaseUrl'; import SumoAcademy from '../../reuse/sumo-logic-academy.md'; import Iframe from 'react-iframe'; import MSSPfeatureMgmt from '../../reuse/mssp-feat-mgmt.md'; import ConvPlaybookLimits from '../../reuse/conv-playbook-limits.md'; Search icon Mobot is Sumo Logic's AI-powered conversational assistant for security analysts, on-call engineers, administrators, and other Sumo Logic users. Ask questions in plain language to investigate log data or learn how to use the platform without selecting an agent or writing queries from scratch. Mobot welcome screen with example prompts grouped by General, Security, Observability, and Administration In a single conversation, Mobot determines whether you have a log data or a how-to question and responds accordingly. For log data questions, it identifies relevant sources, correlates information across logs, and returns inline results with anomaly callouts and suggested next steps. For how-to questions, it provides structured answers and reference links from Sumo Logic documentation. Conversation context lets you refine, pivot, and dig deeper without starting over. ## Use cases * **Security**. Investigate login attempts, data exfiltration, and threat intelligence matches. For example, `Have any IPs or domains in my logs been flagged by threat intelligence?` See [Security investigations](/docs/search/mobot/example-prompts#security-investigations) for more examples. * **Observability**. Spot error spikes, latency anomalies, and timeouts. For example, `Are there any error spikes happening in the last 15 minutes?` See [Observability investigations](/docs/search/mobot/example-prompts#observability-investigations) for more examples. * **Platform administration**. Check on Collectors, data sources, and data usage. For example, `Any collectors that have gone silent in the last few hours?` See [Platform administration](/docs/search/mobot/example-prompts#platform-administration) for more examples. * **How-to questions**. Get setup guidance and answers about the platform, sourced from official Sumo Logic documentation. For example, `How do I configure OpenTelemetry for my service?` See [Sumo Logic how-to questions](/docs/search/mobot/example-prompts#sumo-logic-how-to-questions) for more examples. ## Key capabilities * **Unified conversation**. Investigate logs and ask how-to questions without switching tools or losing context. * **Guided analysis**. Mobot asks targeted questions when your intent is ambiguous and identifies missing sources or partitions when required data is not configured. * **Context-aware analysis**. Mobot plans multi-step analyses and considers relevant data sources, schemas, lookup tables, historical queries, and time ranges. It also uses queries from dashboards opened in your organization in the last 90 days through retrieval-augmented generation (RAG) to better understand your intent and data structure. * **Documentation-grounded answers**. How-to responses include information and reference links from official Sumo Logic documentation. * **Inline findings and visualizations**. Mobot returns structured results, highlights notable findings, recommends next steps, and generates charts that you can add to dashboards. * **Content creation and management**. Create and manage monitors, dashboards, and playbooks through conversation, with a human in the loop before anything is deployed or activated. See [Create and manage content](#create-and-manage-content). * **Cloud SIEM investigations**. On a Cloud SIEM insight, click **Ask Mobot** to continue a [SOC Analyst Agent](/docs/cse/get-started-with-cloud-siem/soc-analyst-agent) investigation in Mobot with the insight's evidence-backed verdict and context loaded. You start this from the insight, not from Mobot directly. * **Conversation history**. Saved conversations let you resume, revisit, or branch previous investigations. ## At a glance - **Response time**. Typically under 2 seconds for most queries. See [response time FAQ](#what-is-the-typical-mobot-response-time) for details. - **Compatible log types**. Structured, semi-structured, and unstructured logs. Unstructured logs already used in dashboards do not require Field Extraction Rules. See [Compatible log formats](#compatible-log-formats) for details. - **AI provider**. Amazon Bedrock (no customer data used for training). See [Security and compliance](#security-and-compliance) for details. :::training Sumo Logic Academy * **Self-paced**. [Hands on with Mobot and Dojo AI](https://learn.sumologic.com/hands-on-with-mobot-and-dojo-ai). * **Instructor-led virtual classes**. [Workshops: Hands on with Mobot and Dojo AI](https://www.sumologic.com/learn/training?_workshops=hands-on-mobot-dojo-ai#section-2). ::: :::training Micro Lesson Watch this micro lesson to learn what Mobot is, its key capabilities, and how its AI-powered, unified conversational interface accelerates your investigations.