<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type="text/xsl" href="rss.xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Sumo Logic Service Release Notes</title>
        <link>https://www.sumologic.com/help/release-notes-service/</link>
        <description>Latest features and bug fixes for Sumo Logic log analytics, AI and automation, observability, alerts, sources, and more.</description>
        <lastBuildDate>Mon, 31 Aug 2026 00:00:00 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <copyright>Copyright © 2026 Sumo Logic</copyright>
        <item>
            <title><![CDATA[Apps, Solutions, and Collection Integrations - August Release]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/</guid>
            <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[New release]]></description>
            <content:encoded><![CDATA[<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-release">New release<a href="https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/#new-release" class="hash-link" aria-label="Direct link to New release" title="Direct link to New release" translate="no">​</a></h3>
<p>We're excited to announce the release of the following Sumo Logic apps:</p>
<ul>
<li class=""><strong>Druva - Platform Events</strong>. This app helps you monitor Druva via a webhook-based integration. <a class="" href="https://www.sumologic.com/help/docs/integrations/webhooks/druva-platform-events/">Learn more</a>.</li>
<li class=""><strong><a href="https://registry.terraform.io/modules/SumoLogic/aws-observability/sumologic/latest" target="_blank" rel="noopener noreferrer" class="">AWS Observability Terraform Module for AWSO 3.0.0</a></strong>. This Terraform module deploys the <a class="" href="https://www.sumologic.com/help/docs/observability/aws/">Sumo Logic AWS Observability Solution</a>, a full-stack observability solution for AWS environments. It configures AWS collection infrastructure and installs Sumo Logic apps, monitors, dashboards, and field extraction rules for supported AWS services.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="automation-service-integrations">Automation service integrations<a href="https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/#automation-service-integrations" class="hash-link" aria-label="Direct link to Automation service integrations" title="Direct link to Automation service integrations" translate="no">​</a></h3>
<p>The following Automation Service Integrations are now generally available:</p>
<ul>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/platform-services/automation-service/app-central/integrations/aws-lambda/">AWS Lambda</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/platform-services/automation-service/app-central/integrations/dfir-iris/">DFIR-IRIS</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/platform-services/automation-service/app-central/integrations/google-cloud-functions/">Google Cloud Functions</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/platform-services/automation-service/app-central/integrations/launchdarkly/">LaunchDarkly</a></li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements">Enhancements<a href="https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/#enhancements" class="hash-link" aria-label="Direct link to Enhancements" title="Direct link to Enhancements" translate="no">​</a></h3>
<ul>
<li class=""><strong>Akamai SIEM API v1.2.26</strong>. Added parser path support. For more information, see <a class="" href="https://www.sumologic.com/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/akamai-siem-api-source/">Akamai SIEM API Source</a>.</li>
<li class=""><strong>Google Cloud SQL</strong>. Added support for PostgreSQL instances. For more information, see <a class="" href="https://www.sumologic.com/help/docs/integrations/google/cloud-sql/">Google Cloud SQL</a>.</li>
<li class=""><strong>Miro</strong>. Aligned the Miro app with the latest Miro Cloud-to-Cloud source, added new out-of-the-box monitors, and included additional fixes. The Miro source also completed a smooth transition to a new API version <strong>Audit Log v2 API</strong>. For more information, see <a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/miro/">Miro App</a> and <a class="" href="https://www.sumologic.com/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/miro-source/">Miro Source</a>.</li>
<li class=""><strong>SumoLogic Terraform Provider <a href="https://github.com/SumoLogic/terraform-provider-sumologic/releases/tag/v3.3.0" target="_blank" rel="noopener noreferrer" class="">v3.3.0</a></strong>. Released with the following resources:<!-- -->
<ul>
<li class=""><a href="https://registry.terraform.io/providers/SumoLogic/sumologic/latest/docs/resources/async_aws_lambda_invocation" target="_blank" rel="noopener noreferrer" class=""><code>sumologic_async_aws_lambda_invocation</code></a>. This resource asynchronously invokes an AWS Lambda function with support for AWS named profiles, enabling multi-account deployments.</li>
<li class=""><a href="https://registry.terraform.io/providers/SumoLogic/sumologic/latest/docs/resources/s3_logging_lambda_enable" target="_blank" rel="noopener noreferrer" class=""><code>sumologic_s3_logging_lambda_enable</code></a>. Renamed from <code>sumologic_lambda_invoke_action</code> and enhanced with <code>region</code> and <code>aws_profile</code> arguments to support explicit AWS region configuration and named AWS credential profiles, enabling multi-account deployments. If you use <code>sumologic_lambda_invoke_action</code> in an existing configuration, update it to <code>sumologic_s3_logging_lambda_enable</code>.</li>
</ul>
</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="bug-fixes">Bug fixes<a href="https://www.sumologic.com/help/release-notes-service/2026/08/31/apps/#bug-fixes" class="hash-link" aria-label="Direct link to Bug fixes" title="Direct link to Bug fixes" translate="no">​</a></h3>
<ul>
<li class=""><strong><a class="" href="https://www.sumologic.com/help/docs/integrations/google/workspace/install-app-dashboards/">Google Workspace</a></strong> and <strong><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/audit/">Azure Audit</a></strong>. Bug fixes were released for these apps.</li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Auto-Refresh Guardrails for Dashboards (Dashboards)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/31/dashboards/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/31/dashboards/</guid>
            <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce the below new guardrails to dashboard auto-refresh:]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce the below new guardrails to <a class="" href="https://www.sumologic.com/help/docs/dashboards/about/#auto-refresh">dashboard auto-refresh</a>:</p>
<ul>
<li class=""><strong>Hidden tab pause</strong>. Auto-refresh pauses when you switch away from a dashboard tab for more than 10 minutes, and resumes automatically when you return.</li>
<li class=""><strong>Panel failure exclusion</strong>. A panel is excluded from auto-refresh after 5 consecutive query failures, so it stops disrupting other healthy panels.</li>
</ul>
<p><a class="" href="https://www.sumologic.com/help/docs/dashboards/about/#auto-refresh">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[SOC Analyst Agent Support in Child Org Baselines (Manage)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/31/manage/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/31/manage/</guid>
            <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that you can now provision the SOC Analyst Agent as part of a child org's baseline. When creating or editing a child org, enable the SOC Analyst Agent checkbox, set the Number of investigation per day, and optionally allow overage, alongside your existing Logs, Metrics, Traces, and Cloud SIEM Enterprise baselines. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that you can now provision the <a class="" href="https://www.sumologic.com/help/docs/cse/get-started-with-cloud-siem/soc-analyst-agent/">SOC Analyst Agent</a> as part of a child org's baseline. When creating or editing a child org, enable the <strong>SOC Analyst Agent</strong> checkbox, set the <strong>Number of investigation per day</strong>, and optionally allow overage, alongside your existing Logs, Metrics, Traces, and Cloud SIEM Enterprise baselines. <a class="" href="https://www.sumologic.com/help/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs/#allocate-credits">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Increased Maximum Log Message Size to 256KB (Search)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/27/search/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/27/search/</guid>
            <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that Sumo Logic now supports a maximum log message size of 256KB, up from 64KB, so large single-line logs are ingested without being split as often.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that Sumo Logic now supports a maximum log message size of <strong>256KB</strong>, up from 64KB, so large single-line logs are ingested without being split as often.</p>
<p>Some Sumo Logic platform features and downstream webhook connections handle messages larger than 64KB differently. See <a class="" href="https://www.sumologic.com/help/docs/search/get-started-with-search/search-basics/search-large-messages/#known-limitations">Known limitations</a> for details.</p>
<p><a class="" href="https://www.sumologic.com/help/docs/search/get-started-with-search/search-basics/search-large-messages/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Support for Longer Dashboard Time Ranges (Dashboards)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/25/dashboards/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/25/dashboards/</guid>
            <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce the support for longer dashboard time ranges. Previously, dashboard queries could exceed the 32-day maximum time range only when using aggregate scheduled views. Currently, dashboard queries will be allowed to run beyond the 32-day time range when using aggregate scheduled views, aggregate scheduled searches, or a combination of both. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce the support for longer dashboard time ranges. Previously, dashboard queries could exceed the 32-day maximum time range only when using aggregate scheduled views. Currently, dashboard queries will be allowed to run beyond the 32-day time range when using aggregate scheduled views, aggregate scheduled searches, or a combination of both. <a class="" href="https://www.sumologic.com/help/docs/dashboards/set-custom-time-ranges/#set-time-range">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Changes to the Save to Index Alert Type for Scheduled Searches (Alerts)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/24/alerts/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/24/alerts/</guid>
            <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[What's changing]]></description>
            <content:encoded><![CDATA[<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="whats-changing">What's changing<a href="https://www.sumologic.com/help/release-notes-service/2026/08/24/alerts/#whats-changing" class="hash-link" aria-label="Direct link to What's changing" title="Direct link to What's changing" translate="no">​</a></h3>
<p>For scheduled searches using the <strong>Save to Index</strong> alert type, Sumo Logic has made the following related changes:</p>
<ul>
<li class="">The Message (<code>_raw</code>) field will be empty. Previously, for aggregate queries (for example, <code>... | timeslice 1m | count by batch, parsedfield</code>), the <strong>Message (<code>_raw</code>)</strong> field was populated with a synthesized, comma-separated string of the row's values (for example, <code>Count=1,batch=3,parsedfield=testlog_HwMoOdtQ00</code>), in addition to the individual named fields.<br>
Going forward, the <code>_raw</code> field will be empty for these results. No data is lost, and every value remains fully available in its own named field (<code>_count</code>, <code>batch</code>, <code>parsedfield</code>, etc.). Only the synthesized message string is no longer generated. <a class="" href="https://www.sumologic.com/help/docs/alerts/scheduled-searches/save-to-index/#limitations">Learn more</a>.</li>
<li class="">The 512-result limit is being removed. Previously, no more than 512 results could be saved to a view each time a scheduled search ran. That cap no longer applies and a scheduled search can now save every result it returns on each run.</li>
</ul>
<div class="theme-admonition theme-admonition-note alert alert--secondary admonition_WoCw"><div class="admonitionHeading_TMsN"><span class="admonitionIcon_Ibzs"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_vXIg"><p>These changes are rolling out to a limited set of accounts and are not yet generally available.</p></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="who-is-affected">Who is affected<a href="https://www.sumologic.com/help/release-notes-service/2026/08/24/alerts/#who-is-affected" class="hash-link" aria-label="Direct link to Who is affected" title="Direct link to Who is affected" translate="no">​</a></h3>
<p>This affects you if you're running scheduled searches with an aggregate query and the <strong>Save to Index</strong> alert type, saving results to a view (typically a <code>ScheduledSearchView</code>, created when you type a new view name rather than selecting an existing one).</p>
<ul>
<li class="">For the <code>_raw</code> change, you're affected if any search queries or other content reading that view does one of the following:<!-- -->
<ul>
<li class="">Pulls values out of <code>_raw</code> using <code>parse</code> (or similar).</li>
<li class="">Searches for plain text/keywords that only exist in the message body, not in a named field.</li>
<li class="">Shows or reads the Message column to get field values.<br>
If your queries already use the named fields directly, you don't need to make any changes for this part.</li>
</ul>
</li>
<li class="">For the 512-result limit change, you likely don't need to do anything. It's only worth reviewing if you're concerned about increased data volume. For example, if your scheduled search runs frequently (such as every 15 minutes) and doesn't already cap its results with a <code>limit</code> operator or similar. Without the previous cap, a run like that can now save more results, and more data, than it did before.</li>
</ul>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="what-you-need-to-do">What you need to do<a href="https://www.sumologic.com/help/release-notes-service/2026/08/24/alerts/#what-you-need-to-do" class="hash-link" aria-label="Direct link to What you need to do" title="Direct link to What you need to do" translate="no">​</a></h3>
<ul>
<li class="">For the <code>_raw</code> change, review your scheduled searches and any downstream content that reads from Save to Index views for reliance on <code>_raw</code>/Message. Update those queries to reference the named fields directly instead of parsing them from the message body. If you're unsure whether a query depends on <code>_raw</code>, check for <code>parse</code> operators run against <code>_raw</code>, or keyword terms in the source expression that aren't tied to a specific field name.</li>
<li class="">For the 512-result limit change, no action is required. If you'd rather bound the amount of data a scheduled search saves per run, add a <code>limit</code> operator (or otherwise bound the result set) to that query. Otherwise, keep an eye on your data volume after rollout, since more results may now be saved per run than before.</li>
</ul>
<p>Contact <a href="https://support.sumologic.com/support/s" target="_blank" rel="noopener noreferrer" class="">Sumo Logic Support</a> if you need help identifying or updating affected queries.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Multi-Notification Support for Scheduled Searches (Alerts)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/19/alerts/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/19/alerts/</guid>
            <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce multiple notification support for Scheduled Searches. Previously limited to one alert type, you can now add up to 10 notifications to a single Scheduled Search. These alerts share the same trigger condition and fire from the same search execution, with each alert configured independently. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce multiple notification support for Scheduled Searches. Previously limited to one alert type, you can now add up to 10 notifications to a single Scheduled Search. These alerts share the same trigger condition and fire from the same search execution, with each alert configured independently. <a class="" href="https://www.sumologic.com/help/docs/alerts/scheduled-searches/schedule-search/#step-6-add-scheduled-search-alert-types">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[AI Parse Assist (Search)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/17/search/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/17/search/</guid>
            <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce AI Parse Assist, which automatically generates a parse statement and field names from any text you highlight in a log message. This eliminates the need to manually identify and label fields, helping you build parse queries faster, especially when working with complex or unfamiliar log formats. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce <strong>AI Parse Assist</strong>, which automatically generates a parse statement and field names from any text you highlight in a log message. This eliminates the need to manually identify and label fields, helping you build parse queries faster, especially when working with complex or unfamiliar log formats. <a class="" href="https://www.sumologic.com/help/docs/search/search-query-language/parse-operators/parse-predictable-patterns-using-an-anchor/#ai-parse-assist">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Create Dashboard Panels with Mobot (Dashboards)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/13/dashboards/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/13/dashboards/</guid>
            <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce a new Mobot skill that lets you create dashboard panels from plain-language prompts, instead of configuring them manually. Describe what you want to see, and Mobot drafts the query, picks a visualization, and adds it to a new or existing dashboard. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce a new Mobot skill that lets you create dashboard panels from plain-language prompts, instead of configuring them manually. Describe what you want to see, and Mobot drafts the query, picks a visualization, and adds it to a new or existing dashboard. <a class="" href="https://www.sumologic.com/help/docs/dashboards/create-panel-with-mobot/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Create and Manage Archive Destinations via API (Manage)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/13/manage/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/13/manage/</guid>
            <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that you can now create and manage AWS S3 archive destinations for Installed Collectors using a new public API, in addition to the UI flow, for automating destination setup at scale. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that you can now create and manage AWS S3 archive destinations for Installed Collectors using a new public API, in addition to the UI flow, for automating destination setup at scale. <a class="" href="https://www.sumologic.com/help/docs/api/data-archiving/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Drill Down from Map Charts (Dashboards)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/11/dashboards/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/11/dashboards/</guid>
            <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce one-click drill-down for map charts. Shift+click a point or line on the map to drill down into that location's data. Sumo Logic redirects you to the Log Search page with the query already updated with the corresponding latitude and longitude values.]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce one-click drill-down for <a class="" href="https://www.sumologic.com/help/docs/dashboards/panels/map-charts/">map charts</a>. <em>Shift+click</em> a point or line on the map to drill down into that location's data. Sumo Logic redirects you to the Log Search page with the query already updated with the corresponding latitude and longitude values.</p>
<p>Previously, you needed to manually find the IP address, or the latitude and longitude, for a location and then edit the query yourself to drill down into that location's data. <em>Shift+click</em> now does this for you automatically. <a class="" href="https://www.sumologic.com/help/docs/dashboards/panels/map-charts/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Threat Intelligence (Security)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/06/security/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/06/security/</guid>
            <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce improvements to how threat intelligence indicators are searched:]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce improvements to how threat intelligence indicators are searched:</p>
<ul>
<li class="">By default, only active threat intelligence indicators are available for search and Cloud SIEM entity enrichment. <a class="" href="https://www.sumologic.com/help/docs/security/threat-intelligence/about-threat-intelligence/">Learn more</a>.</li>
<li class="">You can now use the <code>threatlookup</code> operator to search threat intelligence indicators in your log data. <a class="" href="https://www.sumologic.com/help/docs/search/search-query-language/search-operators/threatlookup/">Learn more</a>.</li>
</ul>
<p>This is in the rollout phase and will be available in all regions shortly.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Manage Playbooks with Mobot (Automation Service)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/05/automation-service/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/05/automation-service/</guid>
            <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce that you can now build and update playbooks by chatting with Mobot instead of wiring up nodes by hand. Describe the automation you want in plain language, and Mobot checks your org's available integrations, asks clarifying questions, proposes a plan, and configures each step for you. Once you approve, it saves the playbook as a draft.]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce that you can now build and update playbooks by chatting with Mobot instead of wiring up nodes by hand. Describe the automation you want in plain language, and Mobot checks your org's available integrations, asks clarifying questions, proposes a plan, and configures each step for you. Once you approve, it saves the playbook as a draft.</p>
<p>To make changes, just send a follow-up request and Mobot updates the plan and rebuilds the playbook automatically. Review the finished flow on the canvas, then publish when you're ready. <a class="" href="https://www.sumologic.com/help/docs/platform-services/automation-service/playbooks/create-playbooks-with-mobot/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Credit Block Burn Rates (Manage)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/03/manage/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/03/manage/</guid>
            <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that mid-subscription upgrades no longer reset burn rates on your existing credits. When you purchase additional credits at a different rate, Sumo Logic now tracks them as a separate credit block, so your original credits continue burning at their original rate instead of being repriced. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that mid-subscription upgrades no longer reset burn rates on your existing credits. When you purchase additional credits at a different rate, Sumo Logic now tracks them as a separate credit block, so your original credits continue burning at their original rate instead of being repriced. <a class="" href="https://www.sumologic.com/help/docs/manage/manage-subscription/sumo-logic-flex-accounts/#credit-blocks">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[New _orgName Field for MSSP Multi-Org Searches (Search)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/08/01/search/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/08/01/search/</guid>
            <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that multi-child-org search results now include an _orgName field alongside orgId, so MSSP users can identify which child org a result came from without having to remember its orgId. For example, * | count by orgId, orgName.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that multi-child-org search results now include an <strong><code>_orgName</code></strong> field alongside <code>_orgId</code>, so MSSP users can identify which child org a result came from without having to remember its <code>_orgId</code>. For example, <code>* | count by _orgId, _orgName</code>.</p>
<p>You can also run these searches programmatically instead of using the Search UI, by setting <code>childOrgIds</code> or <code>includeAllChildOrgs</code> when you create a search job with the <a class="" href="https://www.sumologic.com/help/docs/api/search-job/#search-job-management-api">Search Job Management API</a>.</p>
<p><a class="" href="https://www.sumologic.com/help/docs/search/search-across-child-orgs/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Apps, Solutions, and Collection Integrations - July Release]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/07/31/apps/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/07/31/apps/</guid>
            <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Enhancements]]></description>
            <content:encoded><![CDATA[<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements">Enhancements<a href="https://www.sumologic.com/help/release-notes-service/2026/07/31/apps/#enhancements" class="hash-link" aria-label="Direct link to Enhancements" title="Direct link to Enhancements" translate="no">​</a></h3>
<p>We've enhanced multiple Sumo Logic apps to improve visibility, usability, and proactive monitoring with new and updated dashboards, monitors, and field extraction rules (FERs), built on the latest collection mechanism.</p>
<ul>
<li class="">Added new and updated dashboards, FERs, and monitors for the following apps:<!-- -->
<ul>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/active-directory-json/">Active Directory 2012+ (JSON)</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/amazon-aws/guardduty/">Amazon GuardDuty</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/app-development/jfrog-artifactory/">Artifactory 7</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/amazon-aws/waf/">AWS WAF</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/cloud-security-monitoring-analytics/aws-waf/">AWS WAF CSMA</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/audit/">Azure Audit</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/chatgpt-compliance/">ChatGPT Compliance</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/security-threat-detection/cisco-meraki/">Cisco Meraki</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/cisco-umbrella/">Cisco Umbrella</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/cloudflare/">Cloudflare</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/sumo-apps/cse/">Enterprise Audit - Cloud SIEM</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/web-servers/heroku/">Heroku</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/hosts-operating-systems/host-process-metrics/">Host and Process Metrics</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/hosts-operating-systems/host-metrics/">Host Metrics</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/hosts-operating-systems/linux/">Linux</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/litellm/">LiteLLM</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/office-365/">Microsoft Office 365</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/cloud-security-monitoring-analytics/palo-alto-firewall-10/">Palo Alto Firewall 10</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/amazon-aws/vpc-flow-logs-pci-compliance/">PCI Compliance for Amazon VPC Flow</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/amazon-aws/cloudtrail-pci-compliance/">PCI Compliance for AWS Cloudtrail</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/windows-json/">Windows 2012+ (JSON)</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/windows-legacy/">Windows 7+2008 (Legacy)</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/cloud-security-monitoring-analytics/windows/">Windows CSMA</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/microsoft-azure/performance/">Windows Performance</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/security-threat-detection/zscaler-internet-access/">Zscaler Internet Access</a></li>
<li class=""><a class="" href="https://www.sumologic.com/help/docs/integrations/security-threat-detection/zscaler-private-access/">Zscaler Private Access</a></li>
</ul>
</li>
<li class=""><strong>Amazon ECS(With Container Insights and Traces)</strong>. This app has been migrated from version 1 to version 2. <a class="" href="https://www.sumologic.com/help/docs/integrations/amazon-aws/elastic-container-service-container-insights-cloudwatch/">Learn more</a>.</li>
<li class=""><strong>Claude Compliance C2C v2.0.1</strong>. The Claude Compliance C2C v2.0.1 adds <strong>Activity Feed</strong> collection alongside chat messages, with independent checkpoints and two new checkboxes in the source UI to control which data streams are collected (<strong>Collect Chat Messages</strong> and <strong>Collect Activities</strong>). Existing sources can be upgraded in place with no new collector setup needed. For more information, see <a class="" href="https://www.sumologic.com/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/claude-compliance-source/">Claude Compliance Source</a> and <a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/claude-compliance/">Claude Compliance App</a>.</li>
<li class=""><strong>ChatGPT Compliance C2C v2.0.2</strong>. The ChatGPT Compliance C2C v2.0.2 expands event coverage with 6 new event types (<code>AUDIT_LOG</code>, <code>AUTH_LOG</code>, <code>APP_AUTH_LOG</code>, <code>APP_LOG</code>, <code>CODEX_LOG</code>, and <code>CODEX_SECURITY_LOG</code>), and widens the configurable polling interval from 5 minutes to 24 hours. Existing sources remain fully compatible; no upgrade is required. For more information, see <a class="" href="https://www.sumologic.com/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/chatgpt-compliance-source/">ChatGPT Compliance Source</a> and <a class="" href="https://www.sumologic.com/help/docs/integrations/saas-cloud/chatgpt-compliance/">ChatGPT Compliance App</a>.</li>
<li class=""><strong>SumoLogic Terraform Provider <a href="https://github.com/SumoLogic/terraform-provider-sumologic/releases/tag/v3.2.9" target="_blank" rel="noopener noreferrer" class="">v3.2.9</a></strong>. Released with new resource <code>sumologic_lambda_invoke_action</code>.</li>
<li class=""><strong>Updated 18 setup guide apps</strong>. Legacy ARM-based Azure Metrics Collection has been changed to the latest Azure Metrics Source.</li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Create Monitors with Mobot (Search)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/07/31/search/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/07/31/search/</guid>
            <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce the ability to create and update logs monitors from plain-language prompts in Mobot, instead of filling out the monitor form. Describe the monitor you want, review the suggested configuration, and confirm to create it. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce the ability to create and update logs monitors from plain-language prompts in Mobot, instead of filling out the monitor form. Describe the monitor you want, review the suggested configuration, and confirm to create it. <a class="" href="https://www.sumologic.com/help/docs/alerts/monitors/create-monitor-with-mobot/">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Mobot Now Generally Available with a Unified Conversational Interface (Search)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/07/30/search/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/07/30/search/</guid>
            <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that Mobot, Sumo Logic's AI-powered conversational assistant, is now generally available with a unified conversational interface. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that <strong>Mobot</strong>, Sumo Logic's AI-powered conversational assistant, is now generally available with a unified conversational interface. <a class="" href="https://www.sumologic.com/help/docs/search/mobot/">Learn more</a>.</p>
<p>In a single conversation, ask questions in plain language to investigate your log data or learn how to use the platform, with no agent selection or query syntax required. Mobot determines your intent and responds accordingly:</p>
<ul>
<li class=""><strong>Log analysis</strong>. Mobot plans and runs multi-step analysis across your logs, returns inline results with notable findings, and recommends next steps.</li>
<li class=""><strong>How-to answers</strong>. Mobot answers platform questions with information and reference links from official Sumo Logic documentation.</li>
<li class=""><strong>Content creation</strong>. Create and manage monitors and dashboards through conversation, with a confirmation before anything goes live. Conversational playbook management for Automation Service is rolling out as well.</li>
<li class=""><strong>Cloud SIEM investigations</strong>. Continue a <a class="" href="https://www.sumologic.com/help/docs/cse/get-started-with-cloud-siem/soc-analyst-agent/">SOC Analyst Agent</a> investigation in Mobot with an insight's full context.</li>
</ul>
<p>The former Query Agent and Knowledge Agent now work behind the scenes as the Log Analysis Agent and Platform Optimization Agent, and Mobot routes each prompt to the right one automatically.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Searchable Time Support for Monitors (Alerts)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/07/22/alerts/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/07/22/alerts/</guid>
            <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to announce that you can now also use Searchable Time for Monitors, evaluating logs based on when they became searchable in Sumo Logic. Learn more.]]></description>
            <content:encoded><![CDATA[<p>We're excited to announce that you can now also use <strong>Searchable Time</strong> for Monitors, evaluating logs based on when they became searchable in Sumo Logic. <a class="" href="https://www.sumologic.com/help/docs/search/get-started-with-search/build-search/use-searchable-time/#create-a-monitor-using-searchable-time">Learn more</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Theme and Resolution Options for Dashboard PDF and PNG Exports (Dashboards)]]></title>
            <link>https://www.sumologic.com/help/release-notes-service/2026/07/10/dashboards/</link>
            <guid>https://www.sumologic.com/help/release-notes-service/2026/07/10/dashboards/</guid>
            <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[We're excited to introduce more control over your dashboard exporting and scheduled reports. When you export a dashboard to PDF or PNG or create a scheduled report, you can now:]]></description>
            <content:encoded><![CDATA[<p>We're excited to introduce more control over your dashboard exporting and scheduled reports. When you <a class="" href="https://www.sumologic.com/help/docs/dashboards/export-dashboard-new/">export a dashboard</a> to PDF or PNG or create a <a class="" href="https://www.sumologic.com/help/docs/dashboards/scheduled-report/">scheduled report</a>, you can now:</p>
<ul>
<li class="">Pick a <strong>Light</strong> or <strong>Dark</strong> theme for the output.</li>
<li class="">Set the resolution from 1,500 to 6,000 pixels for a sharper image on large displays.</li>
<li class="">Export panels with their own time range. If you've overridden the time range for a panel, the exported file now uses that panel's time range instead of the dashboard time range (PDF and PNG only).</li>
</ul>
<p><a class="" href="https://www.sumologic.com/help/docs/dashboards/export-dashboard-new/">Learn more</a>.</p>]]></content:encoded>
        </item>
    </channel>
</rss>