New Sumo Logic Cloud SIEM Enterprise Provides Automation to Help SOC Teams Tame Growing Number of Unanalyzed Security Alerts and Events to Bolster Security and Compliance
REDWOOD CITY, Calif. – Feb. 20, 2020 – Sumo Logic, the leader in continuous intelligence, today announced the availability of its new Cloud SIEM Enterprise offering, which includes a rich set of capabilities to ease the burden on security operations center (SOC) personnel. The new capabilities help identify and prioritize high fidelity threats and automate the analyst workflow, allowing SOC personnel to better manage real security events and effectively enforce security and compliance policies. Sumo Logic will be showcasing its Security Intelligence portfolio offerings at RSA Conference 2020 in San Francisco from February 24-28 in booth #252 (South Hall).
Today's SOC teams are fatigued and under pressure from receiving tens of thousands of alerts every day. Compounding this problem, many SOCs were built around legacy solutions designed with SIEM technology invented years, even decades ago.
According to a recent survey of IT and cybersecurity professionals by Enterprise Strategy Group (ESG), 34% of respondents said the volume of security alerts has increased over the past two years. With this increase of volume, many of these alerts are left unnoticed, because many security analysts are still relying on legacy tools, such as on-prem SIEM technology or outsourced security, that do not provide them with actionable intelligence. Analysts spend the bulk of their day manually investigating alerts to separate valid threats from the noise. Unfortunately, this exhaustive work is ineffective at reducing risk to the organization.
With the rapid transformation to the cloud, shifts in the threat landscape, and security operations facing human-scale limitations - it’s clear that the SOC has to change.
“ESG research shows 70% of organizations continue to anchor their security analytics and operations with traditional SIEMs,” said Jon Oltsik, Senior Principal Analyst and Fellow at ESG. “Despite the central role SIEM plays, the research indicates that SOC teams use additional tools beyond SIEM for threat detection and response, investigations and query, threat intelligence analysis, and process automation and orchestration. Sumo Logic’s Cloud SIEM Enterprise, can help bridge this gap with a broader set of automation capabilities targeted directly at the modern SOC. These automation capabilities can help reduce alert fatigue while offering the continuous intelligence needed to collaborate, develop, operate, and secure applications at cloud scale.”
Cloud SIEM Enterprise: Expanding Continuous Intelligence to Security Operations
The newly announced Sumo Logic Cloud SIEM Enterprise is a cloud-native solution that addresses the challenges facing today’s modern SOC. This latest offering by Sumo Logic modernizes security operations by automating the manual work for the security analyst, saving them time and enabling them to be more effective by focusing on higher-value security functions. Sumo Logic Cloud SIEM Enterprise also provides real-time insights and intelligence SOC teams can use to quickly identify evidence of compromise and improve their ability to respond quickly by understanding the impact of an attack. This removes common technology limitations that burden a SOC's efficiency and ability to mitigate risk.
Sumo Logic Cloud SIEM Enterprise innovations include:
- Modern SaaS SIEM that enables customers to collect any security data, better correlate this data with context, prioritize actionable insights, and automate analyst workflows to build and automate security operations from the cloud.
- Improved Analyst Productivity with automated SOC analyst workflows performing routine manual tasks including data collection, correlation, and alert prioritization necessary to support investigations and threat hunting. These automated workflows are combined with deep search capabilities and connectivity to the customer’s existing response platforms.
- Focused and Guided Workflows that help level 1 and level 2 SOC analysts efficiently use their time and resources performing high-value activities, such as threat hunting, automation, and incident response versus managing and maintaining a SIEM.
- 360-Degree Visibility that provides context across user, device, app, and threat intelligence data, including deep packet inspection for full visibility into the customer’s network traffic (and AWS via VPC traffic mirroring with Sumo Logic’s network sensor).
- Elastic Scalability via multi-tenant architecture that supports rapid application growth and security requirements. The service overcomes the inherent limitations of traditional architectures by allowing organizations to burst as needed without any manual intervention.
“As an enterprise with a cloud-first strategy, it's imperative that security easily integrates into our modern application architecture,” said Lewis Brodnax, chief security officer, GreenSky. “Using Sumo Logic’s Cloud SIEM Enterprise solution automates our security processes, so my SOC analysts can focus their time and effort on the real threats. It also allows my team to coordinate and manage incidents and quickly respond to today’s rapidly changing threat landscape.”
“We believe organizations will greatly benefit from our new Cloud SIEM Enterprise offering that features comprehensive functionality from automated security workflows to advanced threat detection and best-in-class cloud visibility to address modern security operation challenges,” said Greg Martin, general manager, security business unit, Sumo Logic. “With the industry’s fast-moving transformation to public cloud, we wanted to give security teams a cloud-native solution with robust features they can use to navigate today’s cloud centric world.”
- Visit the Sumo Logic booth at RSA Conference 2020 (South Hall #252)
- Download the Sumo Logic Cloud SIEM Enterprise solution brief
- Sign up for a Sumo Logic Security Intelligence Platform free trial
- Check out file carving with Cloud SIEM Enterprise and how you can uniquely load YARA rules from your favorite Git repository to scan those extracted files
About Sumo Logic
Sumo Logic is a leader in continuous intelligence, a new category of software, which enables organizations of all sizes address the data challenges and opportunities presented by digital transformation, modern applications, and cloud computing. The Sumo Logic Continuous Intelligence Platform™ automates the collection, ingestion, and analysis of application, infrastructure, security, and IoT data to derive actionable insights within seconds. More than 2,000 customers around the world rely on Sumo Logic to build, run, and secure their modern applications and cloud infrastructures. Only Sumo Logic delivers its platform as a true, multi-tenant SaaS architecture, across multiple use-cases, enabling businesses to thrive in the Intelligence Economy.
Founded in 2010, Sumo Logic is a privately held company based in Redwood City, California, and is backed by Accel Partners, Battery Ventures, DFJ Growth, Franklin Templeton, Greylock Partners, IVP, Sapphire Ventures, Sequoia Capital, Sutter Hill Ventures, and Tiger Global Management. For more information, visit www.sumologic.com.
Sumo Logic is a trademark or registered trademark of Sumo Logic in the United States and in foreign countries. All other company and product names may be trademarks or registered trademarks of their respective owners.
Any information regarding offerings, updates, functionality, or other modifications, including release dates, is subject to change without notice. The development, release, and timing of any offering, update, functionality, or modification described herein remains at the sole discretion of Sumo Logic, and should not be relied upon in making a purchase decision, nor as a representation, warranty, or commitment to deliver specific offerings, updates, functionalities, or modifications in the future.
PAN Communications for Sumo Logic