Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion blog-csoar/2024/12-31.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ Effective today, **December 31, 2024**, Sumo Logic’s on-premises SOAR solution

We [previously announced](/release-notes-csoar/2023/12/31/#november-1-2023---application-update) that as of November 15, 2023, Sumo Logic's on-premises SOAR solution no longer received updates, and Sumo Logic Engineering no longer developed, repaired, maintained, or tested the software as of that date.

To upgrade to Sumo Logic’s [Cloud SOAR](https://help.sumologic.com/docs/cloud-soar/) offering, reach out to your Sumo Logic representative.
To upgrade to Sumo Logic’s [Cloud SOAR](/docs/cloud-soar/) offering, reach out to your Sumo Logic representative.

---
### November 20, 2024 - Content Release
Expand Down
18 changes: 9 additions & 9 deletions blog-service/2021/12-31.md
Original file line number Diff line number Diff line change
Expand Up @@ -257,9 +257,9 @@ New - We have a new [ServiceNow connection](/docs/alerts/webhook-connections/s
---
## August 9, 2021 (Apps)

New - We are excited to release the Sumo Logic [Memcached](/docs/integrations/databases/memcached "https://help.sumologic.com/integrations/databases/Memcached") app. The Memcached app is a unified logs and metrics app that helps you monitor the availability, performance, health, and resource utilization of your Memcached clusters. Preconfigured dashboards provide insight into uptime, cache hits/misses, resource utilization, errors, and commands executed.
New - We are excited to release the Sumo Logic [Memcached](/docs/integrations/databases/memcached) app. The Memcached app is a unified logs and metrics app that helps you monitor the availability, performance, health, and resource utilization of your Memcached clusters. Preconfigured dashboards provide insight into uptime, cache hits/misses, resource utilization, errors, and commands executed.

Update - We have updated the Sumo Logic [Varnish](/docs/integrations/web-servers/varnish "https://help.sumologic.com/integrations/app-development/Varnish") app. The Varnish app provides dashboards that help you analyze log and metric events generated by Varnish servers. This app allows you to identify traffic sources, monitor and improve application and website workflows, and understand how customers use your product.
Update - We have updated the Sumo Logic [Varnish](/docs/integrations/web-servers/varnish) app. The Varnish app provides dashboards that help you analyze log and metric events generated by Varnish servers. This app allows you to identify traffic sources, monitor and improve application and website workflows, and understand how customers use your product.

---
## August 9, 2021 (Manage)
Expand All @@ -274,12 +274,12 @@ New - The [Search Query Language](/docs/search/search-query-language "Search Q
---
## August 1, 2021 (Apps)

New - We are pleased to announce the release of the [Elasticsearch](/docs/integrations/databases/elasticsearch "https://help.sumologic.com/integrations/web-servers/Elasticsearch") app. The Elasticsearch app is a unified logs and metrics app that helps you monitor the availability, performance, health, and resource utilization of your Elasticsearch clusters. Preconfigured dashboards provide insight into cluster health, resource utilization, sharding, search, and index performance.
New - We are pleased to announce the release of the [Elasticsearch](/docs/integrations/databases/elasticsearch) app. The Elasticsearch app is a unified logs and metrics app that helps you monitor the availability, performance, health, and resource utilization of your Elasticsearch clusters. Preconfigured dashboards provide insight into cluster health, resource utilization, sharding, search, and index performance.

---
## July 21, 2021 (Apps)

Update - We've updated the [Apache Tomcat](/docs/integrations/web-servers/apache-tomcat "https://help.sumologic.com/integrations/web-servers/Apache_Tomcat") app. The Apache Tomcat app is a unified logs and metrics app that helps you monitor the availability, performance, health and resource utilization of your Apache Tomcat servers. Preconfigured dashboards provide insight into visitor locations, traffic patterns, errors, resource utilization, garbage collection, web server operations and access from known malicious sources.
Update - We've updated the [Apache Tomcat](/docs/integrations/web-servers/apache-tomcat) app. The Apache Tomcat app is a unified logs and metrics app that helps you monitor the availability, performance, health and resource utilization of your Apache Tomcat servers. Preconfigured dashboards provide insight into visitor locations, traffic patterns, errors, resource utilization, garbage collection, web server operations and access from known malicious sources.

---
## July 3, 2021 (Apps)
Expand Down Expand Up @@ -376,9 +376,9 @@ New - Our [Cloud-to-Cloud Integration Framework](/docs/send-data/hosted-collec
---
## June 7, 2021 (Apps)

New - We are excited to announce the launch of the [Nginx Plus](/docs/integrations/web-servers/nginx-plus "https://help.sumologic.com/integrations/web-servers/nginx-plus") web server App. The app is an unified logs and metrics app that helps you monitor the availability, performance, health and resource utilization of your Nginx Plus web servers. Preconfigured dashboards and searches provide insight into server status, location zones, server zones, upstreams, resolvers, visitor locations, visitor access types, traffic patterns, errors, web server operations and access from known malicious sources.
New - We are excited to announce the launch of the [Nginx Plus](/docs/integrations/web-servers/nginx-plus) web server App. The app is an unified logs and metrics app that helps you monitor the availability, performance, health and resource utilization of your Nginx Plus web servers. Preconfigured dashboards and searches provide insight into server status, location zones, server zones, upstreams, resolvers, visitor locations, visitor access types, traffic patterns, errors, web server operations and access from known malicious sources.

Update - There is a new release for the [Microsoft SQL Server](/docs/integrations/microsoft-azure/sql-server "https://help.sumologic.com/integrations/microsoft-azure/Microsoft_SQL_Server") app. The is an unified logs and metrics app that provides insight into your SQL server performance metrics and errors. The App consists of predefined Dashboards, providing visibility into your environment for real-time or historical analysis on backup, latency, performance counter, restore, mirroring, database monitoring, general health and operations of your system.
Update - There is a new release for the [Microsoft SQL Server](/docs/integrations/microsoft-azure/sql-server) app. The is an unified logs and metrics app that provides insight into your SQL server performance metrics and errors. The App consists of predefined Dashboards, providing visibility into your environment for real-time or historical analysis on backup, latency, performance counter, restore, mirroring, database monitoring, general health and operations of your system.

---
## June 3, 2021 (Search)
Expand All @@ -395,7 +395,7 @@ Update - You can use a [Windows Event Source to collect forwarded events](/docs
---
## June 2, 2021 (Apps)

Update - There is a new release for the [MongoDB](/docs/integrations/databases/mongodb "https://help.sumologic.com/integrations/databases/mongodb") app.The app now provides insight into your MongoDB environment, allowing you to track overall system health, queries, logins and connections, errors and warnings, replication, and sharding.
Update - There is a new release for the [MongoDB](/docs/integrations/databases/mongodb) app.The app now provides insight into your MongoDB environment, allowing you to track overall system health, queries, logins and connections, errors and warnings, replication, and sharding.

---
## June 1, 2021 (Search)
Expand Down Expand Up @@ -452,11 +452,11 @@ New - The [CatchPoint](/docs/integrations/partner-ecosystem-apps) App for Sum

**Cybereason**

New -  The [Cybereason](/docs/integrations/partner-ecosystem-apps "https://help.sumologic.com/integrations/partner-ecosystem-apps") App for Sumo Logic enables Security Operations teams to leverage the Cybereason Malop™ to detect and end attacks faster. 
New -  The [Cybereason](/docs/integrations/partner-ecosystem-apps) App for Sumo Logic enables Security Operations teams to leverage the Cybereason Malop™ to detect and end attacks faster. 

**Nucleon**

New - [Nucleon](/docs/integrations/partner-ecosystem-apps "https://help.sumologic.com/integrations/partner-ecosystem-apps") is a distributed, high-performance invisible, and non-invasive platform that is tailored to secure environments from different common threats such as professional hacking groups, APTs, and others. The Nucleon App for Sumo Logic helps in identifying the overall number of threats, their sources by country, and their targeted segments(critical_infrastructure, energy, fintech, governments, health_care, municipality, general, telecom).
New - [Nucleon](/docs/integrations/partner-ecosystem-apps) is a distributed, high-performance invisible, and non-invasive platform that is tailored to secure environments from different common threats such as professional hacking groups, APTs, and others. The Nucleon App for Sumo Logic helps in identifying the overall number of threats, their sources by country, and their targeted segments(critical_infrastructure, energy, fintech, governments, health_care, municipality, general, telecom).

**Workday App and Workday C2C source**

Expand Down
2 changes: 1 addition & 1 deletion blog-service/2025-05-05-alerts.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,6 @@ The [previously announced](/release-notes-service/2024/12/31/#deprecation-notice

- Existing Real-Time Scheduled Searches will continue to operate as-is.
- Creating new Real-Time Scheduled Searches remains disabled (since May 29, 2024).
- For new real-time alerting use cases, we recommend using [Monitors](https://help.sumologic.com/docs/alerts/monitors/overview).
- For new real-time alerting use cases, we recommend using [Monitors](/docs/alerts/monitors/overview).

[Learn more](/docs/alerts/scheduled-searches/create-real-time-alert).
2 changes: 1 addition & 1 deletion docs/api/service-accounts.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,4 +36,4 @@ The Service Accounts API allows you to manage service accounts. [Service account

* User Management (all role capabilities)

Only administrators can create service accounts. If you are unsure whether you are an administrator, you can view your role in **Preferences** (see [Onboarding Checklists](https://help.sumologic.com/docs/get-started/onboarding-checklists/)).
Only administrators can create service accounts. If you are unsure whether you are an administrator, you can view your role in **Preferences** (see [Onboarding Checklists](/docs/get-started/onboarding-checklists/)).
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Amazon EBS is recommended for data that must be quickly accessible and requires
* [CloudWatch Metrics](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using_cloudwatch_ebs.html)

:::note
For [CloudTrail log](https://docs.aws.amazon.com/ebs/latest/userguide/logging-ebs-apis-using-cloudtrail.html), Amazon EBS and Amazon EC2 are tightly integrated services. Most EBS-related events are captured and reflected as part of EC2 events, since EBS volumes are typically attached to EC2 instances for storage and compute operations. See the [Amazon EC2 app](https://help.sumologic.com/docs/integrations/amazon-aws/ec2-cloudwatch-metrics/#events) for EBS related captured events.
For [CloudTrail log](https://docs.aws.amazon.com/ebs/latest/userguide/logging-ebs-apis-using-cloudtrail.html), Amazon EBS and Amazon EC2 are tightly integrated services. Most EBS-related events are captured and reflected as part of EC2 events, since EBS volumes are typically attached to EC2 instances for storage and compute operations. See the [Amazon EC2 app](/docs/integrations/amazon-aws/ec2-cloudwatch-metrics/#events) for EBS related captured events.
:::

## Setup
Expand Down
6 changes: 3 additions & 3 deletions docs/integrations/saas-cloud/trend-micro-vision-one.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,13 +17,13 @@ This app includes [built-in monitors](#trend-micro-vision-one-monitors). For det

## Log types

This app uses Sumo Logic’s Trend Micro Vision One Source to collect [alert logs](https://help.sumologic.com/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/trend-micro-source/) from the Trend Micro platform.
This app uses Sumo Logic’s Trend Micro Vision One Source to collect [alert logs](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/trend-micro-source/) from the Trend Micro platform.

## Sample log message

<details>
<summary>Alert Log</summary>

```json
{
"schemaVersion": "1.15",
Expand Down Expand Up @@ -193,7 +193,7 @@ This app uses Sumo Logic’s Trend Micro Vision One Source to collect [alert log
}
```
</details>

## Sample queries

```sql title="Total Alerts"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -130,8 +130,8 @@ The table below displays the response for each text box in this section.
| Existing Sumo Logic Lambda CloudWatch Logs Source API URL | Required you already collect AWS Lambda CloudWatch logs. Provide the existing Sumo Logic AWS Lambda CloudWatch Source API URL. The account, region and namespace fields will be added to the Source. For information on how to determine the URL, see [View or Download Source JSON Configuration](/docs/send-data/use-json-configure-sources/local-configuration-file-management/view-download-source-json-configuration.md). |
| Subscribe log groups to destination (lambda or kinesis firehose delivery stream) | <ul><li>**New** - Automatically subscribes new AWS Lambda log groups to Lambda, to send logs to Sumo Logic.</li><li>**Existing** - Automatically subscribes existing log groups to Lambda, to send logs to Sumo Logic.</li><li>**Both** - Automatically subscribes new and existing log groups.</li><li>**None** - Skips automatic subscription of log groups.</li></ul>|
| Regex for AWS Log Groups | Default Value: **aws/(lambda\|apigateway\|rds)** <br/> With default value, log group names matching with lambda or rds will be subscribed and ingesting cloudwatch logs into sumo logic.<br/> Enter a regex for matching log group names. For more information, see [Configuring parameters](/docs/send-data/collect-from-other-data-sources/autosubscribe-arn-destination/#configuringparameters) in the *Auto-Subscribe ARN (Amazon Resource Name) Destination* topic.
| Tags for filtering CloudWatch Log Groups | Enter comma separated key value pairs for filtering logGroups using tags. Ex KeyName1=string,KeyName2=string. This is optional leave it blank if tag based filtering is not needed. Visit https://help.sumologic.com/docs/send-data/collect-from-other-data-sources/autosubscribe-arn-destination/#configuringparameters |
| Tags for filtering CloudWatch Log Groups | Enter comma separated key value pairs for filtering logGroups using tags. Ex KeyName1=string,KeyName2=string. This is optional leave it blank if tag based filtering is not needed. Visit [Configuring parameters](/docs/send-data/collect-from-other-data-sources/autosubscribe-arn-destination/#configuringparameters). |

:::note
* Don't use forward slashes (`/`) to encapsulate the regex. While normally they are needed for raw code, it's not necessary here.
* Use regex `.*` for auto-subscribing all log groups.
Expand Down Expand Up @@ -260,4 +260,3 @@ AWS Observability hierarchy is auto-populated based on the metrics ingested into
### Redeploying the AWS Observability CloudFormation template with existing Sumo Logic resources from a previous deployment

**Ensure that you delete the Sumo Logic resources completely prior to redeployment.** If you have **Delete Sumo Logic Resources when stack is deleted** set to "True", then the Sumo Logic resources will automatically be removed while deleting the AWS Observability CloudFormation template. If you have **Delete Sumo Logic Resources when stack is deleted** set to "False", then the Sumo Logic resources **will not** be removed while deleting the AWS Observability CloudFormation template. If you do not delete the Sumo Logic resources prior to redeployment (that is, collectors and sources), then subsequent deployments may attempt to use the existing resources, which can result in collection issues. This is not recommended.

Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ import AccessKey from '../../../../reuse/automation-service/access-key.md';
* <IntegrationCertificate/>
* **Signals Daemon Query**. Enter the query to be executed in daemons.

* **API Rate Limit Sleep (s)**. Enter the API rate limit in seconds. If the API rate limit exceeded, wait for 1 second and then attempt a retry, with a maximum wait time of 10. more info at https://help.sumologic.com/docs/api/metrics/#rate-limiting.
* **API Rate Limit Sleep (s)**. Enter the API rate limit in seconds. If the API rate limit exceeded, wait for 1 second and then attempt a retry, with a maximum wait time of 10. More info at [Rate limiting](/docs/api/metrics/#rate-limiting).

* **Custom Field Interval Name (Close Insight Trigger)**. This field is only used within the Close Insight Trigger as a custom field for insight ID in Cloud SOAR, for example, `opt_1`.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ import AccessKey from '../../../../reuse/automation-service/access-key.md';
* **Daemon Query**. Enter the query to be executed in daemons.
* <IntegrationTimeout/>
* <IntegrationCertificate/>
* **API Rate Limit Sleep (s)**. Enter the API rate limit in seconds. If the API rate limit exceeded, wait for 1 second and then attempt a retry, with a maximum wait time of 10. more info at https://help.sumologic.com/docs/api/metrics/#rate-limiting.
* **API Rate Limit Sleep (s)**. Enter the API rate limit in seconds. If the API rate limit exceeded, wait for 1 second and then attempt a retry, with a maximum wait time of 10. More info at [Rate limiting](/docs/api/metrics/#rate-limiting).
* <IntegrationEngine/>
* <IntegrationProxy/>

Expand Down
2 changes: 1 addition & 1 deletion docs/reuse/apps/app-install-index-option.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ To install the app, do the following:
:::
1. Click **Next** in the **Setup Data** section.
1. In the **Configure App** section of your respective app, complete the following field.
1. **Index**. Specify value for _index if the collection is configured with custom partition. [Learn more](https://help.sumologic.com/docs/search/optimize-search-partitions). Default value is set to `sumologic_default` (default partition)
1. **Index**. Specify value for _index if the collection is configured with custom partition. [Learn more](/docs/search/optimize-search-partitions). Default value is set to `sumologic_default` (default partition)
1. Click **Next**. You will be redirected to the **Preview & Done** section.

**Post-installation**
Expand Down