Sumo Logic integration
Unify user management, monitoring infrastructure, and cloud SIEM operations with service management for comprehensive observability.
What it connects
- User accounts, roles, and permission assignments across your Sumo Logic organization.
- Infrastructure monitoring collectors and data sources, including agent health and configuration status.
- Cloud SIEM signals and security analytics insights from your monitoring pipeline.
- Alert and muting schedules to coordinate monitoring maintenance with change management.
What it automates
- Create and manage user accounts directly from service tickets, reducing onboarding time.
- Assign or remove user roles to enforce least-privilege access control during offboarding.
- Unlock locked accounts, reset passwords, and disable MFA for helpdesk workflows.
- Create monitoring alerts and muting schedules to silence expected events during maintenance windows.
In practice
A new employee joins; STLabs creates their Sumo Logic user account, assigns security monitoring roles, and routes confirmation to onboarding.
During an incident, an engineer needs temporary elevated permissions; STLabs grants the role, logs the change, and auto-removes access after 4 hours.
A user reports a forgotten password; the helpdesk ticket triggers a reset email and unlocks the account without manual intervention.
A planned maintenance window is scheduled; STLabs creates a muting schedule in Sumo Logic to prevent alert noise while keeping audit records intact.