"Sumo Logic for DevOps: Great Improvements, but Costly"
There have been many improvements since my last review. UI changes are optional; you can try the new UI, but I still prefer the old one. AI Query helps with the learning curve—you can use a query agent to translate natural-language questions into search queries. There are ways to save money like Flex Pricing or assigning data to infrequent/frequent tiers based on your use case, but it's still a bit pricey. CS/Dev teams use Sumo daily to analyze data, find logs, and debug errors. Ops created a dashboard to monitor all deployment pipelines in Prod, tracking status and versions. Sumo provides real-time monitoring of logs, alerting on potential issues to maintain system reliability. This review is based 100% on my experience and use cases, not AI-written.
S
Sr Network Security Engineer
"Strong Logging and Monitoring but UI Needs Modernization"
Sumo Logic solves scalability for various logging sources and data naturalization. I find the application monitoring for secure performance concerns particularly useful. Troubleshooting is easier because I can look across multiple data sources and correlate quickly, which is critical. I also value the security aspect, applying a security lens to data analysis. The application monitoring lets us parse data and correlate with existing logs. Initial setup was extremely easy. However, application monitoring doesn't meet current industry standards, and a modern UI redesign would help. Sumo Logic scales logging sources, naturalizes data, and monitors applications for secure performance. It aids troubleshooting by correlating data across sources and applying a security lens, making it critical for our operations.
P
Platform Solutions Architect - Principal
"MoBot AI Improves Observability and Security Workflows"
As a solution architect, MoBot impressed me most. An AI-guided assistant that helps navigate observability and security workflows, write queries, and refine them with suggestions and a nice UI is a game changer, especially for those new to complex log queries. While Sumo Logic is powerful, it can feel overwhelming initially with metrics, logs, Cloud SIEM, automation, and MoBot—without proper training, you can feel lost. We had trouble sharing visibility across teams and integrating external tools like Auth0, but the ability to build, export, and import dashboards means security and operations stakeholders now view the same data, leading to better collaboration and faster decisions.
"Centralized Log Management with Excellent Search and Integration"
I love the centralized log management capabilities that work in both hybrid and cloud environments. The tool provides robust real-time monitoring reports that help identify issues effectively. Sumo Logic's search abilities are outstanding for investigation and troubleshooting. Dashboards offer helpful operational insights that are easy to manage. The integration with other cloud systems, including security, is brilliant. Sumo Logic is useful for both security monitoring and observability in one place. The query language has a learning curve for new users, and the cost can feel high as data ingestion grows. Sumo Logic centralizes logs and monitors operational data from various systems, supporting DevOps and IT teams in troubleshooting outages for consistent performance. It provides versatile visibility across cloud apps, infrastructure, and networks. The platform has helped monitor security updates seamlessly, detects anomalies, and eliminates manual machine data handling, saving time. Proactive monitoring ensures no downtime or operational distractions.
"Live Tail and LogReduce Speed Real-Time Troubleshooting"
I use Sumo Logic's Live Tail almost daily. Streaming real-time logs during deployments lets me catch anomalies in seconds rather than waiting for alerts. LogReduce clustering has cut my incident investigation time in half by grouping similar error patterns automatically. The dashboard builder is where I face the most friction; there's no drag-and-drop panel resizing, so arranging widgets takes longer than it should, especially during incident reviews. Before Sumo Logic, our observability was fragmented: logs in CloudWatch, metrics in another tool, and correlating them meant constant context switches, adding 20-30 minutes to every triage. Now we investigate the full stack in one unified interface, cutting mean time to resolution by about 40% and making on-call rotations much less stressful.
"AI Summaries Reduce Alert Fatigue, but Onboarding is Clunky"
As a software engineer, I like that Dojo AI genuinely cuts alert fatigue. The Summary Agent gives my team a clear, readable explanation of what triggered each Insight, so instead of digging through 40 lines of raw logs, they get a summary of key signals, scope, and context. Onboarding new data sources still feels clunkier than it should. Last quarter, adding a new SaaS tool took almost a week of back-and-forth with documentation and support to get logs flowing correctly. We had a serious siloing problem: security, DevOps, and infrastructure teams used different tools with different data views, and incidents wasted 30 minutes just getting everyone aligned. Sumo Logic fixed that by becoming our single source of truth for all telemetry.
"AI Activity Monitoring Simplifies Auditing and Debugging"
The AI activity monitoring really stood out. I can now see exactly who's doing what with Claude, user logins, admin actions, and API key creation in one place. For an AI engineer, that audit trail is valuable not just for compliance but for debugging access issues and understanding developer interactions. The detection rules work for standard compliance cases, but as someone building AI-heavy workflows, I'd like more customization for model-level events, not just admin and workspace changes. The biggest challenge I faced was the lack of centralized visibility into our Claude usage. As we scaled AI adoption, security and compliance had no way to track who accessed Claude, admin actions, or API key management—it was a blind spot in our stack.
"Centralized Logging with User-Friendly Dashboards"
I rely on Sumo Logic as a centralized logging and monitoring solution that offers robust search capabilities and simplifies log correlation across systems. It's intuitive for troubleshooting and provides flexible dashboards and alerts. The log search is extremely powerful, with a flexible and fast query language that makes filtering easy. Centralized log aggregation removes the need to switch tools and accelerates root cause analysis. I also value the custom dashboards that give real-time visibility and the simple initial setup. Pricing can get expensive as volume grows, and new users face a learning curve with the query language. More dashboard customization options and guided onboarding would improve the experience. In short, Sumo Logic centralizes logs for rapid issue identification and operational visibility, with powerful search, easy correlation, and flexible dashboards for real-time monitoring and alerts.
"Privacy-First AI Logging Minimizes Data Breach Risks"
Mobot doesn't share or process our log data with third parties. All Sumo Logic AI features operate within recognized security frameworks, which is a major plus for a software company and lowers our data breach risk. I often end up in the Top 100 users because of partition log issues. If logs could automatically go to T1 or T3 based on queries by default, new users would avoid wasting data. The main benefits are less time on root causes, faster incident triage, proactive backlog monitoring, and better operational efficiency. With SumoMobot AI, we can create queries, correlate logs and metrics, summarize trends, and speed up investigations. This lets our support teams resolve customer issues faster and focus on higher-value tasks.
S
Senior Site Reliability Engineer
"API-First Sumo Logic Drives Multi-Cloud Observability at Scale"
Our small DevOps/SRE team manages observability for dozens of isolated production environments on AWS, OCI, and Azure, and Sumo Logic is what makes it work. All data lands in a single org: Kubernetes clusters on EKS and OKE, cloud audit logs, endpoint and identity telemetry, and on-prem Windows infrastructure. Incident triage begins with one search box instead of figuring out which cluster holds the logs. The API-first approach is the hidden gem—we use the API to generate Terraform from the live org and manage our whole collector estate as code, cutting new client onboarding from 5–6 weeks to about one. Scheduled Views keep SLA reporting affordable, AI anomaly monitors catch things static thresholds miss, and Flex pricing with tiered partitions aligns cost with data value. The query language has a learning curve for engineers from other stacks, and the Terraform provider sometimes trails new platform features, which matters for our as-code approach. API-based content management (folders, dashboards) is clunkier than collector management. These aren't dealbreakers, just rough edges. It replaced six separately managed Elasticsearch clusters—patching, scaling, securing, and backups went to zero. One platform now handles log analytics, metrics, SLA reporting, and anomaly detection across all client environments, under SOC 2 with PCI-scoped separation. Since 2020, our client roster has grown, but the team hasn't.