From ee720a95616798bc68356ff038d94e96495fea6a Mon Sep 17 00:00:00 2001 From: Amee Lepcha Date: Thu, 3 Apr 2025 20:07:34 +0530 Subject: [PATCH 1/6] Sumo Collection app --- blog-service/2025-04-04-apps.md | 13 ++ cid-redirects.json | 1 + .../product-list/product-list-m-z.md | 2 +- docs/integrations/saas-cloud/index.md | 6 + .../saas-cloud/sumo-collection.md | 195 ++++++++++++++++++ sidebars.ts | 1 + 6 files changed, 217 insertions(+), 1 deletion(-) create mode 100644 blog-service/2025-04-04-apps.md create mode 100644 docs/integrations/saas-cloud/sumo-collection.md diff --git a/blog-service/2025-04-04-apps.md b/blog-service/2025-04-04-apps.md new file mode 100644 index 0000000000..0413954581 --- /dev/null +++ b/blog-service/2025-04-04-apps.md @@ -0,0 +1,13 @@ +--- +title: Sumo Collection (Apps) +image: https://help.sumologic.com/img/sumo-square.png +keywords: + - apps + - sumo-collection +hide_table_of_contents: true +--- + +import useBaseUrl from '@docusaurus/useBaseUrl'; + + +We're excited to introduce the new Sumo Collection app for Sumo Logic. By leveraging this app, you can get insights into the health and status of Sumo Logic collectors and sources, allowing you to effectively manage and monitor collectors and sources within Sumo Logic. [Learn more](/docs/integrations/saas-cloud/sumo-collection). \ No newline at end of file diff --git a/cid-redirects.json b/cid-redirects.json index f3c708899e..32b0fc7c17 100644 --- a/cid-redirects.json +++ b/cid-redirects.json @@ -1622,6 +1622,7 @@ "/cid/10197": "/docs/integrations/saas-cloud/symantec-web-security-service", "/cid/6016": "/docs/integrations/saas-cloud/trend-micro-vision-one", "/cid/6024": "/docs/integrations/saas-cloud/vmware-workspace-one", + "/cid/6026": "/docs/integrations/saas-cloud/sumo-collection", "/cid/10112": "/docs/integrations/app-development/jfrog-xray", "/cid/10113": "/docs/observability/root-cause-explorer", "/cid/10116": "/docs/manage/fields", diff --git a/docs/integrations/product-list/product-list-m-z.md b/docs/integrations/product-list/product-list-m-z.md index 7913ac66e6..6bb89d24a7 100644 --- a/docs/integrations/product-list/product-list-m-z.md +++ b/docs/integrations/product-list/product-list-m-z.md @@ -161,7 +161,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | Thumbnail icon | [Strimzi](https://strimzi.io/) | App: [Strimzi Kafka](/docs/integrations/containers-orchestration/strimzi-kafka/) | | Thumbnail icon | [Stripe](https://stripe.com/) | Webhook: [Stripe](/docs/integrations/webhooks/stripe/) | | Thumbnail icon | [Sucuri](https://sucuri.net/) | Cloud SIEM integration: [Sucuri](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/cdfd2ba0-77eb-4e11-b071-6f4d01fda607.md) | -| Thumbnail icon | [Sumo Logic](https://www.sumologic.com/) | Apps:
- [Enterprise Audit - Cloud SIEM](/docs/integrations/sumo-apps/cse/)
- [Flex](/docs/integrations/sumo-apps/flex/)
- [Sumo Logic Audit App](/docs/integrations/sumo-apps/audit/)
- [Sumo Logic Data Volume App](/docs/integrations/sumo-apps/data-volume/)
- [Sumo Logic Enterprise Audit Apps](/docs/integrations/sumo-apps/enterprise-audit/) (multiple apps)
- [Sumo Logic Enterprise Search Audit App](/docs/integrations/sumo-apps/enterprise-search-audit/)
- [Sumo Logic Infrequent Data Tier App](/docs/integrations/sumo-apps/infrequent-data-tier/)
- [Sumo Logic Log Analysis QuickStart App](/docs/integrations/sumo-apps/log-analysis-quickstart/)
- [Sumo Logic Security Analytics App](/docs/integrations/sumo-apps/security-analytics/)
Automation integrations:
- [Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools/)
- [Basic Tools](/docs/platform-services/automation-service/app-central/integrations/basic-tools/)
- [ESMTP](/docs/platform-services/automation-service/app-central/integrations/esmtp/)
- [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools/)
- [Incident Tools](/docs/platform-services/automation-service/app-central/integrations/incident-tools/)
- [IMAP](/docs/platform-services/automation-service/app-central/integrations/imap/)
- [Mail Tools](/docs/platform-services/automation-service/app-central/integrations/mail-tools/)
- [POP3](/docs/platform-services/automation-service/app-central/integrations/pop3/)
- [SMTP V3](/docs/platform-services/automation-service/app-central/integrations/smtp-v3/)
- [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem/)
- [Sumo Logic Cloud SIEM Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem-internal/)
- [Sumo Logic Log Analytics](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics/)
- [Sumo Logic Log Analytics Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics-internal/)
- [Sumo Logic Notifications](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications/)
- [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail/)
- [Sumo Logic Notifications by Microsoft](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-microsoft)
- [Triage Tools](/docs/platform-services/automation-service/app-central/integrations/triage-tools/)
- [ZIP Tools](/docs/platform-services/automation-service/app-central/integrations/zip-tools/)
Cloud SIEM integration: [Sumo Logic](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/34A5019C-7BEC-4BF8-A3B7-C38D567126C6.md)
Collector:
- [Sumo Collection](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source)
- [Universal Connector](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/universal-connector-source)
Community app: [Cloud Security Posture Management (CSPM) for Sumo Logic](https://github.com/SumoLogic/sumologic-content/tree/master/CSPM) | +| Thumbnail icon | [Sumo Logic](https://www.sumologic.com/) | Apps:
- [Enterprise Audit - Cloud SIEM](/docs/integrations/sumo-apps/cse/)
- [Flex](/docs/integrations/sumo-apps/flex/)
- [Sumo Collection](/docs/integrations/saas-cloud/sumo-collection)
- [Sumo Logic Audit App](/docs/integrations/sumo-apps/audit/)
- [Sumo Logic Data Volume App](/docs/integrations/sumo-apps/data-volume/)
- [Sumo Logic Enterprise Audit Apps](/docs/integrations/sumo-apps/enterprise-audit/) (multiple apps)
- [Sumo Logic Enterprise Search Audit App](/docs/integrations/sumo-apps/enterprise-search-audit/)
- [Sumo Logic Infrequent Data Tier App](/docs/integrations/sumo-apps/infrequent-data-tier/)
- [Sumo Logic Log Analysis QuickStart App](/docs/integrations/sumo-apps/log-analysis-quickstart/)
- [Sumo Logic Security Analytics App](/docs/integrations/sumo-apps/security-analytics/)
Automation integrations:
- [Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools/)
- [Basic Tools](/docs/platform-services/automation-service/app-central/integrations/basic-tools/)
- [ESMTP](/docs/platform-services/automation-service/app-central/integrations/esmtp/)
- [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools/)
- [Incident Tools](/docs/platform-services/automation-service/app-central/integrations/incident-tools/)
- [IMAP](/docs/platform-services/automation-service/app-central/integrations/imap/)
- [Mail Tools](/docs/platform-services/automation-service/app-central/integrations/mail-tools/)
- [POP3](/docs/platform-services/automation-service/app-central/integrations/pop3/)
- [SMTP V3](/docs/platform-services/automation-service/app-central/integrations/smtp-v3/)
- [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem/)
- [Sumo Logic Cloud SIEM Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem-internal/)
- [Sumo Logic Log Analytics](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics/)
- [Sumo Logic Log Analytics Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics-internal/)
- [Sumo Logic Notifications](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications/)
- [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail/)
- [Sumo Logic Notifications by Microsoft](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-microsoft)
- [Triage Tools](/docs/platform-services/automation-service/app-central/integrations/triage-tools/)
- [ZIP Tools](/docs/platform-services/automation-service/app-central/integrations/zip-tools/)
Cloud SIEM integration: [Sumo Logic](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/34A5019C-7BEC-4BF8-A3B7-C38D567126C6.md)
Collector:
- [Sumo Collection](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source)
- [Universal Connector](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/universal-connector-source)
Community app: [Cloud Security Posture Management (CSPM) for Sumo Logic](https://github.com/SumoLogic/sumologic-content/tree/master/CSPM) | | Thumbnail icon | [Superwise](https://superwise.ai/) | Webhook: [Superwise](/docs/integrations/webhooks/superwise/) | | Thumbnail icon | [Symantec](https://sep.securitycloud.symantec.com/v2/landing) | App:
- [Symantec Endpoint Security Service](/docs/integrations/saas-cloud/symantec-endpoint-security-service/)
- [Symantec Web Security Service](/docs/integrations/saas-cloud/symantec-web-security-service/)
Automation integrations:
- [Javelin AD Protect](/docs/platform-services/automation-service/app-central/integrations/javelin-ad-protect/)
- [Symantec DeepSight](/docs/platform-services/automation-service/app-central/integrations/symantec-deepsight/)
- [Symantec EDR](/docs/platform-services/automation-service/app-central/integrations/symantec-edr/)
- [Symantec Endpoint Protection](/docs/platform-services/automation-service/app-central/integrations/symantec-endpoint-protection/)
- [Symantec Endpoint Protection Cloud](/docs/platform-services/automation-service/app-central/integrations/symantec-endpoint-protection-cloud/)
- [Symantec Secure Web Gateway (Bluecoat)](/docs/platform-services/automation-service/app-central/integrations/symantec-secure-web-gateway-bluecoat/)
- [Symantec WebPulse](/docs/platform-services/automation-service/app-central/integrations/symantec-webpulse/)
Collectors:
- [Symantec Endpoint Security Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source/)
- [Symantec Web Security Service Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-web-security-service-source/)
Cloud SIEM integration: [Symantec](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/64c7f49c-f95a-4f4a-8540-56ec5fb1d96b.md)
Community app: [Sumo Logic for Symantec WSS](https://github.com/SumoLogic/sumologic-content/tree/master/Symantec/WSS) | | Thumbnail icon | [Sysdig](https://sysdig.com/) | Cloud SIEM integration: [Sysdig](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/c4de0854-e718-45e1-a4c8-63623755aa43.md)
Collector: [Sysdig Secure](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source.md) | diff --git a/docs/integrations/saas-cloud/index.md b/docs/integrations/saas-cloud/index.md index a87e6b9490..e2691ccf9e 100644 --- a/docs/integrations/saas-cloud/index.md +++ b/docs/integrations/saas-cloud/index.md @@ -339,6 +339,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.

Identify security threats by analyzing alerts and events logs.

+
+
+ icon

Sumo Collection

+

Identify, manage, and monitor collectors and sources within Sumo Logic.

+
+
icon

Symantec Endpoint Security Service

diff --git a/docs/integrations/saas-cloud/sumo-collection.md b/docs/integrations/saas-cloud/sumo-collection.md new file mode 100644 index 0000000000..a7eb8d0a3e --- /dev/null +++ b/docs/integrations/saas-cloud/sumo-collection.md @@ -0,0 +1,195 @@ +--- +id: sumo-collection +title: Sumo Collection +sidebar_label: Sumo Collection +description: The Sumo Collection app for Sumo Logic provides insights into health and status of Sumo Logic collectors and sources, allowing you to effectively manage and monitor collectors and sources within Sumo Logic. +--- + +import useBaseUrl from '@docusaurus/useBaseUrl'; + +thumbnail icon + +The Sumo Collection app is a comprehensive tool that offers detailed insights into the health and status of Sumo Logic collectors and sources. It enables efficient management and monitoring by tracking key parameters such as collector types, versions, operational status, and source metrics through intuitive analytics and visualizations. By providing organizations with the data they need to make informed decisions and optimize their data management strategies, the app enhances operational efficiency and facilitates proactive issue identification within the Sumo Logic ecosystem. + +With its comprehensive overview of collector and source activities, the app strengthens data collection infrastructure. Leveraging its analytics and visualization capabilities, organizations can drive data-driven decisions, optimize performance, and ensure seamless data collection within the Sumo Logic environment. + +:::info +This app includes [built-in monitors](#sumo-collection-monitors). For details on creating custom monitors, refer to [Create monitors for Sumo Collection app](#create-monitors-for-sumo-collection-app). +::: + +## Log types + +This app uses Sumo Logic’s [Sumo Collection Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source/) to collect the collectors and source logs from the Sumo Logic platform. + +### Sample log messages + +
+Collector Log + +```json +{ + "id": 106288931, + "name": "dc-windows-client2", + "timeZone": "Etc/UTC", + "fields": {}, + "links": [ + { + "rel": "sources", + "href": "/v1/collectors/106288231/sources" + } + ], + "ephemeral": false, + "targetCpu": -1, + "sourceSyncMode": "UI", + "installedCollectorSubtype": "Installed", + "collectorType": "Installable", + "collectorVersion": "19.376-1", + "osVersion": "10.0", + "osName": "Windows Server 2019", + "osArch": "amd64", + "lastSeenAlive": 1741775145414, + "alive": false +} +``` +
+ +
+Source Log + +```json +{ + "id": 116630551, + "schemaRef": { + "type": "Universal Connector" + }, + "config": { + "name": "YL UC continuation", + "paginationContinuationTokenType": "body", + "paginationContinuationTokenKey": "token", + "responseLogsJsonPaths": [ + { + "logTimestampFormat": "2025-03-12T15:55:35.405Z", + "logsPath": "$.data[*]", + "logTimestampPath": "$.modifiedAt" + } + ], + "authBasicUsername": "NEWWWNAME", + "requestEndpoint": "https://daorsXYCahaxe.xyz/api/v1/roles", + "paginationContinuationTokenLocation": "headers", + "paginationContinuationTokenJsonPath": "$.next", + "clientRateLimitBurst": 1000, + "authCategory": "Basic", + "clientTimeoutRetries": 5, + "parserPath": "", + "requestBody": "", + "requestMethod": "GET", + "fields": { + "_siemForward": false + }, + "authBasicPassword": "********", + "category": "yl/continuation", + "clientRateLimitDuration": "1m", + "pollingInterval": "1h", + "requestParams": [ + { + "paramName": "limit", + "paramValue": "1" + } + ], + "clientTimeoutDuration": "5m", + "responseLogsType": "json", + "paginationType": "ContinuationToken", + "progressType": "none", + "clientRateLimitReqs": 1000 + }, + "state": { + "state": "Collecting" + }, + "sourceType": "Universal", + "alive": true +} +``` +
+ +### Sample queries + +```sql title="Total Sources" +_sourceCategory="Labs/SumoCollection" sourceType +| json "id", "sourceType", "alive", "schemaRef.type", "state.state", "state.errorType", "state.errorInfo", "config.name", "state.errorCode", "config.fields._siemForward", "name", "category", "hostName", "automaticDateParsing", "multilineProcessingEnabled", "useAutolineMatching", "forceTimeZone", "encoding", "fields._siemForward" as id, source_type, alive, c2c_source, state, error_type, error_info, name, error_code, siem_forward, source_name, category, host_name, automatic_date_parsing, multiline_processing_enabled, use_autoline_matching, force_time_zone, encoding, source_siem_forward nodrop + +| where source_type matches "{{source_type}}" +| where if ("{{c2c_source}}" = "*", true, c2c_source matches "{{c2c_source}}") +| where if ("{{state}}" = "*", true, state matches "{{state}}") +| where if ("{{error_type}}" = "*", true, error_type matches "{{error_type}}") +| where if ("{{error_code}}" = "*", true, error_code matches "{{error_code}}") +| where alive matches "{{alive}}" + +| count by id +| count +``` + +## Collection configuration and app installation + +import CollectionConfiguration from '../../reuse/apps/collection-configuration.md'; + + + +:::important +Use the [Cloud-to-Cloud Integration for Sumo Collection](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your Sumo Collection app is properly integrated and configured to collect and analyze your Sumo Logic data. +::: + +### Create a new collector and install the app + +import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md'; + + + +### Use an existing collector and install the app + +import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md'; + + + +### Use an existing source and install the app + +import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md'; + + + +## Viewing the Sumo Collection dashboards​​ + +import ViewDashboards from '../../reuse/apps/view-dashboards.md'; + + + +### Collectors Overview + +The **Sumo Collection - Collectors Overview** dashboard provides a comprehensive view of data collection processes within Sumo Logic. It offers insights into total collectors, their distribution by type and version, the operational status of installed and hosted collectors, and collector-source relationships. You can track collectors by time zone, operating system, and associated sources, streamlining management and monitoring. With detailed health and performance metrics, the dashboard enables you to optimize data collection, make informed decisions, and ensure smooth operations. By offering real-time visibility and trend analysis, it empowers you to improve data collection infrastructure and prioritize actions for better performance and reliability.
Collectors-Overview + +### Sources Overview + +The **Sumo Collection - Sources Overview** dashboard provides offers a detailed view of data sources within Sumo Logic, enabling effective monitoring and management of data ingestion. It displays metrics such as total sources, source categorization, distribution of Cloud-to-Cloud (C2C) sources, and the health status of C2C sources. You can analyze sources by error states, identify top C2C vendors, and track error counts to resolve issues quickly. The dashboard also highlights specific error types like THIRD-PARTY-CONFIG and THIRD-PARTY-GENERIC, providing insights to optimize data flow and improve data quality. With its analytics and visualizations, you can proactively manage data sources, make informed decisions, and ensure reliable data ingestion within the Sumo Logic ecosystem.
Sources-Overview + +## Create monitors for Sumo Collection app + +import CreateMonitors from '../../reuse/apps/create-monitors.md'; + + + +### Sumo Collection monitors + +| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | +|:--|:--|:--|:--| +| `C2C Sources with THIRD-PARTY-CONFIG Errors` | This alert is triggered when Cloud-to-Cloud (C2C) sources encounter THIRD-PARTY-CONFIG errors, causing potential issues in the data ingestion process. | Critical | Count > 0 | + +## Upgrading the Sumo Collection app (Optional) + +import AppUpdate from '../../reuse/apps/app-update.md'; + + + +## Uninstalling the Sumo Collection app (Optional) + +import AppUninstall from '../../reuse/apps/app-uninstall.md'; + + \ No newline at end of file diff --git a/sidebars.ts b/sidebars.ts index 4bcd6ac6df..6e89eacd79 100644 --- a/sidebars.ts +++ b/sidebars.ts @@ -2559,6 +2559,7 @@ integrations: [ 'integrations/saas-cloud/sentinelone', 'integrations/saas-cloud/slack', 'integrations/saas-cloud/sophos', + 'integrations/saas-cloud/sumo-collection', 'integrations/saas-cloud/symantec-endpoint-security-service', 'integrations/saas-cloud/symantec-web-security-service', 'integrations/saas-cloud/tenable', From a3fa7897928828d16d6d7d03e4c2ca13ad890845 Mon Sep 17 00:00:00 2001 From: Amee Lepcha Date: Thu, 3 Apr 2025 21:08:15 +0530 Subject: [PATCH 2/6] Update docs/integrations/saas-cloud/sumo-collection.md Co-authored-by: John Pipkin (Sumo Logic) --- docs/integrations/saas-cloud/sumo-collection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/integrations/saas-cloud/sumo-collection.md b/docs/integrations/saas-cloud/sumo-collection.md index a7eb8d0a3e..2c944169ff 100644 --- a/docs/integrations/saas-cloud/sumo-collection.md +++ b/docs/integrations/saas-cloud/sumo-collection.md @@ -11,7 +11,7 @@ import useBaseUrl from '@docusaurus/useBaseUrl'; The Sumo Collection app is a comprehensive tool that offers detailed insights into the health and status of Sumo Logic collectors and sources. It enables efficient management and monitoring by tracking key parameters such as collector types, versions, operational status, and source metrics through intuitive analytics and visualizations. By providing organizations with the data they need to make informed decisions and optimize their data management strategies, the app enhances operational efficiency and facilitates proactive issue identification within the Sumo Logic ecosystem. -With its comprehensive overview of collector and source activities, the app strengthens data collection infrastructure. Leveraging its analytics and visualization capabilities, organizations can drive data-driven decisions, optimize performance, and ensure seamless data collection within the Sumo Logic environment. +With its comprehensive overview of collector and source activities, the app strengthens data collection infrastructure. Leveraging its analytics and visualization capabilities, organizations can make data-driven decisions, optimize performance, and ensure seamless data collection within the Sumo Logic environment. :::info This app includes [built-in monitors](#sumo-collection-monitors). For details on creating custom monitors, refer to [Create monitors for Sumo Collection app](#create-monitors-for-sumo-collection-app). From 04cb2065be3adb084c5e1940dacc994a2dab888c Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Mon, 7 Apr 2025 18:16:49 -0700 Subject: [PATCH 3/6] Clarify Sumo Collection source intro --- .../sumo-collection-source.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source.md b/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source.md index cdc3b1b8e5..e6f83aa47c 100644 --- a/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source.md +++ b/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source.md @@ -17,13 +17,19 @@ import useBaseUrl from '@docusaurus/useBaseUrl'; icon -Sumo Logic enables you to seamlessly gather and analyze valuable insights from diverse sources. By leveraging its robust API capabilities, you can efficiently extract, transform, and load data into your analytics pipeline. This streamlined process allows you to harness the power of real-time data analysis, improving decision-making, troubleshooting, and overall operational efficiency within your organization. +Sumo Logic's Cloud-to-Cloud (C2C) framework enables seamless data integration by leveraging API-based connections to collect insights from external systems and services. The Sumo Collection Source is part of this framework and is designed to gather a list of collectors and their associated sources directly from the Sumo Logic platform. + +This source supports both Installed and Hosted Collectors configured within a C2C environment. By using Sumo Logic’s API, it provides centralized, real-time visibility into collector and source health, operational status, and configuration metrics—helping teams proactively monitor deployments, troubleshoot issues, and maintain a reliable data collection pipeline. + +:::tip +For related info on collector health events, see [this doc](/docs/manage/health-events). +::: ## Data collected | Polling Interval | Data | -| :-- | :-- | -| 12 hours | [Collector API](/docs/api/collector-management/collector-api-methods-examples/#get-a-list-of-collectors) | +| :-- | :-- | +| 12 hours | [Collector API](/docs/api/collector-management/collector-api-methods-examples/#get-a-list-of-collectors) | | 5 minutes | [Source API](/docs/api/collector-management/source-api/#list-sources) | ## Setup @@ -58,7 +64,7 @@ To generate the Access ID and Access Key, refer to [Create an access key](/docs/ When you create a Sumo Collection Source, you add it to a Hosted Collector. Before creating the Source, identify the Hosted Collector you want to use or create a new Hosted Collector. For instructions, see [Configure a Hosted Collector and Source](/docs/send-data/hosted-collectors/configure-hosted-collector). To configure a Sumo Collection Source: -1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data > Collection > Collection**.
[**New UI**](/docs/get-started/sumo-logic-ui). In the Sumo Logic top menu select **Configuration**, and then under **Data Collection** select **Collection**. You can also click the **Go To...** menu at the top of the screen and select **Collection**. +1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data > Collection > Collection**.
[**New UI**](/docs/get-started/sumo-logic-ui). In the Sumo Logic top menu select **Configuration**, and then under **Data Collection** select **Collection**. You can also click the **Go To...** menu at the top of the screen and select **Collection**. 1. On the Collection page, click **Add Source** next to a Hosted Collector. 1. Search for and select **Sumo Collection**. 1. Enter a **Name** for the Source. The description is optional. From bc74d0cd9d5eb9d6f8eacd065abd5db4f416e349 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Tue, 22 Apr 2025 11:02:17 +0530 Subject: [PATCH 4/6] Update and rename 2025-04-04-apps.md to 2025-04-22-apps.md --- blog-service/{2025-04-04-apps.md => 2025-04-22-apps.md} | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) rename blog-service/{2025-04-04-apps.md => 2025-04-22-apps.md} (97%) diff --git a/blog-service/2025-04-04-apps.md b/blog-service/2025-04-22-apps.md similarity index 97% rename from blog-service/2025-04-04-apps.md rename to blog-service/2025-04-22-apps.md index 0413954581..cfeb23dc95 100644 --- a/blog-service/2025-04-04-apps.md +++ b/blog-service/2025-04-22-apps.md @@ -9,5 +9,4 @@ hide_table_of_contents: true import useBaseUrl from '@docusaurus/useBaseUrl'; - -We're excited to introduce the new Sumo Collection app for Sumo Logic. By leveraging this app, you can get insights into the health and status of Sumo Logic collectors and sources, allowing you to effectively manage and monitor collectors and sources within Sumo Logic. [Learn more](/docs/integrations/saas-cloud/sumo-collection). \ No newline at end of file +We're excited to introduce the new Sumo Collection app for Sumo Logic. By leveraging this app, you can get insights into the health and status of Sumo Logic collectors and sources, allowing you to effectively manage and monitor collectors and sources within Sumo Logic. [Learn more](/docs/integrations/saas-cloud/sumo-collection). From a2c02599c32002381b094f9a4cc73b774a8b59ef Mon Sep 17 00:00:00 2001 From: "Kim (Sumo Logic)" <56411016+kimsauce@users.noreply.github.com> Date: Tue, 22 Apr 2025 05:00:03 -0400 Subject: [PATCH 5/6] Update sumo-collection.md --- docs/integrations/saas-cloud/sumo-collection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/integrations/saas-cloud/sumo-collection.md b/docs/integrations/saas-cloud/sumo-collection.md index 4ef1438963..0619fa557a 100644 --- a/docs/integrations/saas-cloud/sumo-collection.md +++ b/docs/integrations/saas-cloud/sumo-collection.md @@ -186,7 +186,7 @@ import CreateMonitors from '../../reuse/apps/create-monitors.md'; ### Sumo Collection monitors -| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | +| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | |:--|:--|:--|:--| | `C2C Sources with THIRD-PARTY-CONFIG Errors` | This alert is triggered when Cloud-to-Cloud (C2C) sources encounter THIRD-PARTY-CONFIG errors, causing potential issues in the data ingestion process. | Critical | Count > 0 | From 908ba6579287677988a539f63fab27b673067091 Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Tue, 22 Apr 2025 02:02:41 -0700 Subject: [PATCH 6/6] rm blog --- blog-service/2025-04-22-apps.md | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 blog-service/2025-04-22-apps.md diff --git a/blog-service/2025-04-22-apps.md b/blog-service/2025-04-22-apps.md deleted file mode 100644 index cfeb23dc95..0000000000 --- a/blog-service/2025-04-22-apps.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -title: Sumo Collection (Apps) -image: https://help.sumologic.com/img/sumo-square.png -keywords: - - apps - - sumo-collection -hide_table_of_contents: true ---- - -import useBaseUrl from '@docusaurus/useBaseUrl'; - -We're excited to introduce the new Sumo Collection app for Sumo Logic. By leveraging this app, you can get insights into the health and status of Sumo Logic collectors and sources, allowing you to effectively manage and monitor collectors and sources within Sumo Logic. [Learn more](/docs/integrations/saas-cloud/sumo-collection).