In this article: |
Sumo Logic
Here you can find how to receive credentials to enable API integration with your Sumo Logic instance in use. You need the same credentials both for content deployment/automation and Attack Detective.
Parameter | Description |
Deployment Region | The region where your Sumo Logic cloud instance is deployed |
Timezone | Your current timezone required for search events |
Access ID | Parameter used for authentication |
Access Key | Parameter used for authentication |
Folder ID | Folder ID where all content will be deployed |
Deployment Region
To receive the Deployment Region parameter, copy the region name displayed in your Sumo Logic instance link. For example, if you access your Sumo Logic instance with the following link: https://service.de.sumologic.com/, your region will be DE, which will be the value of the Deployment Region parameter. To configure it in the Data Plane settings, select the EU (Europe) - DE option from the corresponding Deployment Region drop-down list.
Timezone
To receive the Timezone parameter, find the corresponding Timezone drop-down list and select the timezone in which the events are displayed in your Sumo Logic instance.
Access ID and Access Key
To receive the Access ID and Access Key parameters:
On the Sumo Logic web page, select Administration > Security > Access Keys at https://service.de.sumologic.com/ui/#/security/access-keys
Create a new access key by clicking the Add Access Key button.
Set a new Access Key Name and leave the Domain section empty.
After clicking the Save button, you will see a success notification with your new Access ID and Access Key.
Copy and paste them to the Access ID and Access Key fields in the Sumo Logic Data Plane settings.
Folder ID
To receive the Folder ID parameter, go to your existing folder with content or create a new one. Copy the folder ID from the URL of the folder and paste it to the Folder ID field in the Data Plane settings. All content will be deployed to this folder.
Note:
To ensure searches in Sumo Logic work as expected and have high performance, follow best practices, in particular extract important fields with Field Extraction Rules and use them with keyword searches.
To map extracted field names to field names used in Threat Detection Marketplace content by default, set up a Custom Filed Mapping profile. |
Sumo Logic CSE
To deploy Queries and Rules into the Sumo Logic CSE in use, SOC Prime Platform users need to enable API to their Sumo Logic CSE subscription.
Parameter | Description |
Portal URL | The URL used to access your Sumo Logic CSE instance |
API Token | API token that allows deploying and modifying content in your Sumo Logic CSE account via the Environment specified in the integration settings |
Portal URL
To receive the Portal URL parameter, copy the link used to access your Sumo Logic CSE instance. For example, https://your-company-name.portal.jask.ai/
API Token
To receive the API Token parameter, go to your profile in the top right corner and copy the API Key. In case the API key is not available, ask your administrator to enable it.
