Who is this for? Workspace Admins or Security Engineers who manage a workspace that uses Sumo Logic. This guide walks you through creating a Sumo Logic service account and OAuth client, configuring the module in ContraForce, and verifying that alerts flow end to end.
Before You Begin
What This Module Does
The Sumo Logic Detection module connects a ContraForce workspace to a Sumo Logic organization:Incidents
Monitor alerts become incidents
- Checks Sumo Logic for new monitor alerts about every 2 minutes
- Creates a ContraForce incident for each alert
- Shows the monitor behind each alert and the log messages that triggered it
- Resolves the alert in Sumo Logic when you close the incident in ContraForce
Monitors
Manage the monitors that raise alerts
- Lists the organization’s monitors on the workspace Detection Rules page
- Shows each monitor’s queries, trigger conditions, notifications and playbook
- Enables, disables, edits and deletes monitors from ContraForce
This module works with Sumo Logic monitors, not Cloud SIEM. A ContraForce incident is a Sumo Logic monitor alert. Cloud SIEM Insights and Signals are not ingested, so the module works on any Sumo Logic plan that has monitors.
What Syncs and What Stays in ContraForce
Sumo Logic monitor alerts have no assignee, comments or in-progress state, so those are recorded in ContraForce, where everyone who can see the incident sees them. Sumo Logic resolves an alert on its own when the monitor’s recovery condition is met, and the ContraForce incident follows.
Closing is best effort in Sumo Logic. If Sumo Logic cannot be reached, or the alert no longer exists there, the incident still closes in ContraForce. Reopening an incident in ContraForce does not reopen the alert in Sumo Logic.
Alert Retention
Sumo Logic deletes monitor alerts 30 days after they are created, and ContraForce does not keep a copy of the alert or its logs. The log messages behind an alert are fetched from Sumo Logic each time you open the incident. After 30 days, the incident shows a No longer retained in Sumo Logic notice, and the status, classification, owner, comments and audit trail recorded in ContraForce are still shown.Prerequisites
1
Sumo Logic monitors
A Sumo Logic organization with the monitors you want ContraForce to track.
2
Sumo Logic administrator access
The Sumo Logic Administrator role, which is required to create service accounts and OAuth clients.
3
ContraForce workspace
A ContraForce workspace for the organization, with your account assigned the workspace Owner role.
4
Your Sumo Logic deployment
The Sumo Logic region hosting the organization, for example US1 or EU. It is part of the API endpoint shown on the OAuth client page.
Step 1: Create a Service Account in Sumo Logic
An OAuth client acts as a service account. What ContraForce can do is limited both by the service account’s role and by the OAuth client’s scopes, so the role must allow everything the scopes grant.- In Sumo Logic, go to Administration > Account Security Settings > Service Accounts
- Create a service account, for example
ContraForce - Assign a role that can view alerts, view and manage monitors, and search the log data your monitors query
Step 2: Create the OAuth Client in Sumo Logic
- Go to Administration > Account Security Settings > OAuth Clients (classic UI: Administration > Security)
- Click Add OAuth Client
- Set Client Type to Client Credentials
- Set Name to
ContraForceand add a description - Set Service Account to the service account from Step 1
- Select these four Scopes:
- Click Save
All four scopes are required. The connection test in ContraForce fails if any of them is missing.
Step 3: Configure the Sumo Logic Module in ContraForce
- In the ContraForce portal, go to Workspaces > your workspace > Modules
- Find the Sumo Logic detection module card and click its settings (gear) icon, Configure Sumo Logic
- Fill in these fields:
- Click Test connection. The button changes to Connection verified when the credentials, deployment and scopes are all correct
- Click Configure and save
Step 4: Verify End to End
1
Wait for the first check
ContraForce checks Sumo Logic about every 2 minutes. A new monitor alert appears as an incident within a few minutes.
2
Open an incident
Open a Sumo Logic incident. The Rule tab shows the monitor that raised the alert, and the Logs tab shows the log messages that triggered it, fetched from Sumo Logic.
3
Check the Monitors tab
On the Sumo Logic module card, click Monitors, or open Detection Rules for the workspace and select the Sumo Logic Monitors tab. Your monitors should be listed.
Manage Monitors from ContraForce
The Sumo Logic Monitors tab lists the organization’s monitors with their folder path, type, alert levels, status and last change. Open a monitor to see its queries, trigger conditions, notifications and playbook. From an incident, View monitor details on the Rule tab opens the monitor behind the alert. Users with the workspace Owner or Content Admin role can:- Enable or disable a monitor
- Edit a monitor’s name, description, queries and alert thresholds
- Delete a monitor
Some settings stay in Sumo Logic. Thresholds can be edited for static conditions only. Outlier, anomaly, missing data and SLO conditions are shown but are edited in Sumo Logic. System monitors, and monitors Sumo Logic marks as read-only, cannot be changed from ContraForce.
Limitations
- Cloud SIEM Insights and Signals are not ingested
- Response actions: there are no Gamebook response actions for Sumo Logic
- Log search: there is no ad hoc log search from ContraForce; log messages are shown for the alert that triggered the incident
- Metrics monitors: incidents from metrics monitors show no log messages
- Retention: alerts older than 30 days are deleted by Sumo Logic, as described in Alert Retention
Troubleshooting
Related Documentation
Incident Management
Triage and resolve incidents in ContraForce
Roles and Permissions
Detailed role reference for ContraForce users
Questions about connecting Sumo Logic to ContraForce? Contact us at support@contraforce.com.