Skip to main content
Who is this for? Workspace Admins or Security Engineers who manage a workspace that uses Sumo Logic. This guide walks you through creating a Sumo Logic service account and OAuth client, configuring the module in ContraForce, and verifying that alerts flow end to end.

Before You Begin

What This Module Does

The Sumo Logic Detection module connects a ContraForce workspace to a Sumo Logic organization:

Incidents

Monitor alerts become incidents
  • Checks Sumo Logic for new monitor alerts about every 2 minutes
  • Creates a ContraForce incident for each alert
  • Shows the monitor behind each alert and the log messages that triggered it
  • Resolves the alert in Sumo Logic when you close the incident in ContraForce

Monitors

Manage the monitors that raise alerts
  • Lists the organization’s monitors on the workspace Detection Rules page
  • Shows each monitor’s queries, trigger conditions, notifications and playbook
  • Enables, disables, edits and deletes monitors from ContraForce
This module works with Sumo Logic monitors, not Cloud SIEM. A ContraForce incident is a Sumo Logic monitor alert. Cloud SIEM Insights and Signals are not ingested, so the module works on any Sumo Logic plan that has monitors.

What Syncs and What Stays in ContraForce

Sumo Logic monitor alerts have no assignee, comments or in-progress state, so those are recorded in ContraForce, where everyone who can see the incident sees them. Sumo Logic resolves an alert on its own when the monitor’s recovery condition is met, and the ContraForce incident follows.
Closing is best effort in Sumo Logic. If Sumo Logic cannot be reached, or the alert no longer exists there, the incident still closes in ContraForce. Reopening an incident in ContraForce does not reopen the alert in Sumo Logic.

Alert Retention

Sumo Logic deletes monitor alerts 30 days after they are created, and ContraForce does not keep a copy of the alert or its logs. The log messages behind an alert are fetched from Sumo Logic each time you open the incident. After 30 days, the incident shows a No longer retained in Sumo Logic notice, and the status, classification, owner, comments and audit trail recorded in ContraForce are still shown.

Prerequisites

1

Sumo Logic monitors

A Sumo Logic organization with the monitors you want ContraForce to track.
2

Sumo Logic administrator access

The Sumo Logic Administrator role, which is required to create service accounts and OAuth clients.
3

ContraForce workspace

A ContraForce workspace for the organization, with your account assigned the workspace Owner role.
4

Your Sumo Logic deployment

The Sumo Logic region hosting the organization, for example US1 or EU. It is part of the API endpoint shown on the OAuth client page.

Step 1: Create a Service Account in Sumo Logic

An OAuth client acts as a service account. What ContraForce can do is limited both by the service account’s role and by the OAuth client’s scopes, so the role must allow everything the scopes grant.
  1. In Sumo Logic, go to Administration > Account Security Settings > Service Accounts
  2. Create a service account, for example ContraForce
  3. Assign a role that can view alerts, view and manage monitors, and search the log data your monitors query

Step 2: Create the OAuth Client in Sumo Logic

  1. Go to Administration > Account Security Settings > OAuth Clients (classic UI: Administration > Security)
  2. Click Add OAuth Client
  3. Set Client Type to Client Credentials
  4. Set Name to ContraForce and add a description
  5. Set Service Account to the service account from Step 1
  6. Select these four Scopes:
  1. Click Save
Sumo Logic shows the Client ID and Client Secret.
The client secret is shown once and cannot be retrieved later. Copy it to a secure location immediately. If you lose it, create a new OAuth client.
All four scopes are required. The connection test in ContraForce fails if any of them is missing.

Step 3: Configure the Sumo Logic Module in ContraForce

  1. In the ContraForce portal, go to Workspaces > your workspace > Modules
  2. Find the Sumo Logic detection module card and click its settings (gear) icon, Configure Sumo Logic
  3. Fill in these fields:
  1. Click Test connection. The button changes to Connection verified when the credentials, deployment and scopes are all correct
  2. Click Configure and save
The client secret is stored securely and never shown again. To change the configuration later, enter the secret again. If the test fails, see Troubleshooting.

Step 4: Verify End to End

1

Wait for the first check

ContraForce checks Sumo Logic about every 2 minutes. A new monitor alert appears as an incident within a few minutes.
2

Open an incident

Open a Sumo Logic incident. The Rule tab shows the monitor that raised the alert, and the Logs tab shows the log messages that triggered it, fetched from Sumo Logic.
3

Check the Monitors tab

On the Sumo Logic module card, click Monitors, or open Detection Rules for the workspace and select the Sumo Logic Monitors tab. Your monitors should be listed.

Manage Monitors from ContraForce

The Sumo Logic Monitors tab lists the organization’s monitors with their folder path, type, alert levels, status and last change. Open a monitor to see its queries, trigger conditions, notifications and playbook. From an incident, View monitor details on the Rule tab opens the monitor behind the alert. Users with the workspace Owner or Content Admin role can:
  • Enable or disable a monitor
  • Edit a monitor’s name, description, queries and alert thresholds
  • Delete a monitor
Changes are made directly in Sumo Logic. An edit changes only those fields; every other setting, such as notifications and schedules, is kept as it is in Sumo Logic.
Some settings stay in Sumo Logic. Thresholds can be edited for static conditions only. Outlier, anomaly, missing data and SLO conditions are shown but are edited in Sumo Logic. System monitors, and monitors Sumo Logic marks as read-only, cannot be changed from ContraForce.
If someone changes a monitor in Sumo Logic while you are editing it, ContraForce does not overwrite their change. It asks you to reload the monitor and make your edit again.

Limitations

  • Cloud SIEM Insights and Signals are not ingested
  • Response actions: there are no Gamebook response actions for Sumo Logic
  • Log search: there is no ad hoc log search from ContraForce; log messages are shown for the alert that triggered the incident
  • Metrics monitors: incidents from metrics monitors show no log messages
  • Retention: alerts older than 30 days are deleted by Sumo Logic, as described in Alert Retention

Troubleshooting


Incident Management

Triage and resolve incidents in ContraForce

Roles and Permissions

Detailed role reference for ContraForce users

Questions about connecting Sumo Logic to ContraForce? Contact us at support@contraforce.com.