> ## Documentation Index
> Fetch the complete documentation index at: https://docs.contraforce.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sumo Logic Detection Module

> Connect Sumo Logic to a ContraForce workspace to investigate monitor alerts as incidents and manage the monitors that raise them.

<Info>
  **Who is this for?** Workspace Admins or Security Engineers who manage a workspace that uses Sumo Logic. This guide walks you through creating a Sumo Logic service account and OAuth client, configuring the module in ContraForce, and verifying that alerts flow end to end.
</Info>

## Before You Begin

### What This Module Does

The Sumo Logic Detection module connects a ContraForce workspace to a Sumo Logic organization:

<CardGroup cols={2}>
  <Card title="Incidents" icon="magnifying-glass">
    **Monitor alerts become incidents**

    * Checks Sumo Logic for new monitor alerts about every 2 minutes
    * Creates a ContraForce incident for each alert
    * Shows the monitor behind each alert and the log messages that triggered it
    * Resolves the alert in Sumo Logic when you close the incident in ContraForce
  </Card>

  <Card title="Monitors" icon="sliders">
    **Manage the monitors that raise alerts**

    * Lists the organization's monitors on the workspace **Detection Rules** page
    * Shows each monitor's queries, trigger conditions, notifications and playbook
    * Enables, disables, edits and deletes monitors from ContraForce
  </Card>
</CardGroup>

<Note>
  **This module works with Sumo Logic monitors, not Cloud SIEM.** A ContraForce incident is a Sumo Logic monitor alert. Cloud SIEM Insights and Signals are not ingested, so the module works on any Sumo Logic plan that has monitors.
</Note>

### What Syncs and What Stays in ContraForce

| Action | Where it applies |
| - | - |
| **Close** an incident in ContraForce | ContraForce, and the alert is resolved in Sumo Logic |
| Sumo Logic **auto-resolves** an alert | The ContraForce incident closes |
| Set an incident to **New** or **In Progress**, or **reopen** it | ContraForce only |
| Assign an **owner** | ContraForce only |
| Add a **comment** | ContraForce only |

Sumo Logic monitor alerts have no assignee, comments or in-progress state, so those are recorded in ContraForce, where everyone who can see the incident sees them. Sumo Logic resolves an alert on its own when the monitor's recovery condition is met, and the ContraForce incident follows.

<Note>
  **Closing is best effort in Sumo Logic.** If Sumo Logic cannot be reached, or the alert no longer exists there, the incident still closes in ContraForce. Reopening an incident in ContraForce does not reopen the alert in Sumo Logic.
</Note>

### Alert Retention

Sumo Logic deletes monitor alerts 30 days after they are created, and ContraForce does not keep a copy of the alert or its logs. The log messages behind an alert are fetched from Sumo Logic each time you open the incident. After 30 days, the incident shows a **No longer retained in Sumo Logic** notice, and the status, classification, owner, comments and audit trail recorded in ContraForce are still shown.

### Prerequisites

<Steps>
  <Step title="Sumo Logic monitors">
    A Sumo Logic organization with the monitors you want ContraForce to track.
  </Step>

  <Step title="Sumo Logic administrator access">
    The Sumo Logic **Administrator** role, which is required to create service accounts and OAuth clients.
  </Step>

  <Step title="ContraForce workspace">
    A ContraForce workspace for the organization, with your account assigned the workspace **Owner** role.
  </Step>

  <Step title="Your Sumo Logic deployment">
    The Sumo Logic region hosting the organization, for example **US1** or **EU**. It is part of the API endpoint shown on the OAuth client page.
  </Step>
</Steps>

***

## Step 1: Create a Service Account in Sumo Logic

An OAuth client acts as a service account. What ContraForce can do is limited both by the service account's role and by the OAuth client's scopes, so the role must allow everything the scopes grant.

1. In Sumo Logic, go to **Administration > Account Security Settings > Service Accounts**
2. Create a service account, for example `ContraForce`
3. Assign a role that can view alerts, view and manage monitors, and search the log data your monitors query

***

## Step 2: Create the OAuth Client in Sumo Logic

1. Go to **Administration > Account Security Settings > OAuth Clients** (classic UI: **Administration > Security**)
2. Click **Add OAuth Client**
3. Set **Client Type** to **Client Credentials**
4. Set **Name** to `ContraForce` and add a description
5. Set **Service Account** to the service account from Step 1
6. Select these four **Scopes**:

| Scope | Why ContraForce needs it |
| - | - |
| **View Alerts** (`viewAlerts`) | Ingest monitor alerts as incidents |
| **View Monitors** (`viewMonitorsV2`) | Read the monitor behind each alert |
| **Run Log Search** (`runLogSearch`) | Fetch the log messages that triggered each alert |
| **Manage Monitors** (`manageMonitorsV2`) | Manage monitors from the Monitors tab, and resolve alerts when an incident is closed |

1. Click **Save**

Sumo Logic shows the **Client ID** and **Client Secret**.

<Warning>
  The client secret is shown once and cannot be retrieved later. Copy it to a secure location immediately. If you lose it, create a new OAuth client.
</Warning>

<Info>
  All four scopes are required. The connection test in ContraForce fails if any of them is missing.
</Info>

***

## Step 3: Configure the Sumo Logic Module in ContraForce

1. In the ContraForce portal, go to **Workspaces** > your workspace > **Modules**
2. Find the **Sumo Logic** detection module card and click its settings (gear) icon, **Configure Sumo Logic**
3. Fill in these fields:

| Field | Value |
| - | - |
| **Deployment** | The Sumo Logic region hosting your organization, for example **US1 (US East)** |
| **Client ID** | The client ID from Step 2 |
| **Client secret** | The client secret from Step 2 |

1. Click **Test connection**. The button changes to **Connection verified** when the credentials, deployment and scopes are all correct
2. Click **Configure and save**

The client secret is stored securely and never shown again. To change the configuration later, enter the secret again.

If the test fails, see [Troubleshooting](#troubleshooting).

***

## Step 4: Verify End to End

<Steps>
  <Step title="Wait for the first check">
    ContraForce checks Sumo Logic about every 2 minutes. A new monitor alert appears as an incident within a few minutes.
  </Step>

  <Step title="Open an incident">
    Open a Sumo Logic incident. The **Rule** tab shows the monitor that raised the alert, and the **Logs** tab shows the log messages that triggered it, fetched from Sumo Logic.
  </Step>

  <Step title="Check the Monitors tab">
    On the **Sumo Logic** module card, click **Monitors**, or open **Detection Rules** for the workspace and select the **Sumo Logic Monitors** tab. Your monitors should be listed.
  </Step>
</Steps>

***

## Manage Monitors from ContraForce

The **Sumo Logic Monitors** tab lists the organization's monitors with their folder path, type, alert levels, status and last change. Open a monitor to see its queries, trigger conditions, notifications and playbook. From an incident, **View monitor details** on the **Rule** tab opens the monitor behind the alert.

Users with the workspace **Owner** or **Content Admin** role can:

* **Enable** or **disable** a monitor
* **Edit** a monitor's name, description, queries and alert thresholds
* **Delete** a monitor

Changes are made directly in Sumo Logic. An edit changes only those fields; every other setting, such as notifications and schedules, is kept as it is in Sumo Logic.

<Note>
  **Some settings stay in Sumo Logic.** Thresholds can be edited for static conditions only. Outlier, anomaly, missing data and SLO conditions are shown but are edited in Sumo Logic. System monitors, and monitors Sumo Logic marks as read-only, cannot be changed from ContraForce.
</Note>

If someone changes a monitor in Sumo Logic while you are editing it, ContraForce does not overwrite their change. It asks you to reload the monitor and make your edit again.

***

## Limitations

* **Cloud SIEM** Insights and Signals are not ingested
* **Response actions**: there are no Gamebook response actions for Sumo Logic
* **Log search**: there is no ad hoc log search from ContraForce; log messages are shown for the alert that triggered the incident
* **Metrics monitors**: incidents from metrics monitors show no log messages
* **Retention**: alerts older than 30 days are deleted by Sumo Logic, as described in [Alert Retention](#alert-retention)

***

## Troubleshooting

| Issue | Likely cause | Fix |
| - | - | - |
| Test connection: Sumo Logic rejected the client ID and secret | The client ID or secret is wrong, or the **Deployment** is not the one your organization is hosted in | Check both values, and confirm the deployment matches your organization's region |
| Test connection: not hosted in the selected deployment | The wrong **Deployment** is selected | Select the region shown in the API endpoint on the OAuth client page |
| Test connection: missing required scopes | The OAuth client lacks one of the four scopes | Create a new OAuth client with all four scopes and enter its client ID and secret |
| Test connection: denied access to monitor alerts | The service account's role cannot view alerts | Give the service account's role permission to view alerts |
| No incidents appear after 15 minutes | No monitor alerts have fired since the module was configured | Confirm in Sumo Logic that a monitor has triggered an alert recently |
| An incident shows no log messages | The alert is from a metrics monitor, is older than 30 days, or the service account cannot search the monitor's data | Check the monitor type and alert age, and the service account's data access |
| The Monitors tab says access was denied | Your workspace role cannot manage monitors, or Sumo Logic refused the request | Follow the message shown. For a Sumo Logic refusal, add the missing scopes to the OAuth client and test the connection again |
| A closed incident's alert is still open in Sumo Logic | Resolving in Sumo Logic is best effort | Resolve the alert in Sumo Logic. The incident stays closed in ContraForce |

***

## Related Documentation

<CardGroup cols={2}>
  <Card title="Incident Management" icon="book" href="/guides/getting-started/incident-management">
    Triage and resolve incidents in ContraForce
  </Card>

  <Card title="Roles and Permissions" icon="users" href="/guides/general-support/roles-and-permissions-reference">
    Detailed role reference for ContraForce users
  </Card>
</CardGroup>

***

<Note>
  Questions about connecting Sumo Logic to ContraForce? Contact us at [support@contraforce.com](mailto:support@contraforce.com).
</Note>
