SIEM Integration - Sumo Logic

This article will show the steps required to pair your Sumo Logic instance with Sharetru.

Note: Do not toggle the Enable to "on" until you have filled out the form illustrated below and completed a test of the connection.

Use the SIEM "Select Service..." dropdown and select Sumo Logic.

image-20240724-202159

Sumo Logic has one format: RFC-5424:
image-20240724-202615

To view an example of the SIEM test message click the link button.
image-20240724-202714

Copy all fields (token, host, and TCP TLS Port) and paste into Notepad or similar:
image-20240725-214512

 Sumo Logic uses the TLS protocol with hostname or IP address, and the port:
image-20240724-203113

Login to Sumo Logic instance and find Collection tab:

 image-20240724-144803
 

Then, click on “Show Token”

image-20240724-144834



Enter the Authorization Token:
image-20240725-214745

After the form is completed click "Save".

image-20240715-201420

Now, you will need to test the connection. Click the "Test Connection" button.
image-20240715-201448


If the connection is successful you will receive a message verifying that result.
siemtestsuccess

*You should verify that the message was received by your Sumo Logic instance. *

However, if the connection is not successful you will receive a message regarding the failure. 

Upon successfully completing the test you may toggle the "Enable" switch on and then click "Save".

This will finalize the SIEM integration set up.image-20240715-203324

 

image-20240725-215353