Introducing the Sumo Logic detection module: their monitors, your queue
Reviewed by ContraForce team ยท Updated 2026-10-01
Your delivery runs on Microsoft. Then you win a client whose detection runs in Sumo Logic: monitors their team built and tuned, raising alerts that someone has to work. Their Sumo Logic stays.
Until now that meant running them a second way. Their alerts sit in a console your team does not live in, ownership gets agreed in a chat thread, and every alert is closed in two places. Every alert that lives outside your queue is one your team has to remember to check.
The Sumo Logic detection module changes that for their alerts. Take the client as they are. They keep Sumo Logic and the monitors they rely on. You keep one queue: their monitor alerts arrive in ContraForce as incidents, next to the rest of your book, while Sumo Logic keeps doing detection. That covers the alert work, not the whole delivery, and only monitor alerts. Cloud SIEM Insights and Signals are not ingested, so detections that live in Cloud SIEM stay in Sumo Logic. The module runs on any Sumo Logic plan that has monitors.
One queue and one record for their monitor alerts
ContraForce checks Sumo Logic for new monitor alerts about every two minutes and opens a ContraForce incident for each one. Your team picks it up in the same place it picks up everything else. The incident shows the monitor that raised the alert and the log messages that triggered it, pulled from Sumo Logic each time you open it, so nobody signs in to a second console to see why a log monitor fired.
The incident also carries the delivery work around the alert. Someone owns it. Comments go on it. It moves between New and In Progress, and its status, classification, owner, comments and audit trail are recorded in ContraForce, where everyone who can see the incident sees them. When that client asks who owned an alert and what was decided, the answer is on the incident, and it stays there after Sumo Logic deletes the alert. Apart from closing, none of it is written back to Sumo Logic, so anyone working from the Sumo Logic console will not see who owns an alert or what was said about it.
Close it in one place
Close the incident and ContraForce resolves the alert in Sumo Logic. When the monitor recovers and Sumo Logic resolves the alert on its own, the ContraForce incident closes too. Nobody has to remember to close the same alert in a second tool.
Both directions have an edge. Resolving in Sumo Logic is best effort: if Sumo Logic cannot be reached, or the alert no longer exists there, the incident still closes in ContraForce and the alert may need resolving by hand. And because recovery closes the incident, a monitor that recovers while your team is still looking will close it underneath them. Reopening happens in ContraForce only.
Tune their monitors from the incident
When an alert is noise, the fix is in the monitor. The monitor is reachable from the incident it raised, and the client's Sumo Logic monitors are listed in their own tab on the workspace's detection rules page, with their type, alert levels and status.
Workspace Owners and Content Admins can enable, disable or delete a monitor there, and edit its name, description, queries and alert thresholds. Changes are written straight to Sumo Logic, so disabling or deleting a monitor here does it for the client's own team too. Everything else, notifications and schedules included, stays as it is set in Sumo Logic. Thresholds are editable for static conditions only, and system or read-only monitors cannot be changed from ContraForce. If someone edits the same monitor in Sumo Logic while you are editing it, ContraForce does not overwrite their work. It asks you to reload and make your edit again.
What connecting takes
The client's logs stay in Sumo Logic. ContraForce fetches the log messages behind an alert each time the incident is opened, and does not keep a copy of the alert or its logs. Each connection links one ContraForce workspace to one Sumo Logic organization, set up by someone with the Sumo Logic Administrator role in that organization: a service account, an OAuth client for it, and the region the organization is hosted in. A workspace Owner enters the client ID and secret in ContraForce and tests the connection.
Raise two things early with the client's security team. The OAuth client needs all four scopes, including manage monitors, which ContraForce also uses to resolve alerts, so there is no read-only setup and the connection test fails if a scope is missing. And the service account's role caps what the scopes allow: if it cannot search a monitor's data, that monitor's incidents show no log messages.
What does the module not do?
It does not ingest Cloud SIEM Insights or Signals. There are no Gamebook response actions for Sumo Logic, and there is no ad hoc log search from ContraForce: you see the log messages behind the alert that opened the incident, and incidents from metrics monitors show none at all. Outlier, anomaly, missing data and SLO conditions are shown in ContraForce but edited in Sumo Logic.
Sumo Logic deletes monitor alerts 30 days after they are created, and ContraForce does not keep a copy of the alert or its logs. After that the incident shows a No longer retained in Sumo Logic notice. What your team recorded stays: status, classification, owner, comments and the audit trail.
Start with one client
If you have more than one Sumo Logic client, start with the one your team looks at least often. Look at what their monitors fire on first, because every new monitor alert in that organization will open an incident. Then connect the module from the workspace's Modules page, wait for the next alert, and open the incident. If the monitor and the logs that triggered it are there, that client's monitor alerts are in your queue, not in a console someone has to remember to check.
The step-by-step setup, the sync rules and troubleshooting are in the Sumo Logic Detection Module guide.
Questions about connecting Sumo Logic to ContraForce? Contact us at support@contraforce.com.
What is "Introducing the Sumo Logic detection module: their monitors, your queue" about?
Take on the client who runs Sumo Logic as they are. The Sumo Logic detection module brings their monitor alerts into ContraForce as incidents, next to the rest of your book, with the monitor and the logs that triggered it in view.