SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Sumo Logic unveils new AI tools for security teams

Sumo Logic unveils new AI tools for security teams

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Sumo Logic has launched new and expanded agentic AI tools for security and cloud operations teams, extending its AI features across security and observability workflows.

The additions include the Sumo Logic SOC Analyst Agent, an MCP Server, and an updated version of Mobot, the company's conversational interface. The tools are intended to turn telemetry data into signals and insights that analysts can use in investigations and operational troubleshooting.

Sumo Logic is positioning telemetry as the foundation for trustworthy AI in security operations. It argues that using large language models directly on raw log data can produce unreliable answers and increase computing costs unless the data is first normalised, correlated, and enriched.

Jeremy Powell, Chief Information Security Officer at Sumo Logic, said the company has also applied this approach in its own security operations centre.

"We believe that telemetry is the fuel of the AI future," said Jeremy Powell, Chief Information Security Officer at Sumo Logic. "Every threat detection, investigation, and response traces back to telemetry. As AI agents become an increasingly valuable tool for security operations, telemetry is the source of truth that separates a confident answer from an educated guess. We're seeing this in our own SOC. By building from trusted telemetry from Sumo Logic Dojo AI, we were able to reduce MTTR by 64% and save 25 hours per week per analyst."

Product changes

The SOC Analyst Agent is now generally available. It automatically investigates SIEM alerts, produces evidence-backed verdicts, and lets staff continue an investigation through Mobot.

Mobot has been updated with multi-turn interactions intended to support longer tasks. The revised interface can also help users create and edit playbooks and other content through conversational prompts.

Another addition is conversational playbooks. This feature allows users to describe a workflow in plain language and receive a drafted playbook without building it step by step.

Sumo Logic has also introduced a Log Analysis Agent, intended to guide users from an initial business question to a defensible answer. The tool is aimed at analysts with varying skill levels and goes beyond query writing to support investigations and content management through Mobot.

A Platform Optimization Agent has also been added to help users and administrators troubleshoot issues, tune deployments, and manage configuration tasks through the same interface.

Governed access

The new MCP Server is designed to let users connect external tools, including Claude Code and GitHub Copilot, to Sumo Logic SIEM and log analytics. Access is handled through a governed set of API tools rather than custom integrations or direct exposure to raw data.

The announcement reflects a wider push by software suppliers to embed AI agents into cyber security and IT operations products while addressing concerns over accuracy, oversight, and cost. In security environments, in particular, vendors face pressure to show that AI-generated outputs can be traced back to source data and reviewed by human analysts.

Sumo Logic cited a customer survey that found 68% of respondents only partially trust AI-created results and still require human oversight. Accuracy and explainability remain central issues for teams assessing whether AI systems can be used reliably in investigations and incident response.

The company's approach rests on its broader platform architecture, including its data lake, SIEM, and context layer. These components prepare telemetry so autonomous tools can identify and resolve issues more quickly, and with more reliable context, than systems that rely on raw logs alone.

The latest release brings those functions together across security and observability use cases, reflecting the growing overlap between cyber defence and cloud operations. As organisations manage sprawling application estates and rising volumes of machine data, suppliers are trying to reduce the manual work involved in triage, investigation, and remediation.

For Sumo Logic, the pitch is that analysts remain in control while software takes on more repetitive investigation work. In its own internal operations, the company said, this reduced mean time to resolution by nearly two-thirds and saved more than 25 hours a week for each analyst.