Sumo Logic Integration Guide
Sumo Logic is industry's leading, secure, cloud-based service for logs & metrics management for modern apps, providing real-time analytics and insights.
What can Xurrent IMR do for Sumo Logic users?
With Sumo Logic's Integration, Xurrent IMR sends new Sumo Logic alerts to the right team and notifies them based on on-call schedules via email, text messages(SMS), phone calls(Voice), Slack, Microsoft Teams and iOS & Android push notifications, and escalates alerts until the alert is acknowledged or closed. Xurrent IMR provides your NOC, SRE and application engineers with detailed context around the Sumo Logic alert along with playbooks and a complete incident command framework to triage, remediate and resolve incidents with speed.
Whenever Sumo Logic triggers an alert based on a predefined condition, Xurrent IMR will create an incident. When that condition goes back to normal levels, Xurrent IMR will auto-resolve the incident.
You can also use Alert Rules to custom route specific Sumo Logic alerts to specific users, teams or escalation policies, write suppression rules, auto add notes, responders and incident tasks.
To integrate Sumologic with Xurrent IMR, complete the following steps:
In Xurrent IMR:
- To add a new Sumologic integration, go to Teams on Xurrent IMR and click on the team you want to add the integration to.
- Next, go to Services and click on the relevant Service.
- Go to Integrations and then Add New Integration. Give it a name and select the application Sumologic from the dropdown menu.
- Go to Configure under your integrations and copy the webhooks URL generated.
In Sumologic:
- After logging in, go to Manage Data -> Monitoring -> Connections tab.
- Click the + button at the top right of the screen to add a webhook.

- In the URL field, add the Webhook URL copied from before.
- In the payload section, paste the following:
- To auto resolve the incident on Xurrent IMR when it got resolved on Sumologic paste the below JSON object Under Recovery Payload:
- Click on Save.
- Go to the SumoLogic Scheduled Search screen. Click on Save as under your Search query. In the Save Search As section, enter a name for the search.
- Click Schedule this search.
- Choose an option from the Run Frequency menu.
- For Alert Type, choose Webhook. Select Xurrent IMR.
- Click on Save.
And that's it! The rules should trigger alerts which will then be visible on the Xurrent IMR incidents page.
