Sumo Logic Email Integration Guide

Sumo Logic provides rich query and aggregation capabilities for analyzing vast amounts of log data, helping you to more rapidly troubleshoot critical infrastructure failures and complex application issues. Sumo Logic can also be configured to trigger alerts in PagerDuty based on scheduled searches, so you can react even faster.  Using PagerDuty, you can ensure that the right person is alerted via phone call, SMS, push notification, or email.

Click here to access the generic API Sumo Logic integration guide. 

In PagerDuty

  1. From the Configuration menu, select Services.

  2. On your Services page:

    If you are creating a new service for your integration, click +Add New Service.

    If you are adding your integration to an existing service, click the name of the service you want to add the integration to. Then click the Integrations tab and click the +New Integration button.

    RS-Add-New-Service

    RS-Add-Integration-Existing-Service

  3. Select your app from the Integration Type menu and enter an Integration Name.

    If you are creating a new service for your integration, in General Settings, enter a Name for your new service. Then, in Incident Settings, specify the Escalation Policy, Notification Urgency, and Incident Behavior for your new service.

  4. Click the Add Service or Add Integration button to save your new integration. You will be redirected to the Integrations page for your service.

    RS-Integration-Settings

  5. Copy the Integration Email for your new integration: RS_email_pd_3

In Sumo Logic:

  1. Open an existing search or create a new search.
  2. Choose Save As in order to save that search as a scheduled search.
    SL-SaveSearch
  3. Under Schedule, change the Run frequency to something other than Never, choose a logical Timerange for the search, and set the Recipient to be the Integration Email from the previous steps.  Then, change the Alert condition to Send notification only if the condition below is satisfied and define an appropriate threshold to alert on.  Click Save.
    SL-ScheduleSearch
  4. You’re done!  Emails from Sumo Logic will now be able to trigger incidents in PagerDuty, providing rich information in the body related to your search and a link back to Sumo Logic to view the full result set.

FAQ

Does this support auto-resolution of PagerDuty incidents?

No. Email actions from Sumo Logic can only be used to trigger PagerDuty incidents.

Can I point multiple Sumo Logic scheduled searches at the same PagerDuty service?

Yes. Simply repeat the steps above in Sumo Logic for a different search.

Can I create a second PagerDuty Service for the same Sumo Logic search?

Yes. Simply repeat the steps above in PagerDuty to create another email integration, then append that email address to your scheduled search as an additional Recipient.

Is there an alternative to using email integration?

Yes. Sumo Logic Script Actions can be configured to trigger and even resolve incidents using the PagerDuty API.  Note that your incident resolution logic will depend on the search and the related thresholds you choose, similar to Alert condition above.  Since this is highly customized, it is up to you to define the proper script to match your alerting scenario.