Sumo Logic Integration Guide

Sumo Logic provides rich query and aggregation capabilities for analyzing vast amounts of log data, helping you to more rapidly troubleshoot critical infrastructure failures and complex application issues. Sumo Logic can also be configured to trigger alerts in PagerDuty based on scheduled searches, so you can react even faster.  Using PagerDuty, you can ensure that the right person is alerted via phone call, SMS, push notification, or email.

If you would like to use the previous integration, click here to access the Sumo Logic email integration guide.

In PagerDuty

  1. Go to the Configuration menu and select Services.
  2. On the Services page:
    • If you are creating a new service for your integration, click Add New Service.
    • If you are adding your integration to an existing service, click the name of the service you want to add the integration to. Then click the Integrations tab and click the New Integration button.
  3. In the Integration Type menu, select from the following based on your preference:
    1. Select Tool: Search and select Sumo Logic.
    2. Use our API directly: You may also integrate by selecting Events API v2 (recommended) or Events API v1.
  4. Enter an Integration Name. If you are creating a new service for your integration, in General Settings, enter a Name for your new service. Then, in Incident Settings, specify the Escalation Policy, Notification Urgency, and Incident Behavior for your new service.
  5. Click the Add Service or Add Integration button to save your new integration. You will be redirected to the Integrations page for your service.
  6. Copy the Integration Key for your new integration.

In Sumo Logic

  1. Select Manage Data > Settings > Connections.
  2. Click + to add a new connection.
  3. Click PagerDuty
  4. To configure the PagerDuty Connection:
    1. Enter in a Name for the connection.
    2. In the URL, enter in:
    3. In the Payload, keep everything there, except, where it says “SERVICE KEY”, paste in the integration key you previously copied from PagerDuty.
    4. In the Payload for the description, you will want to specify the description you want sent to PagerDuty.
    5. Click Save.
  5. Next, you will need to create a search, in the search field, that will send events to PagerDuty to create incidents.
  6. After entering in your search criteria, click Save As.
  7. Enter in a name for your search.
  8. Click on Schedule this search > to specify the conditions under which you’d like it to trigger an incident.
  9. Pick a Run frequency. For example, 15 minutes.
  10. Click Save.
  11. Set your additional settings for your scheduled search:
    1. Time range for schedule search: Last 60 minutes
    2. Send notification only if the condition below is satisfied: Number of results Greater than or equal to >= 0.
    3. Alert Type: select Webhook
    4. In the Webhook field, select the webhook we just created (you will see the payload with the integration key appear).
    5. Click Save.

Congrats! You have completed the integration with PagerDuty and Sumo Logic! When an event is sent to PagerDuty and an incident is created there will be a link to view that incident in Sumo Logic.


Can I integrate Sumo Logic with multiple PagerDuty services?

Yes you can! Just follow the integration guide again as many times as you would like!

Start Using PagerDuty Today

Try PagerDuty free for 14 days — no credit card required.