Conversation
…ion into DOCS-1237
|
Hi @kimsauce - Comments include the following:
What to monitorTrack these metrics per request, per identity, and per tool:
Recommended controls
|
@DDeC7 done! |
|
@kimsauce - MCP is closed preview and will be followed by an open/public preview later. |
| hide_table_of_contents: true | ||
| --- | ||
|
|
||
| The Sumo Logic MCP Server, now in closed beta, lets you use Sumo tools for alerts, insights, dashboards, log searches and users in natural language in VS Code and Terminal. |
There was a problem hiding this comment.
| The Sumo Logic MCP Server, now in closed beta, lets you use Sumo tools for alerts, insights, dashboards, log searches and users in natural language in VS Code and Terminal. | |
| The Sumo Logic MCP Server, now in closed beta, lets you use Sumo Logic tools for alerts, insights, dashboards, log searches and users in natural language in VS Code and Terminal. |
|
|
||
| The Sumo Logic MCP Server, now in closed beta, lets you use Sumo tools for alerts, insights, dashboards, log searches and users in natural language in VS Code and Terminal. | ||
|
|
||
| It enables external copilots and proprietary models to securely query logs, investigate SIEM insights, manage alerts and dashboards, and work with existing Dojo AI agents using natural language from IDEs and chat platforms. |
There was a problem hiding this comment.
| It enables external copilots and proprietary models to securely query logs, investigate SIEM insights, manage alerts and dashboards, and work with existing Dojo AI agents using natural language from IDEs and chat platforms. | |
| It enables external copilots and proprietary models to securely query logs, investigate Cloud SIEM insights, manage alerts and dashboards, and work with existing Dojo AI agents using natural language from IDEs and chat platforms. |
| <head> | ||
| <meta name="robots" content="noindex" /> | ||
| </head> | ||
|
|
There was a problem hiding this comment.
| <p><a href={useBaseUrl('docs/beta')}><span className="beta">Beta</span></a></p> | |
There was a problem hiding this comment.
I recommend that you add the beta label.
| cd /path/to/your/project | ||
| claude | ||
| ``` | ||
| 1. In Claude Code, verify the Sumo Logic MCP server connection with `/mcp`.<br/><img src={useBaseUrl('img/platform-services/mcp/claude-mcp-connected.png')} alt="Claude Code CLI showing Sumo Logic MCP server connected" width="600"/> |
There was a problem hiding this comment.
This image is broken because the image is in the /platform-services folder and not in the /platform services/mcp subfolder.
| ] | ||
| } | ||
| ``` | ||
| If you've previously configured other MCP servers here, this should be an additive process (i.e., do not delete existing ones you still intend to use). |
There was a problem hiding this comment.
| If you've previously configured other MCP servers here, this should be an additive process (i.e., do not delete existing ones you still intend to use). | |
| If you've previously configured other MCP servers here, this should be an additive process (that is, do not delete existing ones you still intend to use). |
| `Show me all active alerts from the last 24 hours` | ||
| `Get the history for alert ID <id>` | ||
| `Find alerts related to <id>` | ||
| `Resolve alert <id>` |
There was a problem hiding this comment.
| `Show me all active alerts from the last 24 hours` | |
| `Get the history for alert ID <id>` | |
| `Find alerts related to <id>` | |
| `Resolve alert <id>` | |
| * `Show me all active alerts from the last 24 hours` | |
| * `Get the history for alert ID <id>` | |
| * `Find alerts related to <id>` | |
| * `Resolve alert <id>` |
| `Create a new dashboard called "System Overview" that uses the previous query to power a dashboard panel called "Total Log Count Per Minute"` | ||
| `Add a second panel called "Error Logs Count Per Minute" that is a similar query but only has logs in it that contain the keyword "error" in them` |
There was a problem hiding this comment.
| `Create a new dashboard called "System Overview" that uses the previous query to power a dashboard panel called "Total Log Count Per Minute"` | |
| `Add a second panel called "Error Logs Count Per Minute" that is a similar query but only has logs in it that contain the keyword "error" in them` | |
| * `Create a new dashboard called "System Overview" that uses the previous query to power a dashboard panel called "Total Log Count Per Minute"` | |
| * `Add a second panel called "Error Logs Count Per Minute" that is a similar query but only has logs in it that contain the keyword "error" in them` |
| `Show triage details for INSIGHT-1234` | ||
| `Retrieve the triage details` | ||
| `What are all of the related entities?` | ||
| `Add a comment to this insight: "This warrants deeper investigation"` | ||
| `Show recommended next steps for INSIGHT-1234` | ||
| `Update INSIGHT-1234 status to In Progress` |
There was a problem hiding this comment.
| `Show triage details for INSIGHT-1234` | |
| `Retrieve the triage details` | |
| `What are all of the related entities?` | |
| `Add a comment to this insight: "This warrants deeper investigation"` | |
| `Show recommended next steps for INSIGHT-1234` | |
| `Update INSIGHT-1234 status to In Progress` | |
| * `Show triage details for INSIGHT-1234` | |
| * `Retrieve the triage details` | |
| * `What are all of the related entities?` | |
| * `Add a comment to this insight: "This warrants deeper investigation"` | |
| * `Show recommended next steps for INSIGHT-1234` | |
| * `Update INSIGHT-1234 status to In Progress` |
| `Run a log search for the last 5 minutes across all of my data that counts the data by 1-minute buckets and plots the result as a line graph` | ||
| `Run a 2-day search on _sourcecategory=*proofpoint*, count by recipient and senderip` |
There was a problem hiding this comment.
| `Run a log search for the last 5 minutes across all of my data that counts the data by 1-minute buckets and plots the result as a line graph` | |
| `Run a 2-day search on _sourcecategory=*proofpoint*, count by recipient and senderip` | |
| * `Run a log search for the last 5 minutes across all of my data that counts the data by 1-minute buckets and plots the result as a line graph` | |
| * `Run a 2-day search on _sourcecategory=*proofpoint*, count by recipient and senderip` |
| `List the users in my org and format as an ASCII table` | ||
| `Show users who have never logged in` | ||
| `Delete those users` | ||
| `List all users and their roles` |
There was a problem hiding this comment.
| `List the users in my org and format as an ASCII table` | |
| `Show users who have never logged in` | |
| `Delete those users` | |
| `List all users and their roles` | |
| * `List the users in my org and format as an ASCII table` | |
| * `Show users who have never logged in` | |
| * `Delete those users` | |
| * `List all users and their roles` |
Purpose of this pull request
Pending SME approval from MCP team - do not merge.
External MCP server - Closed Beta. Est. publish: week of 2/23.
Select the type of change
Ticket (if applicable)
https://sumologic.atlassian.net/browse/DOCS-1237