At Black Hat USA, Sumo Logic unveiled a series of agentic AI enhancements designed to help security and cloud operations teams automate investigations and extract actionable insights from enterprise telemetry. The update introduces the general availability of the SOC Analyst Agent, a new Model Context Protocol (MCP) Server, and an upgraded version of its conversational assistant, Mobot. Together, the new capabilities reflect the growing industry focus on AI agents that operate on trusted operational data rather than relying solely on large language models (LLMs).
Artificial intelligence is rapidly changing how enterprise security and IT operations teams investigate incidents, but questions around trust, explainability, and data quality continue to shape adoption. Sumo Logic is addressing those concerns with new agentic AI capabilities that place operational telemetry at the center of AI-powered security workflows.
Announced at Black Hat USA, the company’s latest updates extend its Intelligent Operations Platform with autonomous investigation, conversational workflow automation, and broader integrations for enterprise development tools. The release is aimed at organizations looking to accelerate security operations without sacrificing analyst oversight.
Rather than positioning large language models as standalone decision-makers, Sumo Logic’s approach emphasizes the use of normalized and enriched telemetry as the foundation for AI-driven investigations. The company argues that contextual operational data enables AI agents to deliver more accurate and explainable outcomes than systems that analyze raw log data alone.
Building AI Agents Around Enterprise Telemetry
Telemetry—including logs, metrics, traces, and security events—has become a critical data source for modern Security Information and Event Management (SIEM) platforms and observability solutions. As enterprises deploy more AI applications across cloud environments, the volume of operational data continues to grow, increasing the complexity of incident detection and response.
Sumo Logic’s latest enhancements are built on its Dojo AI platform, which processes telemetry through a secure data lake, SIEM, and contextual intelligence layer before exposing it to AI agents. By normalizing, correlating, and enriching operational data, the platform is designed to provide AI systems with structured context that supports more reliable investigations.
The company says this approach helps reduce unnecessary AI processing costs while improving the quality of recommendations generated by autonomous agents.
New Agentic AI Capabilities
The centerpiece of the release is the SOC Analyst Agent, now generally available, which automatically investigates security alerts, correlates evidence, and produces evidence-backed findings before escalating incidents to analysts. Rather than replacing human decision-making, the agent is intended to shorten investigation times while maintaining human validation for critical security actions.
Sumo Logic also introduced an enhanced version of Mobot, its conversational AI assistant. The updated interface supports multi-turn conversations that allow analysts to iteratively investigate incidents, build automation workflows, and manage operational content through natural language interactions.
Among its new capabilities are Conversational Playbooks, enabling users to describe security workflows in plain language and automatically generate draft playbooks without manually configuring each workflow step. The feature aims to simplify automation for security teams with varying levels of technical expertise.
The platform also adds a Log Analysis Agent, which assists users in translating business questions into structured log investigations. Instead of only generating search queries, the agent guides analysts through investigation workflows and content management.
A Platform Optimization Agent has also been introduced to help administrators troubleshoot deployments, optimize platform configurations, and improve operational efficiency through conversational interactions.
Expanding AI Interoperability with MCP
One of the most significant announcements is the launch of the Sumo Logic MCP Server, which adopts the emerging Model Context Protocol (MCP) for AI interoperability.
The MCP Server enables enterprise developers to connect AI coding assistants and productivity tools—including Anthropic’s Claude Code and GitHub Copilot—to Sumo Logic’s SIEM and Log Analytics services through governed APIs. Rather than exposing raw operational data, the platform provides contextual access designed to improve security and governance.
MCP is gaining traction as an open standard for connecting AI models with enterprise applications, allowing organizations to extend AI capabilities while maintaining tighter control over data access and compliance requirements.
Trust Remains Central to Enterprise AI Adoption
The announcement comes as enterprises continue to evaluate how AI can be safely integrated into security operations.
According to a customer survey conducted by Sumo Logic, 68% of respondents said they only partially trust AI-generated results and still require a human reviewer before taking action. Respondents also identified explainability and accuracy as essential requirements for production AI systems.
These findings align with broader market research. Gartner has identified AI trust, governance, and risk management as key priorities for enterprise adoption, while McKinsey & Company reports that organizations are increasingly investing in AI systems capable of augmenting human expertise rather than operating independently.
Within its own security operations center, Sumo Logic says its AI-assisted workflows have reduced mean time to resolution (MTTR) by 64% while saving approximately 25 analyst hours per week, illustrating how AI agents are increasingly being positioned as productivity tools rather than autonomous replacements for security professionals.
As enterprise AI adoption accelerates, vendors are shifting their focus from simply integrating LLMs into existing platforms toward building intelligent operational systems grounded in trusted enterprise data. Sumo Logic’s latest platform enhancements underscore a growing industry consensus: the effectiveness of agentic AI depends not only on model capabilities, but also on the quality, governance, and contextual understanding of the telemetry that powers them.
Market Landscape
The market for AI-powered security operations is evolving from conversational assistants to autonomous AI agents capable of investigation, workflow automation, and operational decision support. Gartner expects AI-enhanced SecOps and observability platforms to become increasingly central to enterprise cyber resilience strategies, while IDC forecasts continued growth in AI-driven observability and security analytics. At the same time, organizations are emphasizing trustworthy AI, with vendors including Microsoft, Google, Amazon Web Services, Salesforce, and Anthropic investing in governance frameworks, contextual AI architectures, and interoperable standards such as Model Context Protocol (MCP).
Top Insights
- Sumo Logic introduced new agentic AI capabilities that automate security investigations and observability workflows while keeping human analysts involved in critical decisions.
- The general availability of the SOC Analyst Agent enables automated SIEM alert investigations with evidence-backed findings, helping reduce response times and analyst workloads.
- The new MCP Server connects enterprise AI tools such as Claude Code and GitHub Copilot to Sumo Logic through governed APIs, improving interoperability and data governance.
- Enhanced Mobot capabilities allow users to generate security playbooks, conduct guided log analysis, and optimize platform configurations using conversational AI.
- The company’s AI strategy emphasizes trusted telemetry as the foundation for explainable and reliable enterprise AI operations, addressing growing concerns around AI accuracy and governance.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












