Prerequisites
- A Sumo Logic account and its deployment.
- The Create Access Keys role capability, or Manage Access Keys when an administrator creates the key for another account.
- A user or service account whose roles allow the six read scopes listed under Required permissions.
- A Cloud SIEM plan and role capabilities only if agents need to inspect Cloud SIEM insights.
Setup
1
Open Access Keys
Sign in to Sumo Logic. In the new UI, go to Administration → Account Security Settings → Access Keys. In the classic UI, go to Administration → Security → Access Keys. See Sumo Logic Access Keys for details.
2
Create a read-only key
Click + Add Access Key, name the key
cloudthinker, and set Scopes to Custom. Select exactly these scopes: runLogSearch, viewCollectors, viewFields, viewMonitorsV2, viewPartitions, and viewPersonalAccessKeys.Click Save, then copy the Access ID and Access Key before closing the dialog. Sumo Logic shows them only once.3
Add the connection in CloudThinker
Navigate to Connections → Sumo Logic and enter:
- Access ID: the generated Access ID
- Access Key: the generated Access Key
- Deployment: the deployment that matches your Sumo Logic sign-in URL
Connection details
CloudThinker supports these deployment choices:
Use Sumo Logic’s API endpoint guide to identify the deployment from your account URL. The key works only in the deployment where it was created.
Required permissions
The Access Key must contain exactly these assigned scopes and no others:runLogSearchviewCollectorsviewFieldsviewMonitorsV2viewPartitionsviewPersonalAccessKeys
Agent capabilities
This connection is read-only. Log searches create temporary search-job state and remove it after collecting the result.
Verify the connection
Example prompts
Troubleshooting
Scope verification fails
Scope verification fails
Recreate the key with exactly the six required scopes. If an effective scope is missing, grant the owner the matching role capability, then test again.
403 Forbidden on a Sumo Logic resource
403 Forbidden on a Sumo Logic resource
The credentials are valid, but the key owner’s roles do not allow that resource. Ask a Sumo Logic administrator to grant the matching View capability. A permission error does not mean the account has no data.
429 rate limit exceeded
429 rate limit exceeded
Sumo Logic limits API requests. Wait, then retry one focused request with a short time window instead of running several broad searches at once.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Exact read scope: keep both assigned and effective scopes limited to the six required values. CloudThinker refuses broader keys.
- Credential lifecycle: use Sumo Logic’s rotate or delete controls, then update or remove the CloudThinker connection.
Related
Coralogix Connection
Log search, metrics, traces, and incident triage
Datadog Connection
Logs, metrics, infrastructure, and incidents