Skip to main content
2026

Accelerating security analytics using Amazon Nova with Sumo Logic

Learn how security solutions provider Sumo Logic built an AI assistant by using Amazon Nova 2 Lite and Amazon Bedrock.

Benefits

20%
latency improvement
24%
cost reduction

Overview

Security solutions provider Sumo Logic wanted to differentiate itself by creating an AI-powered experience that would make complex security analysis accessible to analysts at almost any skill level. The company needed an AI assistant that could answer natural language queries, process massive datasets with high accuracy, and deliver actionable insights in near real time. By building its solution on Amazon Web Services (AWS), Sumo Logic reduced costs and strengthened its position as an innovator in AI-driven security analytics.

About Sumo Logic

Founded in 2010, Sumo Logic provides a cloud-scale solution for log analytics, security information, and event management to help organizations keep their applications and infrastructure reliable and secure.

Opportunity | Using AWS to build security analytics for Sumo Logic

Enterprise security operations centers, sophisticated small and midsize businesses, and managed-service providers depend on Sumo Logic’s security information and event management solution to protect their operations. The company wanted to make sophisticated security analysis accessible even to junior analysts. As a result, it decided to create an assistant that could answer natural language questions and remove the need for users to learn proprietary query languages.

Sumo Logic needed AI technology that could contextualize large quantities of data and draw precise conclusions. After experimenting with several AI platforms, the company found that AWS delivered high performance infrastructure with robust security and privacy measures at relatively low cost. “AWS keeps giving us great tools and services that we can use to not only get our vision off the ground but also push it to new heights, past where we thought it was likely going to land,” says Eric Avery, global head of infrastructure and data at Sumo Logic.

Solution | Building an assistant using Amazon Nova foundation models

Sumo Logic developed Mobot, an assistant that serves as the primary interface for the company’s Dojo AI software. Without writing complex queries, users interact with Mobot through natural language conversations. They can ask questions such as “What happened in the last 15 minutes?” or “Did any potential security threats arise overnight?” The assistant is accessible through multiple entry points: directly within the Sumo Logic interface, through alerts that are sent to messaging services, or by analyzing existing dashboards.

Sumo Logic implemented Amazon Bedrock, a service for building generative AI applications and agents, and Amazon Nova, which delivers frontier intelligence and industry-leading price performance. This way, the company can power Mobot’s capabilities by accessing multiple foundation models and selecting the right one for each task. To process and contextualize large volumes of log and security data, Sumo Logic uses Amazon Nova 2 Lite, a fast and cost-effective reasoning model.

“We have seen a tremendous impact by using Amazon Nova models to provide proper contextualization,” says Avery. “We might guide them and say, ‘This is what you’re looking for,’ but they do the work to draw those associations and present the findings with high accuracy.”

Behind Mobot, Sumo Logic built AI agents that handle various tasks. The Summary Agent, for example, analyzes multiple security signals, synthesizes them into coherent narratives, and suggests next steps. Instead of presenting 15 separate alerts for a potential security threat, it might explain in a single notification: “This entity clicked an email message, then 15 minutes later logged in from an unexpected location. We suspect a phishing threat. You must restrict access to at-risk services.”

Outcome | Improving latency and reducing costs

Offering advanced reasoning, multiagent capabilities, and fast speed, Amazon Nova 2 Lite perfectly fits Sumo Logic’s needs. The company can now build AI agents that rapidly and cost effectively identify and resolve security threats for customers. What’s more, the security solutions provider has reduced costs by 24 percent and improved latency by 20 percent, all while maintaining high accuracy.

By democratizing security expertise, Sumo Logic helps managed-service providers respond rapidly when their customers call with urgent security requests. And junior security analysts who previously needed to escalate issues can now investigate independently, reducing the burden on senior staff.

Sumo Logic is developing capabilities to help users optimize their configurations, follow best practices, and access relevant documentation through conversational interactions with Mobot. “The challenge is seeing how quickly we can deliver, because the opportunities are there, the investment from AWS is there, and the toolset is growing,” says Avery. “As engineers, we want to capitalize on all of it and get it to our customers as soon as possible, delivering real value.”

Missing alt text value
AWS keeps giving us great tools and services that we can use to not only get our vision off the ground but also push it to new heights, past where we thought it was likely going to land.

Eric Avery

Global Head of Infrastructure and Data at Sumo Logic
sumologic.com

Sumo Logic’s architecture on AWS

Missing alt text value

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages