> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/connect-your-technology/q-z-integrations/sumo-logic/sumo-logic-cloud-infrastructure-security-setup-for-workbench.md).

# Sumo Logic Cloud Infrastructure Security Setup for Workbench

## Prerequisites <a href="#h_01hyedng6eekdq0a53ha6mb21e" id="h_01hyedng6eekdq0a53ha6mb21e"></a>

* You must have the Enterprise account type of Sumo Logic Cloud Infrastructure Security. Other account types don't allow searches using the API, which is key to how Expel uses Sumo Logic Cloud Infrastructure Security. If you don't have the Enterprise account type, contact your Sumo Logic representative to upgrade.
* If you are on a **traditional** Sumo Logic pricing model, the data Expel accesses must be in the **Continuous** (preferred) or **Frequent** data tiers. Expel can not programmatically access data in the Infrequent data tier. [Learn more about Sumo Logic data tiers](https://www.sumologic.com/help/docs/manage/partitions/data-tiers/).

## Step 1: Enable Console Access <a href="#h_01hyedng6ew7dcav6r2snzs7r8" id="h_01hyedng6ew7dcav6r2snzs7r8"></a>

This procedure creates a user account for Expel that keeps the Expel activity separate from other activity happening on the Sumo Logic Cloud Infrastructure Security console.

Expel requires console access to allow analysts to perform investigation and triage. Without this additional level of information, alerts cannot be verified by our analysts, and an investigation cannot be initiated. For more information, see [Why Expel Asks for Console Access](/connect-your-technology/about-integrations/why-expel-asks-for-console-access.md).

### Create a Role <a href="#h_01hyedng6ehfd6nfztdgf42p3z" id="h_01hyedng6ehfd6nfztdgf42p3z"></a>

1. Log into the Sumo Logic Cloud Infrastructure Security device.
2. Navigate to **Administration > Users and Roles**.
3. Select the **Roles** tab and then select the **Add Role** button at the top right of the page.
4. Complete the settings as follows:
   * **Name** - enter "Expel".
   * **Description** - enter "Expel".
   * Scroll down to the **Capabilities** section and select:
     * **View Collectors** - this gives Expel read-only access to your data.
     * **Create Access Keys** - this allows this role to create an API key for programmatic access.
5. Select **Save** at the top to finish creating the role.

### Create a User <a href="#h_01hyedng6ehq7t0x501jvk4sky" id="h_01hyedng6ehq7t0x501jvk4sky"></a>

You have two options for creating a new user:

| Method                                            | Tasks                                                                                                                                                                                                                                                                       | Time frame     |
| ------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| [Self onboarding](#h_01hyedng6e9t7ew4qg24x88wpr)  | <ol><li>Create a user account that you have access to.</li><li>Activate the account and generate API credentials to onboard yourself.</li><li>Change registered email address to an Expel email address allowing Expel to manage the account and API credentials.</li></ol> | Immediate      |
| [Expel onboarding](#h_01hyedng6f7c05sanrmh576aqy) | <ol><li>Create an Expel user account.</li><li>Expel generates the API credentials.</li><li>Expel adds your device to Workbench.</li></ol>                                                                                                                                   | 1 business day |

#### Option 1: Self Onboarding <a href="#h_01hyedng6e9t7ew4qg24x88wpr" id="h_01hyedng6e9t7ew4qg24x88wpr"></a>

1. Select the **Users** tab and then select **Add User** at the top right of the page.
2. Complete the settings as follows:
   * **First Name** - enter "Expel".
   * **Last Name** - enter "SOC".
   * **Email** - provide your email address (<youremailaddress@yourcompanyname.com>).
   * **Assigned Roles** - select the "Expel" role you created in the previous step.
   * Select **Save**.
3. Log out of Sumo Logic Cloud Infrastructure Security from your personal account.
4. Go to your email and open the welcome email from Sumo Logic.
5. Activate your new user account and set a new password. Make note of this password because you will later share it with Expel.
6. Go to [Step 2](#h_01hyedng6f7c05sanrmh576aqy) and proceed from there.

#### Option 2: Expel Onboarding <a href="#h_01hyedng6f7c05sanrmh576aqy" id="h_01hyedng6f7c05sanrmh576aqy"></a>

1. Select the **Users** tab and then select **Add User** at the top right of the page.
2. Complete the settings as follows:
   * **First Name** - enter "Expel".
   * **Last Name** - enter "SOC".
   * **Email** - enter: "soc+\<your\_company\_name>@expel.io".
     * For example, if your organization were Acme Corp, the format would be "<soc+acme_corp@expel.io>".
   * **Assigned Roles** - select the "Expel" role you created in the previous step.
   * Select **Add New User**.
3. Notify your Expel Customer Success Manager (CSM) or [Expel support](/support/how-to-reach-us.md) that you created the new user account.
   * Your Expel team will activate the account, generate API credentials, and add the device to Workbench.
   * You will receive a notification that the device is added in Workbench within one business day.
   * You can **close this guide** as Expel will continue this process for you.

## Step 2: Generate API Credentials <a href="#h_01hyedng6fp4f8prvkvg0vjfxm" id="h_01hyedng6fp4f8prvkvg0vjfxm"></a>

The normal interaction with Sumo Logic Cloud Infrastructure Security is through the API. This step creates the Access Key that allows Expel to use the API.

{% hint style="info" %}
API access keys are associated with the user account that creates them.
{% endhint %}

1. Make sure you're logged into Sumo Logic Cloud Infrastructure Security as the new user created in the previous step.
2. Select the user profile icon in the top right, and select **Personal Access Keys**.
3. Select **Add Access Key**.
4. Configure the key as follows:
   * **Name** - enter "Expel API".
   * Leave **Allowed CORS Domains** blank.
   * Leave **Scopes** set to **Default**.
   * Select **Save.**
5. On the next page, make note of the newly generated **Access ID** and **Access Key** in a safe place, as they will be used when adding the device in Workbench in [Step 4](#h_01hyedng6fd64r9ab09kxjgfyd).
6. Select **Done**.

## Step 3: Change Email Address <a href="#h_01hyedng6f54x0ztwgrzqdmxga" id="h_01hyedng6f54x0ztwgrzqdmxga"></a>

Email access to the Sumo Logic account enables us to rotate the password on the account when necessary.

1. Select the user profile icon in the top right and select **Preferences**.
2. Select **Change Email**.
3. For Your New Email, type "soc+**\<Your\_Organization\_Name>**@expel.io".
   * For example, if your organization were Acme Corp, the format would be "<soc+acme_corp@expel.io>".
4. Type your current password to authorize the change.
5. Select **Submit**.

## Step 4: Add Sumo Logic Cloud Infrastructure Security as a Security Device in Workbench <a href="#h_01hyedng6fd64r9ab09kxjgfyd" id="h_01hyedng6fd64r9ab09kxjgfyd"></a>

Now that you have the correct access configured and noted the credentials, you can integrate your tech with Workbench.

1. [Log in to Workbench](https://workbench.expel.io/).
2. In the side menu, navigate to **Organization Settings > Security Devices**.
3. In the search box, type “Sumo Logic” and then select the **Sumo Logic Cloud Infrastructure Security** integration.
4. A configuration pane displays. Complete the fields as follows:
   * **Name** - enter a name that might help you more easily identify this integration, such as “CompanyName Sumo Logic Cloud Infrastructure Security”; this name will display in Workbench under the Name column, and is a text string that you can filter on.
   * **Location** - enter the location of your integration, for example “cloud;” this is also a text string that you can filter on, so we recommend being consistent with location naming across your Expel integrations.
   * **Username** - enter the **Access ID** from [Step 2](#h_01hyedng6f7c05sanrmh576aqy).
   * **Password** - enter the the **Access Key** from [Step 2](#h_01hyedng6f7c05sanrmh576aqy).
   * **Server address** - enter "<https://service.us2.sumologic.com>".
   * **Data tier** - configure this depending on your Sumo Logic pricing model:
     * If you have **Traditional Sumo Logic pricing:**
       * **Continuous** is the preferred data tier and the default selection.
       * **Frequent** is supported by Expel, but isn't recommended.
       * **Infrequent** is not supported by Expel.
     * If you have **Sumo Logic Flex pricing:**
       * Select **All.** *Before selecting this option, please be sure to configure index filters in all via SIEM devices connected to your Sumo instance. This is to prevent Expel from pulling more data than you intend.*
5. Select **Save**.
6. On the console access screen, select **Set up now**.
7. In the Console Login area, complete the fields as follows:
   * **Console URL** - enter the console URL from the Server address in the Connection Settings area above. At the end of the URL, enter "**/login"**.
   * **Username** - enter the username for the new user you created in [Step 1](#h_01hyedng6ew7dcav6r2snzs7r8).
   * **Password** - enter the password for the new user.
   * **Two-factor secret key (32-character code)** - depending on how your organization enforces log-ins, this field may not apply to you. In these cases, you can leave it blank. This field is optional. If you have questions or concerns, reach out to your Customer Success Manager (CSM) or Expel support.
8. Select **Save**.

Your device should be created successfully within a few seconds. A few reminders:

* After your connection is healthy, it will take some time for your device to begin polling and receiving data.
* To check on the status, select the downward arrow for your device in the first column and choose **View details**.
* Polling will happen first; data will be received after that. **You must refresh the page to see updates.**
* If your device does not begin polling within 15 minutes, and does not begin receiving data within 30 minutes, [contact our support team for help](/support/how-to-reach-us.md).
* To check if alerts are coming through, navigate to **Dashboards > Alert Analysis**. Scroll to the device you want to check, and select the **Expel Alerts** tab to reveal more alert information. It can take 36 to 72 hours for alerts to appear after setup, as we [tune your device](/workbench-reference/alerts/how-expel-alerts-work.md#device-tuning).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/connect-your-technology/q-z-integrations/sumo-logic/sumo-logic-cloud-infrastructure-security-setup-for-workbench.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
