AiStrike Documentation

Sumo Logic

This guide outlines the process to create a service account in Sumo Logic with read-only access to all components, including Cloud SIEM, SOAR, Alerts, Dashboards, Search, Insights, Indexes, Metrics, Collections, and Monitors.◼︎

Step 1: Log in with Admin Access

Log in to your Sumo Logic instance using an account with administrative privileges.

Step 2: Create a Role with Full Read-Only Permissions

Navigation: Administration → Security → Roles → Add Role

  • Role Name: AiStrikeReadOnlyRole

  • Description: Provides read-only access to all Sumo Logic components.

Enable the following permissions:

Category

View Permissions

Index Access

(Controlled separately: Allow all/few indexes)

Data Management

View Collectors; View Fields; View Connections; View Scheduled Views; View Partitions; View Account Overview; Download Search Results; View * [All]

Cloud SOAR

View Cloud SOAR

Cloud SIEM

View Cloud SIEM; View Rules; View Threat Intelligence; View Match List; View File Analysis; View Customer Insights; View Network Blocks; View Mappings; View Entity; View * [All]

Automation Service

Task View

Content

View Rules; View Threat Intelligence; View Match Lists; View File Analysis; View Custom Insights; View Network Blocks; View Suppressed Entities; View * [All]

Configuration [Optional]

View Mappings; View Workflow; View Context Actions; View Actions; View Enrichments; View Custom Entity Types; View Entity; View Entity Normalization; View Entity Criticality; View Tag Schemas; View Entity Groups; View * [All]

Alerting

View Monitors; View Alerts; View Muting Schedules; View * [All]

Threat Intel [Optional]

View Threat Intel Data Store; View * [All]

Organizations

View Organisations

Step 3: Assign Index Access

Navigation: Administration → Security → Roles → [AiStrikeReadOnlyRole] → Index Access

  • Select All Indexes or manually select required ones.

  • Click Save.

Step 4: Create a Service Account

Navigation: Administration → Security → Service Accounts → Add Service Account

  • Name: AiStrike_ReadOnly_Service_Account

  • Description: Service account with full read-only access for connectors and APIs.

  • Assign Role: AiStrikeReadOnlyRole

  • Add New Access Key/Secret Generation, keep scope for access key default

Once the account is created, copy and securely store the:

  • Access Key

  • Access Secret

These credentials are used to authenticate API requests and application integrations.

Step 5: Use the Service Account in Integrations

  • Access Key: <your_access_key>

  • Access Secret: <your_access_secret>

Share the access key and secret key with the AiStrike team.

If you face any issue, please reach out to the AiStrike technical team.