Opens in a new tab
vmblog logo 2024 wht (updated)

Sumo Logic’s Dojo AI Aims to Turn SIEM Into a Decision Engine at RSA 2026 – VMblog QA

Share: 

David Marshall | Published: March 16, 2026
RSAC 2026 Q&A

As security teams grapple with alert fatigue, tool sprawl, and an avalanche of telemetry data, Sumo Logic will arrive at RSA 2026 with a pointed message: detection alone is no longer enough. At Booth #6465, the company will showcase Dojo AI, its agentic AI framework designed to transform traditional SIEM from a tool that surfaces threats into one that actively recommends what to do about them — with explainable reasoning that analysts can act on immediately. From a SOC Analyst Agent that delivers clear verdicts and remediation guidance, to a Query Agent that eliminates complex search syntax, Sumo Logic is betting that the future of security operations lives at the intersection of data clarity and autonomous decision-making.

But the company’s ambitions extend beyond flashy demos. Eric Avery, Head of Infrastructure and Data at Sumo Logic, makes clear that the foundation of any credible AI security strategy starts long before the agents are deployed. “Focus on the data strategy first, security second, and AI innovation last,” Avery told VMblog ahead of the show. It’s a grounded, practitioner-first philosophy that runs through everything Sumo Logic is bringing to San Francisco — and one that will resonate with security leaders tired of AI hype that outpaces real-world results.

++

VMblog: Give VMblog readers a quick overview of your company and its core mission.

Eric Avery: Sumo Logic helps make the digital world secure, fast, and reliable by unifying critical security and operational data through its intelligent platform. Built to address the increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness—combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights to protect against security threats, ensure reliability, and gain powerful insights into their digital environments.

VMblog: Where can attendees find you at RSA 2026? What’s your booth number, and what kind of experience can visitors expect when they stop by?

Avery: Sumo Logic will be at Booth #6465 and will be demonstrating how organizations can protect intelligent security operations with Dojo AI. Sumo Logic will showcase how Dojo AI agents reduce friction and accelerate decision-making across the TDIR lifecycle. Those agents include:

  • SOC Analyst Agent (Beta) – assesses risk, delivers clear verdicts, and recommends explainable remediation actions (e.g., “Disable this service account and rotate credentials”)
  • Query Agent (GA) – converts intent into precise searches, eliminating complex query writing
  • Knowledge Agent (GA) – answers how the product works using official documentation inside the workflow
  • Sumo Logic MCP Server (Beta) – extends AI assistance across tools to avoid product boundaries becoming process boundaries

VMblog: What is your message to RSA attendees coming out to the show this year?

Avery: Focus on the data strategy first, security second, and AI innovation last. Without a firm understanding of the data, a solid and scoped architecture for agent interaction, and security wrapping it up like the perfect package to create a high trust threshold from the offset, AI innovation will struggle and generate unexpected risk. Sumo Logic is the perfect marriage of data understanding and security focus come to life in an operational context. Our agents follow that same philosophy, which enables our customers to receive trusted data quickly in order to make decisions or take action faster than they could on their own. 

VMblog: What were your key learnings from 2025’s security landscape, and how have those insights shaped your solutions for 2026?

Avery: 2025 was a truly informative year on the maturity of AI tooling as it compares against the understanding of AI capability for the everyday user. In AI, change is constant and features are rolling out at the speed of services in the early cloud days. The opportunity to innovate is endless and building is easier than ever, but you must stay focused on the basics of well-architected design in order to maintain solution integrity, reliability, and security – the hardest pillar to govern depending on your AI utilization.

VMblog: How is your company addressing the intersection of generative AI and cybersecurity – both defending against AI-powered attacks and leveraging AI agents for security operations?

Avery: Security teams are drowning in telemetry, with more than half of security leaders surveyed expressing that they have too many point tools in their stack. Cloud adoption, identity sprawl, and distributed architectures have created a new challenge: data abundance without decision clarity. Traditional SIEM platforms excel at surfacing context, highlighting suspicious login patterns or flagging anomalous behavior, but stop short of guiding analysts on what to do next. That gap forces analysts to manually piece together response plans, slowing mean time to remediation and leaving critical decisions to human interpretation under pressure.

Sumo Logic is redefining the SOC by consolidating the data layer and the decision layer. The platform starts with logs as the system of record, enriches signals through Cloud SIEM correlation, and applies Dojo AI to transform SIEM from a detection tool into a decision engine. Instead of just alerting analysts, the SOC Analyst Agent actively recommends the next-best action with explainable reasoning.

VMblog: With the proliferation of AI agents and autonomous systems in enterprise environments, how is your solution addressing the security challenges of agentic AI?

Avery: Attackers use AI and other advanced techniques to outpace defenders, overwhelming SOC teams with alert fatigue, context switching, manual triage, and slow responses from disparate tools. At a time when every vendor is bringing new AI tools to market, the C-Suite is asking which agents can deliver measurable value. Dojo AI brings agentic AI directly into the enterprise security stack at cloud scale. By automating hours of manual work and reducing MTTR, Dojo AI helps customers not just keep pace with threats but get ahead of them.

VMblog: What sets your solution apart in today’s crowded cybersecurity marketplace? Why should RSA attendees prioritize visiting your booth?

Avery: Sumo Logic’s Dojo AI doesn’t just tell security teams what’s wrong so they can chase another alert, it actively recommends what to do to solve the problem with explainable reasoning. 

VMblog: How does your platform help organizations manage the security implications of shadow AI and unauthorized generative AI tool usage by employees?

Avery: In a world where shadow AI is a growing problem and tracking it is easier said than done, Sumo Logic serves as the stop gap between now and the future when shadow AI is brought into the light more consistently. Our platform is your one stop shop for reacting to shadow AI, unauthorized AI actions, and operational risk. Put your logs into Sumo Logic, ensure those logs include the depth of logging you need to track AI (and all service-related) feature actions inside applications, and then set up your response alerts and prepare to engage with our agents at hybrid human and machine speed. From there, you can take the appropriate action to stop the actor in question from unauthorized action, be it vendor or employee. The good news – this is tried, time-tested, and works. AI is just the newest technology for the industry to keep under careful observation. 

VMblog: Are you participating in any speaking sessions or panel discussions at RSA 2026? Can you tell us more about these presentations?

Avery: Yes.

Agentic AI in SecOps: What’s Real, What’s Noise
Agentic AI has the potential to reshape security operations, but only if applied responsibly. In this session, Chas Clawson, VP of Security Strategy at Sumo Logic, will break down the real capabilities of AI agents today, offer guidance for evaluating them, and highlight the mindshifts SOC leaders need as humans and AI begin working side-by-side.
Wednesday, 3/25/26, (30 min) 2:40PM
North Briefing Center theater

Presenter
Chas Clawson, VP, Security Strategy, Sumo Logic

VMblog: What exciting demos or interactive experiences can attendees expect at your booth?

Avery: Sumo Logic will be demonstrating Dojo AI in booth #6465. Dojo AI agents reduce friction and accelerate decision-making across the TDIR lifecycle. Those agents include:

  • SOC Analyst Agent (Beta) – assesses risk, delivers clear verdicts, and recommends explainable remediation actions (e.g., “Disable this service account and rotate credentials”)
  • Query Agent (GA) – converts intent into precise searches, eliminating complex query writing
  • Knowledge Agent (GA) – answers how the product works using official documentation inside the workflow
  • Sumo Logic MCP Server (Beta) – extends AI assistance across tools to avoid product boundaries becoming process boundaries

VMblog: What success stories or case studies will you be highlighting at RSA 2026?

Avery: Megaport is a customer who will actually be present in the booth. Their speaker will present on Tuesday and Wednesday evenings, sharing how they use Sumo Logic to improve their TDIR workflows.

VMblog: Does your company have anything special or interesting happening at your booth this year?

Avery: We are very lucky to have Forrester Research analyst Allie Mellen at our booth on Wednesday, March 25 from 3:30-4:30pm for a signing event for her new book Code War: How nations hack, spy and shape the digital battlefield

Visitors to our booth can also take the Dojo Challenge and earn special swag.

VMblog: As an experienced RSA participant, what advice would you give to attendees to make the most of their conference experience in 2026?

Avery: You won’t get to everything and that’s okay. Immerse yourself in the experience, prioritize key topics of interest ahead of time and focus on bridging knowledge gaps you aim to address for yourself or your teams. Most of all, bring snacks and stay hydrated. Learning, networking, and excitement stops for nothing and no one in the peak experience that is RSAC, including lunch refueling.

##