Linking Sumo Logic as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Sumo Logic connector syncs logs, users, roles, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Connect your Sumo Logic account to sync log search results, collectors, monitors, dashboards, users, and more.
Create an access ID and access key in your Sumo Logic preferences (or use a service account's access key). Pick the deployment region your account lives on - it's the subdomain of your Sumo Logic URL (e.g. service.eu.sumologic.com is the EU deployment).
The logs table runs your log search query through the Search Job API over rolling time windows. Leave the query as * to sync everything, or narrow it (e.g. _sourceCategory=prod/api) to control volume.
You'll be asked for:
- Deployment region: choose between US1 (api.sumologic.com), US2 (api.us2.sumologic.com), AU (api.au.sumologic.com), CA (api.ca.sumologic.com), DE (api.de.sumologic.com), EU (api.eu.sumologic.com), FED (api.fed.sumologic.com), IN (api.in.sumologic.com), JP (api.jp.sumologic.com) and KR (api.kr.sumologic.com).
- Access ID: for example
su.... - Access key
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All Sumo Logic tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
Deployment region | select | Yes |
Access ID | text | Yes |
Access key | password | Yes |
Log search query | textarea | No |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
logs | Raw log messages matching your search query. Only syncs the last 7 days on initial sync | Incremental, Full refresh | message_time | — |
users | Users in your Sumo Logic organization. | Full refresh | — | — |
roles | Roles in your Sumo Logic organization and the capabilities they grant. | Full refresh | — | — |
collectors | Installed and hosted collectors that ingest data into Sumo Logic. | Full refresh | — | — |
collector_sources | Data sources configured on each collector, one row per source with its parent collector id. | Full refresh | — | — |
dashboards | Dashboards in your Sumo Logic organization. | Full refresh | — | — |
monitors | Alerting monitors configured in your Sumo Logic organization. | Full refresh | — | — |
partitions | Partitions that route your log data into separate indexes. | Full refresh | — | — |
ingest_budgets | Ingest budgets that cap daily data ingestion volume. | Full refresh | — | — |
connections | Outbound connections (webhooks) used by monitors and scheduled searches to send notifications. Credential-bearing fields (the destination URL, headers, and default payload) are dropped on import. | Full refresh | — | — |
field_extraction_rules | Field extraction rules that parse fields out of messages at ingest time. | Full refresh | — | — |
scheduled_views | Scheduled views that pre-aggregate log data into indexed views. | Full refresh | — | — |
health_events | Health events reporting operational issues with collectors, sources, and ingest budgets. | Full refresh | — | — |
Troubleshooting
- If the connection fails with an authorization error, the access key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.