Skip to content
downpipes docs

Forward the downpipes audit trail to Sumo Logic

Sumo Logic receives the downpipes audit trail through an HTTP Logs Source on a Hosted Collector. The engine dials out to the source’s unique URL on the scheduler tick.

Sumo’s HTTP Logs Source is a generic JSON intake, not a Splunk-compatible HEC, so never pair it with the Splunk HEC format. This vendor’s tile in the console fixes the push format to NDJSON, one raw event per Sumo log message (see below); if you want a JSON array or the wrapped raw-json batch instead, set the push up from Custom endpoint, with the same URL-token option. The source URL itself carries the secret (a unique code in its path), so there is no separate auth header to set either way.

Because the engine makes the outbound call, a Cloudflare Access perimeter on your console hostname never blocks this: there is no inbound request for Access to turn away.

What you need

  • A Sumo Logic role that can add an HTTP Logs Source to a Hosted Collector.
  • The source’s unique URL (which carries the secret in its path), and owner access to the downpipes console.

Set it up

  1. In Sumo Logic, add an HTTP Logs and Metrics Source to a Hosted Collector, set its source category, and copy its unique URL. The URL ends in a long unique code, which is the credential.
  2. In the downpipes console, open Integrations and choose this vendor’s tile. Its push panel fixes Delivery to HTTP endpoint and Format to NDJSON, with no picker to set either. Setting up the push is owner-only and asks for a fresh step-up sign-in.
  3. If you want Sumo to see a JSON array or the wrapped raw-json batch instead, skip this vendor’s tile and use Custom endpoint to pick that format yourself, with the same URL-token option and the same Sumo source URL.
  4. Because Sumo authenticates by the URL rather than a header, turn on Carry the auth token in the URL. Set Endpoint URL to the source URL up to (but not including) the final unique code, and paste that final code as the Auth secret. The engine appends it back as the last path segment and sends no auth header.
  5. Leave Enabled ticked to start draining on the first scheduler tick after you save, or clear it to test before any real event leaves. Choose Configure to save. If a second owner must approve a save or an enable, nothing changes until they approve it.
  6. Choose Test send and confirm Sumo accepts the batch. A test send works whether the destination is enabled or not, and never advances the delivery cursor. If you cleared Enabled, choose Enable now.

What lands in Sumo Logic

From this vendor’s tile, each batch arrives as newline-delimited JSON, one raw audit event per Sumo log message:

{"seq":4097,"ts":"2026-06-19T02:14:08.221Z","actorEmail":"ops@acme.example","action":"restore-approve","outcome":"success","...":"..."}

Sumo parses the JSON on ingest. For a JSON array or the wrapped raw-json batch instead, set the push up from Custom endpoint with that format. The source category you set on the Sumo source is what you scope a search to either way.

Good to know

  • Send generic JSON, not the Splunk HEC shape. Sumo’s HTTP Logs Source is not a HEC, so the Splunk HEC format would arrive as unparsed text.
  • The URL is the credential, so keep it in the sealed secret. With the URL-token option on, the code sits in the write-only secret field rather than the stored endpoint; use Test send to confirm Sumo accepts the reconstructed URL. Delivery is at-least-once, so dedup on the stable seq or hash; the feed carries operator identity (member emails, source IPs, roles and approver emails) and no backup data or secret values. For the shared push mechanics and the pull alternative, see forwarding the audit log to your SIEM.

Last updated .