Sumo Logic today extended the reach of its observability of the platform to now be able to collect log data from data lake platforms provided by Snowflake and Databricks.
Bill Peterson, senior director of product marketing for observability at Sumo Logic, said these extensions will make it simpler for IT teams to centralize the management of IT operations as more organizations adopt these two services to manage data at scale.
Via those integrations it is now able to identify anomalies or potentially suspicious behavior for logins using the Sumo Logic Snowflake Logs App. Additionally, IT teams can analyze and optimize data pipelines and workloads with insights into long-running or failing queries.
The Databricks Audit App provides centralized visibility into user activity, job execution, access patterns, and administrative operations. IT teams can detect in real-time unauthorized access attempts, privilege escalations, and anomalous behavior.
There are, of course, multiple existing tools for collecting Snowflake and Databricks log data. Sumo Logic is making a case for collecting that data alongside all the other log data it already collects from more than 200 applications and platforms, said Peterson.
The overall goal is to make it simpler to aggregate telemetry data in a way that will make it possible to automate workflows using artificial intelligence (AI) tools that need access to accurate data to reliably execute a task, he added.
It’s not clear to what degree IT teams are moving beyond the simple monitoring of pre-configured metrics to embrace observability platforms that enable them to analyze telemetry data to determine the root cause of an issue. The overall goal is to make it simpler for IT teams to either prevent incidents in the first place or dramatically reduce mean time to resolution (MTTR).
At the same time, organizations can reduce the cost of collecting telemetry data by standardizing on a single platform that can be used across IT, DevOps and cybersecurity workflows.
Hopefully, the collection of telemetry data using observability platforms will reduce the overall amount of toil and stress that many IT teams experience today. Undoubtedly, roles within IT teams will change and evolve as AI is embedded more deeply into IT operations but there will continue to be a need for humans to create and manage those automated workflows. In many cases, however, the level of experience needed to manage those workflows should be substantially reduced using a natural language interface to invoke AI agents.
Regardless of how IT operations are managed, the overall state of IT management should improve as more observability platforms are deployed. A recent Futurum Group survey finds 29% of respondents cited improved security detection and response capabilities as the most impactful outcome of observability strategies. Tightened alignment between IT, developers, and security followed closely at 22%, with increased visibility across cloud-native and traditional applications at 21%. Other notable impacts included improved operational costs (20%), improved service level agreement (SLA) performance (20%), and reduced risk (18%). The only question left to determine now is how quickly the bulk of most IT organizations will see similar benefits.


