Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions blog-service/2026-08-28-manage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
title: SOC Analyst Agent Support in Child Org Baselines (Manage)
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
keywords:
- manage
- organizations
- soc analyst agent
- baseline
hide_table_of_contents: true
---

We're excited to announce that you can now provision the [SOC Analyst Agent](/docs/cse/get-started-with-cloud-siem/soc-analyst-agent) as part of a child org's baseline. When creating or editing a child org, enable the **SOC Analyst Agent** checkbox, set the **Number of investigation per day**, and optionally allow overage, alongside your existing Logs, Metrics, Traces, and Cloud SIEM Enterprise baselines. [Learn more](/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs/#allocate-credits).
4 changes: 3 additions & 1 deletion docs/cse/get-started-with-cloud-siem/soc-analyst-agent.md
Original file line number Diff line number Diff line change
Expand Up @@ -252,7 +252,9 @@ No. The SOC Analyst Agent does not have persistent learning.

The SOC Analyst Agent automatically investigates insights in priority order, up to your organization's committed daily investigation volume, which resets daily per Sumo Logic Org ID. When that volume is reached, additional insights receive a **Not Investigated** verdict, and analysts can manually trigger an investigation on any of them by clicking the **Investigate** button. A banner also appears on the **Insights** page when your investigation capacity is reached.

To control how that capacity is used, including whether investigation continues past your committed volume, see [Configure SOC Analyst Agent settings](#configure-soc-analyst-agent-settings). If you have questions about your organization's investigation volume, ask your Sumo Logic representative.
To control how that capacity is used, including whether investigation continues past your committed volume, see [Configure SOC Analyst Agent settings](#configure-soc-analyst-agent-settings). Parent org administrators can also set a child org's investigation volume when [creating or editing a child org](/docs/manage/manage-subscription/create-and-manage-orgs/create-manage-orgs/#allocate-credits).

If you have questions about your organization's investigation volume, ask your Sumo Logic representative.

### Does continuing an investigation in Mobot count against Mobot's usage limits?

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -58,11 +58,12 @@ You cannot delete a new child org once it is created.
- Set the value between 750-1500 if your analytic usage profile is **Medium**.
- Set the value between 1500-2000 if your analytic usage profile is **High**.
* **Traces Ingest**. Enter estimated daily ingestion of traces.
* **Metrics**. Enter estimated daily metric data points per minute (DPM) ingestion.<br/> <img src={useBaseUrl('img/manage/subscriptions/credits-calculator-flex.png')} alt="calculator" style={{border:'1px solid gray'}} width="450" />
* **Metrics**. Enter estimated daily metric data points per minute (DPM) ingestion.
1. **Cloud SIEM Enterprise**. Click the checkbox to enable Cloud SIEM. When the **Cloud Log Ingest** field appears, enter a value in GB.
:::note
Provisioning Cloud SIEM can take up to 24 hours. See [Monitor Cloud SIEM provisioning](#monitor-cloud-siem-provisioning), below.
:::
1. **[SOC Analyst Agent](/docs/cse/get-started-with-cloud-siem/soc-analyst-agent)**. Click the checkbox to enable the SOC Analyst Agent for the child org. Enter the **Number of investigation per day**, and optionally select **Allow Overage** to permit investigations beyond that daily limit.<br/> <img src={useBaseUrl('img/manage/subscriptions/soc-analyst-agent-baseline.png')} alt="SOC Analyst Agent baseline fields" style={{border:'1px solid gray'}} width="450" />
1. As you enter the ingestion estimates, the number of credits required for the specified ingestion levels will be incremented.
1. The calculator now shows the recommended credit allocation, which provides you a suggestion on how many credits you would need for the child org. This is calculated based on the baseline added, the burndowns in your contract, and the days remaining in your contract.
1. Throttling limits displays the rate of ingestion. To learn more, refer to [Log Ingestion](/docs/manage/ingestion-volume/log-ingestion/).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -78,11 +78,12 @@ After you create a new org, you can’t delete it.
* **Frequent Log Ingest.** Enter estimated daily ingestion to the Frequent Tier.
* **Infrequent Log Ingest.** Enter estimated daily ingestion to the Infrequent Tier.
* **Metrics**. Enter estimated daily metric data points per minute (DPM) ingestion.
* **Tracing**. Enter estimated daily ingestion of traces.<br/> <img src={useBaseUrl('img/manage/subscriptions/credits-calculator.png')} alt="calculator" style={{border:'1px solid gray'}} width="450" />
* **Tracing**. Enter estimated daily ingestion of traces.
1. **Cloud SIEM Enterprise**. Click the checkbox to enable Cloud SIEM. When the **Cloud Log Ingest** field appears, enter a value in GB.
:::note
Provisioning Cloud SIEM can take up to 24 hours. See [Monitor Cloud SIEM Provisioning](#monitor-cloud-siem-provisioning), below.
:::
1. **[SOC Analyst Agent](/docs/cse/get-started-with-cloud-siem/soc-analyst-agent)**. Click the checkbox to enable the SOC Analyst Agent for the child org. Enter the **Number of investigation per day**, and optionally select **Allow Overage** to permit investigations beyond that daily limit.<br/> <img src={useBaseUrl('img/manage/subscriptions/soc-analyst-agent-baseline.png')} alt="SOC Analyst Agent baseline fields" style={{border:'1px solid gray'}} width="450" />
1. As you enter the ingestion estimates, the number of credits required for the specified ingestion levels will be incremented.
1. The calculator now shows the recommended credit allocation, which provides you a suggestion on how many credits you would need for the child org. This is calculated based on the baseline added, the burndowns in your contract, and the days remaining in your contract.
1. Throttling limits displays the rate of ingestion. To learn more, refer to [Log Ingestion](/docs/manage/ingestion-volume/log-ingestion/).
Expand Down
Binary file not shown.
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.