sumo-mcp
by droyad
README.md
# sumo-mcp
Minimal MCP server that exposes a single `search_logs` tool for Sumo Logic.
## Build
```powershell
npm install
npm run build
```
## Configure in Claude Code
## API Key
In Sumo:
- Click on your username and select `Personal Access Keys`
- Click `Add New Access Key`
- Enter a name, e.g. `Claude Local`
- Select `Custom` under scope
- Check `Run Log Search` under the `Log Search` section
- Save the key
## Install
The commands below prompt for the access ID and key interactively so the secrets never appear on the command line or in shell history.
`SUMO_ENDPOINT` must match `https://api.*.sumologic.com`. Pick the host for your Sumo deployment region (US2, EU, AU, etc.).
### PowerShell
```powershell
$accessId = Read-Host "Sumo Access ID"
$accessKey = [System.Net.NetworkCredential]::new('', (Read-Host "Sumo Access Key" -AsSecureString)).Password
claude mcp add --scope user sumo `
--env SUMO_ACCESS_ID=$accessId `
--env SUMO_ACCESS_KEY=$accessKey `
--env SUMO_ENDPOINT=https://api.us2.sumologic.com `
-- node C:\Source\SumoMcp\dist\index.js
Remove-Variable accessId, accessKey
```
### Bash
```bash
read -r -p "Sumo Access ID: " SUMO_ACCESS_ID
read -r -s -p "Sumo Access Key: " SUMO_ACCESS_KEY
echo
SUMO_ACCESS_ID="$SUMO_ACCESS_ID" SUMO_ACCESS_KEY="$SUMO_ACCESS_KEY" \
claude mcp add --scope user sumo \
--env SUMO_ACCESS_ID="$SUMO_ACCESS_ID" \
--env SUMO_ACCESS_KEY="$SUMO_ACCESS_KEY" \
--env SUMO_ENDPOINT=https://api.us2.sumologic.com \
-- node /path/to/sumo-mcp/dist/index.js
unset SUMO_ACCESS_ID SUMO_ACCESS_KEY
```
## Tool
`search_logs(query, from?, to?, max_results?, timezone?)`
- `query` — Sumo search expression
- `from` / `to` — ISO 8601 without timezone designator (`2026-05-07T10:00:00`), epoch milliseconds, or relative shorthand `now` / `-<N><unit>` where unit is `s|m|h|d|w` (e.g. `-15m`, `-1h`, `-7d`). Relative values are translated to epoch milliseconds before being sent to Sumo. Default `-15m` / `now`
- `max_results` — default 100, capped at 1000
- `timezone` — IANA name, default `UTC` (used when `from`/`to` are ISO 8601 without an explicit offset)
Returns a JSON array of messages with `_messageTime`, `_sourceCategory`, `_sourceHost`, `_sourceName`, `_raw`.
Hard timeout 60s — narrow the time range or query if you hit it.
## Design
See `docs/superpowers/specs/2026-05-07-sumo-mcp-design.md`.
TDQS
A4.1/5.0
Scored across 1 tool
Disambiguation5/5
With only one tool, there is no potential for ambiguity. The single tool is clearly defined and cannot be confused with any other.
Naming Consistency5/5
The single tool name 'search_logs' follows a clear verb_noun pattern, which is consistent and predictable.
Tool Count2/5
A single tool for a logging platform seems insufficient. Typical users would expect additional tools for managing searches, retrieving past results, or listing sources, making the count feel too limited for the domain.
Completeness2/5
The server only offers a search functionality without supporting operations like listing saved searches, polling search status, or retrieving historical results. This leaves significant gaps for a complete log investigation workflow.
Maintenance
ActivityInactive
ResponsivenessNo issues