# Sumo Logic

EvoHub receives Sumo Logic monitor notifications through a **webhook connection**. The same body is used for the alert and the recovery payload; the recovery resolves the EvoHub alert.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Sumo Logic**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create the connection
In Sumo Logic, go to **Manage Data → Monitoring → Connections → + → Webhook**. Set **URL** to your webhook URL and paste the body below as both the **Alert Payload** and the **Recovery Payload**.
### Use it in monitors
In each monitor, under **Notifications**, add the connection, select the trigger types to send and turn on **Recovery**.
:::

```json
{"id":"{{Id}}","name":"{{Name}}","description":"{{Description}}","trigger_type":"{{TriggerType}}","trigger_value":"{{TriggerValue}}","trigger_condition":"{{TriggerCondition}}","num_results":"{{NumQueryResults}}","query_url":"{{QueryURL}}","alert_url":"{{AlertResponseUrl}}"}
```

Leave `{{ResultsJson}}` out of the body: Sumo Logic inserts it as raw JSON, and an empty result would make the body invalid.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `name` (the monitor name). |
| Description | `description`. |
| Labels | `monitor_id`, `trigger_type`, `trigger_value`, `trigger_condition`, `num_results`, `query_url`, and `url` (the alert response page). |

### Severity

| Trigger type | EvoHub severity |
| --- | --- |
| Critical | critical |
| Warning | medium |
| Missing Data | low |
| ResolvedCritical, ResolvedWarning, ResolvedMissingData | resolves the alert |

## Resolve and deduplication

An alert is identified by the monitor. A repeat while it is open is recorded as **Retriggered**, and the recovery payload resolves it.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Elastic / Kibana](https://docs-dev.evohub.io/elastic-kibana.md)
