---
title: "Sumo Logic destinations: sumologic-http() and sumologic-syslog()"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-sumologic-intro/"
last_modified: "2026-09-23T14:09:57+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# Sumo Logic destinations: sumologic-http() and sumologic-syslog()

AxoSyslog can send log messages to [Sumo Logic](https://www.sumologic.com/), a cloud-based log management and security analytics service, by using the `sumologic-http()` and `sumologic-syslog()` destinations.

## Prerequisites

Currently, using the `sumologic-http()` and `sumologic-syslog()` destinations with AxoSyslog has the following prerequisites:

- AxoSyslog version 3.27.1 or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `sumologic-http()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/sumologic/sumologic.conf](https://github.com/axoflow/axosyslog/blob/main/scl/sumologic/sumologic.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-http` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-http` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).
- A Sumo Logic account.

  If you do not yet have a Sumo Logic account, visit [the official Sumo Logic website](https://www.sumologic.com/), and click `Start free trial` to create an account.

  > **Note:**
  > A free trial version of the Sumo Logic account has limited functionalities and is only available for 90 days.
- A [Cloud Syslog Source](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source) configured with your Sumo Logic account.

  For details, follow the configuration instructions under [the Configure a Cloud Syslog Source section](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#configure-a-cloud%C2%A0syslog%C2%A0source) on the official Sumo Logic website.

  > **Note:**
  > Transport-level security (TLS) 1.2 over TCP is required.
- A Cloud Syslog Source Token (from the Cloud Syslog Source side).
- TLS set up on your Sumo Logic account.

  For detailed information about setting up TLS in your Sumo Logic account, see [the description for setting up TLS on the Sumo Logic official website](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#set%C2%A0up-tls).

  > **Note:**
  > After you download the `DigiCert` certificate, make sure you follow the certificate setup steps under [the syslog-ng section](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#syslog-ng-1).
- Your Sumo Logic syslog client, configured to send data to the Sumo Logic cloud syslog service, by using AxoSyslog.

  For detailed information, follow the instructions under [the Send data to cloud syslog source with syslog-ng section](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#send-data-to%C2%A0cloud-syslog-source-with-syslog-ng) on the official Sumo Logic website.
- A verified connection and client configuration with the Sumo Logic service.

  > **Warning:**
  > To avoid potential data loss, we strongly recommend that you verify your [connection](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#verify-connection-with-sumo-service) and [client configuration](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#verify-client-configuration) with the Sumo Logic service before you start using the `sumologic-http()` or `sumologic-syslog()` destination with AxoSyslog in a production environment.
- (Optional) For using the `sumologic-http()` destination, you need a [HTTP Hosted Collector](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/HTTP-Source) configured in the Sumo Logic service.

  To configure a Hosted Collector, follow the configuration instructions under [the Configure a Hosted Collector section](https://help.sumologic.com/03Send-Data/Hosted-Collectors/Configure-a-Hosted-Collector) on the official Sumo Logic website.
- (Optional) For using the `sumologic-http()` destination, you need the unique HTTP collector code you receive while configuring your Host Collector for HTTP requests.

## Limitations

Currently, using the `sumologic-syslog()` and `sumologic-http()` destinations with AxoSyslog has the following limitations:

- The minimum required version of AxoSyslog is version 3.27.1.
- Message format must be in [RFC 5424-compliant form](https://tools.ietf.org/html/rfc5424#page-8). Messages over 64KB in length are truncated.

  For more information about the message format limitations, see [the Message format section](https://help.sumologic.com/03Send-Data/Sources/02Sources-for-Hosted-Collectors/Cloud-Syslog-Source#message-format) on the official Sumo Logic website.
- 64 characters long Sumo Logic tokens must be passed in the message body.

  > **Note:**
  > Although [RFC 5424](https://tools.ietf.org/html/rfc5424) limits the structured data field ([SD-ID](https://tools.ietf.org/html/rfc5424#page-15)) to 32 characters, Sumo Logic tokens are 64 characters long. If your logging client enforces the 32 characters length limit, you must pass the token in the message body.

## Declaration for the sumologic-http() destination

```shell
@include "scl.conf"
# ...

destination d_sumo_http {
    sumologic-http(
    collector("ZaVnC4dhaV3_[...]UF2D8DRSnHiGKoq9Onvz-XT7RJG2FA6RuyE5z4A==")
    deployment("eu")
    );
};
```

## Declaration for the sumologic-syslog() destination

```shell
@include "scl.conf"
# ...

destination d_sumo_syslog {
    sumologic-syslog(
    token("rqf/bdxYVaBLFMoU39[...]CCC5jwETm@41123")
    deployment("eu")
    tls(peer-verify(yes) ca-dir('/etc/syslog-ng/ca.d'))
    );
};
```

---

[sumologic-http()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-sumologic-intro/destination-sumologic-http/index.md)

[sumologic-syslog()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-sumologic-intro/destination-sumologic-syslog/index.md)

[sumologic-http() and sumologic-syslog() destination options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-sumologic-intro/destination-sumologic-options/index.md)

Last modified September 23, 2026: [Typo fixes (f8ce1864)](https://github.com/axoflow/axosyslog-core-docs/commit/f8ce1864cd0b21cc012d57c7dde41b8e37d8a58a)
