Skip to content

DOCS-1565 - SOC Analyst Agent GA - Docs and release notes - #6971

Merged
mafsumo merged 5 commits into
mainfrom
DOCS-1565-soc-analyst-agent-ga
Aug 3, 2026
Merged

DOCS-1565 - SOC Analyst Agent GA - Docs and release notes#6971
mafsumo merged 5 commits into
mainfrom
DOCS-1565-soc-analyst-agent-ga

Conversation

@kimsauce

@kimsauce kimsauce commented Jul 29, 2026

Copy link
Copy Markdown
Collaborator

Purpose of this pull request

This pull request promotes the SOC Analyst Agent from Public Preview to GA. It's a successor to #6901, which had merged into the Mobot GA branch (#6897) before the two release schedules diverged — Mobot ships 7/29, SOC Analyst Agent targets August 3, 2026.

Changes:

  • soc-analyst-agent.md — full GA rewrite (previously Public Preview)
  • CSE hub cards (index.md, about-cse-insight-ui.md) updated to point to the SOC Analyst Agent instead of Insight Summary
  • insight-summary.md removed (content absorbed into the SOC Analyst Agent's "What Happened" field) — sidebar entry removed, 301 redirect added
  • blog-cse/2026-08-03-application.md — GA release note
  • Updated AI Verdict screenshots reflecting the redesigned insight UI
  • ai-machine-learning.md — removes the "Summary Agent" section, restores the "Summary Agent → absorbed into SOC Analyst Agent" FAQ bullet, and un-hides the FedRAMP availability FAQ mentioning the SOC Analyst Agent (all three were held back in DOCS-1548 - Mobot, Example Prompts, AI/ML FAQ | GA docs #6897 pending this PR)

Note for whoever merges this: since #6897 (Mobot GA) hasn't merged to main yet as of this PR's creation, the diff for ai-machine-learning.md currently shows both Mobot and SOC changes mixed together (main doesn't have Mobot's changes yet either). Once #6897 merges, rebase this branch onto the updated main — the diff for that file will collapse down to just the SOC-specific delta described above.

Select the type of change

  • Minor Changes - Typos, formatting, slight revisions
  • New Content - New features, sections, pages, tutorials
  • Update Content - Revisions, updating sections
  • Site and Tools - .clabot, version updates, maintenance, dependencies, new packages for the site (Docusaurus, Gatsby, React, etc.)

Ticket (if applicable)

https://sumologic.atlassian.net/browse/DOCS-1565

@cla-bot cla-bot Bot added the cla-signed Contributor approved, listed in .clabot file label Jul 29, 2026
@kimsauce kimsauce self-assigned this Jul 29, 2026
kimsauce and others added 2 commits July 29, 2026 15:01
Successor to #6901 (merged into the Mobot GA branch before the release
schedules diverged). Promotes soc-analyst-agent.md from Public Preview
to GA, updates the CSE hub cards and About the Insight UI page to
point to it, adds the Aug 3 release note and updated screenshots, and
removes insight-summary.md now that its content is absorbed into the
SOC Analyst Agent's "What Happened" field.

Also finishes the ai-machine-learning.md work started in the Mobot PR:
removes the "Summary Agent" section, restores the "Summary Agent ->
absorbed into SOC Analyst Agent" FAQ bullet, and un-hides the FedRAMP
availability FAQ that names the SOC Analyst Agent.

Target: August 3, 2026.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The first cut of this PR only carried over 2 of the 15 screenshots
soc-analyst-agent.md's GA rewrite actually needs, since the source
branch's own split initially missed the rest. Add the 4 new images
the GA content introduces (Auto-Investigation Filter, AI Verdict
filter, Ask Mobot from an insight, Volume & Overage Settings), update
9 images whose GA-era versions replaced the Public Preview screenshots
under the same filename, and remove 3 images only the old Public
Preview content used. Also repoint the Dec 31 2025 release note's
"Learn more" link from insight-summary to soc-analyst-agent, matching
the Insight Summary -> SOC Analyst Agent absorption this PR completes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@kimsauce
kimsauce force-pushed the DOCS-1565-soc-analyst-agent-ga branch from bd73091 to 8fe4c22 Compare July 29, 2026 22:23
kimsauce and others added 2 commits July 29, 2026 16:22
Add cross-links between the AI/ML hub page and the SOC Analyst Agent/
Mobot/MCP server docs, and clarify the side-panel and insight-ID click
steps in the AI verdicts walkthrough with updated screenshots.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…l section to Mobot investigation

Recommended Actions (playbook execution from the AI Investigation tab) is not
part of GA scope yet, so comment it out for later re-enablement and update the
related FAQ answer. Add a new section describing how auto-investigation and
Mobot check insight indicators against threat intel feeds and inventory
sources, plus an example prompt.
@mafsumo

mafsumo commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

Pushed two doc updates per SME feedback:

  1. Removed Recommended Actions from GA scope. Commented out the Execute Action → playbook → Automations tab flow in the AI Investigation tab (not deleted, so it's easy to re-enable later). Updated the FAQ "Can the agent take containment actions on its own?" accordingly.
  2. Added a "Check indicators against threat intelligence" section under the Mobot investigation flow, covering auto-investigation and Mobot checking insight indicators against Sumo Logic's global threat intel feeds, custom feeds, and connected inventory sources, plus example prompts. Also added one example prompt to the Mobot Example Prompts doc.

— via Claude Code

@mafsumo
mafsumo requested a review from orensh81 August 3, 2026 13:59
@mafsumo
mafsumo added this pull request to the merge queue Aug 3, 2026
Merged via the queue into main with commit 1153f90 Aug 3, 2026
4 checks passed
@mafsumo
mafsumo deleted the DOCS-1565-soc-analyst-agent-ga branch August 3, 2026 14:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed Contributor approved, listed in .clabot file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants