File Activity Becomes Searchable
Files.com sends logins, uploads, downloads, automation runs, external connections, and API calls into Sumo Logic in real time, ready for your security team to search and alert on.
Files.com is the File Orchestration Platform your transfers run on, and it keeps a record of everything that happens: every login, upload, download, automation run, and outside connection. This integration sends that record into Sumo Logic as it happens, so file activity becomes searchable on the same dashboards your security team already runs.
No credit card required · 7-day free trial · Live in minutes




Real companies. Real file flows. Real results.





















Your team already sends system and app logs into Sumo Logic. File movement is usually the gap: it happens inside the file platform, invisible to the SIEM. Files.com becomes a Sumo Logic data source and sends its own activity in, so file events line up with the rest of your data instead of sitting off on their own.
Files.com sends logins, uploads, downloads, automation runs, external connections, and API calls into Sumo Logic in real time, ready for your security team to search and alert on.
Files.com sends events to a Sumo Logic HTTP source. The token that secures it is already baked into the source address Sumo Logic gives you, so there's nothing separate to configure. Paste the URL, name it, done.
Everything streams by default. If you only want some of it, pick what each Sumo Logic collector gets. You can split it by environment too, one set to dev, another to prod.
The events come from the Files.com audit log, the system of record behind the stream. Sumo Logic does the searching and alerting. Files.com holds the original record.
The same stream carries login activity, transfer volumes, and automation results. Spotting anomalies, planning capacity, and pulling audit reports all draw from one feed.
Sumo Logic reads the events. It doesn't decide who can touch which files or keep the record of what they did. Files.com does that part: access folder by folder, every action written to a record that can't be changed, and the same company logins your team already uses.
Hand each team, project, or person the exact folders they need. The person you see in a Sumo Logic query is the same account Files.com controls access for.
Every login, upload, download, and permission change is written to a record that can’t be altered and is kept for 7+ years. That is the evidence a SOC 2, HIPAA, or GDPR review asks for, ready to report on in Sumo Logic.
People sign in with your company login through SSO, and SCIM provisions and removes accounts from your directory. When someone leaves, you cut their file access in one place.
The stream to Sumo Logic is encrypted. Since the token lives in the source address, you rotate the credential by rotating the source. Files.com logs the act of sending, so a failed delivery is easy to spot.
Files.com sends each event into a Sumo Logic HTTP source the moment it happens, ready to monitor and investigate. Live streaming is an Enterprise-plan feature and isn't on Starter or Power.
Instead of a live stream, Files.com can write log files to a folder on a schedule you set, from every 5 minutes up to every 6 hours. This runs alongside the live feed and fits batch ingest, a long-term archive, or a locked-down network.
Files.com login and download events flow into Sumo Logic, where a rule can flag password-guessing attempts, repeated failed logins, or one account pulling far more files than usual. Sumo Logic checks each alert against activity from your other systems, so a real attack stands out.
Keep your Files.com file-activity record in Sumo Logic and run SOC 2, HIPAA, or GDPR audit reports from one dashboard.
Your IT team builds Sumo Logic dashboards on transfer volumes, usage patterns, and which automations succeed. Trends over time help you plan capacity, and live views catch a job the moment it breaks.
After a suspected breach, your security team searches every Files.com event the account touched in Sumo Logic: uploads, downloads, outside connections, permission changes.
The 7+ year record that can't be altered. It is the trustworthy source every event sent to Sumo Logic comes from.
Learn MoreEvery automation run is an event you can watch in Sumo Logic, so a job that breaks shows up instead of failing quietly.
Learn MoreSOC 2, HIPAA, and GDPR reports drawn from the same record you keep in Sumo Logic.
Learn MoreEach new deal’s counterparty feed is now a matter of configuration rather than another engineering project.
Read The Story

Thousands of retailer scripts and decades of downstream dependencies left AWG only one practical place to modernize: the transfer edge.
Read The Story
“Files.com's strengths are simplicity, ease of use, and the cloud connectors. We don't have to invent custom infrastructure for every partner.”

“Files.com is versatile — it can manage many different situations from a single platform. We've consolidated multiple tools onto it.”

“Files.com is robust and scales to a large enterprise. We get multiple files per minute, per second — and we're a 24/7 organization, so everything has to always be up.”

How Files.com streams file activity into Sumo Logic, which events you can watch, what plan it takes, and what happens if a delivery fails.
Files.com sends events to a Sumo Logic HTTP source over an encrypted connection. You create a hosted collector with an HTTP source in Sumo Logic, paste the source address into Files.com, and events start streaming in real time.
Files.com streams logins and access attempts, file uploads, downloads, moves and deletions, outside connection and API activity, and automation and scheduled-job runs. Everything streams by default, and you can choose which types each collector gets.
Yes. Files.com lets you choose which log types go to each Sumo Logic collector and environment. For example, send one set to a dev collector and another to prod.
No. Streaming to a SIEM is a Files.com Enterprise-plan feature and is not on the Starter or Power plans. Starter also keeps only one week of logs. See what each plan includes on the pricing page.
No. Files.com records every event in a tamper-proof audit log and streams those events into Sumo Logic as they happen. Sumo Logic does the searching, alerts, dashboards, compliance reports, and storage. Files.com delivers the events; Sumo Logic does the SIEM work.
Files.com holds the last 7 days of logs for the stream and re-sends them in batches once the connection to Sumo Logic is restored, so nothing is lost. Every event also stays in the immutable Files.com audit log, independent of the stream, and Event Channels can alert your team the moment a delivery fails.
Yes. Files.com Log File Streaming writes the same audit and activity log categories to a folder on your site at a configured interval, as JSON or CSV, for archival and batch workflows alongside or instead of the live stream.
Files.com keeps its tamper-proof audit log for 7+ years, independent of how long Sumo Logic retains the same events. Sumo Logic governs its own retention; the Files.com record stays the long-term system of record for file activity.
Files.com log streaming batches and forwards complete audit log categories to Sumo Logic roughly every 60 seconds. Event Channels deliver individual operational events, like SSO failures, user lockouts, and automation failures, to a webhook, Slack, Teams, SNS, or Pub/Sub target as they occur.
Start a 7-day free trial. Create a hosted collector, paste the Source Address, and watch file activity become searchable in Sumo Logic.
No credit card required • 7-day free trial • Live in minutes