Okay. Good afternoon, everyone. I am Mark Murphy, an Enterprise Software Analyst at JPMorgan. It is a great pleasure to be joined virtually today with Ramin Sayar, the CEO of Sumo Logic, as well as Sydney Carey, the CFO. Ramin and Sydney, thank you so much for joining us. Thanks for having us. Good to see you. Absolutely. I want to begin by just reminding our viewers that you should be able to submit a Q&A in a chat format at a link or a chat button, Q&A button that you should see below the video feed on the screen. I'm going to try to keep that open, and we'll be watching that a little deeper into the presentation. Ramin, maybe we could begin with just a brief introduction of the two of you and the company, just for the benefit of anyone online who's not familiar. Sure. Sydney, why don't you start? Sure. I've been at Sumo now for about three years. I've been associated with many, several high-growth pre-IPO companies. This is the first IPO I've done. I'm excited to be here. My CFO public company experience goes back to TIBCO Software, where I was there for nine years and CFO for about three. I joined Sumo back in 2014, but I first got a chance to meet the team shortly after the Series A in 2010. Kept my eye on them, tried to quote-unquote "partner," but they didn't want to sell early on. I got the pleasure and fortunate opportunity to join them in December 2014 and have been here since. We've completely transformed a lot of our product go-to-markets, we'll talk about. My background has always been in product. I was at VMware. I ran the cloud management business. I was acquired by Hewlett Packard, was in APM and infrastructure monitoring. I've built all those products from ground up at Mercury and started early on in Netscape back in 1996. Had some great companies to work for and some great mentors and bosses, and I'm fortunate to be in this role today with Sumo. Much history here, Ramin. Actually, I remember being on the IPO roadshow for Netscape, and that is a long time ago. Obviously, we go back to VMware and Sydney, we go back to TIBCO and I think beyond. Maybe you can give us a little historical perspective then on the evolution of Sumo Logic, because there are all these vectors of change. Can you help us understand, Ramin, the context of just where Sumo Logic started and where it's headed? What do you think the vision for this company is? Sure. Well, I think the vision hasn't changed and the mission hasn't changed. Our founders started in the security space with both ArcSight and SenSage, and were frustrated with a lot of the challenges that security practitioners had with not the technology, but the supporting tools and hardware and the like, to be able to run what effectively was going to be a distributed system looking at structured and semi-structured data analysis. They started off with a mission of providing it in the cloud for the cloud for security practitioners. Early in that journey, a lot of developers, DevOps, and other individuals started to leverage the service for troubleshooting of their cloud infrastructure and applications, and then evolved into full-stack observability and now obviously full Cloud SIEM and more. What's different about Sumo and the journey then to now is we've always been architected to be able to look at streaming data and analyze that streaming data, versus have to take other techniques to be able to look at samples or other technologies' limitations or technological limitations. We've always had an analytics stint and therefore a bias towards more data, all data, to look for patterns and apply that to specific use cases such as ops or security. Ramin, the product is incredible. You talked about sampling, and I want to come back to that in just a moment. The breadth of the product, you're ingesting so many different types of data, and you refer to this notion of continuous intelligence. Can you help us just understand what are the types of data that you have to ingest? Because you'll mention logs and metrics and traces and security data and all that. Then help us understand the way that you have overlaid some of the AI and machine learning techniques so that your customers are able to extract the most value out of that data. Yeah. I think the first important aspect of our strategy and vision is that it's not just about the technology. It's also about the people and process. If we bear in mind the fact that there's very few security practitioners and a lot more developers, there's this notion of how security is shifting left and DevOps is shifting right. Building a single platform that effectively provides continuous intelligence, to your point around the category we created, was an intentional and is an intentional strategy and effort for us. That is to make people accountable upstream for what they code, deploy, and manage, and similarly help ease the pain and burden of potential risk, compliance, and breaches downstream in SecOps or strategies. If you look at that vision and how we've been attacking that, it starts with the premise of streaming data analytics. Secondly, ubiquitous access to all types of data. Third, ubiquitous access for all users, irrespective of roles, so they can communicate, collaborate, and fundamentally do their jobs better. Now, in order to do that, you have to use a lot of technological innovations that we've built into our platform and service over the years. Excuse me. Some of that has to do with how we collect, how we process, and how we normalize various types of streaming data. It could be logs, it could be metadata, it could be events, it could be any type, right? In the security use case, for example. That's also very applicable to someone upstream in the operations use case. We're also converting a lot of that log data to time series or actionable insights to look for patterns. We're trying to connect the dots constantly to take a lot of the guesswork out. The simple reason is, this is no longer a human scale problem, it's a machine scale problem. It fundamentally requires a technology that's looking at streaming data analytics to be able to ascertain what's normal, abnormal, and so that you can address the what, the where, the why, and the how. The what is happening right now, whether it's a security event or alarm or breach or an operational performance issue, typically, that's monitoring. Other tools will do monitoring, just like Sumo does. Quickly you have to get to where did this happen? Why did this happen? Is this an abnormal, infrequent thing, or is this something that I need to address more broadly? Then after that, you go into more diagnosing, not just troubleshooting and remediation, and that is, how do I go fix this? How do I go automate and remediate this to prevent it from happening again? If you look at that full stack, therefore, you're going to be constantly looking at different types of algorithms applied through that monitoring, through the troubleshooting, to the diagnosing and resolution process. That's what we've continued to build out and refine in our platform and service. You use that term, it's become a machine scale problem. I think periodically we'll hear you reference the average daily ingest rates, right? Those continue to grow pretty rapidly. I believe you said it was something like 35% year-over-year, if not more. The volume of that, you are scanning 800 PB daily. Of course, I'm speaking back to the most recently reported quarter. You've built this platform, it's supporting a massive scale. Can you help us understand what is it that's enabling that on the back end? What type of engineering challenge did it pose just to be able to handle this incredible amount of data? We've had to architect, re-architect, architect, re-architect a lot of components of how we collect our ingest pipeline, our various persistent stores, how we reason and analyze that data throughout the years. That's a combination of a lot of proprietary technology we've built, as well as leveraging some other open source technologies, like Kafka, for example. One of the biggest advantages that Sumo customers have is what we hear oftentimes, set it and forget it. They set the collection, the data gets ingested, we normalize a lot of that, and we provide effectively the ding-dong lights all the way from the what, the where, the why, and the how. You don't need to then become an expert to go search for the data, because it has to be structured. You don't need to be an expert to go write rules to look for patterns, because we look for anomalies, and we detect those patterns. It's taken a lot of the guesswork out, and it's taken a lot of the manual work out, versus other tools that are out there trying to solve similar problems, because we are full stack. Bear in mind that one of the biggest challenges right now is a lot of enterprise organizations are straddling this very uncomfortable line, this bimodal world that they live in, where the trillion dollar spend in the data center is shackled with locks that's now starting to open up. The folks that are running infrastructure applications and security are concerned as all heck because the users have gone to the cloud, and now this is effectively a very distributed potential risk for the security practitioners in the sense that the surface of attack is much, much broader, right? Just by virtue of adoption of cloud and SaaS and the like. They know that they can't do this job alone, and so they're striving to partner with development and ops teams upstream. This is where it becomes a human issue and a process issue and an organizational issue, not just a technology issue. When we target a lot of these enterprise customers going through cloud migration, going through digital transformation, over the last 12 months and 14 months or so, a lot of that's been led by the security and infrastructure team bringing Sumo in to help the lines of business. Whereas prior to that, you saw a lot of innovation agility purely start in the lines of business with development teams, then security was informed after the fact, right? Now you're seeing both sales motions and both teams wanting a single partner, and they'll still choose best of breed, but they want us to integrate their endpoint. Most often it's more than one endpoint. Their firewall, their traditional appliance versus the cloud services, let alone open source and commercial technology. The advantage that we provide them is they're not having to rip and replace.They can extend and embrace as they make that migration from on-prem to the cloud or non-distributed to more distributed microservices and complex environments. How differentiated of a funnel is your ingestion engine, right? When you consider this 800 PB a day, you're absorbing it from on-prem systems and cloud systems simultaneously, right? You've got this vector of change you're talking about with the attack surface, which is expanding like crazy, and then you're able to kind of layer it on top, like you called it the ding-dong layer or whatever you said it was. You're applying the machine learning and the filtering right on top of that. Does that aggregation feel like something that's pretty differentiated just in terms of the ingestion? I think so, considering how much volume of growth and ingestion that we've consistently seen year-over-year while doing it at efficient margins, right? Yeah. A lot of those other tools that just do monitoring or just do search or just do security are nowhere near the size and scale, right? They have to take other techniques to aggregate and sample and the like because they can't scale the back end and architecture. We've talked a lot about various techniques and machine learning, statistical correlation, anomaly detection, but you can't lose sight of the fact that we also have tiered persistent stores that allows you to apply the persistent technologies for different types of use case at a much lower cost versus what other tools do, which is one size fits all. That's the next piece that I wanted to actually kind of go right into. You're using this term sampling, right, and aggregating, which is something that some or most of your competitors are using that process. They're sampling, they're aggregating. Can you contrast that a little bit against Sumo Logic where you're ingesting all of the pure raw logs, correct? Like full fidelity. Full fidelity, but it's not just logs, it's also all the metrics. Yeah. Awesome traces, metadata, events. It's the combination of all that, Mark, I think where you're going, that we're correlating and analyzing versus discrete sources that are aggregated that may give you one data point but not the picture of what's going on. Are you seeing a trend where customers of those sampling vendors, right, are struggling because those vendors have this different kind of limitation on the sampling? I mean, that's how they're architected, right? They're architected to sample. Are they struggling with that? Are they picking up the phone and calling Sumo because of those limitations of the vendors? It kind of depends on the use case and the team, right? The simple answer is yes, particularly when the customers have actually moved their microservices development services into production because that's when scale and reliability starts to come in, right? Where you can't rely on sampling or collecting a set of the logs, not all the logs, right, to correlate drift or to correlate and troubleshoot things. That's where predominantly a lot of these larger shops that have moved from three-tier to n-tier, from containerized VMs to microservices and Docker and Kubernetes realize we have a much more distributed system, and the average life of a container now is seconds versus days or weeks. I need to be able to stream and analyze all that data, not hope and pray that I caught it when that instance spun up and then spun back down. That's the reality. Why wouldn't you have a tailwind, or I guess I should say, should we expect you to have a tailwind from that multi-year? The world is moving to microservices, the world is moving to Kubernetes, and you're that much more differentiated in that realm. That must be a trend that you're very much embracing. We do feel like we're set up because of the architectural advantage and the portfolio expansion that we've done over the last year and announced in the fall and then earlier this year in terms of new capabilities, to not only do the troubleshooting diagnosis, but also now the monitoring, therefore full stack observability. Secondly, I think the thing that we believe that we're also well-positioned for is to address not just the reliability aspects but also the compliance and security aspects, right? Of these environments that are ephemeral data coming in, that are very complex in architecture, that are very distributed, and you need to be able to manage that from a lifecycle perspective, not just when I deploy to production. Meaning from source code repository through deployment into production and ops, but also into security. I think that's where we're seeing traction as well. You mentioned the efficiency and the margins that you have here. What is the cost profile here? Again, you're capturing and storing the very granular elements of the logs and the metrics and the traces and all that. You mentioned something, I think, about the tiering of the storage. What is it that you've innovated there so that you can do this at a low cost? Well, just to be clear, it's not storage or persistent tier, so a lot of it's in memory still, right? You need to be able to access it. You've heard about schema on read and write and various techniques and the things we do there. We're trying to make sure that through the tiers, it's very seamless for you to be able to look between continuous, frequent, and infrequent data access across different types of data. I'll give you an example. For PCI and HIPAA and audit types of purposes, that's a scheduled report. It's ad hoc. You don't need real-time dashboards and alerts and in-memory troubleshooting. Right? That should go to your lowest tier. You shouldn't be trying to pay for S3 even. You can do it for a fraction of that. Versus the real-time SOC use case, the security operations center or real-time troubleshooting monitoring for microservices, you need that continuous and frequent both types of data to be able to look at what's happened in the last few minutes, last few hours, and how is this compared over the last few days, weeks, and months. This is where you're seamlessly now going from one persistent store to another using the algorithms such as LogReduce or Log Compare or Time Compare. Now show me over this time, over that window for this type of exception, a null or error or whatever it might be, and show me all relevant data around that. That's with a click of a button. We call it the easy button, the Staples button, we call LogReduce or Log Compare. That's not requiring someone to write a query or to be proficient in our language. This is the application of statistical machine learning anomaly detection to a use case leveraging different types of analytics and tiered storage below. Okay. Maybe we can spend a moment on your various solution areas. I know this is always evolving, and sometimes the lines are kind of blurring, but if we think about it from operational use cases, security, business intelligence, global intelligence, et cetera, anything else you think is relevant in there, what are customers deploying most commonly today? Is there any insight into the mix, the trends, and then how many of them are deploying kind of all of the above? Well, I guess, first and foremost, what we've seen is a movement away from proprietary collectors, agents, probes, whatever you want to call them, to more open source. Right? Therefore, you're really in most organizations that are leveraging Sumo Logic, it's still the best of breed of commercial open source that we're interacting with daily on the DevOps side for observability and monitoring. Right? You compare and contrast that on the security side, it's very much I have my old real estate, and I'm firewalling off that, no pun intended, maybe so. My new real estate is all going to be cloud services or SaaS technologies versus traditional software that I'm managing for endpoint and firewall and the like, and identity and access control. Two different worlds. In terms of the second part of your question around the use cases, it's not much different than we've highlighted before and after our Q4 and Q3, where security and enterprise is leading indicator for us, particularly for the cloud migration type of customers. Everyone's going through digital, but at the end of the day, they've identified Tier 1, Tier 2, Tier 3 workloads that they're going to either migrate and modernize, they're going to modernize and either just maintain or they're going to deprecate. Right. In that journey that they're looking at their digital transformation and their application tiering, there's a lot of traditional stuff that we have to integrate to on-prem, like you said. Top of rack switch, endpoint, firewall, all that stuff. You have to be able to run that bridge from the old to the new. Today, security is still about 30%-40% of our business in a given quarter, but you're seeing more than just logs from on-prem being fed into Sumo. You're seeing other types of data as they're trying to baseline those workloads and figure out how they're performing in a three-tier architecture versus an n-tier architecture in the cloud. This is where it allows us to collect time series data in addition to logs for the migrational workloads, and then via the full stack observability as it migrates to the cloud. That 30- The second- I'm sorry, go ahead. The second use case, which was observability- It's still about 55% of our business, and the remaining is for that customer success, BI type use case that we referred to. The security mix at 30%-40%. We have the SolarWinds hack. We've got Microsoft's hack, a pretty global email hack. What is that customer discussion like right now today? Well, I think it starts with us assessing where the maturity is for cloud and SaaS technologies. I think over the last few quarters, it's not about if, but when and how fast now that they need to move. It's not an overnight thing that they can get rid of these agents from SolarWinds or XYZ tool that they've deployed. They're trying to bring in rescue services, I call them, to be able to understand and assess their sphere of potential risk and then figure out how they can migrate and modify their tooling and processes associated with that. The front end of this problem for a lot of customers is actually with consulting companies. Right? That's what's been going on. To consult to figure out how to migrate to a Sumo-like architecture and service and a Cloud SIEM to address the kind of breaches of risk. Usually, that includes then the trial or POC with Sumo, working with a VAR or consulting implementation or an AWS in terms of the technology evaluation. I think first phase of that where a lot of customers are going through is assessment. The second phase is then the plan. The third is the POCs and trials of the services, right. I think a lot of customers are still between one and two, to be blunt. They're reacting as a result of what happens forward. Is there a good flow or a good lead-in for them, like for Sumo to be in that discussion as they get into Stage 3, which would be getting a little more into a pilot or into production? Yeah. I think it's a combination of the reality that they can't rely on the old technologies and ways, and secondly, the people that implement a lot of those tools, wrote the rules, and everything else, are not typically around or know those systems, right? Yeah someone that can help bridge that, not necessarily rip and replace it. I think that's where we're well-positioned. I think the other aspect of this is, we're constantly building out our security portfolio, right? Not only in terms of our Cloud SIEM and the ecosystem of technologies that we're continuing to enhance and integrate to Sumo, but also now with the acquisition of DFLabs closing and the SOAR capabilities that we'll be adding to the mix, will help a lot of those customers in that transition. Okay. Ramin, that's extremely helpful. I wanted to ask you about one other element of Sumo Logic's differentiation, which is, I'm thinking back to when we were really heavy into the customer diligence that we were doing, we were just constantly hearing from those customers that the breadth of use cases with Sumo Logic is just inherently broader, right? The use cases, then they would also say the breadth of user roles is a lot broader. I think because as you said, they're not in there coding and writing heavy scripts, right? They would say, it's not just developers. It could be someone in sales ops. It could be someone on a product team. It could be someone in finance. Where do you think you are in this journey? It was a very powerful situation for them. Where do you think you are in this journey of democratizing access? I wish we were a little further along. I think truth be told, we're seeing strong traction in the core user base, which is predominantly the technical folks on the development side, the op side, the security side. It starts with them, right? Then extends into these other support functions that are dealing with the interface to the customers and managing the metrics of the business, like retention and risk and renewal and CSAT and all that stuff, right? I think truth be told, there's also another aspect to that that we haven't yet really tapped and scratched. As the data center footprint continues to shrink and things move more and more to the edge, it allows us to go after some of the traditional data center infrastructure folks that are responsible for that strategy, both on infrastructure, architecture, and tooling, in addition to those other ancillary support functions that we just talked about. I think given that's such a small percentage of our business today, that's an opportunity for us going forward. Make no mistake, we're focused on what is core to our business, which is first and foremost, the observability and reliability area, where there's thousands and thousands of opportunities out there to go after as they build new or migrate. We're continuing to double down on supporting, integrating, and doing more for the open source community, in terms of our technology and integrations. Second, it's connecting that to any cloud and any data type. Third, it's around ensuring compliance and security so that security can't be an afterthought. That in itself is a $50+ billion TAM. We're not trying to create a bigger TAM. The TAM is becoming bigger by nature of people moving to the cloud and the architecture of the applications and the volume of data growth that we keep talking about. We're well-positioned to go after not just the cloud-native companies that we've been historically talking to and selling to, but now over the last couple of years, those that are cloud laggers and going through that migration. Okay. $50 billion to go after there. Sumo, it's been a business that it just continues to grow and grow and grow, year-after-year, quarter-after-quarter. You did have, like many businesses, there was a hiring pause, right, in the early days of COVID. You have to stop and assess and think about what's going on in the world. Again, like many businesses, that affects the sales capacity now today because you have this lag effect. You had a couple customers that did capacity downgrades, right? It hit the retention a little bit. Again, most businesses saw that. How do you feel you've been addressing some of those factors or some of those elements in the business? What are the signals now that might be giving you pretty good confidence in the progress there? You want to tag in this one? Well, sure, you can start. Sure. You are right. We did pause hiring in the business, and we are a direct selling model, so that quota capacity is extremely important for our growth as we look forward. We resumed that hiring in Q3 and Q4 of last year. We did hit our quota rep targets for hires ending the year, and we've continued to expand that hiring. As we think about navigating that, as we came out of Q4, we saw some good stats coming back. We saw one of the best quarters we've seen in four quarters in our international business, specifically EMEA. We saw the average deal size come up. We saw momentum in enterprise business and, in particular, enterprise security. As we were exiting the year and coming into this year, we were starting to see that momentum come back. Having said that, I think it's headwinds and tailwinds. We also saw that sales cycles were a little bit longer. We saw that our mid-market business, those budgets, and that directly impacted our dollar-based net retention, was condensed down a bit during the COVID. We've seen both headwinds and tailwinds on the business, but we were encouraged as we were exiting Q4. Only thing I'll add to that is, probably like many other companies, when we first entered COVID, we thought it was a matter of weeks or maybe months, and so there was a lot of focus on return to office. I think now there's a lot of focus is on the look and shape of the workforce. It's about distributed teams and being where the talent is instead of having hubs or headquarters or the like, and find that right balance. We're still maturing that way because we were predominantly North America in terms of a lot of our headcount, outside of engineering, I mean. We've been distributed more and more, and that gives us an opportunity to go where the talent is. It also allows us to support more locale in terms of the investments we're doing on the go-to-market side as we expand into other regions. Because we have great opportunity ahead of us in terms of contribution from international, in addition to channel and the like. That gives us a different view as to where and how we need to hire, not just in our North American enterprise. The only other comment I'd make is that we've talked a lot about the COVID impact of industries. It's not just about COVID. It's the macroeconomic situation where, in the last couple months in India, it's a very delicate situation for employees and the community, right? We've had to do stuff over the last few months, last few quarters, to support customers as they've had issues with their own employees and their own business, right? As much as we feel that in the U.S. things are turning around, it's not the case everywhere else. We got to remember that. We're trying to make sure we continue to support our own employees, our community, and global strategy, not just the U.S.-centric strategy. It sounds like, Ramin, and not to put words in your mouth, but it sounds like you saw some good signs, Sydney mentioned, coming off of Q4, and that the hiring cadence was solid for the quota-carrying reps, right? It sounds like you're cautiously optimistic on the reopening in the U.S. You're balanced in terms of it's going to be a little touch and go with some of the geos, some of the customers, maybe some of the industries outside the U.S. Is that a fair way of summing it up? Yeah, I think we all should be realistic. Yeah Because it's easy to let your guard down and assume because the vaccination rate in California or this locale or city, and therefore everywhere else is the same. That's not fact. Secondly, many people are not yet returned back to the office, and they're still struggling with mental health and well-being and the like, and that's just a fact. I think third, where a lot of budgets last year shifted to VPN, work from home, and more, they're gradually shifting to those digital cloud migration, not just signing up with the cloud vendors. You still need the people to move those workloads, so there's still time in that process that I still have to play into fact. Those are the things that we see as realities, but we're not mistaken in any way. We think more and more of the market opportunity continues to come with us and is going to come to us, I mean. It's not, again, just the cloud-native folks that we've been targeting, but the massive opportunity for those that are in that transition to cloud and frankly, having to modernize security at the same time. It's great note to end on. Sydney and Ramin, I can't thank you enough for taking the time here, and both of you, great to spend some time virtually in the Sumo Logic office with you today. We look forward to seeing you in person soon. Likewise. Can't wait. Have a good one. Cheers.
Loading workspace