Good afternoon. I'm Sanjit Singh for the Morgan Stanley Software Research Team. We are coming at the end of day two of the Morgan Stanley TMT Conference, and we're ending it with a bang. We're so happy to have the CEO and the CFO of Sumo Logic. Ramin Sayar is the CEO, Sydney Carey is the Chief Financial Officer. Ramin and Sydney, thank you so much for joining us this afternoon. Looking forward to an interesting conversation. Sumo Logic went public. It's one of the leaders in the log analytics and observability space, and we're going to talk about their differentiation in this market. Before we get there, though, let me go through some quick disclosures. For important disclosures, please see the Morgan Stanley Research Disclosure website at www.morganstanley.com/researchdisclosures. If you have any questions, please reach out to your Morgan Stanley sales representative. With that, let's start the conversation, and maybe we'll start from a high level. Ramin, can you just sort of walk us through the thesis behind the company back when it started in 2010, and the types of problems you were solving initially and the types of problems that you're solving today for customers? Just giving people listening to the webcast an idea of the positioning of Sumo Logic and what problems you're solving for customers. That probably- Sure. A good place to start. First, Sanjit, good to see you. Looking forward to doing these hopefully in person as things open up. Rewinding the clock a little bit, Sumo was founded in 2010 to really solve some challenges that were effectively felt in security, but a lot of cases were developed upstream in how applications and infrastructure was managed. As a result, the team early on had a vision to bet big and go big in terms of building a cloud-native architecture that would analyze all streaming data, not just log data, but metric and metadata and much, much more, to be able to provide a full analytics suite so that customers could better do several things. One, build software applications. Two, ensure reliability of those applications. Three, ensure quality of those applications. Actually that's a little bit inverse because of how DevSecOps works. Last, but definitely not least, four, ensure security and compliance of these applications. Hence, the strategy around DevSecOps. Great. That's a great introduction. If I could actually do just a first quick follow-up. You started talking about this vision around a cloud-native architecture way back in 2010. How long did it take before that became the reason why people chose Sumo Logic over your competitors? Was that something that you saw early on in 2012, 2013, or was it until more recently where part of the main reason why I want Sumo Logic is because they're cloud-native versus some of the incumbents in this space? Well, truth be told, a little bit of both. I think what we saw early on, was that the vision that we had, customers wanted. However, not all organizations were ready to move to the cloud and were building workloads in the cloud, and hence, weren't transforming security associated with that. As a result, we were targeting like-minded individuals that were cloud-native architectures or born in the cloud, like Sumo, in the early years. Then over the last however many, three to four years, seeing more of the mainstream market, and particularly even during COVID, start to stop, pause, and rethink, how am I going to be spending and investing my dollars in terms of infrastructure as well as application, and last, but definitely not least, security going forward. We had the right vision a little bit early to the security practitioners, but definitely right timing and vision for those that were building native in the cloud. Hence, why 60% of our business is around DevOps and site reliability and core platform engineering in terms of users and revenue, and 40% today is around the security part of our business. That's great context. In terms of the look back into calendar year 2020, how has the pandemic, which unfortunately we're still going through, but hopefully coming out of it, how has the pandemic sort of changed your view about the market opportunity overall? As you look forward over the next two or three years, how has it sort of changed your view on the market opportunity? Having to do everything remote has fundamentally changed the way we operate. That is not only how we hire people, but also how we grow and develop people. The second is the buying behavior and the process changed. Not so much for mid-market, but definitely for enterprise and definitely for certain geographies or countries where you're used to selling face-to-face. In EMEA and Asia-Pacific, in Japan in particular, right, in Korea. They're not used to doing Zoom calls to buy software, right? That was kind of a learning thing for not just Sumo, but the partners as well as the practitioners as they're looking at embarking on that journey. The third part, I think that's very obvious, is that we had certain segments and verticals that were heavily impacted, like others, travel, in particular hospitality, and some of those are stabilizing. By and large, there's still a bit of caution related to when their business will return. I think net-net, we've learned and adapted and grown. We've definitely continued to invest because we believe that the market opportunity, particularly for the enterprise segment of our business, is accelerating coming to us, driven by cloud and digital, and to some degree, even with COVID. Understood. To pick up on some of the last comments you made there, this would be really directed to Sydney. Sydney, as you look back on calendar year 2020 and summarize some of the challenges that you've seen from a growth perspective in some parts of the customer base, and how much of the customer base saw a benefit, whether it's customers in verticals like e-commerce or digital retail or gaming. What's the summary and the impacts across the customer base, and how would you summarize the net impact on year to date overall? Sure. Just to remind everyone, we're in our quiet period for Q4, I'll comment back from Q3. COVID definitely provided uncertainty and volatility. As we look at our business, we saw some headwinds in our mid-market and international segments. As Ramin said, our enterprise business has actually done well through this COVID impacted times. We're seeing that our businesses, less than 7% of our ARR is actually in travel and hospitality, although those businesses have been impacted, and we've seen on the flip side, the enterprise segment and security being a growth driver for us. Great. Moving to the discussion in terms of the product capabilities. I think of Sumo Logic in three major pieces, and there's probably actually four. If you think of it as a core IT operations platform, a security analytics platform, and then increasingly an observability platform, can you talk us through the journey and the traction you've seen across those three dimensions of the business over the last year or two, Ramin? From your customer's perspective, the adoption in these particular teams, in these particular use cases across departments. Okay, let's start, I think, because security tends to be top of mind for many folks, given what's happened in the industry. I think one of the biggest changes that we've seen as a result of unfortunate circumstances with some companies being hacked, also because of COVID, which has accelerated a lot of enterprise migration to the cloud, is the importance of security transformation, right? No longer is it acceptable to have a non-real-time analytics-based service that's really helping you get a full 360 on everything from infrastructure to application to data flows. I think we're very strongly positioned there. The second thing relevant to that, it's not just about the traditional security aspects, meaning firewall and endpoint, and everyone's calling XDR the next thing. That gives you a sliver or a subset of really what's going on. You have to go upstream to understand components of the application architectures, API to API calls, to really get that holistic view as to your vulnerability and threats, as well as reliability quality, like I mentioned earlier. What we're seeing now is security teams and the CISO is becoming that champion and that partner for these transformation deals in the enterprise. Whereas before, they were a little bit after the fact coming in because the DevOps teams had already moved. That's one trend. Second trend is the acceleration of modern application architectures. We've seen this in our lifespan when you went from client server to three tier architectures, now to N-tier architecture applications. Everyone talks about microservices and Kubernetes. Well, the acceleration of that in production is creating a lot of complexity, meaning that it's not just a developer that has this issue, it's the site reliability engineer. It's also the security teams downstream that have to look at this collectively. The silos that existed that prevented this collaboration are now having to be torn down because they want a collaborative view and an integrated view of how things are performing. Net net, in one case, you're seeing enterprise security teams and CISOs lead the charge. Another case, you're seeing DevOps teams look holistically and also want to partner with security to be able to drive on a centralized strategy. The reality still is best of breed prevails in most of these organizations. They're bringing together multiple tools and architectures to solve the velocity challenge of how to get software out faster. They're trying to bring a variety of tools together to solve the reliability, not just observability. Observability is about monitoring, right? It's more than monitoring. It's more than the what. It's the why, the how, and the where, and this is why reliability comes in. Third, again, the security. These trends are effectively allowing us to do more multi-use case sales out of the gates for net new logos in enterprise, as well as for existing customers as they expand from the initial use case to cross use cases. As we've evidenced and talked about in our last earnings call. That's right. Just to pick on the security topic, with the sort of framework that you've laid out around these secular trends around microservices, Kubernetes, and more complexity in the cloud, how does that inform how you guys are approaching security and security analytics versus some of your competitors, whether it's Splunk or Dynatrace and some newer entrants into the market, Datadog? Where do you see as sort of the key distinction between how you guys are looking at these capabilities versus some of the others? Yeah. Let's try to separate some of the FUD, right? I think security monitoring is different than security analytics or Cloud SIEM. It doesn't take much to be able to collect some log data or security monitoring events and to try to present that in the dashboard. That's basically the what. You still are struggling with the why, the where, and the how. This is back to not just monitoring versus observability, but even more so for security. How are we different? We started from security bent and background. That's our legacy and our strength. We started with the architecture, again, that looked at all data types and streaming data types, and not necessarily having to shortcut things by sampling, aggregating other techniques, because monitoring tool architectures can't address security problems. Second differentiator for us is not only do we have that security strength, but we have that analytic strength. Because we provide not just analytics across the pipeline as data comes in and is processed, but allows you to have the economic value across different types of tiered analytics per the use case and per the user's needs. You're not being overcharged, over-penalized like you are with some of the traditional vendors. There's always this data tax overhang for customers. The third thing is, you don't always innovate through IP. You have to also innovate through the value of the service. The time to value, the ability to get multiple users, thousands of users on without having performance issues, having other access issues or licensing issues, is another strength that Sumo sees from a lot of our customers. Last but definitely not least, it's the quality of service. Bar none, if you talk to our customers, and the majority of them, whether it's an SMB customer to a large global enterprise, what they see and feel every day when they log in or they experience a Sumo employee interacting with them, it's that passion they have for what we do. It's also the service and reliability they get from us. Another thing that's happening in the market, not just with the monitoring players, but you're starting to see the traditional security-focused vendors, a CrowdStrike, a Zscaler, Palo Alto, starting to bring in monitoring capabilities. I was wondering if you just help me do my job and be a market prognosticator is, what's going on here in terms of monitoring guys trying to move into the security space and vice versa. As we think about who has the strategic high ground in terms of solving these problems for customers, what's the best place to begin? The policy layer coming from the security side, or on the data processing analytics intelligence layer, as we think about this market over the next three to five years? I think that depends on the customer's maturity, to be blunt, Sanjit. I think those that have banged their heads against the walls for more than a decade trying to make the legacy SIEM on-prem or the legacy firewall appliance, you name it, model work. They're done. They're fed up. They want a service. They want an analytics-based architecture, and they want something that's broader than just firewall endpoint and traditional components. That's why they're moving to cloud-native architectures for SIEM as well as applications. I think that's where we're continuing to be uniquely positioned. Now, despite what anyone, the security vendors like CrowdStrike or Palo Alto or Sumo says, it goes back to the customer needs and where they are in that migration. Our approach is really consultative, not to try to go in and rip and replace. Because a lot of these large enterprises are running bimodal. They need to transition to the cloud. They need to transform their security practices. They can't just rip out their appliances and move to firewall services overnight. They're changing their email and security practices because of challenges there. You have to be able to integrate to those non-third-party solutions, and this is where we differentiate. When you have a point vendor that does endpoint trying to do broader, and they're not historically ever been doing that, it's a big challenge. When you have a point vendor like Palo Alto now has to integrate their competitor's data, or similarly, CrowdStrike has to integrate their competitor's data, how much trust is there from a customer to be able to rely on that? We've been independent and we've been integrating all that data for a decade plus. Right. Probably another area that you have some good perspective on, this is not to say that all things are moving to the cloud, but in terms of an operating model, I think what's high on the strategic priority list is moving to a cloud operating model. I was wondering if you could just describe the challenges that are involved with that from both IT operations, but from a business execution standpoint, as well as a security standpoint. For a large enterprise customer that didn't start in the cloud, just how much of a challenge is this going to be? Is that something that they should think about, this taking three years, two years, five years, in terms of getting the business to operate at this cloud-native operating model? Yeah. I think what's interesting about that is, there are three distinct types of challenges. One is around the economics. Because a lot of cases, these customers that are going through this transformation have to make a shift from CapEx to OpEx. In doing so, they need that time to bridge from traditional legacy tools to new modern tools. The other aspect from a commercial's perspective is the types of indemnities, liabilities, contracts, the commercials are all different. If you haven't really done that much SaaS or cloud agreements as an enterprise or mid-enterprise customer, there's some learnings they have to go through there. There's a bunch on the commercials. Second is around the teams and the process associated with those teams. If you look at most enterprises, they have typically a centralized IT team that's a shared service. That model is going away, right? It's no longer, I'm going to charge back, show back. In most cases, now the budgets are gone to the lines of business for DevOps, or they've gone to security. Centralized IT doesn't necessarily, in all these cases, have that authority or budget. Now they have to go partner, develop their own skills, and then pull in the lines of business dev teams and/or security teams to make a holistic architecture. In result, what's happening is they're creating centralized architecture teams that's combining security professionals and practitioners, DevOps professionals and architects, as well as centralized IT to make those decisions. Right? It doesn't mean that they're going to pick one platform. A lot of cases, they have to integrate still a best of breed. There's a lot of process and organizational challenges that we see as enterprises, in particular, go through this maturation and go through this transformation. I think the third piece is really on the technology, right? If you rewind the clock and say four or five years ago, majority of CISOs weren't adopting SaaS and cloud and weren't familiar with a lot of the common components that were used to build, manage, and release software or some of the infrastructure services. Now they know those. They have to know those, right? They have to be understanding how they have to integrate the application context as well as the web app infrastructure context, in addition to what they've traditionally done with respect to network, server, storage, endpoint, firewall, and everything else. Now their teams are having to broaden their knowledge, right? Understand broader technologies and be able to leverage those technologies. What's happening, unfortunately, they're being inundated with false alerts. They're hooking up more pipes of data coming in. This is why back to the conversation earlier and the question about some of the network or firewall or others claiming XDR. They don't need yet another dashboard with a ding-dong light. They need less noise. They need less duplication. They need analytics. They need all that data that's rationalized and provided to them in an intuitive way so they can take meaningful action on threats, not false positives. That was a great overview in terms of the challenge that a lot of these companies are going to be facing in terms of moving to that model. Let's do a quick update on just the core monitoring observability capabilities at Sumo Logic. From my perspective, 2019 was a year where you really sort of stepped up that investment in terms of Kubernetes clustering monitoring. Where do you think you stand today from a capability standpoint around microservices, Kubernetes, application tracing, ability to monitor a serverless environment as of last quarter. What's been the progress from 2019 to today? What would you highlight from a capability standpoint? I think from a timeline perspective, if you look at when we entered the monitoring space, this was much earlier in our company trajectory. I don't know why I said career, we were always ingesting logs, metrics, metadata, right? In fact, we were the first vendor in 2015 to announce unified logs and metrics natively that were correlating those, not disparately in different backends or tools, right? What's transpired since 2015 and started really in 2017, is the acceleration of more of the modern architecture components, right, that were being not just in design and build phase, but actually in production phase coming to fruition. More services from the cloud vendors, cloud hyperscale vendors being adopted as well. That created, as a result, more complexity. This is where we started to really step up, not just the environments that we cover and integrate from a data collection point of view, but also the analytics and things around outlier predictor operators, time compare, and others that actually brought logs and metrics, correlate those together, so you can address not just that what, but the where, the why, and the how, again. In 2017 is when we really debuted a lot more of the monitoring and full stack capabilities. In 2019, we started adding distributed tracing beta, but more importantly, Kubernetes monitoring and auto-discovery, right? In 2020, which was last September, our fiscal 2021, just to be clear, this is when we had the full stack of observability suite packaged up things for CDN, AWS observability, and the like. The innovation engine at Sumo has been very strong. That's a great overview. I sort of mentioned earlier that I thought of Sumo Logic in three core pieces, and there's actually probably four, which is your global benchmarking capabilities. Can you talk about why was it important for you guys to offer this service to customers, and how has it sort of made it a differentiator? Is it helping to sort of improve new customer acquisition? Because there's not, like, remember, most of your competitors don't offer a similar service. Why is benchmarking capability important? Does it drive any sort of network effects? Well, I think first and foremost, it goes back to the point around false positives, right? An average enterprise IT organization or enterprise IT or security organization has over 30 different types of analytics and reporting tools. They don't need another one giving them more worse data, right? Monitoring creates a lot of noise. All along, that's been core to our strategy, as you know, we not only provide the mechanism of collecting that data to do monitoring and full observability, but also bring together the analytics capabilities to be able to reason and ration over that data, to separate signal to noise, and more importantly, what to go fix and/or remediate. The Global Intelligence Service that you're talking about helps with a couple things. One, takes some of the guesswork out. We look at thousands of customers, users, all the data that we analyze every day, and we look at anonymized data to start to look for patterns, and then we'll compare those patterns to your specific environment. No longer are you asking yourself, "Is this normal for me for this time of year?" Maybe, how does it compare to other peers of like size, not just the industry? That gives them that extra assurance that the reliability of that data and the analytics that we're providing is helping them identify something faster and, more importantly, resolve something faster. When we think about some of the key debates in this space, one of them has been pricing, and you guys have differentiated yourselves on the pricing element as well, and there's a number of different approaches there. There's per user, there's per host. Other people price by product. You guys have gone out with a very specific credit-based system, and you've evolved your pricing strategy over the years. Can you speak to the current way you're looking at licensing and pricing, and why do you think that offers an advantage over the multitude of approaches out there in the market today? Yeah. Unfortunately, customers are being nickeled and dimed, right, with respect to various pricing schemes by various vendors because of either limitations of their product, their architecture, their transition of packaging, whatever else, right? All along at Sumo, we've been very transparent. When we first introduced our service, as you know, we allowed for customers to not be penalized if they went over the day, right? Specifically to charge them an average for the month. That Cloud Flex model is an important distinction because the expectation is that the economic model has to mirror the operating model of the cloud. As more users come on, as more data comes on, I shouldn't be penalized, right? Particularly because I have variability in that pattern, I should be able to pay for what I use or be able to have some freedom of being able to mix and match features based on release cycles or criticality of a security event. That's how we've architected our platform, that's how we've developed packages, and that's how our licensing has evolved to really provide that economic value to meet the operating value of the cloud. We're not doing these gimmicks that we're charging for CPU and core and users and all that. Ultimately, you end up with, guess what? Sticker shock and frustration. There's too much of that. It's very transparent. What you see is what you get. You see how much you're using it, you see when you're about to run out, and how to optimize it. We find with that transparency, it allows more users to come on, more data to come in, more use cases to grow. Your economic value becomes more because your unit cost goes down, and therefore, everyone's happy. Great. The second debate that I get asked about increasingly over the last six, nine months is sort of the technology wars. You hit it a little bit at this. For people listening on this webcast today and they hear the debate around schema on read versus schema on write, do you pre-index, do you sample, how many databases support your product? Do you have a unified database architecture? Do you have multiple databases? If you sort of bottom line it in terms of looking in from the eyes of the customer as they make their purchasing decisions and look to go bigger with particular vendors, is this just sort of a myopic, idealistic technology debate, or is this something that customers are increasingly looking to in terms of points of differentiation along these dimensions? Well, I think part of the reason why that issue or that topic comes up is that there's a shift in perceived or actual value of where the IP is, right? For quite some time, monitoring vendors were charging a lot for proprietary collection. I have all these library of collectors, right? Therefore, you can get access to from Unix to Linux to XYZ systems, right? We'll keep maintaining those as you evolve or upgrade or don't. Now, what's happened is if you look at cloud, things are available through an API. If you look at cloud architectures and applications, more open source is used to develop components there. As a result, more protocols for collection and instrumentation are used as part of the architecture of applications and infrastructure. What does that mean? That means that traditional monitoring tools and what they charge value for has shifted to be able to ingest all types of data, right, streaming data, and not necessarily sampling or aggregating or charging by code or component or by code instrumentation. That's what's really customers need is to be able to send all the data, normalize that data, be able to get instant value as to what has happened, where has it happened, why did this happen, and how do I need to go fix it? They need that full understanding. They can't have partial understanding. When they try to go test the vendor's technology and they understand that in limitations of scale because of concurrency of users or limitation of scale because of schema on read or write. That's because they're evolving to what they're expecting to be charged for. Secondly, they're expecting real-time accessibility and viability of access to the data that's ingested, not latency. That's great. Well, Ramin and Sydney, we're all out of time. 30 minutes goes fast. We really appreciate you coming in the middle of your quarter to give us an overview on the Sumo Logic story. It's great to get an update. For everyone that's been joining us on the webcast, thank you for joining us. We still have some great presentations left. Please visit those. Again, to the Sumo Logic team, thank you for joining us. Have a great evening and afternoon.
Loading workspace