All right. Well, welcome everyone to day three of the Morgan Stanley TMT conference. I am Sanjit Singh, the infrastructure software analyst on the Morgan Stanley software team. Super pleased to have the management team from Sumo Logic. We have Ramin Sayar, CEO, and we have Stewart Grierson, Chief Financial Officer. Thank you both for coming to the conference. Thanks for having us. To kick off the conversation, I was thinking maybe we could just do a little sort of year in review. You reported results last night, Ramin, and saw revenue growth accelerate. As you look back to sort of calendar 2021, and you think about how the business has performed coming out of the worst parts of the pandemic, where do you think the company's executed well, what needs improvement, and what are the sort of remaining frictions to getting to that faster growth rate? Well, first of all, I think we executed the plan and beat what we guided to. But that came from a lot of inspection around where our product was, where the market's going, and we dramatically built out our product portfolio over the last 12-18 months to be able to capitalize on this massive market opportunity. I think we executed the product portfolio build-out as well. Second, I think we talked quite a bit about the evolution of our go-to market and how we're trying to make sure we get the transactional run rate business back, as well as diversifying our business domestically, internationally, and direct versus indirect. By all means, Q4 was a very balanced quarter. We ended the year with good contribution across all those vehicles and routes to market. We just need to be doing more of that as we head into this fiscal year, and that's exactly what we communicated. Increased investment 'cause we have increased conviction in terms of our ability to execute, reaccelerate revenue, and drive more cross-sell as well as new business. Great. If we look at Sumo Logic's set of opportunities across operational intelligence, observability, security intelligence, and even business intelligence, 'cause you guys do a great benchmarking work, for your customers, how do we think these portfolio opportunities, what do you think will be, like, kind of the dominant drivers of growth over the next one to three years? Well, they're interesting, they're separate markets, first and foremost, because the motion for cyber and security analytics necessitates, you know, practitioners, which are security analysts, threat hunters, in addition to a CISO, right? So they're different buying centers. Versus monitoring to observability, it's really developers, site reliability engineers. That's something we've been doing all of our life- Mm-hmm. in terms of existence. Now, as we look at our strategy, we're trying to have a balanced portfolio of observability and security, right? Secondly, contribution across those use cases. To execute on that, we've built a single platform that addresses both those use cases and a licensing and pricing mechanism that allows for customers to start with one and expand to the others pretty seamlessly. We've tried to guide and give some context around the contribution of ARR and revenue around those two. You could think of it as pretty balanced 50/50, so to speak, across observability and security. I think that by and large will be there. I think if you flip it around, for the customer, the value is this is not a static life cycle, right? As you release new digital applications and you modernize it, you also have to think about not just observability and reliability, but also security. Our single platform allows them, as the life cycle of these services evolve, in the event they have a critical operational issue, in the event they have a critical security issue, they can dial up the usage of Sumo, so to speak, by not just ingesting more data, but analyzing that through metering. That's not what they can do with other technologies or tools or platforms. Right. I think one of the things I've been most impressed by over the last 18 months since you guys have become a public company. I mean, you've really expanded that security portfolio side of the house quite significantly from SIEM to security analytics. You made an acquisition in SOAR. You address the audit and compliance use case very well. As you think about the broader security environment, which seems very positive, how do you feel about where the portfolio stands today to satisfy kind of the more demanding requirements from these security operations teams? These are sophisticated buyers. What needs to happen to really unlock growth and get the payoff from this investment in the security portfolio that you've been embarking upon? I would argue the payoff is starting already. Mm-hmm. Mm-hmm. Secondly, that's our heritage. We started from cyberspace, as you may recall. Founders came from security companies, and we started off building log analytics for security professionals, and then ultimately developers started using it. We have that understanding of mission-critical SaaS provided technology so that you can quickly investigate, not just identify issues pretty quickly. To maybe double-click on that a little bit, if you look at where the security market's going, there's a few challenging trends for the practitioners. One, shortage of staff. Two, a lot of legacy tools that are still in the enterprise. Three, the surface of attack is much broader now than ever because a lot of the data is now shifted from your on-prem colos to SaaS and endpoints and things that are outside your control. Now you need a holistic approach, not just by the security team, but also those who are deploying code and pushing codes to work collaboratively. That's what we're uniquely positioned to do, is to break the barriers between development operations and security by one single platform product. Observability tools will do one, security tools will do another, we do all. You and I have talked in the past about XDR and its relationship with the SIEM. When you see the role of the SIEM in relation to some of these newer frameworks, in terms of how these two pieces can come together over time, and how are you sort of thinking about enabling that? I think you made an announcement, you know, joining an OpenXDR community. Can you talk about these two pieces and how these are gonna evolve, and what does that mean for a growth opportunity for Sumo Logic? Well, first and foremost, they're complementary, not competitive. The fact that CrowdStrike has their own or some endpoint creates a repository dump the data, that's great because data's growing faster than budgets, and you need a way to persist that in a domain manager, and that's what XDR is. It's an element domain manager. It's no different than what was called before with a different acronym or letter in front of the D or the R, right? You know, tongue-in-cheek aside for a second, collectively, we're all dealing with the growth and explosion of data, and things have to be persistently analyzed in those element domain managers like they were in the network tier or now the endpoint tier, and you still need an agnostic solution that takes all of it and from all competitors and all providers and analyzes that from on-prem to the cloud, and that's what Sumo's done for over a decade. We came from that experience, and we provide that capability. When customers make the decision to migrate off of one endpoint to another, or migrate off one network firewall provider to another, or from on-prem to the cloud, they're future-proof. That's what Sumo can help do with the security perspective as well as reliability perspective. Right. I think when we looked at sort of the observability market, what are the things that the forcing functions, if you will, that brought APM, infrastructure monitoring, log analytics together was frankly that the collection of data became more open source, right, with the OpenTelemetry movement. Didn't really feel like that's the case with security-related data. I wanted to get your view on when we think about trying to create more improved threat detection, bring more automation, and maybe you can sort of touch on this with this sort of OpenXDR movement. Where are we in that curve of trying to sort of democratize the data on the security side as we have seen on the observability side? Truthfully, the industry as a whole, we're behind. Right. If you compare and contrast what's going on in the other side of observability or metrics and monitoring, long gone are the days of paying overpriced, you know, for host or per agent because you're collecting memory, disk, CPU, latency, IO. Like, those are bread and butter kind of metrics. Table stakes. What's happening there is the movement to OpenTelemetry, to your point, is to standardize on the data formats for logging, for metrics, for tracing, which we contributed a lot to, and it was a foundational part of our observability strategy. Unfortunately, though, the same is not true on the security side because the endpoints are changing, the network interfaces and APIs are changing, the access controls and gateways are changing. Until those normalize to new, more cloud architectures from a security point of view, you can't see the same benefit that we're seeing in the observability side. But I fundamentally believe it will happen. Mm-hmm. We all have an important role to play there. Mm-hmm. When you think about where security is going and becoming more sophisticated, if you will, in terms of the battleground, I think you know, my colleague, Tom, and I put out a report just talking about where security analytics might be going. We sort of arranged or sort of organized kind of two groups. The guys that have the domain expertise, which is sort of been your security incumbents, and then kind of a new class of players that have that advanced data processing, data correlation, kind of your machine learning- Yep big data capabilities. What's going to be more important to buyers over the next few years? Is it gonna be the ability to do that event correlation analysis, or is it gonna be, you know, "Hey, my security vendor knows my business really well, knows security really well. Adding a little bit of log analytics, that's the way I'm gonna go." How do you see that sort of playing out over the next couple years? I think the answer is pretty clear. Practitioners can't keep up, so they don't need another tool to manually visually correlate. They need machine learning algorithms. They need AI. They need ways to quickly determine what's real and what's not, what we refer to as signals. Those signals need to be a lot less. In an average day, a security practitioner and security operations role is inundated with 100-300 events. These are after these old tools that have done their correlation and deduplication. It's clear that those cannot keep up, even if you add log analytics to it. You need a cloud scale model that looks across all customers, that looks for patterns to determine signals, and normalize a lot of that data, but personalizes to its current environment, and that's what Sumo does. That's exactly why we've been aggressively building out our security portfolio from log analytics, to compliance, to Cloud SIEM, to Cloud SOAR, and even more. Yes. Let's talk a little bit about the observability side of the house, which I think when we looked at the results from Q4, that observability was a pretty strong contributor to the accelerating growth that you've seen. How has the capabilities of the platform on the observability side evolved over the last year? Heading into 2022, what do you see is gonna be the reasons why more demand is going to funnel more observability that's gonna funnel to Sumo Logic versus, you know, where frankly, there's a number of alternatives out there in the market? You want me to start or you want to start? You go ahead. Okay. Well, let's start outside in. I think if you look at the number of workloads that are in the cloud versus those that are being migrated, there's still a huge opportunity to go after that. Secondly, less than 20-25% of those workloads are being monitored today, right? That tells me and tells all of us there's a huge greenfield opportunity for those that are being migrated versus organically and new built in the cloud. I think we're early innings on that. Secondly, as it pertains to inside Sumo, when we look at where we're uniquely differentiated, it's those digital native companies or those digitally transforming companies that are building modern architected apps. What do I mean? It's not the simple three-tier apps anymore. When you move to the cloud and you're building a new application that's for media, for entertainment, it's underpinning a streaming service, a data service, and that means you're using a microservices-based architecture. You heard about Kubernetes and all these other things, and that necessitates you collecting and analyzing all of the data, not some of the data. That's what we're primed for. I think as we look at our own capabilities, the fact that we've built out distributed tracing, Real User Monitoring on the foundation of a streaming data engine that we have with log analytics back end is where we'll take more advantage of the market opportunity for greenfield and existing. Got it. Stewart, do you want to chime in? Well, the only thing I'd add to that, Rami, is you sort of touched on it, but to be a little more explicit, I think that the data tiering we have in the platform allows our customers to deal with this massive growth of data that they can't continue to pay for, right? Mm-hmm. It's not linear from their perspective. I think we're uniquely positioned there, you know, over the competition. We can take on more of the data. We talked about a use case just on the call yesterday with the crypto company, where the volume of data was, you know, 5x-10x what the competition could do for the same price. Mm-hmm. That's a differentiator for us, both winning new business against the other players in the market, but then also being able to expand once we've landed. Yeah, maybe it's a good opportunity just to talk about the pricing model and how that's evolved. Essentially, correct me if I'm wrong, but Sumo Logic has a credit-based system that allows customers to consume different capabilities across the platform. Why do you feel that the credit-based approach is the better one? Because there's a multitude of different pricing models out there in the market. I can't think of any two vendors that have exactly the same thing. Why do you feel like yours is the right approach? As customers scale, how does approach help customers sort of gain better visibility into their budgets? Well, I'll go first. Yeah, go ahead. I would say it's flexibility and transparency. Mm-hmm are the two key things, right? Is that what you were gonna say? Exactly. We're not forcing them to choose, right? They can license the platform, and as the business needs arise, they can move between. They see exactly how they're consuming the credits, right? There's no surprises for them. It's the combination of the two. Whereas I think if you look at the other types of license models out there in the marketplace, there are. I don't want to say hidden restrictions necessarily, but there are restrictions in terms of your ability to leverage the entire platform or different products within the platform. Cool. More commercials have to come in because there's different licensing mechanisms, and so that just slows down kind of the adoption. The other thing I'll add is that, we keep going back to this. You know, data is growing much faster because of not just budgets, because of acceleration of workloads, because of security posture needs, right? Not having a transparent licensing and pricing model that's real time inhibits that. That's something we've been committed to all along, from when we first put our product and service out and available in 2012. Okay. You've done a lot of work on the product side of the house, on the innovation side of the house. We've talked about pricing. None of this is gonna turn into bookings without an efficient sales model. I think yesterday you mentioned some of the initiatives that Lynne, your new Chief Revenue Officer, is embarking on. Can you talk about, like, what her sort of mission statement is for the sales organization going into calendar 2022? What are some of the muscle motions that she's looking to build, and what changes she's building into the organization? Well, I guess, first mission is growth. Cool. Second is scale, and third is focus. We talked about it in the inverse because of the model, meaning focused sales organization which has a hunter versus a farmer, but that drives the other two. That feeds into itself because you get more coverage, more capacity as you add more heads by focusing the roles, and then you're able to get more efficient by focusing the roles as well. Do you have to, in terms of, you know, executing in 2022, is there a different skill set that you need to recruit, or is it more about how the team is gonna be organized to tap the opportunity going into next year? A little bit of a new skill set, but I would argue that, it's actually easier to hire, account teams and account executives that are either hunters or farmers. That's not new to the industry. Mm-hmm. Right? Versus hiring an AE or account executive that's expected to do both. This is not a new model, right? It allows us to incent the right way for the two types of teams and allows us to dial up and dial down the investments as we need to when we're in existing territory patch versus new and know what the payback period is, right, more efficiently. Mm-hmm. We're actually pretty confident in the strategy. We're pretty confident in our opportunity to go continue with conviction and drive revenue growth. We're pretty confident in Lynne and her ability to bring people in, and she's already done that. Great. It's nothing revolutionary that you're going after here. Hunter-farmer model is something that's kind of well known in enterprise sales. Sticking on the sales topic, when we had the investor day last year, I think one of the takeaways for me is that you're starting to build out that product-led growth muscle. What parts of the portfolio are gonna most benefit from more of a bottoms up model? Where do we stand today in terms of building that capability? Good distinction because security practitioners don't buy that way, right? Very much a trusted circle, herd mentality. They wanna know where it's been proven, right? Developers, on the other hand, they don't wanna talk so long, they wanna try it. Great motion for that piece of our business in terms of trial and activation. We launched in Q3 late, early Q4, full stack observability, pay-as-you-go credit-based model for the first time. That's obviously trying to drive the transactional pay-as-you-go monthly to annual motion versus security is very much you sell through partners, you have to sell through the community. We're trying to get a little more self-service, but that's not the way that market buys. That's why it's so hard to take one go-to-market motion and apply it to the other side. Mm-hmm. We've been doing both for years. Makes sense. I want to talk a little bit about guidance and how you sort of the assumptions that underpin the guidance that you laid out last time. You came off a really strong Q4. What was sort of the puts and takes and sort of the factors that either make you more cautious or the factors that make you more aggressive when you set that initial guide for fiscal year 2023? Sure. I think, you know, listen, you start with what's the existing momentum in the business, right? How's the business operating today? Obviously we are really accelerating growth from the back half of the year. You start with that. You know, you also look at things that could impact the company, right? From a macro perspective, there's a lot going on clearly. I can't say we see any near term impact to us, but it's something you just think about as you calibrate how it is. Obviously, you know, as we've made this, you know, evolutionary change within the sales force, right, where it's Mm-hmm ... you know, bifurcating it to the hunters or farmers, we took that into consideration as well. You basically look at all of that, and at the end of the day, what we wanted to do was give guidance that we had a high degree of confidence we could deliver on. Mm-hmm. Those are the factors we thought through. Okay. Now, in terms of like the kind of operational metrics or the KPIs that you're thinking about, we've had been sort of in this, you know, dollar-based and expansion rate framework. What are the metrics that you point investors to sort of assess the progress as you start this part of the journey? Sure. I think I would lead with the newest one that we introduced yesterday on the call, which is ARR. Mm-hmm. I think for a SaaS company, ARR is, it tells you what's happened in the current period, right? You can really see what the growth is in the current period, whereas obviously revenue is a lagging indicator for a SaaS company. First and foremost, I would point to that. I think if you look at our disclosures and how people have been trying to evaluate the growth prospects of the company, they've been attaching to things like RPO and billings. Mm-hmm. I don't think those are as strong as indicators for future growth. I would definitely, in all the conversations we're having with investors now, is pointing to ARR as the best leading indicator of growth. One of the challenges I think is that, you know, we obviously cover a number of companies and a decent chunk report ARR. I think the challenge has been that ARR has been defined differently by companies. If I just think about an example of how you guys define- Yeah ARR, you know, if you have a three-year contract and customer commits to a ramp deal of $1 million year one, $2 million year two, $3 million three, what is the ARR, right? Different companies sort of define that differently. Anyways you can sort of put some guardrails on how you define ARR as a metric? The way we look at it is, it is the annual recurring revenue run rate. On your example. Mm-hmm We would average that out for the three-year deal, right? Say that's what the contract value is. If you think about someone who signed up to a monthly subscription, we would gross that up by 12 months, right? Give you the annual value. By the way, the company's not changed the way it's defined ARR. It's been doing this way, you know, since it went public. Mm-hmm. We've been consistent with that. I think it's also pretty much, sort of the normal way, if there is such a thing, candidly. Mm-hmm. Maybe the most common way people think about calculating or characterizing ARR. Got it. Well, let's see if there's any questions from the audience before I ask my next question. Dean, if you wanna just raise your hand, I can get a mic. Quite a group, huh? Quite a group. Exactly. Just one more question on ARR, actually. So you have the financial metric, but then you have a sales team that has to get compensated. Are those two aligned, from a sales perspective? Very closely aligned, yes. They're not compensated on TCV. No or usage. It's, you know, here's They may get compensation. Their quota is tied to ARR. That's the most important thing. Yeah. Okay. Yeah. Qu-quota. There could be elements of comp tied to some of the other things, but that's not how they're quoted. Understood. I think the next thing we need to talk about is that who knows how long it lasts, but it seems like we're entering a new regime for the first time in at least some time where, you know, profitability and margins matter. Now, clearly, you guys are investing ahead of a large opportunity. If we think about, like, your margin guidance that you gave out last night for the full year. You know, what sort of the justification to take the margins down, sort of question number one. But more importantly, number two, in a scenario where the market's just demanding that, "Hey, a lot more on the profitability side," what are some of the levers that you have to accelerate that path to profitability, if that needs to be the case? I think, you know, in terms of the thought process that went into it. Mm-hmm. You know, the company has been in the process of re-accelerating growth. That's right. Right? If you look at FY 2022, the company, you know, ARR grew 24%, the prior year grew 15%. That's a pretty significant re-acceleration. Mm-hmm. That requires investment. The company started investing in FY 2022. We're continuing that into FY 2023, as we have confidence on the continued re-acceleration. You know, that was our rationale for essentially running the business where we think we optimize it for the long term, right? This is about winning market share. I think, you know, in terms of, you know, how can we manage that, it'll be a quarterly exercise of looking at our continued conviction. Mm-hmm. around the growth re-acceleration, and then continuing to spend versus moderating. We have the ability to do that. You know, obviously the guidance we set out for the next 12 months says that we've got the conviction we can continue to execute in the market. The underlying unit economics are largely there. The gross margins are in the 70%+ range. Gross retention rates are probably industry average or better. Hopefully this is the question of LTV to CAC essentially, right? In terms of the long-term unit economics of the business. The one topic that we haven't addressed before we close is around partnerships and particularly how you guys are working with the cloud hyperscalers. What's been the evolution there across the big three, AWS, Azure, GCP, in terms of that is them helping them bring in more deals or are you guys working in more sort of joint go-to-market activities? What's been the history and what's been the evolution more recently? Sure. First off, I'll say that over the last 18 months, we're seeing more and more customers actively license and deploy a multi-cloud strategy. That means they have more than one hyperscale provider. Therefore the way they choose to procure will vary depending on when the EDPs are coming up or whatever else. By and large, they're deploying workloads on more than one provider. We have to be where the workloads are, and we always have been. We'll collect natively on Amazon versus GCP versus Azure versus on-prem. Now, as pertains to how we go to market, we were awarded the ISV Global Partner of the Year because we're driving a lot of workloads to AWS. We're driving a lot of business to AWS because for every dollar we bring a workload, the trailing attach, right? Now it puts us in a unique position to go actually do some creative things in the market for security, for observability, right? That we'll be capitalizing on. For example, the marketplace, the SaaS marketplace. Today, it's a lot of work for customers to procure through that, right? We're trying to simplify that and make it more of a seamless, frictionless motion. Or selling with Sumo plus another ISV or two and an SI for a security transformation deal. That's what allows us now to go do with them. As it pertains to the other hyperscale providers, we're transacting through Red Hat, we're transacting through Azure Marketplace, and we'll let the customer choose, not Sumo. Makes sense. I think with that, we're all out of time. Thank you so much, Ramin and Stewart. Really appreciate the conversation. Thank you. Thanks for having us. Thank you. Bye. Thanks for having us.
Loading workspace