Sumo Logic Keys

Bridgecrew Policy ID: BC_GIT_67
Chekov Check ID: CKV_SECRET_67
Severity: LOW

Sumo Logic Keys

Description

The Sumo Logic Access Keys Management API allows developers to securely register new Collectors or access Sumo Logic APIs. This API was built with OpenAPI. Developers can generate client libraries in many languages and explore automated testing.

Fix - Buildtime

Sumo Logic

  1. If you have the Create Access Keys role capability, you can use the Preferences page to create access keys. You can use the Preferences page to edit, activate, deactivate, and delete your access keys.
  2. When you mouse over an access key on the Preferences page, several controls appear.
  3. Use the trash can icon to permanently remove the access key. The key will no longer be usable for API calls. However, deleting a key used to register a Collector does not affect the Collector, as the only time a Collector uses the access key is at installation.