We spent a lot of money on Sumo indeed. But when it helps you keep churn down it can pay off.
You can also parse the logs and create alerts and dashboards from the parsed values.
We only retained the logs for 30 days, so you could use Elastic/Kibana and we did for our dev/qa environments. However people hated it compared to Sumo.