Introducing G2.ai, the future of software buying.Try now
ManageEngine Log360
Sponsored
ManageEngine Log360
Visit Website
Product Avatar Image
Microsoft Sentinel

By Microsoft

4.4 out of 5 stars

How would you rate your experience with Microsoft Sentinel?

ManageEngine Log360
Sponsored
ManageEngine Log360
Visit Website
Verified User in Information Services
UI
Enterprise (> 1000 emp.)
"Does Microsoft Sentinel simplifies security monitoring?"
What do you like best about Microsoft Sentinel?

There bunch of SIEM tools available in market like Splunk, MS Sentinel and IBM QRadar. Let's see pros of MS Sentinel today:-

1. This tool is completely build on Azure and does not require on-prem infrastructure.

2. As it is deployed on Azure, it scales automatically based on the data ingestion.

3. Integration with Azure AD, Defender for Cloud and MS tools is very easy and quick.

4. It has multiple features, one of them is AI which automatically detects anomalies and correlates signals across data sources.

5. It makes use of KQL which helps in reporting and getting deep analytics with custom queries.

6. It has very large community rules, workbooks, and playbooks available on the GitHub and Sentinel communit which makes things much easier when compared with other SIEM tools. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

1. Sentinel has a "pay as you go" pricing model which makes it really expensive if you are ingesting lot of data.

2. Sentinel makes use of KQL (Kusto Query Language) is powerful but not intuitive for beginners needs good amount of training for a kick start.

3. Sentinel has a good amount of prebuilt connectors but when it comes to integration with legacy system it is complex process and take good amount of time.

4. When dealing with large, complex queries it may take time and consume high compute resources.

5. Once completely set up the tool and has been used over a long period they switching to another SIEM platform becomes a tedious task. Review collected by and hosted on G2.com.

Microsoft Sentinel Reviews & Product Details

Profile Status

This profile is currently managed by Microsoft Sentinel but has limited features.

Are you part of the Microsoft Sentinel team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Pricing

Pricing provided by Microsoft Sentinel.

Pay-As-You-Go

Pay As You Go

100 GB per Day

$123.00

Microsoft Sentinel Integrations

(2)
Integration information sourced from real user reviews.

Microsoft Sentinel Media

Microsoft Sentinel Demo - Cloud Native SIEM + SOAR
Collect - Detect- Investigate - Respond
Microsoft Sentinel Demo - Microsoft Sentinel
Visibility across your entire Organization with Microsoft 365 Defender and Microsoft Defender for Cloud
Product Avatar Image

Have you used Microsoft Sentinel before?

Answer a few questions to help the Microsoft Sentinel community

Microsoft Sentinel Reviews (289)

View 1 Video Reviews
Reviews

Microsoft Sentinel Reviews (289)

View 1 Video Reviews
4.4
289 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
AI
Enterprise (> 1000 emp.)
"Comprehensive Visibility and Seamless Azure Integration in MS Sentinel"
What do you like best about Microsoft Sentinel?

We have both logs and incidents visible in MS Sentinel unlike our previous SIEM tool. Also, it is an advantage to have the visibility of other services of Azure in the Sentinel and many more. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

We don't have an RBAC option to the tables in the Sentinel like we have in the ADX. It would be great if we have these RBAC option so that we can grant permissions to specific user or group to specific tables Review collected by and hosted on G2.com.

Christian Noel C.
CC
Jefe Regional de Inteligencia de Ciberseguridad | CIC |
Enterprise (> 1000 emp.)
"Siem with excellent capabilities to infest logs and create use cases for the Soc service"
What do you like best about Microsoft Sentinel?

Integrations with multiple cybersecurity tools Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

The cost of monthly intake is a high price that is paid Review collected by and hosted on G2.com.

SHAIKH S.
SS
Field Monitor
Small-Business (50 or fewer emp.)
"Microsoft Sentinel Review"
What do you like best about Microsoft Sentinel?

Microsoft sentinel has very good capabilities to integrate the data. It is easy to connet with the ongoing security softwares and other tools also. This helps organizations to improve their security at different level. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

To generate custom reports using Microsoft Sentinel sometimes may be time consuming due to its dependency on KQLscript writing. If we want to combine the non microsoft data in order to generate log anaysis, it will be difficult. Additionally, learning KQL is also difficult for the new comers. Review collected by and hosted on G2.com.

Anugrah Pratap S.
AS
Technical Lead
Enterprise (> 1000 emp.)
"Streamlining Security Operation with Azure Sentinel !!!!"
What do you like best about Microsoft Sentinel?

Integration with almost all tools and applications. Ease of use, Implementation, migration from other solutions, User friendly and lot much capable Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

Whenever you need to search for a rule or use case, you first need to find the proper alert name (proper naming convention) from analytics; after that, you can search for it. Review collected by and hosted on G2.com.

SG
Cyber Security Architecture
Enterprise (> 1000 emp.)
"Microsoft Sentinel is a Cloud-native security intelligence platform for Microsoft Azure."
What do you like best about Microsoft Sentinel?

Microsoft Sentinel seamlessly integrates with Azure security services, capturing data from different sources like VMs using the Azure monitor agent, Azure Activity log, and Azure event hub. Its built on cloud native architecture. Its a centralized monitoring system. Azure sentinel uses playbooks for automated threat response, streamlining incident handeling. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

Some users find the user interface challenging to navigate, understanding its features may take time. This conprehensive soltuin comes with a price tag. Review collected by and hosted on G2.com.

Luciano P.
LP
Cybersecurity Analyst
Mid-Market (51-1000 emp.)
"It's a very powerful SIEM-tool for conducting cloud security operations"
What do you like best about Microsoft Sentinel?

It's easy intergration with Azure Services and the Microsoft Security Tools. Also the pay-as-you-go model. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

The high costs at scale and the alert fatigue that it gets. Review collected by and hosted on G2.com.

SU
Cyber Security Consultant
Enterprise (> 1000 emp.)
""Microsoft Sentinel - Future of the SOC""
What do you like best about Microsoft Sentinel?

This tool has a very good platform and user friendly to all new user as well.It is a easy to use platform and a soc monitoring tool. it's ease of implementaion makes user to use it. It has a good customer support and I have been using this tool since past years .I am frequently using this .It has good integration with other tools. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

The cost of this platform is little bit higher and the complexity of the tool is there. Review collected by and hosted on G2.com.

Siddharth Ranjan S.
SS
Senior System Engineer
Enterprise (> 1000 emp.)
"Sentinel- A cloud native SIEM"
What do you like best about Microsoft Sentinel?

The best features of Microsoft Sentinel includes scalability, seamless integration with Microsoft products, automated incident response etc. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

So far there is nothing to dislike instead of the integration challenges with third party tool which are non-Microsoft tools. But it can be doable with guides or plugins. Review collected by and hosted on G2.com.

Himanshu P.
HP
Cyber Security Analyst
Enterprise (> 1000 emp.)
"Azure Sentinel SIEM review"
What do you like best about Microsoft Sentinel?

All option and log analytics are handy in single view! Well microsoft is really working on UI specially incident dashboard, new incident view section is better we can see alerts, incident timeline and previous related incident in single window which is good.

There are too much data connector in content hub which is amazing and makes our life easy to integrate new log source. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

Bug fixes and funtionality issue.

Recently the data connector were not visible in data connector page and we faced lot of problem in health checks.

Microsoft should build an alternate workbook to monitor all data connectors manually.

Speed issue: data query speed is low microsoft should work on that. Review collected by and hosted on G2.com.

Manish D.
MD
Staff Security Engineer - SecOps
Enterprise (> 1000 emp.)
"The most feature centric and AI driven cloud SIEM solution"
What do you like best about Microsoft Sentinel?

The MS Sentinel is one of the leading cloud SIEM solution provider. The ease of integration with any 3rd party software solution and native support for all microsoft suite products is what makes it a SIEM leader in Gartner Magic quadrant. The one click deployment of MMA agents to your azure hosted VMs and on-prem workloads (using azure arc) makes it really scalable and easy to manage. The out of the box integration with almost all type of applications are an added advantage. The extensive library of detection/automation rules prepared by Microsoft security research team and community supported content makes it a very rich SIEM product in the market. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

Currently the feature of ingesting logs from private resources is bit complicated and expensive. Microsoft needs to come up with an connectivity model for Sentinel which enables organisations to ingest logs over private communication channel easily instead of leveraging public log analytics API. Review collected by and hosted on G2.com.

Pricing Options

Pricing provided by Microsoft Sentinel.

Pay-As-You-Go

Pay As You Go

100 GB per Day

$123.00

200 GB per Day

$222.00
Microsoft Sentinel Comparisons
Product Avatar Image
Splunk
Compare Now
Product Avatar Image
LogRhythm SIEM
Compare Now
Product Avatar Image
Google Cloud Platform Security Overview
Compare Now
Microsoft Sentinel Features
Activity Monitoring
Asset Management
Log Management
Event Management
Automated Response
Incident Reporting
Threat Intelligence
Vulnerability Assessment
Advanced Analytics
Log Monitoring
Product Avatar Image
Microsoft Sentinel
View Alternatives