No more typing reviews! Try our Samantha, our new voice AI agent.

Graylog Security vs SentinelOne Singularity Endpoint comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Graylog Security
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Security Information and Event Management (SIEM) (59th)
SentinelOne Singularity End...
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
289
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Anti-Malware Tools (2nd), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), AI-Powered Cybersecurity Platforms (2nd), AI Observability (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Graylog Security is designed for Security Information and Event Management (SIEM) and holds a mindshare of 0.6%, up 0.6% compared to last year.
SentinelOne Singularity Endpoint, on the other hand, focuses on Endpoint Detection and Response (EDR), holds 5.3% mindshare, down 5.8% since last year.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Graylog Security0.6%
Splunk Enterprise Security7.8%
IBM Security QRadar5.6%
Other86.0%
Security Information and Event Management (SIEM)
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint5.3%
CrowdStrike Falcon7.1%
Microsoft Defender for Endpoint5.5%
Other82.1%
Endpoint Detection and Response (EDR)
 

Featured Reviews

Tony Zafiropoulos - PeerSpot reviewer
Owner/ Chief Engineer at Fixvirus.com
Aggregates logs in one place and helps to review data points
We tried Graylog Security, starting with their inexpensive open-source version. We tested it out and continued using it for a while. As for the main differences between Graylog Security and other vendors, some users might prefer cloud-based platforms over on-premises solutions. It isn't inherently cloud-native, but that might not matter much for some.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool aggregates logs. We can see the logs in one place."
"We use the solution to collect logs."
"The rollback feature is the most valuable aspect of the solution."
"The Ranger feature is valuable."
"It is easy to collect and retain logs with SentinelOne."
"Singularity Complete has helped me free up time for my staff, allowing them to focus on other projects or tasks; it has saved a lot of time, because normally, when you do checks in a standard console for another solution, SentinelOne Singularity Endpoint reduces review time by about 50–60% of the tasks, since it's such a robust tool and at the same time has such an easy-to-understand interface."
"The product can scale."
"Comparing SentinelOne Singularty Endpoint with other XDR solutions, the first thing is that it is easier to understand with a user-friendly interface."
"The CapEX is very low because you don't have to buy any management tools or install them on your hardware."
"When I compare SentinelOne Singularity Endpoint with other solutions like CrowdStrike, I find that SentinelOne Singularity Endpoint is the best because the threat detection is real-time and incident response is also real-time."
 

Cons

"Graylog Security needs to incorporate security scorecards."
"The solution can improve by adding more granular firewall capabilities."
"Having an additional logic layer could improve the solution, mainly because I run multiple systems with different layers. For example, if I'm running a very important server with this agent, and that server gets infected, I may not necessarily be sure that I want to shut it down right away. Maybe I want to isolate some of the connectivity but not do the entire security remediation automatedly or curtail network access type of activity."
"It shows the vulnerability but does not provide the package to resolve that vulnerability."
"Regarding alerts, SentinelOne Singularity Endpoint sometimes produces too many false positives, and sometimes produces true positives."
"There are things that they can do to improve the console or improve the product, and they are making strides in it."
"We are not utilizing all the features available with SentinelOne Singularity Complete, including the built-in XDR and Ranger, due to the substantial associated costs."
"I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience."
"SentinelOne is causing a problem with the data service that causes one of our applications to crash randomly. We're still looking for a permanent fix, but we have implemented a temporary workaround that excludes that application from the scan."
 

Pricing and Cost Advice

"I rate the tool's pricing a one out of ten."
"The pricing for SentinelOne Singularity Complete is competitive."
"I rate Singularity Complete a seven out of ten for affordability. It's more expensive than our previous solution, but it does its job well. At the same time, there is some room for improvement. Cheaper is always better."
"It's around $8 per client per month."
"Nothing good is cheap, and SentinelOne is no exception."
"SentinelOne Singularity Complete is reasonably priced."
"Its cost is yearly. It is not much costlier than other leading products available in the market. I would rate it a four out of five in terms of pricing."
"SentinelOne Singularity Complete is expensive, but we must be willing to pay for it if we want a high level of protection."
"For our use case, the solution is affordable. There are not any hidden fees."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
912,930 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
13%
Comms Service Provider
9%
Retailer
8%
Outsourcing Company
8%
Outsourcing Company
11%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business140
Midsize Enterprise73
Large Enterprise98
 

Questions from the Community

Ask a question
Earn 20 points
Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the pricing.
 

Also Known As

No data available
Sentinel Labs, SentinelOne Singularity, Singularity Platform
 

Overview

 

Sample Customers

Information Not Available
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about Splunk, IBM, Microsoft and others in Security Information and Event Management (SIEM). Updated: September 2026.
912,930 professionals have used our research since 2012.