

Sentinel and LogRhythm SIEM compete in the security information and event management (SIEM) category. Based on comparisons, LogRhythm SIEM appears to have the upper hand due to its advanced features and comprehensive threat management capabilities.
Features: Sentinel provides robust integration capabilities, automated response functions, and easy scalability, which users find enhances operational efficiency. LogRhythm SIEM includes superior threat intelligence, advanced analytical tools, and detailed reporting, receiving positive feedback for comprehensive visibility and more detailed insights.
Room for Improvement: Sentinel could benefit from improvements in detailed reporting, real-time alerts, and threat detection accuracy. LogRhythm SIEM needs to address its steep learning curve, better documentation for user training, and user interface complexity.
Ease of Deployment and Customer Service: Sentinel is known for straightforward deployment and responsive customer service, making it suitable for smaller teams or those new to SIEM solutions. LogRhythm SIEM takes more time to deploy but is supported by expert services that are invaluable in complex environments.
Pricing and ROI: Sentinel offers a lower initial setup cost and fast ROI due to efficient implementation and low operational overhead. LogRhythm SIEM, though more costly upfront, is perceived as offering greater long-term value with its extensive feature set and effective threat management capabilities, which justify the investment.
The technical support is good; we have a separate portal for partners, and since we are paying for the service, they provide a response timeframe based on severity—critical issues are addressed within four hours, medium issues within one day, and non-urgent issues may take a couple of days.
The automated responses and detections of LogRhythm SIEM are much better and faster compared to others.
Customer support is very helpful and effectively solves my problems.
The scalability of LogRhythm SIEM is good enough, warranting an eight out of ten rating.
LogRhythm SIEM is highly scalable as it has modular components allowing me to expand storage, indexing, or other resources as needed.
LogRhythm SIEM is scalable; it can handle about 200 or 500 devices without much difference.
LogRhythm SIEM still needs improvement regarding stability, particularly in environments with heavy data consumption.
The platform needs regular updates to fix problems encountered with each quarterly patch and version release.
I have noticed some problems with parsing errors, event mismatches, and data mismatching, so ensuring accurate parsing and continuous improvement according to device updates are my basic expectations as a detection engineer.
If LogRhythm SIEM could make a lightweight version of their solution, that would be quite competitive because some of my customers have a very large need but refuse to go with LogRhythm SIEM due to its complexity and high resource intensity.
There is currently no way to determine how much data is being consumed in terms of gigabytes, terabytes, or petabytes from particular devices or environments.
Price is always a consideration, so the price would be nice if it were lower.
The license cost is around $10 per MPS.
I find LogRhythm SIEM affordable, as it is a bit less costly than QRadar.
They nearly always bill it in dollars, so if it can be billed in our currency, that would be helpful and fixed in our currency.
This helps SOC analysts significantly as they can monitor all log sources through a dashboard, quickly identifying which sources haven't reported within their specified timeframes.
We have enough budget for cloud deployment, but we choose to keep it on-prem to ensure data privacy; cyberattacks are a concern, but data privacy is the foremost priority due to sensitive government information.
The seamless integration for case management, along with a user-friendly dashboard user interface, makes tasks like threat hunting more efficient.
Sentinel's best features include that it's a very easy product to use.
| Product | Mindshare (%) |
|---|---|
| LogRhythm SIEM | 2.5% |
| Sentinel | 2.9% |
| Other | 94.6% |

| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 39 |
| Large Enterprise | 83 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
LogRhythm SIEM offers advanced threat intelligence, scalable deployment, and streamlined log management. It enhances security posture with AI-driven threat detection and comprehensive monitoring.
LogRhythm SIEM stands out for its AI-driven threat correlation, ease of log aggregation, and robust reporting. Offering real-time visibility and analytics through consistent navigation and dashboards, it integrates with security components for enhanced monitoring and response. Advanced threat intelligence and customizable alerts streamline processes and bolster security. While it faces challenges with log parsing, reporting, and dashboard intuitiveness, plans to enhance cloud integration and transition to Linux are noted.
What are the standout features?In industries like banking and finance, organizations utilize LogRhythm SIEM for centralized log management, security monitoring, and compliance. It helps detect insider threats, analyze server logs, correlate events, and monitor user behaviors. Appreciated for log ingestion and anomaly identification, it ensures robust cybersecurity and incident response by integrating data from multiple sources.
Sentinel is a robust platform offering seamless native integration, enhanced security through transactional data, and a user-friendly interface reminiscent of Microsoft Windows. Its capabilities in threat detection, monitoring, and business intelligence integration make it an attractive choice for organizations.
Sentinel simplifies security management with its advanced features, including the Kusto Query Language and automation abilities that reduce the complexity of coding tasks. The platform's correlation engine allows for efficient rule generation, while its threat visibility and intelligence features offer preparation against risks. Advanced hunting queries, anomaly dashboards, and scalability options enhance its utility. Users appreciate its seamless connections with Microsoft tools and ability to improve threat detection through cloud and business intelligence integration. However, enhancements could improve documentation on security aspects, simplify dashboards, and optimize drag-and-drop features. There are suggestions for better device integration, a shift to web interfaces, and improved customization options, although some users face challenges with Unix scripting.
What are the most important features of Sentinel?Sentinel finds application across sectors for logging, security event monitoring, and integration with tools like Microsoft Defender for Endpoint. Users from industries such as government and academic institutions leverage its advanced SQL query support for customized responses, enhancing security measures with AI capabilities in diverse environments.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.