Try our new research platform with insights from 80,000+ expert users

Microsoft Sentinel vs Tines comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Microsoft Sentinel
Ranking in Security Orchestration Automation and Response (SOAR)
1st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
89
Ranking in other categories
Security Information and Event Management (SIEM) (2nd), Microsoft Security Suite (5th)
Tines
Ranking in Security Orchestration Automation and Response (SOAR)
13th
Average Rating
9.0
Number of Reviews
3
Ranking in other categories
Vulnerability Management (32nd), Threat Intelligence Platforms (20th), Endpoint Detection and Response (EDR) (42nd)
 

Mindshare comparison

As of November 2024, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Microsoft Sentinel is 20.8%, up from 20.3% compared to the previous year. The mindshare of Tines is 5.3%, up from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Nitin Arora - PeerSpot reviewer
Nov 2, 2022
Gives us one place to investigate and respond to threats, and automation eliminates manual work
They can work on the EDR side of things. It is already really superb, because of the kinds of features we get with the EDR solution. It's not a standard EDR and they have recently enhanced things. But the problem is with onboarding devices. I have different OS flavors, including a large number of Linux, Windows, macOS, and some on-prem machines as well. Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work. They can eliminate having to do manual configuration for the machines, and check the different types of configurations for each OS. In some cases, it does not support some OSs. If they could reduce this type of work, that would be really amazing.
Del Tice - PeerSpot reviewer
Aug 21, 2024
Automate daily tasks, phishing emails, ticket creation and IOC investigations
Support is pretty top-notch. If they identify an issue, they notify their customers. For instance, they monitor the tenants, and if a problem occurs, they send an email to inform you. They provide a lot of their support through Slack channels. Each customer has a dedicated channel where you can post questions or mention issues you’re facing. You’ll usually receive a response quickly. Recently, they’ve integrated AI into this process, so you often get useful suggestions within a minute. If needed, you can also request a human to take a look. Their response time is generally quick, although it might be slower at night since they aren’t available 24/7.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Mainly, this is a cloud-native product. So, there are zero concerns about managing the whole infrastructure on-premises."
"The connectivity and analytics are great."
"You can fine-tune the SOAR and you'll be charged only when your playbooks are triggered. That is the beauty of the solution because the SOAR is the costliest component in the market today... but with Sentinel it is upside-down: the SOAR is the lowest-hanging fruit. It's the least costly and it delivers more value to the customer."
"The features that stand out are the detection engine and its integration with multiple data sources."
"I like the ability to run custom KQL queries. I don't know if that feature is specific to Sentinel. As far as I know, they are using technology built into Azure's Log Analytics app. Sentinel integrates with that, and we use this functionality heavily."
"We didn't have anything similar. So, it really provides value from the incidents and automation point of view. The overview of the security fabric is most valuable."
"While Microsoft Sentinel provides a log of security events, its true power lies in its integration with Microsoft Defender."
"The most valuable feature is the UEBA. It's very easy for a security operations analyst. It has a one-touch analysis where you can search for a particular entity, and you can get a complete overview of that entity or user."
"One of the most valuable features is that it’s a low-code solution."
"The tool was vendor-neutral."
"The best thing is that it's no code, so it doesn't require coding knowledge."
 

Cons

"Everyone has their favorites. There is always room for improvement, and everybody will say, "I wish you could do this for me or that for me." It is a personal thing based on how you use the tool. I do not necessarily have those thoughts, and they are probably not really valuable because they are unique to the context of the user, but broadly, where it can continue to improve is by adding more connectors to more systems."
"It could have a better API to be able to automate many things more extensively and get more extensive data and more expensive deployment possibilities. It can gain some points on the automation part and the integration part. The API is very limited, and I would like to see it extended a bit more."
"The product can be improved by reducing the cost to use AI machine learning."
"I think the number one area of improvement for Sentinel would be the cost."
"We'd like also a better ticketing system, which is older."
"While I appreciate the UI itself and the vast amount of information available on the platform, I'm finding the overall user experience to be frustrating due to frequent disconnections and the requirement to repeatedly re-authenticate."
"We do see continuous improvement all the time, however, I haven't got a specific feature that is lacking or not well designed."
"When we pass KPIs to the governance department, there's no option to provide rights to the data or dashboard to colleagues. We can use Power BI for this, but it isn't easy or convenient. They should just come up with a way to provide limited role-based access to auditing personnel"
"Maybe Tines can add more features and demonstrations, like videos on how to use the features within the tool."
"They started implementing some AI, and their AI is isolated."
"Tines was a little bit more expensive than Torq."
 

Pricing and Cost Advice

"Microsoft Sentinel can be costly, particularly for data management."
"The combination of the ease of accessibility and the free cost of the service is great. But we buy storage based on our events per second and on how many sources are integrated into the solution."
"I am not involved on the financial side, but from an enterprise-wide use perspective, I think the price is good enough."
"I don't know yet because they gave us a 30-day test window for free."
"Sentinel is costly."
"Microsoft Sentinel is pretty expensive, and they recently announced that they will increase the price of all Microsoft services running in Azure by 11 percent. Luckily, I'm not responsible for the financial side. For one of my clients, the estimated cost is 880,000 euros for one year. There are additional costs for the service agreement."
"Microsoft can enhance the licensing side. I feel there is confusion sometimes... They should have a single license in which we have the opportunity to use the EDR or CASB solution."
"The pricing isn't very high. It depends on the number of logs you have. If you're expecting to ingest 50 to 60G in a day, but you're only ingesting 20 to 25G per day at first and you have a good team to analyze the logs, then you can segregate the ingestion at under 15G."
Information not available
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
10%
Government
8%
Manufacturing Company
8%
Computer Software Company
15%
Financial Services Firm
13%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
What needs improvement with Tines?
Maybe Tines can add more features and demonstrations, like videos on how to use the features within the tool. For example, when you click on a feature, it could show a video link explaining how to ...
What is your primary use case for Tines?
We use it for automations on the enterprise security aspect.
What advice do you have for others considering Tines?
If someone needs tasks performed daily that can be automated between different systems, and if there's a cybersecurity or SOC analyst team, they can also use it by creating various API calls, setti...
 

Comparisons

 

Also Known As

Azure Sentinel
No data available
 

Learn More

 

Overview

 

Sample Customers

Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Information Not Available
Find out what your peers are saying about Microsoft Sentinel vs. Tines and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.