On Azure, we have workloads on virtual machines, Kubernetes clusters, and SQL Servers. The way Sentinel works is that logs from our Kubernetes services, virtual machines, and database servers go into what is called Log Analytics on Azure. Log Analytics connects to Azure Sentinel, then all the logs move from the resources to Log Analytics down to Sentinel. Sentinel is configured to do some form of threat detection on these logs. For example, there is a firewall log connected to Log Analytics. Sentinel looks at those firewall logs for repeated IPs that are trying to either do an attack on our system or get access into our system. There is some form of machine learning and AI implemented in it to be able to tell us which particular IP address is trying to do this.
Cloud and DevOps Architect at a financial services firm with 11-50 employees
Improves our security posture by using automated threat detection, but the learning curve needs to be faster
Pros and Cons
- "Having your logs put all in one place with machine learning working on those logs is a good feature. I don't need to start thinking, "Where are my logs?" My logs are in a centralized repository, like Log Analytics, which is why you can't use Sentinel without Log Analytics. Having all those logs in one place is an advantage."
- "The learning curve could be improved. I am still learning it. We were able to implement the basic features to get them up and running, but there are still so many things that I don't know about all its features. They have a lot of features that we have not been able to use or apply. If they could work on reducing the solution's learning curve, that would be good. While there is a training course held by Microsoft to learn more about this solution, there is a cost associated with it."
What is our primary use case?
How has it helped my organization?
It is mainly used for securing our platform. As the infrastructure person who works on it, I have some automated ways of seeing threats. We have seen a few possible issues that might come up. So, our customers are safe on some level when we are using Sentinel.
What is most valuable?
It improves our security posture by using automated threat detection.
Having your logs put all in one place with machine learning working on those logs is a good feature. I don't need to start thinking, "Where are my logs?" My logs are in a centralized repository, like Log Analytics, which is why you can't use Sentinel without Log Analytics. Having all those logs in one place is an advantage.
We have not really had any major threats. We have had alarms about four times. In the end, they were false positive alarms. Over time, the machine learning feature understands that something is a false positive, then you don't see them anymore. So, it reduces the number of false positives.
What needs improvement?
The learning curve could be improved. I am still learning it. We were able to implement the basic features to get them up and running, but there are still so many things that I don't know about all its features. They have a lot of features that we have not been able to use or apply. If they could work on reducing the solution's learning curve, that would be good. While there is a training course held by Microsoft to learn more about this solution, there is a cost associated with it.
Buyer's Guide
Microsoft Sentinel
January 2025
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
For how long have I used the solution?
We have been using it in our organization for six months.
What do I think about the stability of the solution?
It is quite stable. It is one of the most mature SIEM solutions that I know.
Currently, I am the person maintaining the solution since we are a startup. However, it probably needs a team of four people to work on it. It needs an infrastructure person to configure it, a security analyst to tell us what they want configured, and a business person to tell us what kind of security targets are needed.
What do I think about the scalability of the solution?
Scalability is good. We are increasing usage for different use cases. For compliance reasons, we will probably expand usage in the future.
Also, there are a lot of features that we have still not tested.
How are customer service and support?
I have not had to use the technical support yet.
Which solution did I use previously and why did I switch?
We were starting from scratch with Azure Sentinel.
We started using it because we were trying to get PCI certified. The updated PCI requirements requested that we have a security information and event management tool. If it wasn't for PCI compliance, then we probably would not have used Sentinel.
How was the initial setup?
The initial setup was complex, not straightforward. Connecting it is easy once you have an Azure resource on the cloud. We also have on-prem resources, but we have not been able to connect those. Trying to create your on-prem resource with Azure Sentinel is not straightforward. I have not seen many implementation videos that I can watch on YouTube to learn how to do it.
It is not just Azure. Other SIEMs solutions are a bit complex when trying to connect them.
Deployment took no more than 10 minutes. Configuring it in our workloads was the major issue, not the deployment. The configuration timeframe depends on the number of resources that you are connected to and your prior knowledge of Sentinel before starting your configuration.
What about the implementation team?
I did the deployment.
What's my experience with pricing, setup cost, and licensing?
From a cost perspective, there are certain Azure resources that we don't need to additionally pay for when using Sentinel.
When we looked at other SIEM tools, they were quite expensive. Sentinel is also expensive for a startup, but we were able to configure it so there are some logs that Azure frees up, like your firewall, Office 365, or Kubernetes logs. From a cost perspective, this works well financially for us.
Sentinel is a bit expensive. If you can figure a way of configuring it to meet your needs, then you can find a way around the cost.
Which other solutions did I evaluate?
We looked at so many tools, like Elastic Search and IBM. We went with Sentinel because the majority of our workloads were on Azure already, so the integration was easier rather than going with something external and integrating it.
What other advice do I have?
If you are purely on Azure, Sentinel is the way to go. Also, it easily works with on-premise workloads from what I have been able to determine. When I look at connectors, it integrates with other cloud providers. I see it integrates with GCP.
I would rate Sentinel as seven out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Principal Cloud Architect at Viria Security Oy
UI-based analytics are excellent; great tools for cleaning data
Pros and Cons
- "The UI-based analytics are excellent."
- "The on-prem log sources still require a lot of development."
What is our primary use case?
We use this solution for analyzing Microsoft cloud-based log services and for security data. The services include Microsoft 365, Azure Security Center logs and Microsoft cache logs. We are gold security partners with Azure.
What is most valuable?
The UI-based analytics are excellent, it's something I haven't seen with any other SIEM products. Microsoft has excellent tools for cleaning data, sorting out irrelevant log data and even fixing log data.
What needs improvement?
There's not much that needs improvement but the on-prem log sources still require a lot of development. It's clear that there are limitations there. I also think that the implementation and on-prem data sources could be done in a better way. We've used some functions with Python and whole scripting on FortiSIEM, which is something that Microsoft could easily provide, but so far hasn't.
What do I think about the stability of the solution?
The product has been very reliable. I don't know that there have been any service outbreaks. We haven't had any problems.
What do I think about the scalability of the solution?
We have 700 users and from our perspective, it has unlimited processing power, but this is quite common for cloud services. I think the scalability has to be some kind of ABM and feeding all of the log stats, which could possibly have limits, but Azure has huge computing power behind it.
How are customer service and technical support?
The support is good, the only issue is getting past the level one people who ask if you've tried rebooting. If you have Microsoft's Unified Support, the most expensive support, then you'll be very happy. It's not the best support in the industry, but it's pretty good and they also support Sentinel.
How was the initial setup?
The initial setup was extremely straightforward. It was the easiest I have seen because it's an SaaS service. I think anybody can do it by just clicking and clicking and saying yes. Straight out of the box and that's the strength of the SaaS service because there's no installation, you just use it.
Which other solutions did I evaluate?
We compared Azure to Splunk and to our current mainstream implementation, FortiSIEM. If you have a lot of security data, then you feel that Azure is quite expensive but it's nowhere near as costly as Splunk which is four or five times more expensive. FortiSIEM wasn't good enough and Splunk was way to expensive.
What other advice do I have?
I would definitely recommend this solution. If you have cloud-based workloads and different cloud or cloud lookalike services that require security data, or if you are looking for SOAR functionalities, then it's a no brainer. It's the best in that market. On the other hand, if you are mainly working and operating with on-prem stuff then there's no advantage over FortiSIEM or other solutions.
I rate this solution a nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Microsoft Sentinel
January 2025
Learn what your peers think about Microsoft Sentinel. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Senior Microsoft 365 Consultant at The Collective Consulting
Quick to set up with good automation and integrates well with Microsoft products
Pros and Cons
- "Sentinel uses Azure Logic Apps for automation, which is really powerful. This allows us to easily automate responses to incidents."
- "The solution should allow for a streamlined CI/CD procedure."
What is our primary use case?
We are running an MDR service for our customers and use Azure Sentinel as the SIEM product to allow us to have an overview of all our customers, but also to easily push configurations to different customers.
We use Azure Sentinel as an alert aggregator to import all of the incidents/alerts from the different (Microsoft) security products in order to have a single pane of glass. On top of that, we create our own custom Analytics Rule that can be used to add our own added value. This enables us to create our own IP to protect customers.
How has it helped my organization?
It's really convenient for us to aggregate the logs/alerts from all our customers into a single pane of glass. By using the automation capabilities, it's relatively easy to sync all incidents to our ITSM tool which we can use to follow up on incidents. As it's based on the Microsoft stack, it's convenient for our engineers to learn the product. As Azure Sentinel is also a big focus for Microsoft, we have the ability to work with them on certain products. This creates visibility within the community and for new customers.
What is most valuable?
There are three valuable aspects of the solution: MSSP support, integration with Microsoft, and Automation. By using Azure Lighthouse, an MSSP can easily integrate their applications into their own baseline of policies/configurations.
Because Sentinel is built as an MS-first product, it integrates natively with other Microsoft products, which is really convenient as we are standardized on it. Without much work, you can connect any Microsoft product to it.
Last, but not least, Sentinel uses Azure Logic Apps for automation, which is really powerful. This allows us to easily automate responses to incidents.
What needs improvement?
Azure Sentinel is constantly growing. Throughout the two years we have been using it, we have seen it expand tremendously. A lot of the limitations we had originally seen have already been mitigated. A couple of potential improvements could be: allow for a streamlined CI/CD procedure. Now it's a combination of using API/Powershell and ARM which is not ideal. Also, it should allow us to ingest on-prem logs by using a SaaS platform to ingest CEF/Syslog logs that also allow for prefiltering. This would allow us to minimize the cost of the solution.
For how long have I used the solution?
I've been using the solution for 1.5 years.
Which solution did I use previously and why did I switch?
We didn't use another SIEM product before Azure Sentinel.
What's my experience with pricing, setup cost, and licensing?
The cost can be a little confusing at first, but the Azure calculator is a great place to start. I would advise to start with integrating Microsoft products first, as this is the most convenient way forward and allows you to learn the product as you go.
In general, Azure Sentinel can be set up really quickly.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: We are a Microsoft partner
Information Security Officer at a computer software company with 11-50 employees
Good integrations, comprehensive and offers good visibility
Pros and Cons
- "It has a lot of great features."
- "We'd like also a better ticketing system, which is older."
What is our primary use case?
We primarily use the solution for security operations.
What is most valuable?
It has a lot of great features.
The integrations on offer are very good. They have a lot of frequent updates on the integrations as well.
We also use other Microsoft products with it, such as Active Directory and Defender for Endpoint and Identity. Everything is well integrated together. The integration itself is seamless.
Its connectors are helpful.
We get good logs from the solution.
Threat visibility is good so far. We are able to prioritize threats based on many factors.
The comprehensiveness of the solution is good.
What needs improvement?
The alert response could be better. We'd also like a better ticketing system, which is older.
For how long have I used the solution?
I've been using the solution for two years.
What other advice do I have?
I'd rate the solution nine out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
SOC Analyst at a wholesaler/distributor with 10,001+ employees
Scalable and offers good pricing but needs a better user interface
Pros and Cons
- "The pricing of the product is excellent."
- "The interface could be more user-friendly. It''s a small improvement that they could make if they wanted to."
What is our primary use case?
The primary use case is the same use case as Splunk.
Requirements differ. We're still doing fine-tuning. However, lots of users are added to its security group to note activities.
What is most valuable?
So far, the solution has been perfect.
The pricing of the product is excellent.
So far, we have found the stability to be very good.
The solution, as a SIEM tool, has very good integration capabilities, at least, according to our needs.
What needs improvement?
We have just recently migrated to this product. We haven't used it long enough to note all of the features. Therefore, it would be impossible to note what is lacking just yet.
The interface could be more user-friendly. It''s a small improvement that they could make if they wanted to.
For how long have I used the solution?
We've recently migrated to this solution. We've only been using it for a month.
What do I think about the stability of the solution?
The stability of the product is very good. It doesn't have bugs. It's not glitchy. It doesn't crash or freeze. It's been reliable so far.
What do I think about the scalability of the solution?
As a Microsoft product, customers get scalability and elasticity. We have policies in place, and, based on them, we can upgrade if we need to. A company shouldn't have issues scaling should they have the need to expand.
Only the security team uses this product. It's not accessible for every user. We have a team of about 20.
We have just invested in the solution, and therefore we have plans to use it for the foreseeable future.
How are customer service and technical support?
We do have access to support, and if we need them, we can call on them. However, the solution is so new, we have yet to need their services. Therefore, I can't speak to their level of responsiveness or knowledgeability just yet.
How was the initial setup?
The installation is very straightforward and easy. It's not complex. It's a cloud deployment, and therefore, it is very quick. You just connect the APIs to the data center.
What's my experience with pricing, setup cost, and licensing?
The product is extremely cost-effective and affordable for customers.
I'm more on the technical side. Therefore, I don't have any insights into the actual cost or the structure of the license.
Which other solutions did I evaluate?
We looked at Splunk as well and compared to that solution, this one is less expensive.
What other advice do I have?
We're using the latest version of the solution.
Choosing this solution was a management decision. Due to cost-effectiveness, they opted for Azure Sentinel.
Whether this product would work for another organization or not depends on the company's requirements.
As it is still very early in terms of our experience with the solution, I would rate the product at a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at SecureOps
Has a fast log query feature and can detect what type of attack is occurring
Pros and Cons
- "The log query feature has been the most valuable because it's very good. You can put your data on the cloud and run queues from Sentinel. It will do it all very fast. I love that I don't have to upload it to an Excel file and then manually look for a piece of information. Sentinel is much faster and is good for big databases."
- "If I can use Sentinel offline at home and use it on a local network, it would be great. I'm not sure if I can use Sentinel offline versus the tools I have."
What is our primary use case?
We actually use it for queuing logs and checking log systems that we have downloading from other devices to see if there are any issues. For example, if we get an alert, then we triage it and query the logs and the devices that we're looking for.
How has it helped my organization?
Microsoft Sentinel has greatly increased our security. We can quickly complete our investigation by using Sentinel and get to the results and escalation points.
What is most valuable?
The log query feature has been the most valuable because it's very good. You can put your data on the cloud and run queues from Sentinel. It will do it all very fast. I love that I don't have to upload it to an Excel file and then manually look for a piece of information. Sentinel is much faster and is good for big databases.
Microsoft Sentinel is able to figure out what type of attack is occurring. It will tell you whether it is a DDoS attack, whether someone's trying to scam the site, or if someone is doing a group force attack. That is, Microsoft Sentinel will actually tell you what it is based on the type of activities it's seeing on the web server. It's a smart tool.
If I'm typing queries, it knows what I'm looking for.
What needs improvement?
If I can use Sentinel offline at home and use it on a local network, it would be great. I'm not sure if I can use Sentinel offline versus the tools I have.
For how long have I used the solution?
I just started using Microsoft Sentinel and have used it for two months.
What do I think about the stability of the solution?
As for availability, I haven't seen any downtime or any issues with the services yet. The stability looks like it's 99.9% and is great.
What do I think about the scalability of the solution?
I believe that Sentinel is good at scaling up their database or services. We are a large company with big data and have thousands of users.
Which solution did I use previously and why did I switch?
I have used Splunk, which has similar log type of queries. I feel that Sentinel is smarter. It is able to detect what type of attacks are occurring, unlike Splunk, which is just a query log tool.
There's Elastic ELK, which is similar to Splunk, but it isn't a smart tool like Sentinel is.
Sentinel is at the top of the tools that I've used so far in terms of smart tools.
What's my experience with pricing, setup cost, and licensing?
Pricing is pay-as-you-go with Sentinel, which is good because it all depends on the number of users and the number of devices to which you connect.
What other advice do I have?
If you're using the cloud and Azure, I would really recommend Sentinel as it will keep making sure that the devices that you have in your environment are safe. Sentinel is very smart at detecting what type of attack is occurring and is actually able to detect and tell us the type of hash file. It is is able to go on the internet, look at the virus total, and see if this is a virus, scam, or phishing. I like how it's able to detect it and how we can make it learn what type of spam or email issue query it is. So, it's a very adaptive type of tool.
I would rate Microsoft Sentinel at ten on a scale from one to ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Engineer at a performing arts with 1,001-5,000 employees
A straightforward solution that is helpful for an overview of the security fabric, but its implementation could be simpler
Pros and Cons
- "We didn't have anything similar. So, it really provides value from the incidents and automation point of view. The overview of the security fabric is most valuable."
- "Its implementation could be simpler. It is not really simple or straightforward. It is in the middle. Sometimes, connectors are a little bit complex."
What is our primary use case?
It is for tracking the logs. I'm working on automation. So, the use case basically includes logs, incidents, automation, UEBA, and endpoint integration with Office 365 Defender.
What is most valuable?
We didn't have anything similar. So, it really provides value from the incidents and automation point of view. The overview of the security fabric is most valuable.
What needs improvement?
Its implementation could be simpler. It is not really simple or straightforward. It is in the middle. Sometimes, connectors are a little bit complex.
For how long have I used the solution?
I just started using it. I have just set it up.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
I haven't dealt with Microsoft's tech support. I haven't reached out to them.
How was the initial setup?
It was of medium complexity. It wasn't too bad, but it can be complex because of the connectors.
What's my experience with pricing, setup cost, and licensing?
I don't know yet because they gave us a 30-day test window for free.
What other advice do I have?
Because it is mainly artificial intelligence and machine learning, you would need some time to learn it. It is a good solution, and it is straightforward.
I would rate it a six out of 10. I haven't really dealt with other ones.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at Danastar Professional Services, LLC
Included with Microsoft, and we have no complaints about functionality
Pros and Cons
- "We have no complaints about the features or functionality."
- "I would like to be able to monitor applications outside of the Azure Cloud."
What is our primary use case?
We are security system integrators.
What is most valuable?
We have no complaints about the features or functionality.
What needs improvement?
Azure Sentinel, the Microsoft Azure product is, from what I understand, used for the Microsoft applications. I don't know if it works outside of the Microsoft Azure cloud.
I would like to be able to monitor applications outside of the Azure Cloud. That is one of the reasons one of the customers has multiple tools.
For how long have I used the solution?
I have been using Azure Sentinel for approximately one year.
What's my experience with pricing, setup cost, and licensing?
It's free. It comes with a Microsoft subscription which the customer has, so they don't have to invest somewhere else. That'd be great if it was supporting other things.
What other advice do I have?
If it's a security integrator like us, quite often people push the client into buying different vendors' products and the client already has the tool in-house. Microsoft is one of those tools that most clients already have.
Many vendors, or integrators, that we know of, are not familiar with Microsoft Sentinel product classification security. So that's one thing I would encourage both potential customers, and users, to look into what suite of products do they have with existing Microsoft accounts that they have.
Also, the integrators should be quite familiar with all the things that are available to their clients, so they don't have to invest tons of money in other tools.
Based on having no complaints, I would rate Azure Sentinel an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Sentinel Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM) Security Orchestration Automation and Response (SOAR) Microsoft Security Suite AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
USM Anywhere
ManageEngine Log360
Buyer's Guide
Download our free Microsoft Sentinel Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are your approaches on Azure Sentinel content deployment automation?
- Which is better - Azure Sentinel or AWS Security Hub?
- What is a better choice, Splunk or Azure Sentinel?
- Which solution do you prefer: Microsoft Sentinel or Palo Alto Networks Cortex XSOAR?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?