What users are saying about
<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
630 Ratings
4 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.6 out of 100

Microsoft Azure

<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
630 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.4 out of 100

Likelihood to Recommend

Azure Sentinel

If you are new to SIEM and have not invested in pre-exiting SIEM solutions, Azure Sentinel is a great way to start your SIEM journey. This is especially true if you are involved in other Microsoft products or are using Office 365 or Azure, it would be very easy to deploy and will have the logs in no time.
Anonymous | TrustRadius Reviewer

Microsoft Azure

[Microsoft] Azure provides a great "get up and running" environment particularly when you need to map multiple resources together, such as database, web app, storage, and analytics. The "Application Insights" feature is particularly strong because it allows you to do a "one click" install of an agent that can track performance and transactions all the way down to the database level. The [Microsoft] Azure dashboard allows you to easily find resources you need and access the current resources you have. Setting up new resources also uses a well managed "wizard" like structure to make it easy.
Sean Patterson | TrustRadius Reviewer

Feature Rating Comparison

Security Information and Event Management (SIEM)

Azure Sentinel
7.8
Microsoft Azure
Centralized event and log data collection
Azure Sentinel
9.0
Microsoft Azure
Correlation
Azure Sentinel
9.0
Microsoft Azure
Deployment flexibility
Azure Sentinel
6.0
Microsoft Azure
Integration with Identity and Access Management Tools
Azure Sentinel
8.0
Microsoft Azure
Custom dashboards and views
Azure Sentinel
7.0
Microsoft Azure

Platform-as-a-Service

Azure Sentinel
Microsoft Azure
8.0
Ease of building user interfaces
Azure Sentinel
Microsoft Azure
7.2
Scalability
Azure Sentinel
Microsoft Azure
9.0
Platform management overhead
Azure Sentinel
Microsoft Azure
7.7
Workflow engine capability
Azure Sentinel
Microsoft Azure
7.5
Platform access control
Azure Sentinel
Microsoft Azure
7.9
Services-enabled integration
Azure Sentinel
Microsoft Azure
8.5
Development environment creation
Azure Sentinel
Microsoft Azure
8.5
Development environment replication
Azure Sentinel
Microsoft Azure
8.4
Issue monitoring and notification
Azure Sentinel
Microsoft Azure
7.8
Issue recovery
Azure Sentinel
Microsoft Azure
7.8
Upgrades and platform fixes
Azure Sentinel
Microsoft Azure
8.0

Pros

Azure Sentinel

  • Very easy to setup
  • Pay as you use--month-to-month subscription--no lengthily contracts
  • Works very well with other Microsoft tools as it has native integration
  • Cheaper then other SIEM products
  • No need to deploy any infrastructure on-premises to manage it
  • Very fast deployment
Anonymous | TrustRadius Reviewer

Microsoft Azure

  • Azure Functions is the easiest serverless service to work with in my experience. Easy to ship Node.js functions without bundling dependencies.
  • Proactive and responsive support. We've worked with most other cloud providers - Amazon, Google, Oracle. Amazon Web Services' customer support is a black hole and their documentation is worthless. Google and Oracle are better, but Azure's support is responsive and their docs are pretty good.
  • Azure's Web UI is pretty easy to work with
Valeri Karpov | TrustRadius Reviewer

Cons

Azure Sentinel

  • Better integration with third-party tools
  • More connectors for third-party tools
  • Better online training available
  • More built-in queries
Anonymous | TrustRadius Reviewer

Microsoft Azure

  • Could be easier to setup redundancy
  • Feels as if there are too many options, bells, and whistles you could add.
  • Microsoft Azure functions does not have a "Configure Services" method. Programming Azure functions has a slightly different programming model than does a "normal" API application. I would prefer that the startup process be identical.
João Almeida | TrustRadius Reviewer

Likelihood to Renew

Azure Sentinel

No score
No answers yet
No answers on this topic

Microsoft Azure

Microsoft Azure 10.0
Based on 15 answers
Moving to Azure was and still is an organizational strategy and not simply changing vendors. Our product roadmap revolved around Azure as we are in the business of humanitarian relief and Azure and Microsoft play an important part in quickly and efficiently serving all of the world. Migration and investment in Azure should be considered as an overall strategy of an organization and communicated companywide.
Amir Tabei | TrustRadius Reviewer

Usability

Azure Sentinel

Azure Sentinel 9.0
Based on 1 answer
I think the solution is robust, very usable, and user friendly. Overall it is very solid product that might not have all the functionality that Splunk has, but considering the time it has been on the market, I think it's really good. Having in mind how much Microsoft has invested in Cloud (i.e., Azure), this product will only grow stronger and better. I have been using it for a year, and since we started using it, there have been a lot of improvements and the number of connectors has increased.
Anonymous | TrustRadius Reviewer

Microsoft Azure

Microsoft Azure 8.8
Based on 22 answers
Such a great platform for a novice or expert to use. There is significant training available to learn how to do complex things with little to know background doing them before. Especially if you live close to a Microsoft training center, they offer many courses for free on site. Even if not, the virtual training they provide is also free and plentiful.
Anonymous | TrustRadius Reviewer

Reliability and Availability

Azure Sentinel

No score
No answers yet
No answers on this topic

Microsoft Azure

Microsoft Azure 6.8
Based on 2 answers
It has proven to be unreliable in our production environment and services become unavailable without proper notification to system administrators
Anonymous | TrustRadius Reviewer

Support Rating

Azure Sentinel

Azure Sentinel 6.0
Based on 1 answer
The support is standard Microsoft support. It's not bad, but far from best in the industry. Compared to not having too many online courses/training available, this can be a roadblock, but in all honesty, deployment and day-to-day operations are easy and the product is intuitive. If you know how to read and understand Windows logs and have basic knowledge in any query language, you won't have much difficulty getting around. If you have some urgent investigation to do and you are stuck in understanding what happened and have difficulty correlating logs from different systems, other products probably will have better support where you can call someone and have screen sharing session/assistance in finding what's going on, but you pay premium for that, so at the end it all depends on your budget, technical skills, and comfort level.
Anonymous | TrustRadius Reviewer

Microsoft Azure

Microsoft Azure 8.3
Based on 26 answers
Microsoft products are well-known for 24x7 global coverage of customer support. They also sometimes come with a multiple support plan, which caters to different business requirements and needs. However, more support will also mean more cost to bare. Other than that, limited options in technical training sometimes make it quite challenging in finding the right talents for managing Microsoft Azure clouds and more dependency in Microsoft technical support.
Anonymous | TrustRadius Reviewer

Implementation Rating

Azure Sentinel

No score
No answers yet
No answers on this topic

Microsoft Azure

Microsoft Azure 8.0
Based on 2 answers
As I have mentioned before the issue with my Oracle Mismatch Version issues that have put a delay on moving one of my platforms will justify my 7 rating.
Amir Tabei | TrustRadius Reviewer

Alternatives Considered

Azure Sentinel

Azure Sentinel is much more cost effective and affordable than FortiSIEM and especially compared to Splunk Enterprise. Azure Sentinel is easier and faster to implement and does not require having any on-premises setup. It's purely software. There is no need to install any hardware on your network and you do not need to tap into the network and sniff all the traffic. All the software components of the solutions reside in Azure. You need to send the logs to Azure. The only thing that needs to be done on the servers where you want to monitor logs is install a small, small agent that will have the info of your Log Anaytics and a key to be able to connect and upload the logs. If you are versed in Microsoft technology, there is not much training required to get it going. There is the KQL language for writing queries that might be kind of new but then, on the other hand, any SIEM product has its own subscription language and syntax that needs to be learned, so Azure Sentinel is no different.
Anonymous | TrustRadius Reviewer

Microsoft Azure

  • With Hybrid Cloud, organizations can integrate onsite servers with Cloud instances.
  • Machines are grouped into cloud service and respond to the same domain name with various ports
  • High performance, Low cost
  • Multiple Storage Services
  • Native MS SQL Database & No SQL support
  • Little Cheaper than piers
  • Offers inbuilt tool like Azure stack to help the organization deliver Azure service from the own data center
Anonymous | TrustRadius Reviewer

Return on Investment

Azure Sentinel

  • It provide us with visibility in what's going on in our Azure deployments, Office 365 and on-premises servers
  • Allows us to investigate incidents
  • Allows to detect suspicious behavior
  • Fulfills the requirement to have SIEM/centralized log system that is required by security standards and certifications
Anonymous | TrustRadius Reviewer

Microsoft Azure

  • It has taken a few years of planning and growth (which continue), but we've been able to successfully budget and plan for ever increased capacity by starting first with some Virtual Machines and factoring in on-prem maintenance vs cloud constant improvements. VM (server, compute, networking) costs even out quickly over time and will show savings very soon.
  • Because of Azure Application Gateways (which cost very little to set up and maintain), we were able to build a state of the art single-sign-on hub for all of our users and other enterprise platforms (mostly non-Microsoft and non Azure systems), reducing the amount of time to switch among these for workers and increasing overall productivity.
  • With Azure Active Directory, we do not need to maintain separate identity systems and can more easily integrate our organizations credentials into authorization for access to other systems.
Matt Varney | TrustRadius Reviewer

Pricing Details

Azure Sentinel

General

Free Trial
Yes
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Azure Sentinel Editions & Modules

Edition
Azure Sentinel$2.461
100 GB per day$123.002
200 GB per day$221.402
300 GB per day$319.802
400 GB per day$410.002
500 GB per day$492.002
More than 500 GB per day$492.00 + $98.403
  1. per GB ingested
  2. per day
  3. per day/plus each additional 100 GB increment
Additional Pricing Details

Microsoft Azure

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Microsoft Azure Editions & Modules

Additional Pricing Details

Rating Summary

Likelihood to Recommend

Azure Sentinel
10.0
Microsoft Azure
8.7

Likelihood to Renew

Azure Sentinel
Microsoft Azure
10.0

Usability

Azure Sentinel
9.0
Microsoft Azure
8.8

Reliability and Availability

Azure Sentinel
Microsoft Azure
6.8

Support Rating

Azure Sentinel
6.0
Microsoft Azure
8.3

Implementation Rating

Azure Sentinel
Microsoft Azure
8.0

Add comparison