What users are saying about
55 Ratings
4 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.6 out of 100
55 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.6 out of 100

Likelihood to Recommend

Azure Sentinel

If you are new to SIEM and have not invested in pre-exiting SIEM solutions, Azure Sentinel is a great way to start your SIEM journey. This is especially true if you are involved in other Microsoft products or are using Office 365 or Azure, it would be very easy to deploy and will have the logs in no time.
Anonymous | TrustRadius Reviewer

Splunk Cloud

I find that Splunk Cloud is well suited for tracking user logins, Server Reboots, failed login attempts, account lockouts, and sorting these items by host or user. We often trace failed user logins to someone having cached credentials on an endpoint which can result in locked accounts that drive the Help Desk ticket volume up unnecessarily.
Jeff Kitchens | TrustRadius Reviewer

Feature Rating Comparison

Security Information and Event Management (SIEM)

Azure Sentinel
7.8
Splunk Cloud
9.3
Centralized event and log data collection
Azure Sentinel
9.0
Splunk Cloud
9.8
Correlation
Azure Sentinel
9.0
Splunk Cloud
9.2
Deployment flexibility
Azure Sentinel
6.0
Splunk Cloud
9.1
Integration with Identity and Access Management Tools
Azure Sentinel
8.0
Splunk Cloud
9.2
Custom dashboards and views
Azure Sentinel
7.0
Splunk Cloud
9.5
Event and log normalization
Azure Sentinel
Splunk Cloud
9.5
Host and network-based intrusion detection
Azure Sentinel
Splunk Cloud
8.8

Pros

Azure Sentinel

  • Very easy to setup
  • Pay as you use--month-to-month subscription--no lengthily contracts
  • Works very well with other Microsoft tools as it has native integration
  • Cheaper then other SIEM products
  • No need to deploy any infrastructure on-premises to manage it
  • Very fast deployment
Anonymous | TrustRadius Reviewer

Splunk Cloud

  • With Splunk Cloud you get the advantage of moving from POC to Production in a matter of days rather than in months allowing the Business to gain a lot.
  • Takes you away from managing infrastructure/administration, allows saving time & money. Reduce the overall TCO (Total Cost of Ownership)
  • Move from Reactive to Proactive Monitoring
  • Highly secure environment at your finger-tips
Manan Bhatt | TrustRadius Reviewer

Cons

Azure Sentinel

  • Better integration with third-party tools
  • More connectors for third-party tools
  • Better online training available
  • More built-in queries
Anonymous | TrustRadius Reviewer

Splunk Cloud

  • The query language is well-documented but has a bit of a learning curve.
  • I wish copy/pasting JSON from the logs were easier without going to the completely raw (condensed) form.
Kevin Smith | TrustRadius Reviewer

Usability

Azure Sentinel

Azure Sentinel 9.0
Based on 1 answer
I think the solution is robust, very usable, and user friendly. Overall it is very solid product that might not have all the functionality that Splunk has, but considering the time it has been on the market, I think it's really good. Having in mind how much Microsoft has invested in Cloud (i.e., Azure), this product will only grow stronger and better. I have been using it for a year, and since we started using it, there have been a lot of improvements and the number of connectors has increased.
Anonymous | TrustRadius Reviewer

Splunk Cloud

Splunk Cloud 8.0
Based on 1 answer
Overall, it is very usable. I would like if recent searches were saved for longer because I always have to refer to my notes when I'm looking for something specific and it's been a few weeks. But that's a small issue, and the actual search and browsing interface is easy to use and powerful.
Kevin Smith | TrustRadius Reviewer

Support Rating

Azure Sentinel

Azure Sentinel 6.0
Based on 1 answer
The support is standard Microsoft support. It's not bad, but far from best in the industry. Compared to not having too many online courses/training available, this can be a roadblock, but in all honesty, deployment and day-to-day operations are easy and the product is intuitive. If you know how to read and understand Windows logs and have basic knowledge in any query language, you won't have much difficulty getting around. If you have some urgent investigation to do and you are stuck in understanding what happened and have difficulty correlating logs from different systems, other products probably will have better support where you can call someone and have screen sharing session/assistance in finding what's going on, but you pay premium for that, so at the end it all depends on your budget, technical skills, and comfort level.
Anonymous | TrustRadius Reviewer

Splunk Cloud

Splunk Cloud 7.8
Based on 4 answers
There is plenty of community-driven support, which is always a very good thing to have. Getting support from your peers worldwide means answers can be very quick, even quicker than official support channels.
Anonymous | TrustRadius Reviewer

Alternatives Considered

Azure Sentinel

Azure Sentinel is much more cost effective and affordable than FortiSIEM and especially compared to Splunk Enterprise. Azure Sentinel is easier and faster to implement and does not require having any on-premises setup. It's purely software. There is no need to install any hardware on your network and you do not need to tap into the network and sniff all the traffic. All the software components of the solutions reside in Azure. You need to send the logs to Azure. The only thing that needs to be done on the servers where you want to monitor logs is install a small, small agent that will have the info of your Log Anaytics and a key to be able to connect and upload the logs. If you are versed in Microsoft technology, there is not much training required to get it going. There is the KQL language for writing queries that might be kind of new but then, on the other hand, any SIEM product has its own subscription language and syntax that needs to be learned, so Azure Sentinel is no different.
Anonymous | TrustRadius Reviewer

Splunk Cloud

All the products in this category do log aggregation very well, however the winning factor was that we have experience with Splunk already and this has proved invaluable as Splunk has a steep learning curve. Especially the Splunk administration part of the tool as that is a very complex area if you wish to get into it.
Fraser Clark | TrustRadius Reviewer

Return on Investment

Azure Sentinel

  • It provide us with visibility in what's going on in our Azure deployments, Office 365 and on-premises servers
  • Allows us to investigate incidents
  • Allows to detect suspicious behavior
  • Fulfills the requirement to have SIEM/centralized log system that is required by security standards and certifications
Anonymous | TrustRadius Reviewer

Splunk Cloud

  • Reduced the amount of time needed from internal security resources (freed up at least 3 FTEs).
  • Reduced the cost per daily GB ingests of our SIEM by 33%.
  • Allowed us to migrate to a lower cost SOC model.
Joseph Sweet | TrustRadius Reviewer

Pricing Details

Azure Sentinel

General

Free Trial
Yes
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Azure Sentinel Editions & Modules

Edition
Azure Sentinel$2.461
100 GB per day$123.002
200 GB per day$221.402
300 GB per day$319.802
400 GB per day$410.002
500 GB per day$492.002
More than 500 GB per day$492.00 + $98.403
  1. per GB ingested
  2. per day
  3. per day/plus each additional 100 GB increment
Additional Pricing Details

Splunk Cloud

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Splunk Cloud Editions & Modules

Additional Pricing Details

Rating Summary

Likelihood to Recommend

Azure Sentinel
10.0
Splunk Cloud
9.1

Usability

Azure Sentinel
9.0
Splunk Cloud
8.0

Support Rating

Azure Sentinel
6.0
Splunk Cloud
7.8

Add comparison