Check Point CloudGuard is a comprehensive cloud security platform used to prevent threats and prioritize risks in the cloud across applications, network, and workloads.
N/A
Microsoft Sentinel
Score 8.6 out of 10
N/A
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
Checkpoint Cloud Guard Native Security Platform is much better in native cloud infra security requirements. It works well, and the manageability of said product is good. But If you are having some hybrid kind of environment, it is not suitable, and the products have more complexity to deploy. There are so many other players to do well in this segment.
Microsoft Sentinel can be more suited for teams that are already using the Microsoft ecosystem,since integration with other tools is easy.It can be more useful to the business with fluctuating growth of data volumes due to elastic scaling.Also suitable for teams that need faster deployments.
The visual presentation of data is terrific, so including what we had prior to Microsoft Sentinel, it presents data in a much more usable way, so that's been quite refreshing. It's not quite as complex to understand what you're looking at.
One feature that I would like to see improved is probably the log parsing. I think one of the big things that Splunk does better than Microsoft Sentinel is that it makes it easy to bring in new log streams of arbitrary formats and parse them out into columns and tables. Microsoft Sentinel is a lot more involved, though. It takes a lot more manual work to bring in different log sources and parse them out.
It's the simplicity. I know it sounds crazy, but I previously talked about the ability for us to do our own analysis and our own things on the data. However, to pull those reports together to make something that is then, I take it to my deck and say, "Hey, look at this. That's a lot of time and effort." Or, "I just turned on Microsoft Sentinel, go to the pre-populated reports, I want to look at this, click, bang, and it comes up." That is phenomenal.
Microsoft support is one of the highest rated on the market. It has global and multilingual support. Calls can be made over the phone and the solution is virtually instantaneous with the help of Microsoft engineers. It's great!
Most products have their pros and cons but Dome9 does everything Evident.io and Redlock can do and more. Evident was a good tool but merging the two products into one complicated things.
Compared to platforms such as Splunk, LogRhythm, and Devo, Microsoft Sentinel’s cloud‑native, consumption‑based pricing model and reduced infrastructure overhead tend to offer better overall cost efficiency. This is especially true for organizations already invested in the Microsoft ecosystem, where Sentinel can deliver strong capabilities with a lower total cost of ownership.
As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.