Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Microsoft Sentinel
Score 8.6 out of 10
N/A
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
$2.46
per GB ingested
Arcsight by OpenText
Score 6.8 out of 10
N/A
A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.N/A
Splunk Enterprise
Score 8.5 out of 10
N/A
Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.N/A
Pricing
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Editions & Modules
Azure Sentinel
$2.46
per GB ingested
100 GB per day
$123.00
per day
200 GB per day
$221.40
per day
300 GB per day
$319.80
per day
400 GB per day
$410.00
per day
500 GB per day
$492.00
per day
More than 500 GB per day
$492.00 + $98.40
per day/plus each additional 100 GB increment
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Free Trial
YesNoYes
Free/Freemium Version
NoNoYes
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Considered Multiple Products
Microsoft Sentinel
Chose Microsoft Sentinel
Prior to using Sentinel, we were using Splunk specifically Splunk Enterprise Security and Splunk Cloud, so their on-prem and their cloud-based products. We switched originally for cost reasons, specifically cost control, but I have found that the ability to create reports, the …
Chose Microsoft Sentinel
Microsoft Sentinel feels on another different level from these solutions , all in the cloud . No need for troubleshooting , deployment or upgrades. Constant updates from the vendor and good support
Chose Microsoft Sentinel
Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and …
Chose Microsoft Sentinel
Well before there was Microsoft Sentinel, you had other competing products like ArcSight or Splunk, et cetera. I think they have their own qualities, but the Microsoft integration story is really why we're using it.
Chose Microsoft Sentinel
Well, we didn't select, we selected Sentinel for our Azure stuff, our Microsoft stuff, but we do use a different SIEM for the other stuff still.
Chose Microsoft Sentinel
As mentioned, the product was part of the purchase of several Microsoft Suites that we did earlier last year and with 200 licenses included, we can exclude those from the other SIEM and SOAR product, it just work well with the Microsoft's environment that we partially have
Is …
Chose Microsoft Sentinel
ArcSight is an on-prem solution that has a different approach than Sentinel.

In a basis this product is more complex to maintain and deploy. The query functionality in Sentinel is more powerful and easier to maintain. ArcSight has a much slower performance and an interface that …
Chose Microsoft Sentinel
Microsoft Sentinel really goes the extra mile when it comes to an SIEM that slowly improves toward a proper SOAR, this may be the best selling point of the entire solution. Highly scalable, cloud-based, and nearly perfect when dealing with Microsoft-based infrastructures, …
Chose Microsoft Sentinel
As the vast majority of our users have Windows machine and uses all 365 cloud features, we finally decided not to implement any 3rd party security solutions on desktops/laptops in order to keep our infrastructure simple. In this case, Microsoft Sentinel is the best way to …
Arcsight by OpenText

No answer on this topic

Splunk Enterprise
Chose Splunk Enterprise
While both are market-leading SIEM platforms, they cater to different environments and organization priorities. The choice often comes down to a company's existing infrastructure, integration needs, and long-term security strategy.
Deployment and architecture - Splunk offeres …
Chose Splunk Enterprise
Cost, flexibility, management overhead.
Chose Splunk Enterprise
Splunk is certainly much more versatile than either of these three products. Unless ArcSight makes a "connector" for your product, you will be required to use Flex Connectors which is an additional license and apparently requires some serious development. Without Logger, you …
Features
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Microsoft Sentinel
8.0
31 Ratings
2% above category average
Arcsight by OpenText
5.5
4 Ratings
35% below category average
Splunk Enterprise
8.1
85 Ratings
3% above category average
Centralized event and log data collection8.630 Ratings8.04 Ratings9.081 Ratings
Correlation8.431 Ratings9.04 Ratings8.383 Ratings
Event and log normalization/management8.031 Ratings8.04 Ratings8.482 Ratings
Deployment flexibility6.929 Ratings6.04 Ratings7.975 Ratings
Integration with Identity and Access Management Tools8.329 Ratings6.03 Ratings8.176 Ratings
Custom dashboards and workspaces8.031 Ratings5.04 Ratings8.682 Ratings
Host and network-based intrusion detection8.126 Ratings8.02 Ratings7.761 Ratings
Data integration/API management7.829 Ratings5.01 Ratings8.229 Ratings
Behavioral analytics and baselining8.027 Ratings2.01 Ratings7.527 Ratings
Rules-based and algorithmic detection thresholds8.429 Ratings8.01 Ratings7.728 Ratings
Response orchestration and automation8.428 Ratings2.01 Ratings7.324 Ratings
Reporting and compliance management7.35 Ratings4.01 Ratings8.529 Ratings
Incident indexing/searching8.429 Ratings1.01 Ratings8.632 Ratings
Best Alternatives
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.7 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.7 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.7 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Likelihood to Recommend
8.7
(53 ratings)
9.0
(6 ratings)
8.6
(86 ratings)
Likelihood to Renew
6.8
(2 ratings)
-
(0 ratings)
7.0
(18 ratings)
Usability
6.5
(7 ratings)
7.0
(1 ratings)
8.3
(19 ratings)
Availability
-
(0 ratings)
-
(0 ratings)
10.0
(1 ratings)
Support Rating
8.0
(3 ratings)
8.0
(4 ratings)
8.0
(18 ratings)
Online Training
-
(0 ratings)
-
(0 ratings)
8.0
(1 ratings)
Implementation Rating
-
(0 ratings)
-
(0 ratings)
7.0
(3 ratings)
Product Scalability
-
(0 ratings)
-
(0 ratings)
9.1
(1 ratings)
Professional Services
5.0
(1 ratings)
-
(0 ratings)
-
(0 ratings)
User Testimonials
Microsoft SentinelArcsight by OpenTextSplunk Enterprise
Likelihood to Recommend
Microsoft
It's certainly well-suited in environments that rely heavily on Microsoft products, and it's well-suited for environments where you have other business drivers to go to the E5 license. If I were to say where I would not and why, I only gave it a seven on the recommendation, that answer would probably vary if you already owned E5 or not. It's extremely expensive. And if there are other alternatives, if you don't have any other driving reason to go to E5, I would coach you not to go to Microsoft Sentinel. But if you're there, it's a fantastic property. It's certainly part of the cost argument for moving to E5, but it's only a part. It can't by itself justify the move to E5.
Read full review
OpenText
In the current lot of hundreds of SIEM solutions out there in the market, ArcSight ESM is fairly less expensive with strong fundamentals in place. The log ingestion, correlation are very well performing and totally worth ROI. However, the tool has lost its way when it comes to staying abreast with current feature curve of SIEM technology and the evolution has not been done by MicroFocus. Search times are high and there is no major plug-in that has been introduced as part of the product life cycle.
Read full review
Cisco
It's well suited for what I do, which is network security operations. And that's for anything from troubleshooting incidents, troubleshooting performance, troubleshooting for the purpose of a compliance and auditing. It's not best suited for users who are new in terms of they're new to the product and they have expectations that probably Splunk cannot meet.
Read full review
Pros
Microsoft
  • It's the scale. Having built-in detections and vulnerabilities and the ability to see into the traffic flows is absolutely key. Look at it from my perspective as network security. We want to see what's going on east, west, between all the kinds of subscriptions and the tenants. We don't have that. We don't have that with any other product. Microsoft Sentinel gives us that kind of visibility.
Read full review
OpenText
  • Integration with smart logger and ESM to create rules and easy management of the same.
  • Easy integration with all end point security management tool(IPS/IDS, Firewall, Anti-Virus) and their consolidated output at a single place to effectively rectifying true and false positives.
Read full review
Cisco
  • It is very useful in creating custom rules for analyzing system logs and display relevant information. The query language is very easy to learn.
  • We can create custom UI to visualize the output of our data. The interface is very flexible. It also allows the sharing of rules among users.
  • There is an open online community to help others. Stackoverflow also has a splunk community. These resources make it more convenient to learn.
Read full review
Cons
Microsoft
  • An area for improvement is how case management is surfaced within the Microsoft Sentinel experience, as clearer integration into Sentinel workflows would reduce context switching and improve incident handling.
  • There is an opportunity to further expand agentic, autonomous investigation and response capabilities.
Read full review
OpenText
  • It is slow comparing to any other SIEM Tool.
  • We have to create filter for each alerts need some custom filter .
  • Here we dont have any single tab for see all the alerts .also need some attractive features for dashboard.
Read full review
Cisco
  • Splunk light limits number of users to 5. Wish there was a flexible license, where one could add more users.
  • Splunk light does not let you add > few realtime alerts. Wish there was a flexible license, where one could add as many realtime alerts as wanted.
  • Better insight into daily ingestion values
Read full review
Likelihood to Renew
Microsoft
it does the job reasonably well
Read full review
OpenText
No answers on this topic
Cisco
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
Read full review
Usability
Microsoft
Because, as I said, it still lacks a lot of things, like many playbooks outside the Copilot integrations and the actual remediation. For example, for Microsoft Sentinel and SAP, I would want to see Copilot doing a lot of remediations in Microsoft Sentinel at SAPN, like executing the transaction code, maybe creating certain increases, or remediating stuff like that, which is all customized.
Read full review
OpenText
Overall, it is a good investment in order for an organization to stay compliant and stay secure from all the wild things happening. It is definitely a cost effective tool with some good features including correlation, log storage, reporting and dashboards. If a customer is looking for advanced set of features, then I would highly not recommend this.
Read full review
Cisco
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Read full review
Reliability and Availability
Microsoft
No answers on this topic
OpenText
No answers on this topic
Cisco
When properly setup and configured, Splunk is extremely reliable.
Read full review
Support Rating
Microsoft
Microsoft support is one of the highest rated on the market. It has global and multilingual support. Calls can be made over the phone and the solution is virtually instantaneous with the help of Microsoft engineers. It's great!
Read full review
OpenText
I personally haven't reached the support team, however, the engineers never complained about the Arcsight support team. We had some issues with the tool in the past but every time we reached the support, all issues were resolved in a timely manner.
Read full review
Cisco
Splunk maintains a well resourced support system that has been consistent since we purchased the product. They help out in a timely manner and provide expert level information as needed. We typically open cases online and communicate when possible via e-mail and are able to resolve most issues with that method.
Read full review
Online Training
Microsoft
No answers on this topic
OpenText
No answers on this topic
Cisco
The online course was simple clear and described the main capabilities of the solution. There is also an initial module that can be done for free so anyone can familiarize themselves with the functionality of this solution. On the other hand, however, there could be more free online courses. Maybe even with a certificate, this would broaden the group of people who are familiar with the platform while increasing familiarity with the solution itself.
Read full review
Implementation Rating
Microsoft
No answers on this topic
OpenText
No answers on this topic
Cisco
Smooth without too many major issues.
Read full review
Alternatives Considered
Microsoft
Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and Wazuh. It lags in third-party integrations and syslog parsing. Organizations choose Microsoft Sentinel for its cost-effectiveness, automation, and Microsoft synergy, especially in Azure-heavy environments, though Splunk and Exabeam lead in flexibility and UEBA, respectively.
Read full review
OpenText
Multiple platforms are already supported by Arcsight. Support is good. Scripts can be used to get data from multiple threat intel sources & the same can be used in correlation rules to detect any suspicious activity. Reporting features are good & you can check any backdated information within new clicks.
Read full review
Cisco
I didn't get to fully evaluate Logstash as our corporation was already using Logstash, but both seemed like viable solutions to the problem that we were having. I wanted to evaluate Logstash some more, both did seem like they would work for the business needs that we had, we went with splunk as many teams were already using it.
Read full review
Scalability
Microsoft
No answers on this topic
OpenText
No answers on this topic
Cisco
Splunk can scale in to the petabyte per day range which of course is awesome
Read full review
Professional Services
Microsoft
Did not use professional services
Read full review
OpenText
No answers on this topic
Cisco
No answers on this topic
Return on Investment
Microsoft
  • As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.
Read full review
OpenText
  • Logger helps us to decrease incident response times.
  • It also decreased our project times with the man/day calculations. Before this solution, it may take up to 10 men/days to do something. After this, it becomes nearly half of the time.
Read full review
Cisco
  • I don't have any numbers to share but Splunk has positively served as a 24/7 monitoring tool that has saved hours of work by self-detecting, saving statistics and alerting problems in the system or from external interfaces as soon as they happen.
  • Splunk dashboards does a solid job in collecting, analyzing data and creating reports that contain an entire day's activity and then automatically sent out to the business.
  • Splunk is very easy to learn and very useful to any program or business application.
Read full review
ScreenShots

Microsoft Sentinel Screenshots

Screenshot of Screenshot of Screenshot of Microsoft Sentinel Capabilities