Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
$2.46
per GB ingested
SolarWinds Kiwi Syslog Server
Score 7.5 out of 10
N/A
Solarwinds® Kiwi Syslog® Server is a syslog management tool for network and systems engineers. It receives syslog messages and SNMP traps from network devices (routers, switches, firewalls, etc.), and Linux®/Unix® hosts. Users can filter and view these messages based on time, hostname, severity, etc., and set up custom alerts. Kiwi Syslog Server has built-in actions to react appropriately to syslog messages. There are also log archival and clean-up features to help comply with security policies.
We use it because when a user sees the suspicious activity on his account, Microsoft Sentinel gives alerts to the user's system and the admin system as well. When a user of one of our systems clicked a spam email, that email was trying to install a virus on our server, but Microsoft Sentinel gave an alert to the user and admin both, so that is why our team was able to fix that issue with Microsoft Sentinel very fast. However, it will not be the best option for you if your team is utilizing every feature but you are on a tight budget.
To monitor syslog events Kiwi syslog much helpful and needed .Its saving human efforts and cost.Easy to check on GUI panel flow and status of server ,start and stop services we can do them from GUI panel it self . Recent version also no need C++ libraries to install .We can store the ingested events and archive based on our threshold criteria .We can import and export INI file which contain everything what we have configured
I appreciate that it keeps the data within our, what we call our, authorization boundary. The fact that the data remains within Microsoft's, I guess, walled garden if you will, is very helpful for certain compliance needs in particular.
The large library of ingestion: ability to ingest is basically as easy as I can basically get it to be most of the time. There's occasionally some vendors that it's a little bit more challenging for, but given the ease of integration for a lot of things, basically it's become one of my requirements when I am looking at other tools is how easily do they integrate with Sentinel.
Collection of SNMP traps a reliable and stable collection server for these is crucial to troubleshooting and time to ROS. Kiwi excels at this.
Easy to install set up and train users on.
The free version is a good free tool and handy to use for personal labs and other smalle use cases.
SNMP traps to user readable format is great, sometimes syslog and smnp messages can be hard to interpret and read with out a knowledge of how to do this.
I think it should include more third party integration with non microsoft products as well as with other cloud providers. These integrations should be native.
It should improve ML and AI capabilities.
I find its documentation a little bit difficult to understand at the start. So the words should be simple.
The Microsoft Azure Sentinel solution is very good and even better if you use Azure. It's easy to implement and learn how to use the tool with an intuitive and simple interface. New updates are happening to always bring new news and improve the experience and usability. The solution brings reliability as it is from a very reliable manufacturer.
Kiwi Syslog has the best usability of any syslog server. While not being able to offer the most features, the ones it does have are intuitive and easy to work with. Everything that it has is where you think it should be. If you can't find it in the menus, it doesn't exist.
Because the solution is so simple to use and implement, support wasn't very necessary. The one time I did call them to better understand where logs were stored, they were very helpful and friendly. Kiwi has been around for some time and not a lot has changed over the years, so support for it is pretty straightforward and quick.
Well before there was Microsoft Sentinel, you had other competing products like ArcSight or Splunk, et cetera. I think they have their own qualities, but the Microsoft integration story is really why we're using it.
PRTG is a great package and very useful, but the jump from the free 100 sensor price model to the first tier of the paid model is WAY too expensive. SolarWinds Kiwi Syslog Server is very inexpensive and provides us with the results we needed for log monitoring.
As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.