Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
$2.46
per GB ingested
Splunk Cloud Platform
Score 7.9 out of 10
N/A
Splunk Cloud Platform is a data platform service thats help users search, analyze, visualize and act on data. The service can go live in as little as two days, and with an IT backend managed by Splunk experts.
Compared to platforms such as Splunk, LogRhythm, and Devo, Microsoft Sentinel’s cloud‑native, consumption‑based pricing model and reduced infrastructure overhead tend to offer better overall cost efficiency. This is especially true for organizations already invested in the …
These are all the Microsoft products. We have used Splunk. And again, I would say Microsoft Sentinel stacks up because it's a native tool that is more like an ecosystem. It's not a standalone tool. It's like if you're in the Microsoft stack, Microsoft Sentinel will stack up …
Microsoft Sentinel gave us the opportunity to move to pay as you go model. This allows us to determine the value of a log source rather than paying a flat rate for data ingested or hosting a server ourself.
Most of our landscape, both on prem and cloude, is based in Microsoft technologies, while the unification of tools implies some risk, decreasing the vendor levels simplify integrations, and by scale, help us to reduce costs too. Yes, the tool itself is a good contender, but the …
They are for different use cases, field effect helps us monitor network traffic and decide what to do with it while Microsoft Defender Threat Intelligence allows more robust monitoring and control over 365 variables such as emails that come in and out and Entra ID information.
Microsoft Sentinel feels on another different level from these solutions , all in the cloud . No need for troubleshooting , deployment or upgrades. Constant updates from the vendor and good support
Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and …
We decided to go with Microsoft Sentinel because it works really well with Microsoft tools we are already using. Microsoft Sentinel's intelligent features detect and resolve problems more quickly than Sumo Logic. It also allows us to pay for what we use and grow as we need. …
Well, primarily we use different stuff like CrowdStrike. We use different sign-on features. We primarily use those different products because we support a wider ecosystem.
Splunk, Google, SecOps. I look at how it stacks up based on the fact that it's the primary solution that we sell. So I think it stacks up really well. Why do we select it? Well, we selected it primarily because we're a very large Microsoft partner. The technology is very good …
Well before there was Microsoft Sentinel, you had other competing products like ArcSight or Splunk, et cetera. I think they have their own qualities, but the Microsoft integration story is really why we're using it.
We use intune to protect endpoints and we pull logs from all the endpoints through the intune connector into the Microsoft Sentinel SIEM and that way we can run rules on those logs to find anomalies.
Elastic seems to have a much better interface for log search and is able to filter out noise. Microsoft Sentinel also appears to generate a lot of false positives.
Elastic is some carbon for various use cases. So because Elastic is a very, very wrong history in the market. So Sentinel is very recent for products from my understanding.
Prior to using Sentinel, we were using Splunk specifically Splunk Enterprise Security and Splunk Cloud, so their on-prem and their cloud-based products. We switched originally for cost reasons, specifically cost control, but I have found that the ability to create reports, the …
Based on the overall infrastructure configuration that we have and also after analysing various solutions provided by Microsoft Sentinel, we came to a conclusion that the Microsoft Sentinel is the best option for us to help us in overall threat detection on our custom servers, …
I use most of the Sims that are out there, but RSAs, old Sim Log, logic, elastic, a lot of them. Sumo, we checked out Sumo too. We're a Microsoft shop and live almost entirely on top of a Microsoft ecosystem. We are considering other Microsoft security products to integrate …
As mentioned, the product was part of the purchase of several Microsoft Suites that we did earlier last year and with 200 licenses included, we can exclude those from the other SIEM and SOAR product, it just work well with the Microsoft's environment that we partially have Is …
The key advantage of using Sentinel lies in Microsoft already being a renowned name in cloud services. Hence, the Collection of data at the cloud scale across all users, devices, applications, and infrastructure, both on-premises and especially in the MS Cloud, is super easy. …
FortiAnalyzer more focus on security while Splunk Cloud Platform integrates with all infrastructure products and not does it do security but do well with basic event correlation.
Search Processing Language really is a game changer for writing easy-to-understand and maintainable queries on your data base logs. Once understood, setting up and validating a query can be done in no time- which leaves us the option to focus on more monitoring and improved …
Microsoft Dynamics is far more complex and far more costly to implement and configure in comparison to Splunk. It can be useful for integrations into existing Microsoft databases. Grafana is quick and easy to deploy and configure. However, it lacks the scale required for an …
We selected Splunk Cloud due to the simplicity to use and get data in. We found that Splunk Cloud gives a unified simple searching and dashboarding interface which can be used to search and visualise data from multiple systems with ease.
I have selected Splunk Cloud because Sumo Logic is blown away by Splunk Cloud. It's a night and day difference. My experience with Splunk Cloud is faster and more reliable. It consists of more features than Sumo Logic.
All the products in this category do log aggregation very well, however the winning factor was that we have experience with Splunk already and this has proved invaluable as Splunk has a steep learning curve. Especially the Splunk administration part of the tool as that is a …
Splunk Cloud blows Sumo Logic out of the water. The experience is night and day. We went from several highly stressed IT security professionals who were unsure if the data they were getting was valuable, to very happy IT security professionals who can now be more proactive and …
I believe there is no existing competitor of Splunk and the way Splunk Cloud provides support is way better than all the other competitors. No one can beat Splunk Cloud!!
My company used to use Loggly, and while I can't speak to the specifics of why we switched to Splunk, I do know that Splunk seems faster and has more features than Loggly. On the other hand, I've used Splunk much more than I used Loggly when we had it before, so my view could …
Other solutions weren't able to consume the volume of logs that we were producing on a daily basis. Searching was difficult because of proprietary or simply confusing search mechanisms. Splunk simplified the searching by using regular expressions. Although the cost of Splunk …
I feel that the alternatives are great products and they are also things we use in our own monitoring in addition to Splunk. However, when it comes to finding things in the data as opposed to just looks for trends the competition just doesn't even come close. Splunk has become …
I have used several Solar Winds tools in the past to monitor and track similar things. Both tools are comparable in their performance. Each one has it's own set of challenges when getting set up for the first time as well as a learning curve to get comfortable with usage.
It's certainly well-suited in environments that rely heavily on Microsoft products, and it's well-suited for environments where you have other business drivers to go to the E5 license. If I were to say where I would not and why, I only gave it a seven on the recommendation, that answer would probably vary if you already owned E5 or not. It's extremely expensive. And if there are other alternatives, if you don't have any other driving reason to go to E5, I would coach you not to go to Microsoft Sentinel. But if you're there, it's a fantastic property. It's certainly part of the cost argument for moving to E5, but it's only a part. It can't by itself justify the move to E5.
I will highly recommend this software because using Splunk Cloud has helped us become more proactive about handling our security concerns and better manage our environment. It is one of the finest security software that is easy to use and also provides analytics. It has excellent features like creating dashboard security and managing features etc. So you must give it a try once!
It's mainly the data correlation. For example, in the Microsoft ecosystem, Microsoft Entra ID is a primary component of the authentication and authorization mechanism. So whenever you're using tools like Microsoft Intune, Defender for Endpoint, Entra ID is the key signal, right? So Microsoft Sentinel correlates the logs from all these devices and services very well, so I can see a very detailed attack shape to figure out what's going on.
With Splunk Cloud you get the advantage of moving from POC to Production in a matter of days rather than in months allowing the Business to gain a lot.
Takes you away from managing infrastructure/administration, allows saving time & money. Reduce the overall TCO (Total Cost of Ownership)
I think it should include more third party integration with non microsoft products as well as with other cloud providers. These integrations should be native.
It should improve ML and AI capabilities.
I find its documentation a little bit difficult to understand at the start. So the words should be simple.
The Microsoft Azure Sentinel solution is very good and even better if you use Azure. It's easy to implement and learn how to use the tool with an intuitive and simple interface. New updates are happening to always bring new news and improve the experience and usability. The solution brings reliability as it is from a very reliable manufacturer.
Splunk Cloud support is sorely lacking unfortunately. The portal where you submit tickets is not very good and is lacking polish. Tickets are left for days without any updates and when chased it is only sometimes you get a reply back. I get the feeling the support team are very understaffed and have far too much going on. From what I know, Splunk is aware of this and seem to be trying to remedy it.
Compared to platforms such as Splunk, LogRhythm, and Devo, Microsoft Sentinel’s cloud‑native, consumption‑based pricing model and reduced infrastructure overhead tend to offer better overall cost efficiency. This is especially true for organizations already invested in the Microsoft ecosystem, where Sentinel can deliver strong capabilities with a lower total cost of ownership.
Microsoft Dynamics is far more complex and far more costly to implement and configure in comparison to Splunk. It can be useful for integrations into existing Microsoft databases. Grafana is quick and easy to deploy and configure. However, it lacks the scale required for an enterprise of our size. It is great for smaller test cases.
It's probably neutral. We see value, but it's, again, tick that kind of expense stuff. We're getting more insight and value into what is going on in that cloud workspace, but just noting the cost. So it's probably neutral. I'm not directly responsible, so the full kind of return on investment kind of cycle, that's someone else's problem. I'm like the end user. It's my team that will look at the data and look at the output of Microsoft Sentinel. So the ROI, someone else can worry about that.