Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Microsoft Sentinel
Score 8.6 out of 10
N/A
Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.
$2.46
per GB ingested
Splunk Enterprise
Score 8.6 out of 10
N/A
Splunk is software for searching, monitoring, and analyzing machine-generated big data, via a web-style interface. It captures, indexes and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards and visualizations.N/A
vRealize Operations (discontinued)
Score 9.0 out of 10
N/A
vRealize Operations, or Aria Operations, provided simplified and automated IT Operations Management across private, hybrid, and multi-cloud environments, and visibility into the entire tech stack, including all physical, virtual, and cloud infrastructure components. The product is no longer available for sale.N/A
Pricing
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Editions & Modules
Azure Sentinel
$2.46
per GB ingested
100 GB per day
$123.00
per day
200 GB per day
$221.40
per day
300 GB per day
$319.80
per day
400 GB per day
$410.00
per day
500 GB per day
$492.00
per day
More than 500 GB per day
$492.00 + $98.40
per day/plus each additional 100 GB increment
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Free Trial
YesYesNo
Free/Freemium Version
NoYesNo
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeNo setup feeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Considered Multiple Products
Microsoft Sentinel
Chose Microsoft Sentinel
Prior to using Sentinel, we were using Splunk specifically Splunk Enterprise Security and Splunk Cloud, so their on-prem and their cloud-based products. We switched originally for cost reasons, specifically cost control, but I have found that the ability to create reports, the …
Chose Microsoft Sentinel
Microsoft Sentinel feels on another different level from these solutions , all in the cloud . No need for troubleshooting , deployment or upgrades. Constant updates from the vendor and good support
Chose Microsoft Sentinel
Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and …
Chose Microsoft Sentinel
Well before there was Microsoft Sentinel, you had other competing products like ArcSight or Splunk, et cetera. I think they have their own qualities, but the Microsoft integration story is really why we're using it.
Chose Microsoft Sentinel
Well, we didn't select, we selected Sentinel for our Azure stuff, our Microsoft stuff, but we do use a different SIEM for the other stuff still.
Chose Microsoft Sentinel
As mentioned, the product was part of the purchase of several Microsoft Suites that we did earlier last year and with 200 licenses included, we can exclude those from the other SIEM and SOAR product, it just work well with the Microsoft's environment that we partially have
Is …
Chose Microsoft Sentinel
Microsoft Sentinel really goes the extra mile when it comes to an SIEM that slowly improves toward a proper SOAR, this may be the best selling point of the entire solution. Highly scalable, cloud-based, and nearly perfect when dealing with Microsoft-based infrastructures, …
Chose Microsoft Sentinel
As the vast majority of our users have Windows machine and uses all 365 cloud features, we finally decided not to implement any 3rd party security solutions on desktops/laptops in order to keep our infrastructure simple. In this case, Microsoft Sentinel is the best way to …
Splunk Enterprise
Chose Splunk Enterprise
While both are market-leading SIEM platforms, they cater to different environments and organization priorities. The choice often comes down to a company's existing infrastructure, integration needs, and long-term security strategy.
Deployment and architecture - Splunk offeres …
vRealize Operations (discontinued)
Chose vRealize Operations (discontinued)
We are a VMware shop and need monitoring from VMware. Also, I am not the decision maker here. I believe because of being a VMware shop we choose VRO and also may be my company got a great deal. I like this product although there is a lot of stuff to improve.
Features
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Microsoft Sentinel
8.1
31 Ratings
3% above category average
Splunk Enterprise
8.2
91 Ratings
5% above category average
vRealize Operations (discontinued)
-
Ratings
Centralized event and log data collection8.730 Ratings9.085 Ratings00 Ratings
Correlation8.531 Ratings8.487 Ratings00 Ratings
Event and log normalization/management8.131 Ratings8.488 Ratings00 Ratings
Deployment flexibility6.929 Ratings8.081 Ratings00 Ratings
Integration with Identity and Access Management Tools8.429 Ratings8.282 Ratings00 Ratings
Custom dashboards and workspaces8.031 Ratings8.787 Ratings00 Ratings
Host and network-based intrusion detection8.226 Ratings7.865 Ratings00 Ratings
Data integration/API management8.029 Ratings8.334 Ratings00 Ratings
Behavioral analytics and baselining8.127 Ratings7.632 Ratings00 Ratings
Rules-based and algorithmic detection thresholds8.429 Ratings7.833 Ratings00 Ratings
Response orchestration and automation8.428 Ratings7.529 Ratings00 Ratings
Reporting and compliance management7.35 Ratings8.634 Ratings00 Ratings
Incident indexing/searching8.429 Ratings8.737 Ratings00 Ratings
Best Alternatives
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.9 out of 10
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.9 out of 10
Hyper-V
Hyper-V
Score 8.2 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Red Hat OpenShift
Red Hat OpenShift
Score 9.1 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Sumo Logic
Sumo Logic
Score 8.8 out of 10
Red Hat OpenShift
Red Hat OpenShift
Score 9.1 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Likelihood to Recommend
8.3
(65 ratings)
8.7
(112 ratings)
10.0
(6 ratings)
Likelihood to Renew
6.7
(2 ratings)
8.5
(25 ratings)
-
(0 ratings)
Usability
7.0
(18 ratings)
8.5
(45 ratings)
8.0
(1 ratings)
Availability
-
(0 ratings)
10.0
(1 ratings)
-
(0 ratings)
Support Rating
8.0
(3 ratings)
8.0
(19 ratings)
8.0
(3 ratings)
Online Training
-
(0 ratings)
8.0
(1 ratings)
-
(0 ratings)
Implementation Rating
-
(0 ratings)
7.0
(3 ratings)
-
(0 ratings)
Product Scalability
-
(0 ratings)
9.1
(1 ratings)
-
(0 ratings)
Professional Services
5.0
(1 ratings)
-
(0 ratings)
-
(0 ratings)
User Testimonials
Microsoft SentinelSplunk EnterprisevRealize Operations (discontinued)
Likelihood to Recommend
Microsoft
It's certainly well-suited in environments that rely heavily on Microsoft products, and it's well-suited for environments where you have other business drivers to go to the E5 license. If I were to say where I would not and why, I only gave it a seven on the recommendation, that answer would probably vary if you already owned E5 or not. It's extremely expensive. And if there are other alternatives, if you don't have any other driving reason to go to E5, I would coach you not to go to Microsoft Sentinel. But if you're there, it's a fantastic property. It's certainly part of the cost argument for moving to E5, but it's only a part. It can't by itself justify the move to E5.
Read full review
Cisco
I'm liking the newer products, and I'm looking forward to how they integrate with the overall product when they come together. Just log in and be able to query a large number of systems for similar issues or a unique one. That is a great fit for Splunk Enterprise, looking for a simple case or a simple String or something of that nature across multiple machines. It's a great fit for that to identify issues or particular software, whatever your scenario is, String, to find it across any particular server or group of servers, so that you can update or do a deployment or whatever it is you're looking to do.
Read full review
Discontinued Products
With the introduction of API-based event alerts, there is no need for a proxy, which is a good option. Its ability to manage infra on a real-time basis is a good option that helps monitor, administer and troubleshoot virtual machines.
Read full review
Pros
Microsoft
  • It's the scale. Having built-in detections and vulnerabilities and the ability to see into the traffic flows is absolutely key. Look at it from my perspective as network security. We want to see what's going on east, west, between all the kinds of subscriptions and the tenants. We don't have that. We don't have that with any other product. Microsoft Sentinel gives us that kind of visibility.
Read full review
Cisco
  • It is very useful in creating custom rules for analyzing system logs and display relevant information. The query language is very easy to learn.
  • We can create custom UI to visualize the output of our data. The interface is very flexible. It also allows the sharing of rules among users.
  • There is an open online community to help others. Stackoverflow also has a splunk community. These resources make it more convenient to learn.
Read full review
Discontinued Products
  • Shows us where we can save on cost of keeping machines running, or boosting resources on VM's
  • the ability to plan deployments with scenario plans that can be customized over a specific timeline
  • reports that can be sent and shared with different teams or departments
Read full review
Cons
Microsoft
  • An area for improvement is how case management is surfaced within the Microsoft Sentinel experience, as clearer integration into Sentinel workflows would reduce context switching and improve incident handling.
  • There is an opportunity to further expand agentic, autonomous investigation and response capabilities.
Read full review
Cisco
  • Splunk light limits number of users to 5. Wish there was a flexible license, where one could add more users.
  • Splunk light does not let you add > few realtime alerts. Wish there was a flexible license, where one could add as many realtime alerts as wanted.
  • Better insight into daily ingestion values
Read full review
Discontinued Products
  • There are less space for customization.
  • Cannot use for OS monitoring.
  • Some option are very complex like getting an ideal VM report.
Read full review
Likelihood to Renew
Microsoft
it does the job reasonably well
Read full review
Cisco
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
Read full review
Discontinued Products
No answers on this topic
Usability
Microsoft
Because, as I said, it still lacks a lot of things, like many playbooks outside the Copilot integrations and the actual remediation. For example, for Microsoft Sentinel and SAP, I would want to see Copilot doing a lot of remediations in Microsoft Sentinel at SAPN, like executing the transaction code, maybe creating certain increases, or remediating stuff like that, which is all customized.
Read full review
Cisco
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Read full review
Discontinued Products
It has a good GUI to monitor real-time logs for cloud applications. This is quite a useful tool and preferred over most of the competitive applications in the market.
Read full review
Reliability and Availability
Microsoft
No answers on this topic
Cisco
When properly setup and configured, Splunk is extremely reliable.
Read full review
Discontinued Products
No answers on this topic
Support Rating
Microsoft
Microsoft support is one of the highest rated on the market. It has global and multilingual support. Calls can be made over the phone and the solution is virtually instantaneous with the help of Microsoft engineers. It's great!
Read full review
Cisco
Splunk maintains a well resourced support system that has been consistent since we purchased the product. They help out in a timely manner and provide expert level information as needed. We typically open cases online and communicate when possible via e-mail and are able to resolve most issues with that method.
Read full review
Discontinued Products
The support is pretty good however some of the KB articles still reference different versions of the product so it can be hard to find answers to common questions
Read full review
Online Training
Microsoft
No answers on this topic
Cisco
The online course was simple clear and described the main capabilities of the solution. There is also an initial module that can be done for free so anyone can familiarize themselves with the functionality of this solution. On the other hand, however, there could be more free online courses. Maybe even with a certificate, this would broaden the group of people who are familiar with the platform while increasing familiarity with the solution itself.
Read full review
Discontinued Products
No answers on this topic
Implementation Rating
Microsoft
No answers on this topic
Cisco
Smooth without too many major issues.
Read full review
Discontinued Products
No answers on this topic
Alternatives Considered
Microsoft
Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and Wazuh. It lags in third-party integrations and syslog parsing. Organizations choose Microsoft Sentinel for its cost-effectiveness, automation, and Microsoft synergy, especially in Azure-heavy environments, though Splunk and Exabeam lead in flexibility and UEBA, respectively.
Read full review
Cisco
A lot of products have natively inside their own dashboards and or their own logging repositories. And each one is difficult to learn or they're too complex or they're not verbose in the sense that they're not easy to mine the data that you're looking for. So that could be anything from the native logging that you find in other Cisco products. It's easier to use Splunk to draw the data that you're looking for as opposed to going to the individual's products themselves to get the logs that you're looking for.
Read full review
Discontinued Products
SCOM was quite overwhelming when we first set up a POC for it. There was just too much for one person to handle. With vROPs I can manage the product and provide the support needed for my environment. We also have a Solarwinds environment that provides us with a level of detail and alerting we have come to rely upon. vROPS takes it to another level because it links directly into vCenter to provide you with a complete picture of your virtual environment.
Read full review
Contract Terms and Pricing Model
Microsoft
No answers on this topic
Cisco
No answers on this topic
Discontinued Products
Not involved in purchasing.
Read full review
Scalability
Microsoft
No answers on this topic
Cisco
Splunk can scale in to the petabyte per day range which of course is awesome
Read full review
Discontinued Products
No answers on this topic
Professional Services
Microsoft
Did not use professional services
Read full review
Cisco
No answers on this topic
Discontinued Products
No answers on this topic
Return on Investment
Microsoft
  • As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.
Read full review
Cisco
  • Splunk has allowed developers to diagnose production issues when access of control was taken away from them to be allowed to view items in production environments and I believe that is invaluable.
  • At times some developers weren't super happy about using it, but it was more of the fact that they were used to having production access and not creating their splunk queries to get information.
  • Going one place to view logs was very beneficial to have.
Read full review
Discontinued Products
  • We believe that the ability to preplan deployments with vRealize has proven its return on investments.
  • Our troubleshooting time has been reduced with vrealize because its constantly collecting performance data. typically vrealize will tell us cause of fault before we can determine it ourselves.
Read full review
ScreenShots

Microsoft Sentinel Screenshots

Screenshot of Screenshot of Screenshot of Microsoft Sentinel Capabilities