Microsoft Sentinel Review
August 09, 2024

Microsoft Sentinel Review

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Sentinel

We use it to aggregate alerts from different technologies. We look for a deposit target to ingest all our logs and we decided to go with the Microsoft stack.

Pros

  • It's very good to ingest logs. It's easy.
  • I also like the built-in libraries for detection.

Cons

  • I would like to be easier to whitelist alerts when I have a lot of noise from second and technology.
  • Positive: It's much easier to investigate the logs.
  • Negative: I have many more logs to investigate.
Mostly Microsoft XDR, Entra ID and the Microsoft stack.
I didn't do sub, third party did, but it seems quite straightforward.
I use it as a guy CM, so I image like a sock would work.

Do you think Microsoft Sentinel delivers good value for the price?

Yes

Are you happy with Microsoft Sentinel's feature set?

Yes

Did Microsoft Sentinel live up to sales and marketing promises?

Yes

Did implementation of Microsoft Sentinel go as expected?

Yes

Would you buy Microsoft Sentinel again?

Yes

It's buggy, but well suited if you use the full Microsoft stack. So if you use X-D-R-E-D-R is buggy easy to investigate to alerts. Sometimes when you ingest log from different technologies it might be harder.

Microsoft Sentinel Feature Ratings

Centralized event and log data collection
Not Rated
Correlation
Not Rated
Event and log normalization/management
Not Rated
Deployment flexibility
Not Rated
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
Not Rated
Host and network-based intrusion detection
Not Rated
Log retention
Not Rated
Data integration/API management
Not Rated
Behavioral analytics and baselining
Not Rated
Rules-based and algorithmic detection thresholds
Not Rated
Response orchestration and automation
Not Rated
Incident indexing/searching
Not Rated

Comments

More Reviews of Microsoft Sentinel