Sentinel Review
August 12, 2024

Sentinel Review

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Sentinel

The scope of our use case is we use it just as a SIEM, so alerting, triage, some logging. That's kind of the main gist of it.

Pros

  • I would be quite happy with the as code deployment through Bicep, being able to code up use cases and analytical rules has been quite good.

Cons

  • One thing I think recommendation that I've gotten from our team is adding a task section. So having a SOC analyst have certain tasks you can check off and have that be able to deploy through code as well.
  • It's been average. We've chosen it because of the cost reduction.
We pull data mainly from the office 365 stack end user devices.
Pretty easy.
No, so I can't answer the rest.
Don't really, it's mostly manual
We've used Splunk before, but it really is just pick your poison. They're all very similar.

Do you think Microsoft Sentinel delivers good value for the price?

No

Are you happy with Microsoft Sentinel's feature set?

Yes

Did Microsoft Sentinel live up to sales and marketing promises?

Yes

Did implementation of Microsoft Sentinel go as expected?

Yes

Would you buy Microsoft Sentinel again?

Yes

I suppose it's a serviceable SIEM. It's similar to most other ones really.

Microsoft Sentinel Feature Ratings

Centralized event and log data collection
Not Rated
Correlation
Not Rated
Event and log normalization/management
Not Rated
Deployment flexibility
Not Rated
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
Not Rated
Host and network-based intrusion detection
Not Rated
Log retention
Not Rated
Data integration/API management
Not Rated
Behavioral analytics and baselining
Not Rated
Rules-based and algorithmic detection thresholds
Not Rated
Response orchestration and automation
Not Rated
Incident indexing/searching
Not Rated

Comments

More Reviews of Microsoft Sentinel