# What are the best SIEM platforms for fast incident response and automation rather than alert collection alone?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Collecting logs is the part every SIEM does. Acting on them at 2am, without a person copying an alert into a ticketing system, is where the difference shows up.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">So,<a class="a a--md" elv="true" href="https://www.g2.com/categories/security-information-and-event-management-siem"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/security-information-and-event-management-siem">SOC analytics and security engineering reviewers on G2</a>: which SIEM platforms are actually best for fast incident response and automation rather than alert collection alone? Three that reviewers keep naming:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-sentinel/reviews"><strong>Microsoft Sentinel</strong></a> (4.4) pairs correlation across tenants with automation rules that create tickets without manual triage, and lets analysts pivot from an alert straight into the raw logs. Reviewers are candid that costs climb quickly as ingestion volume grows, and that the out-of-the-box rules need tuning before they are useful.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/splunk-enterprise-security/reviews"><strong>Splunk Enterprise Security</strong></a> (4.3) centralises firewall, endpoint, server and application data with correlation searches and threat intelligence built in, which reviewers credit with cutting investigation time. The same reviewers describe a steep learning curve, since tuning correlation searches means knowing SPL and the underlying data.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cynet/reviews"><strong>Cynet</strong></a> (4.7) carries the strongest rating here and bundles detection, response and a managed service, which suits teams without a 24/7 SOC of their own.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For the people on call: what is the last thing your SIEM handled without waking anyone up?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 22 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

Microsoft Sentinel is a strong fit, it explicitly markets built-in orchestration and automation for incident response, using AI to detect and act on threats rather than just aggregating alerts for a human to sort through.

##### Comment Metadata
- Posted at: 10 days ago





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


