vimal p.
VP
Sr. Security Analyst
Mid-Market (51-1000 emp.)
"Best Cloud native SIEM - Microsoft Sentinel"
4.5/5
What do you like best about Microsoft Sentinel?

Correlates logs across our multi-tenant environment really well, especially with custom analytics rules. Integration with Log Analytics and the automation rules (like auto-ticket creation) saves a lot of manual triage time. Threat hunting queries in KQL are powerful once you get the hang of them, way more flexible than our old SIEM. Liked the overall UI-UX. performance compared to other SIEM tools and and they now also provide inbuilt AI agent integration work even more faster and smarter. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Sentinel?

Cost can spiral fast once log ingestion volume goes up, especially with verbose data connectors like firewall logs.

Some out-of-the-box analytics rules generate noisy alerts, needed a lot of tuning before they were actually useful. Review collected by and hosted on G2.com.

See what 275 reviewers think of Microsoft Sentinel

4.4 out of 5 · Verified reviews from real users

Read all reviews