Elizabeth E.
EE
Cyber Security / SOC Analyst Intern
Mid-Market (51-1000 emp.)
"Unified Visibility and AI-Assisted Investigations That Speed Up Response"
4/5
What do you like best about Singularity AI SIEM?

What I like most about SentinelOne Singularity AI SIEM is its ability to unify endpoint telemetry, cloud data, identity events, and third-party log sources into a single platform for investigation and threat detection. Having centralized visibility significantly reduces the time spent switching between multiple security tools during an investigation.

The AI-assisted investigation capabilities have been particularly valuable. Instead of manually correlating events across different data sources, the platform automatically connects related activities into a single attack story, making it much easier to understand the full scope of an incident. This has helped reduce investigation time and enabled faster incident response.

I also use the advanced search and threat hunting features regularly. The search performance is fast, allowing me to query large volumes of logs and quickly identify indicators of compromise, suspicious user activity, or lateral movement. This has improved my workflow by helping me validate alerts and perform proactive threat hunting more efficiently. Review collected by and hosted on G2.com.

What do you dislike about Singularity AI SIEM?

Some advanced searches and rule tuning have a learning curve, and more granular customization options for dashboards and reporting would make it easier to tailor the platform to different SOC workflow Review collected by and hosted on G2.com.

See what 5 reviewers think of Singularity AI SIEM

4.4 out of 5 · Verified reviews from real users

Read all reviews