Sentinel Review
August 12, 2024

Sentinel Review

Anonymous | TrustRadius Reviewer
Score 5 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Sentinel

We are using it for our Microsoft based events, Azure, 365, things like that, and only for Microsoft. And the reason why we are using it is because we're of the impression that Microsoft knows Microsoft and that the prebuilt alerting and detections will have value.

Pros

  • Azure Logs, specifically the detections and alerting.

Cons

  • Because it can be so complicated pulling in outside log sources, we don't. It's just hard to do that when you do bring in a log source, even if it's Azure, that's also pretty difficult. It has to go to a single log location regardless of the subscription that you're sending it from. And then of course it's really hard to find the original events.
Right now, just Azure Activity, Entra ID, O365
Complex. It's really difficult to manage the permissions and the roles.
We have tried using them. We haven't accomplished anything yet.
I'm not using that yet.
Well, we didn't select, we selected Sentinel for our Azure stuff, our Microsoft stuff, but we do use a different SIEM for the other stuff still.

Do you think Microsoft Sentinel delivers good value for the price?

No

Are you happy with Microsoft Sentinel's feature set?

Yes

Did Microsoft Sentinel live up to sales and marketing promises?

No

Did implementation of Microsoft Sentinel go as expected?

Yes

Would you buy Microsoft Sentinel again?

Yes

It's well suited for Microsoft Azure Logs, assuming you can get them in there, but when you're in a multi subscription environment and you have a lot of ambiguity, it makes it really difficult to pull stuff in.

Microsoft Sentinel Feature Ratings

Centralized event and log data collection
Not Rated
Correlation
Not Rated
Event and log normalization/management
Not Rated
Deployment flexibility
Not Rated
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
Not Rated
Host and network-based intrusion detection
Not Rated
Log retention
Not Rated
Data integration/API management
Not Rated
Behavioral analytics and baselining
Not Rated
Rules-based and algorithmic detection thresholds
Not Rated
Response orchestration and automation
Not Rated
Incident indexing/searching
Not Rated

Comments

More Reviews of Microsoft Sentinel