TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Microsoft Sentinel

    Score8.7 out of 10
    N/AMicrosoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

    $2.46

    per GB ingested

    Splunk Enterprise Security

    Score9.8 out of 10
    N/ASplunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
    Pricing
    Microsoft SentinelSplunk Enterprise Security
    Editions & Modules
    Azure Sentinel
    $2.46
    per GB ingested
    100 GB per day
    $123.00
    per day
    200 GB per day
    $221.40
    per day
    300 GB per day
    $319.80
    per day
    400 GB per day
    $410.00
    per day
    500 GB per day
    $492.00
    per day
    More than 500 GB per day
    $492.00 + $98.40
    per day/plus each additional 100 GB increment
    No answers on this topic
    Offerings
    Pricing Offerings
    Microsoft SentinelSplunk Enterprise Security
    Free Trial
    YesNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Community Pulse
    Microsoft SentinelSplunk Enterprise Security
    Considered Both Products
    Microsoft
    Chose Microsoft Sentinel
    Prior to using Sentinel, we were using Splunk specifically Splunk Enterprise Security and Splunk Cloud, so their on-prem and their cloud-based products. We switched originally for cost reasons, specifically cost control, but I have found that the ability to create reports, the …
    Incentivized
    Chose Microsoft Sentinel
    As the vast majority of our users have Windows machine and uses all 365 cloud features, we finally decided not to implement any 3rd party security solutions on desktops/laptops in order to keep our infrastructure simple. In this case, Microsoft Sentinel is the best way to …
    Incentivized
    Chose Microsoft Sentinel
    Microsoft Sentinel feels on another different level from these solutions , all in the cloud . No need for troubleshooting , deployment or upgrades. Constant updates from the vendor and good support
    Incentivized
    Chose Microsoft Sentinel
    Microsoft Sentinel excels in cloud-native scalability, Microsoft ecosystem integration, and AI-driven threat detection with UEBA and Fusion rules, offering faster deployment and lower costs (48% cheaper per Forrester) than Splunk, QRadar, Exabeam, SentinelOne, Securonix, and …
    Incentivized
    Cisco
    Chose Splunk Enterprise Security
    I did not choose this product. Overall although I like ES, I think Sentinel in certain ways is the superior product. The Kusto Query language is a lot easier to use. For instance anything that requires manual parsing in query can be more difficult with this product. Also some …
    Incentivized
    Chose Splunk Enterprise Security
    Using Splunk Enterprise Security allows the combination of security data sources from any number of services or products, giving analysts a single view of the entire security footprint throughout the organization and correlating events across services that may otherwise be …
    Incentivized
    Chose Splunk Enterprise Security
    In our tests, Sentinel came really close. It was even easier to deploy for cloud native environments. However, once we started integrating OT logs and custom threat intel feeds, the performance and correlation didn't scale as efficiently.
    Incentivized
    Key User Insights
    Would buy again
    98%
    Would buy again
    46 Answers
    99%
    Would buy again
    100 Answers
    Delivers good value for the price
    90%
    Delivers good value for the price
    38 Answers
    94%
    Delivers good value for the price
    84 Answers
    Happy with the feature set
    98%
    Happy with the feature set
    46 Answers
    94%
    Happy with the feature set
    95 Answers
    Lived up to sales and marketing promises
    92%
    Lived up to sales and marketing promises
    35 Answers
    93%
    Lived up to sales and marketing promises
    74 Answers
    Implementation went as expected
    98%
    Implementation went as expected
    43 Answers
    91%
    Implementation went as expected
    84 Answers
    Features
    Microsoft SentinelSplunk Enterprise Security
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of Microsoft Sentinel and Splunk Enterprise Security
    Feature
    Microsoft Sentinel
    7.3
    24 Ratings
    6% below category average
    Splunk Enterprise Security
    8.4
    102 Ratings
    8% above category average
    Centralized event and log data collection8.324 Ratings9.3100 Ratings
    Correlation7.124 Ratings8.699 Ratings
    Event and log normalization/management6.924 Ratings8.5100 Ratings
    Deployment flexibility7.522 Ratings8.3101 Ratings
    Integration with Identity and Access Management Tools6.422 Ratings7.896 Ratings
    Custom dashboards and workspaces7.524 Ratings9.2102 Ratings
    Host and network-based intrusion detection5.020 Ratings7.996 Ratings
    Data integration/API management6.522 Ratings8.498 Ratings
    Behavioral analytics and baselining6.920 Ratings7.795 Ratings
    Rules-based and algorithmic detection thresholds7.922 Ratings8.596 Ratings
    Response orchestration and automation7.221 Ratings7.087 Ratings
    Reporting and compliance management9.04 Ratings8.695 Ratings
    Incident indexing/searching8.622 Ratings9.2101 Ratings
    Best Alternatives
    Microsoft SentinelSplunk Enterprise Security
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    IBM Security QRadar SIEM
    Score9 out of 10
    IBM Security QRadar SIEM
    Score9 out of 10
    Enterprises
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    Microsoft SentinelSplunk Enterprise Security
    Likelihood to Recommend
    8.6
    (43 ratings)
    8.9
    (103 ratings)
    Likelihood to Renew
    8.2
    (1 ratings)
    9.0
    (3 ratings)
    Usability
    7.3
    (4 ratings)
    7.5
    (2 ratings)
    Availability
    -
    (0 ratings)
    9.1
    (1 ratings)
    Performance
    -
    (0 ratings)
    8.2
    (1 ratings)
    Support Rating
    8.0
    (3 ratings)
    6.6
    (6 ratings)
    In-Person Training
    -
    (0 ratings)
    9.1
    (1 ratings)
    Online Training
    -
    (0 ratings)
    8.2
    (1 ratings)
    Implementation Rating
    -
    (0 ratings)
    9.1
    (1 ratings)
    Configurability
    -
    (0 ratings)
    7.3
    (1 ratings)
    Contract Terms and Pricing Model
    -
    (0 ratings)
    7.3
    (1 ratings)
    Ease of integration
    -
    (0 ratings)
    6.4
    (1 ratings)
    Product Scalability
    -
    (0 ratings)
    9.3
    (100 ratings)
    Professional Services
    5.0
    (1 ratings)
    9.1
    (1 ratings)
    Vendor post-sale
    -
    (0 ratings)
    8.2
    (1 ratings)
    Vendor pre-sale
    -
    (0 ratings)
    8.2
    (1 ratings)
    User Testimonials
    Microsoft SentinelSplunk Enterprise Security
    Likelihood to Recommend
    Microsoft
    Microsoft Sentinel excels in centralized monitoring, AI-driven threat detection, and automation, but improvements in cost transparency, user experience, third-party integrations, and support for emerging technologies could make it even more effective. Addressing these areas would enhance its appeal for small-to-medium businesses, large enterprises, and organizations with complex or specialized IT environments.
    Incentivized
    Read full review
    Cisco
    Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.
    Incentivized
    Read full review
    Pros
    Microsoft
    • I appreciate that it keeps the data within our, what we call our, authorization boundary. The fact that the data remains within Microsoft's, I guess, walled garden if you will, is very helpful for certain compliance needs in particular.
    • The large library of ingestion: ability to ingest is basically as easy as I can basically get it to be most of the time. There's occasionally some vendors that it's a little bit more challenging for, but given the ease of integration for a lot of things, basically it's become one of my requirements when I am looking at other tools is how easily do they integrate with Sentinel.
    Incentivized
    Read full review
    Cisco
    • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
    • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
    • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.
    Incentivized
    Read full review
    Cons
    Microsoft
    • I think it should include more third party integration with non microsoft products as well as with other cloud providers. These integrations should be native.
    • It should improve ML and AI capabilities.
    • I find its documentation a little bit difficult to understand at the start. So the words should be simple.
    Incentivized
    Read full review
    Cisco
    • ES on the cloud (SaaS) has too many limitations with platform administration.
    • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
    • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
    Read full review
    Likelihood to Renew
    Microsoft
    it does the job reasonably well
    Incentivized
    Read full review
    Cisco
    We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
    Incentivized
    Read full review
    Usability
    Microsoft
    The Microsoft Azure Sentinel solution is very good and even better if you use Azure. It's easy to implement and learn how to use the tool with an intuitive and simple interface. New updates are happening to always bring new news and improve the experience and usability. The solution brings reliability as it is from a very reliable manufacturer.
    Incentivized
    Read full review
    Cisco
    You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.
    Incentivized
    Read full review
    Reliability and Availability
    Microsoft
    No answers on this topic
    Cisco
    I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.
    Incentivized
    Read full review
    Performance
    Microsoft
    No answers on this topic
    Cisco
    ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.
    Incentivized
    Read full review
    Support Rating
    Microsoft
    Azure Sentinel is very easy to use and configure. If you are stuck somewhere, Microsoft support is excellent in assisting and solving your issue.
    Incentivized
    Read full review
    Cisco
    It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
    Incentivized
    Read full review
    In-Person Training
    Microsoft
    No answers on this topic
    Cisco
    I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
    Incentivized
    Read full review
    Online Training
    Microsoft
    No answers on this topic
    Cisco
    It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
    Incentivized
    Read full review
    Implementation Rating
    Microsoft
    No answers on this topic
    Cisco
    It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
    Incentivized
    Read full review
    Alternatives Considered
    Microsoft
    We decided to go with Microsoft Sentinel because it works really well with Microsoft tools we are already using. Microsoft Sentinel's intelligent features detect and resolve problems more quickly than Sumo Logic. It also allows us to pay for what we use and grow as we need. While Sumo Logic is good at analyzing data, Microsoft Sentinel fits our needs.
    Read full review
    Cisco
    Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
    Incentivized
    Read full review
    Contract Terms and Pricing Model
    Microsoft
    No answers on this topic
    Cisco
    for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
    Incentivized
    Read full review
    Scalability
    Microsoft
    No answers on this topic
    Cisco
    - 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
    Incentivized
    Read full review
    Professional Services
    Microsoft
    Did not use professional services
    Incentivized
    Read full review
    Cisco
    I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
    Incentivized
    Read full review
    Return on Investment
    Microsoft
    • As any cybersecurity product, this has to be more with risk to avoid loss in case of a ransomware that more than relate to a productivity increase. Maybe the impact could be that instead of having people that are checking 24/7 the dashboard, you could implement Sentinel and have less people checking that or people with less expertise. So the saving will be a minor but will be a saving in the cost of your team.
    Incentivized
    Read full review
    Cisco
    • ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
    • The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
    • The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.
    Incentivized
    Read full review
    ScreenShots

    Microsoft Sentinel Screenshots

    Product screenshotProduct screenshotScreenshot of Microsoft Sentinel Capabilities