Microsoft Sentinel review
Use Cases and Deployment Scope
Microsoft Sentinel is used both as siem and soar solution in our customer environment . We are also sending logs from Microsoft Sentinel to prisma. We are running kql queries on Microsoft Sentinel to do threat hunting
Pros
- siem solution
- automation with runbooks
- soar solution
- compatible with other vendor solution
- providing compliance
Cons
- ticketing system
- other third party app should also be compatible
- pricing
- better features for hybrid cloud
Return on Investment
- reduced cost occured for legacy system and saving 50000 dollar upto 1 year
- reduced false positive incidents up to 90 percent
- faster deployment over 100000 dollar up to 1 year
Alternatives Considered
Splunk Cloud
Other Software Used
Splunk Cloud, IBM Security QRadar EDR, LogRhythm NetworkXDR






