• HOME
  • CATEGORIES

    • CATEGORIES

    • Application Development

      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • View All
    • Artificial Intelligence

      • AI Code Assistants (Transitioning to AI Coding Agents)
      • Generative AI Knowledge Management Apps/General Productivity
      • AI Application Development Platforms
      • Conversational AI Platforms
      • Artificial Intelligence Applications in IT Service Management (Transitioning to AI Applications in IT Service Management)
      • View All
    • Cloud Computing

      • Backup and Data Protection Platforms
      • Cloud Database Management Systems
      • Strategic Cloud Platform Services
      • Server Virtualization (Transitioning to Server Virtualization Platforms)
      • Hybrid Cloud Storage
      • View All
    • Customer Relationship Management

      • Contact Center as a Service
      • CRM Customer Engagement Center
      • Digital Experience Platforms
      • Web Content Management
      • Field Service Management
      • View All
    • Data and Analytics

      • Analytics and Business Intelligence Platforms
      • Data Science and Machine Learning Platforms (Transitioning to AI Platforms For Data Science and Machine Learning)
      • Data Integration Tools
      • Process Mining Platforms (Transitioning to Process Intelligence Platforms)
      • Augmented Data Quality Solutions
      • View All
    • Education

      • Manager and Leadership Training
      • Corporate Learning Technologies
      • eLearning Authoring Tools
      • Higher Education Student Information System Software as a Service (Transitioning to Higher Education SaaS Student Information Systems)
      • Digital Learning Content Providers
      • View All
    • Enterprise Networking and Communications

      • Unified Communications as a Service
      • Global WAN Services
      • Intranet Packaged Solutions
      • SD-WAN
      • Edge Distribution Platforms
      • View All
    • Finance

      • Expense Management Software
      • Financial Close and Consolidation Solutions
      • Financial Planning Software
      • Cloud Financial Management Tools
      • Accounts Payable Applications
      • View All
    • Healthcare and Life Sciences

      • Medical Device Security Solutions (Transitioning to Medical Device Risk Management Platforms)
      • Health Navigation Solutions
      • Claim Editor Software
      • Revenue Cycle Management Software (Transitioning to Revenue Cycle Management Solutions)
      • Digital Health Platforms (Transitioning to Healthcare Provider Industry Cloud Platforms)
      • View All
    • Human Resources

      • Employee Recognition and Reward Systems
      • Workforce Management Applications (Transitioning to Workforce Management (WFM) Technology)
      • Digital Employee Experience Management Tools
      • Talent Acquisition (Recruiting) Suites
      • Cloud HCM Suites for Regional and/or Sub-1,000 Employee Enterprises
      • View All
    • IT Infrastructure and IoT

      • Enterprise Wired and Wireless LAN Infrastructure (Transitioning to Enterprise Wired and Wireless LAN)
      • Endpoint Management Tools
      • IT Service Management Platforms
      • Container Management
      • Infrastructure Monitoring Tools
      • View All
    • IT Security

      • Endpoint Protection Platforms
      • Email Security
      • Managed Detection and Response
      • Security Information and Event Management
      • Security Awareness Computer-Based Training
      • View All
    • Legal

      • Contract Life Cycle Management
      • Electronic Signature
      • Governance, Risk and Compliance Tools, Assurance Leaders
      • Compliance Monitoring Solutions
      • Corporate Governance Services
      • View All
    • Manufacturing

      • Enterprise Asset Management Software
      • Manufacturing Execution Systems
      • Global Industrial IoT Platforms
      • PLM Software in Discrete Manufacturing Industries
      • Computer-Aided Design (CAD) Software
      • View All
    • Marketing

      • Video Editing Software
      • Email Marketing
      • Multichannel Marketing Hubs
      • Customer Data Platforms
      • Event Marketing and Management Platforms
      • View All
    • Productivity and Collaboration

      • Document Management
      • Visual Collaboration Applications
      • Collaborative Work Management
      • Knowledge Management (KM) Software
      • Meeting Solutions
      • View All
    • Public Sector and Government

      • Government Budgeting and Planning Solution
      • Cloud-Based ERP for U.S. Local Government
      • Citizen Service Delivery
      • Government ERP Solutions
      • Government Contracting Software
      • View All
    • Retail

      • Digital Commerce
      • Digital Commerce Payment Vendors (Transitioning to Digital Commerce Payment Platforms)
      • Retail Assortment Management Applications: Long Life Cycle Products
      • Retail Workforce Management Applications (Transitioning to Retail Workforce Management Technology)
      • Digital Shelf Analytics
      • View All
    • Sales

      • Sales Force Automation Platforms (Transitioning to CRM Sales Platforms)
      • Revenue Enablement Platforms
      • Revenue Intelligence (Transitioning to Revenue Action Orchestration)
      • Configure, Price and Quote Applications
      • Search and Product Discovery
      • View All
    • Supply Chain Management

      • Supply Chain Planning Solutions
      • Transportation Management Systems
      • Real-Time Transportation Visibility Platforms
      • Warehouse Management Systems
      • Supply Chain Strategy, Planning and Operations Consulting
      • View All
    • Utilities

      • Geospatial Information Systems for Energy and Utilities
      • Mobile Workforce Management Software for Utilities (Transitioning to Mobile Workforce Management Solutions for Power and Utilities)
      • Energy Management and Optimization Systems
      • Energy Trading and Risk Management
      • Advanced Distribution Management Systems
      • View All
    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

      • Application Development
      • Artificial Intelligence
      • Cloud Computing
      • Customer Relationship Management
      • Data and Analytics
      • Education
      • Enterprise Networking and Communications
      • Finance
      • Healthcare and Life Sciences
      • Human Resources
      • IT Infrastructure and IoT
      • IT Security
      • Legal
      • Manufacturing
      • Marketing
      • Productivity and Collaboration
      • Public Sector and Government
      • Retail
      • Sales
      • Supply Chain Management
      • Utilities
      Browse All Categories

      Application Development

      69 markets
      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • API Management
      • Enterprise Low-Code Application Platforms
      • Robotic Process Automation
      • DevOps Platforms (Transitioning to DevSecOps Platforms)
      • Business Process Automation Tools
      • Enterprise Architecture Tools
      • Business Orchestration and Automation Technologies
      • Custom Software Development Services
      • Code Review Tools
      • Digital Adoption Platforms
      • Domain Registrars
      • Public Cloud IT Transformation Services (Transitioning to Public Cloud Optimization and Transformation Services)
      • Game Engine Software
      • Website Builders
      • Developer Productivity Insight Platforms
      • AI Agents for Application Developers
      • Application Platforms (Transitioning to Cloud-Native Application Protection Platforms)
      • Feature Management
      • Application Crowdtesting Services
      • Test Data Management
      • API Generation Software
      • Prototyping Software
      • Mobile App Analytics
      • AI-Augmented Code Modernization Tools
      • Virtual Reality Development Software
      • Application Testing Services, Worldwide (Transitioning to Quality Engineering Services)
      • Green Software Engineering
      • Application Integration Platforms
      • Event Brokers
      • Digital Twin of an Organization Platforms
      • Independent Third-Party Software Support of Megavendors
      • Microsoft 365 Implementation and Support Services
      • Application Development Life Cycle Management (Transitioning to DevOps Platforms)
      • BPM-Platform-Based Case Management Frameworks
      • Microsoft Product Support Services
      • Product Roadmapping Tools for Software Engineering
      • Multiexperience Development Platforms
      • AI Agent Development Platforms for Software Engineering
      • Application Portfolio Management Tools
      • Application Composition Platform
      • Internal Developer Portals
      • Cloud Development Environments
      • Mobile Development Frameworks (Transitioning to Web and Mobile Development Frameworks)
      • Load Testing Tools
      • Blockchain Consulting and Proof-of-Concept Development Services
      • B2B Gateway Software
      • Citizen Application Development Platforms
      • Mobile Application Testing Services
      • SAP S/4HANA Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Oracle Cloud Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • SAP Application Services, Worldwide
      • SAP SuccessFactors Service Providers (Transitioning to Cloud ERP Services)
      • Service Mesh
      • Value Stream Management Platforms
      • Business-Outcome-Driven Enterprise Architecture Consulting (Retired)
      • Oracle Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Rapid Mobile App Development Tools
      • SAP Selective Test Data Management Tools
      • API and MCP Testing Tools
      • Augmented Reality Development Software
      • Blockchain as a Service
      • Mobile Application Management (Transitioning to Endpoint Management Tools)
      • Mobile Back-End Services
      • R&D Outsourcing Providers
      View More
  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Microsoft Sentinel
Logo of Microsoft Sentinel

Microsoft Sentinel

byMicrosoft
in
4.5
Market Presence: Security Information and Event Management, SAP Security Software

Overview

Product Information on Microsoft Sentinel

Updated 14th October 2025

What is Microsoft Sentinel?

Microsoft Sentinel is a security information and event management software designed to help organizations detect, investigate, and respond to potential threats across their digital environments. The software aggregates and analyzes data from various sources such as users, applications, servers, and devices, both on-premises and in the cloud. It utilizes artificial intelligence to identify patterns and anomalies that may indicate security risks. Microsoft Sentinel provides capabilities for automated incident response, threat intelligence enrichment, and customizable dashboards for monitoring and reporting. The software aims to streamline security operations, reduce the time to investigate incidents, and support compliance with various regulatory requirements by offering integrated management and analytics tools for safeguarding enterprise assets.

Microsoft Sentinel Pricing

Microsoft Sentinel is a software that follows a usage-based pricing model, where charges are determined by the volume of data ingested for analysis and log retention, with additional costs for automation and incident response features. The software provides options for flexible data retention periods and allows organizations to select and pay for capabilities according to their intake and operational requirements.

Overall experience with Microsoft Sentinel

MANAGER, IT SECURITY AND RISK MANAGEMENT
250M - 500M USD, Manufacturing
FAVORABLE

“Automation With Logic Apps Shines, But GUI Features Remain Limited In Sentinel”

4.0
Nov 29, 2025
Sentinel is by far my favorite SIEM. We migrated away from another vendor and have been all in on Sentinel for about 2 years now. Being able to use Logic apps for automation is great and I just find KQL to be far more intuitive than dealing with SPL, which is likely because the same skills can be used on other various logs in Azure for Diagnostics.
IT MANAGER
<50M USD, Banking
CRITICAL

“Integration with Microsoft Smooth, Third-Party and Querying Hinder Experience”

3.0
Jul 18, 2025
Its a tool that is a bit difficult to undestand since the portal is not friendly to a rookie user

About Company

Company Description

Updated 11th August 2023

Microsoft enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. Microsoft is dedicated to advancing human and organizational achievement. Microsoft Security helps protect people and data against cyberthreats to give peace of mind.

Company Details

Updated 25th March 2024
Company type
Public
Year Founded
1975
Head office location
Redmond, Washington, United States
Number of employees
10000+
Annual Revenue
30B+ USD
Website
https://microsoft.com

Do You Manage Peer Insights at Microsoft?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Microsoft Sentinel
Reviewer Insights for: Microsoft Sentinel
Deciding Factors: Microsoft Sentinel Vs. Market Average
Performance of Microsoft Sentinel Across Market Features

Microsoft Sentinel Likes & Dislikes

Like

KQL is awesome to work with, and easy to pick up and start working with. There are always other things you can really dive into to improve your skills, like functions or setting up ASIM tables to format your data. The transformations on a data collection rule make it very easy to bring in just the data that you need, even if you do pay a bit for some transformation if you are dropping a lot of data.

Like

It is easu to integrate with Microsoft envioronments, both cloud and on-premise

Like

Microsoft Sentinel offers the most efficient threat detection features which makes it possible for us to capture even the most hidden and advanced security threats. It has powerful threat investigation and analytics features powered by AI, allowing us to gather all the information we need about a specific threat and this allows us to respond to the threats the right way. Microsoft Sentinel has automation features which have allowed us to setup custom threat response workflows to automatically resolve threats as soon as they are detected. It provides us with clear threat reports that allow us to find connections between related threats making it easy to take all the necessary measures to avoid the threats from ever happening again.

Dislike

Some of the areas of the main page just do not work as expected. For example, on an entity, you can click on it and there is an Insights tab that almost never loads information. The investigation page is almost worthless as well. I love Sentinel for the automation, but the GUI features are just not there, and with the migration into Defender, I don't see them being updated.

Dislike

What I dont like at all is the thir-party integration, the associated costs when integrating new sources, and keeping in mind that every GB used must be included in the budget. On the other hand, theres the issue of queries, for which you must have knowledge of KQL

Dislike

For the entire period we have been working with Microsoft Sentinel, we have not seen any issues to report or anything that we dislike. All its features are very responsive and work incredibly perfect for us.

Top Microsoft Sentinel Alternatives

Logo of Splunk Enterprise
1. Splunk Enterprise
4.5
(1036 Ratings)
Logo of LogRhythm SIEM
2. LogRhythm SIEM
4.3
(715 Ratings)
Logo of IBM Security QRadar SIEM
3. IBM Security QRadar SIEM
4.3
(657 Ratings)
View All Alternatives

Peer Discussions

Microsoft Sentinel Reviews and Ratings

4.5

(274 Ratings)

Rating Distribution

5 Star
56%
4 Star
40%
3 Star
3%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.6

Service & Support

4.4

Product Capabilities

4.6

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • MANAGER, IT SECURITY AND RISK MANAGEMENT
    50M-1B USD
    Manufacturing
    Review Source

    Automation With Logic Apps Shines, But GUI Features Remain Limited In Sentinel

    4.0
    Nov 28, 2025
    Sentinel is by far my favorite SIEM. We migrated away from another vendor and have been all in on Sentinel for about 2 years now. Being able to use Logic apps for automation is great and I just find KQL to be far more intuitive than dealing with SPL, which is likely because the same skills can be used on other various logs in Azure for Diagnostics.
  • Senior Network Engineer
    50M-1B USD
    Telecommunication
    Review Source

    Boost security with Microsoft Sentinel's advanced threat detection, intelligence and management features.

    5.0
    Mar 9, 2026
    We have been using Microsoft Sentinel for a while now to handle security threats management operations and the experience has been very productive. Microsoft Sentinel provides us with a range of very powerful security management features that allow us to analyze, detect, investigate and respond to security threats thoroughly. With its advanced threat detection features, we have been able to stay alert and capture all suspicious security activities before they cause any harm. Microsoft Sentinel offers us outstanding threat intelligence features that allow us to investigate all detected threats, making it easy to understand their root causes, their origin and the best way to respond to them.
  • Psychoanalyst, Psychotherapist Membro Or
    50M-1B USD
    Healthcare and Biotech
    Review Source

    Enhance data security with Microsoft Sentinel's powerful threat detection features.

    5.0
    Mar 5, 2026
    Microsoft Sentinel has been a very reliable security enhancement tool for us that allows us to keep all our data and resources safe from security threats. It has been providing with very effective security threat analytics and detection features which help us to discover any threats and respond to them quickly. With Microsoft Sentinel, it has been easily possible for us to achieve and maintain a safe working environment for everyone and to keep our data safeguarded from all sorts of security threats.
  • Manager Of It Services
    50M-1B USD
    Banking
    Review Source

    AI-Driven Sentinel Enhances Security Efficiency, Yet Presents Learning And Cost Challenges

    4.0
    Mar 7, 2026
    Microsoft Sentinel helps you spot, investigate and prevent threats and cyberattacks. it acts as a SIEM and SOAR, which gathers the data and prepares automated responses. As a cloud-native solution, you do not need to maintain a physical server to run Microsoft Sentinel. It connects to different tools like Microsoft 365, AWS, GCP which helps to monitor security alerts in one single place. It has the ability to take required action whenever required using the playbook, which saves the time and effort of security team members of organization. As the solution comes with AI-driven capabilities that help to enhance the security posture of an organization by mitigating or neutralizing threats before any damage is done.
  • Manager, IT Security and Risk Management
    50M-1B USD
    Banking
    Review Source

    Copilot Integration in Microsoft Sentinel Transforms Incident Investigation Process

    4.0
    Mar 4, 2026
    Microsoft Sentinel is one of the next generation SIEM platform that offers core SIEM capabilities along with AI powered features. With Copilot integration, we can speed up the incident investigation as Copilot generates incident summary, readymade email template and much more. The advanced KQL is very powerful for investigating and correlating logs. We can even use sql functions like join, union to perform threat hunting, use in rules for real time detections etc.
...
Showing Result 1-5 of 453

Recommended Gartner Research

  • Critical Capabilities for Security Information and Event Management
  • Magic Quadrant for Security Information and Event Management

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.