• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Microsoft Sentinel
Logo of Microsoft Sentinel

Microsoft Sentinel

byMicrosoft
in
4.5
Market Presence: Security Information and Event Management, SAP Security Software

Overview

Product Information on Microsoft Sentinel

Updated 14th October 2025

What is Microsoft Sentinel?

Microsoft Sentinel is a security information and event management software designed to help organizations detect, investigate, and respond to potential threats across their digital environments. The software aggregates and analyzes data from various sources such as users, applications, servers, and devices, both on-premises and in the cloud. It utilizes artificial intelligence to identify patterns and anomalies that may indicate security risks. Microsoft Sentinel provides capabilities for automated incident response, threat intelligence enrichment, and customizable dashboards for monitoring and reporting. The software aims to streamline security operations, reduce the time to investigate incidents, and support compliance with various regulatory requirements by offering integrated management and analytics tools for safeguarding enterprise assets.

Microsoft Sentinel Pricing

Microsoft Sentinel is a software that follows a usage-based pricing model, where charges are determined by the volume of data ingested for analysis and log retention, with additional costs for automation and incident response features. The software provides options for flexible data retention periods and allows organizations to select and pay for capabilities according to their intake and operational requirements.

Overall experience with Microsoft Sentinel

MANAGER, IT SECURITY AND RISK MANAGEMENT
250M - 500M USD, Manufacturing
FAVORABLE

“Automation With Logic Apps Shines, But GUI Features Remain Limited In Sentinel”

4.0
Nov 29, 2025
Sentinel is by far my favorite SIEM. We migrated away from another vendor and have been all in on Sentinel for about 2 years now. Being able to use Logic apps for automation is great and I just find KQL to be far more intuitive than dealing with SPL, which is likely because the same skills can be used on other various logs in Azure for Diagnostics.
IT MANAGER
<50M USD, Banking
CRITICAL

“Integration with Microsoft Smooth, Third-Party and Querying Hinder Experience”

3.0
Jul 18, 2025
Its a tool that is a bit difficult to undestand since the portal is not friendly to a rookie user

About Company

Company Description

Updated 11th August 2023

Microsoft enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. Microsoft is dedicated to advancing human and organizational achievement. Microsoft Security helps protect people and data against cyberthreats to give peace of mind.

Company Details

Updated 25th March 2024
Company type
Public
Year Founded
1975
Head office location
Redmond, Washington, United States
Number of employees
10000+
Annual Revenue
30B+ USD
Website
https://microsoft.com

Do You Manage Peer Insights at Microsoft?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Microsoft Sentinel
Reviewer Insights for: Microsoft Sentinel
Deciding Factors: Microsoft Sentinel Vs. Market Average
Performance of Microsoft Sentinel Across Market Features

Microsoft Sentinel Likes & Dislikes

Like

KQL is awesome to work with, and easy to pick up and start working with. There are always other things you can really dive into to improve your skills, like functions or setting up ASIM tables to format your data. The transformations on a data collection rule make it very easy to bring in just the data that you need, even if you do pay a bit for some transformation if you are dropping a lot of data.

Like

It is easu to integrate with Microsoft envioronments, both cloud and on-premise

Like

Strong log correlations and analytics across a wide and ever expanding selection of data sources. Integration with the Microsoft Defender portal to have all Microsoft security related data in a common location. Ability to leverage the Customer Community Program to work closely with developers on my deployment needs. New AI features such as Security Copilot and the ability to query data in the data lake with natural language prompts.

Dislike

Some of the areas of the main page just do not work as expected. For example, on an entity, you can click on it and there is an Insights tab that almost never loads information. The investigation page is almost worthless as well. I love Sentinel for the automation, but the GUI features are just not there, and with the migration into Defender, I don't see them being updated.

Dislike

What I dont like at all is the thir-party integration, the associated costs when integrating new sources, and keeping in mind that every GB used must be included in the budget. On the other hand, theres the issue of queries, for which you must have knowledge of KQL

Dislike

The product always seems to be in a state of flux. It's not easy to keep up with new features and I wish there was some sort of versioning to the product. Bundle a bunch of changes into a release at a specified cadence.

Top Microsoft Sentinel Alternatives

Logo of Splunk Enterprise
1. Splunk Enterprise
4.5
(1027 Ratings)
Logo of LogRhythm SIEM
2. LogRhythm SIEM
4.3
(715 Ratings)
Logo of IBM Security QRadar SIEM
3. IBM Security QRadar SIEM
4.3
(657 Ratings)
View All Alternatives

Peer Discussions

Microsoft Sentinel Reviews and Ratings

4.5

(267 Ratings)

Rating Distribution

5 Star
57%
4 Star
39%
3 Star
3%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.4

Integration & Deployment

4.6

Service & Support

4.4

Product Capabilities

4.6

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • MANAGER, IT SECURITY AND RISK MANAGEMENT
    50M-1B USD
    Manufacturing
    Review Source

    Automation With Logic Apps Shines, But GUI Features Remain Limited In Sentinel

    4.0
    Nov 28, 2025
    Sentinel is by far my favorite SIEM. We migrated away from another vendor and have been all in on Sentinel for about 2 years now. Being able to use Logic apps for automation is great and I just find KQL to be far more intuitive than dealing with SPL, which is likely because the same skills can be used on other various logs in Azure for Diagnostics.
  • IT Security & Risk Management Associate
    50M-1B USD
    Software
    Review Source

    Microsoft Sentinel: The evolving SIEM for the AI Age

    5.0
    Dec 2, 2025
    Deploying or migrating a SIEM is not an easy task. While we had some teething pains in the beginning of our deployment, Microsoft has continually improved the product, including changes based on feedback I have provided to developers. We require a multi-workspace sentinel environment which was not initially supported by Sentinel. I worked with developers to help test out private-preview features to support the multi-workpace deployment. It
  • It Security Associate
    10B+ USD
    IT Services
    Review Source

    Advanced Threat Detection and Investigation Features Available With Kusto Query Language

    4.0
    Dec 31, 2025
    One of the best SIEM solutions in the market for large as well as small environments. We have been using it for the last few years. It is one of the best SOC platform to hunt for advanced threats using kusto query language. We can also investigate for lateral movement and all the other mitre attacks ttps.
  • Director of IT
    10B+ USD
    Manufacturing
    Review Source

    Use of Sentinel Reduces Infrastructure Hassles but Can Complicate Unconnected Integrations

    5.0
    Dec 9, 2025
    We came from an on-prem solution and capacity based licensing as well as the required infrastructure made it very expensive. With Sentinel we pay for what we use and don't have to worry about growth and scaling of infrastructure.
  • It Support Specialist
    1B-10B USD
    Services (non-Government)
    Review Source

    Real-Time Security Analytics and Centralized Event Management With Microsoft Sentinel

    4.0
    Feb 16, 2026
    Microsoft Sentinel is helpful in our organization for its effectiveness in security information and event management services. The software provides us with real-time security analytics and real-time threat detection and response. It also provides us with privileged access management and behavioural analytics management. Microsoft Sentinel is easy to deploy and implement and is well suited for centralised event management and real-time log data collection.
...
Showing Result 1-5 of 447

Recommended Gartner Research

  • Critical Capabilities for Security Information and Event Management
  • Magic Quadrant for Security Information and Event Management

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.