Try our new research platform with insights from 80,000+ expert users

Microsoft Sentinel vs SmartEvent Event Management comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Sentinel
Ranking in Security Information and Event Management (SIEM)
3rd
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
98
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st), Microsoft Security Suite (6th), AI-Powered Cybersecurity Platforms (5th)
SmartEvent Event Management
Ranking in Security Information and Event Management (SIEM)
52nd
Average Rating
5.6
Reviews Sentiment
6.7
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Microsoft Sentinel is 6.2%, down from 8.0% compared to the previous year. The mindshare of SmartEvent Event Management is 0.1%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Microsoft Sentinel6.2%
SmartEvent Event Management0.1%
Other93.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

Ivan Angelov - PeerSpot reviewer
Threat detection and response capabilities enhance investigation processes
My security team has been using Microsoft Sentinel for around two years. We also have Bastion and SolarWinds as part of our monitoring tools. We use a three-way tool, alongside Microsoft Sentinel, in our environment The most valuable features for us include threat collection, threat detection,…
Adhi Wahyu - PeerSpot reviewer
Transparent and offers real-time analysis but needs more documentation
The solution provides us with transparency to give us information about what happens in the network. With this information, the administrator can see a lot of things. They can see hacking attempts from the internet that target our servers, and, with that information, they can check the security settings in the server to see if it is strong enough or not, and make sure the servers is safe. They also can see attacks directed to the endpoint. We know which endpoint got infected so we can take action to clean it. The software also has good reporting capabilities. We can create custom reports according to our needs.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Sentinel has reduced the work involved in the event investigation by quite a lot."
"The dashboard that allows me to view all the incidents is the most valuable feature."
"The automation feature is valuable."
"Microsoft Sentinel stands out mainly for its signal-to-noise reduction; LogRhythm required numerous AI rules to reach a similar level of noise reduction."
"The signal correlation and dashboards features of Microsoft Sentinel are fantastic because it correlates the signal logs with other products. The customizable dashboards are also valuable."
"It has a lot of great features."
"The pricing of the product is excellent."
"The solution has features that helped improve the security posture of our clients. It provides the ability to correlate a large variety of log sources very cost-effectively, especially for Microsoft sources."
"SmartEvent Event Management is a solid platform overall, and I would definitely recommend it."
"The capability of real-time analysis of security events is useful."
 

Cons

"We do see continuous improvement all the time, however, I haven't got a specific feature that is lacking or not well designed."
"They can work on the EDR side of things... Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work."
"The KQL query does not function effectively with Windows 11 machines, and in the majority of machine-based investigations, KQL queries are essential for organizing the data during investigations."
"The three challenges we have are outside of the Microsoft ecosystem. In New Zealand, there are customers that run dual stack, running Microsoft but also competitor products, EDR software, cloud security software, and other tooling."
"We'd like to see more connectors."
"They could use some kind of workbook. There is some limitation doing the editing and creating the workbook."
"The solution should allow for a streamlined CI/CD procedure."
"Microsoft Defender has a built-in threat expert option that enables you to contact an expert. That feature isn't available in Sentinel because it's a huge product that integrates all the technologies. I would like Microsoft to add the threat expert option so we can contact them. There are a few other features, like threat assessment that the PG team is working on. I expect them to release this feature in the next quarter."
"They should provide easy to access guides or manuals, maybe videos, about how to manage or use the software effectively and efficiently, to maximize its features."
"The only downside I've encountered with SmartEvent Event Management is occasional lag during video calls, especially with a lot of participants."
 

Pricing and Cost Advice

"Cost-wise, Sentinel is based on the volume of information being ingested, so it can be quite pricey. The ability to use strategies to control what data is being ingested is important."
"It varies on a case-by-case basis. It is about $2,000 per month. The cost is very low in comparison to other SIEMs if you are already a Microsoft customer. If you are using the complete Microsoft stack, the cost reduces by almost 42% to 50%. Its cost depends on the number of logs and the type of subscription you have. You need to have an Azure subscription, and there are charges for log ingestion, and there are charges for the connectors."
"I am just paying for the log space with Azure Sentinel. It costs us about $2,000 a month. Most of the logs are free. We are only paying money for Azure Firewall logs because email logs or Azure AD logs are free to use for us."
"We only pay for the amount of data we bring in, which is fair."
"Microsoft Sentinel's pricing is relatively expensive and extremely confusing."
"Azure Sentinel is very costly, or at least it appears to be very costly. The costs vary based on your ingestion and your retention charges."
"Microsoft Sentinel can be costly, particularly for data management."
"It comes with a Microsoft subscription which the customer has, so they don't have to invest somewhere else."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
869,566 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
11%
Manufacturing Company
8%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise20
Large Enterprise41
No data available
 

Questions from the Community

Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
What is your experience regarding pricing and costs for SmartEvent Event Management?
The product has annual licensing; make sure you really use it well to help you secure the network so you don't waste the license cost.
What needs improvement with SmartEvent Event Management?
The only downside I've encountered with SmartEvent Event Management ( /categories/event-monitoring ) is occasional lag during video calls, especially with a lot of participants. Although it is not ...
What is your primary use case for SmartEvent Event Management?
Our primary use case involves utilizing SmartEvent Event Management ( /products/smartevent-event-management-reviews ) for video conferencing, file sharing, and integration with other productivity t...
 

Also Known As

Azure Sentinel
No data available
 

Overview

 

Sample Customers

Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Information Not Available
Find out what your peers are saying about Microsoft Sentinel vs. SmartEvent Event Management and other solutions. Updated: September 2025.
869,566 professionals have used our research since 2012.