No more typing reviews! Try our Samantha, our new voice AI agent.

Sentinel vs Snare comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Sentinel
Ranking in Security Information and Event Management (SIEM)
14th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
Snare
Ranking in Security Information and Event Management (SIEM)
54th
Average Rating
8.0
Reviews Sentiment
7.4
Number of Reviews
3
Ranking in other categories
Log Management (46th)
 

Mindshare comparison

As of October 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Sentinel is 2.7%, down from 4.1% compared to the previous year. The mindshare of Snare is 0.9%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Sentinel2.7%
Snare0.9%
Other96.4%
Security Information and Event Management (SIEM)
 

Featured Reviews

PT
Senior Specialist at a tech vendor with 10,001+ employees
Improved incident monitoring has reduced false positives and supports audit-ready reporting
The best features Sentinel offers, in my experience, include the filtering features and the ability to run KQL queries so that I can understand what table has what and when the last log has been monitored and reported. Sentinel has positively impacted my organization by improving monitoring significantly. As a pay-as-you-go service, we are ingesting logs as needed. When the pay-as-you-go service is enabled, we can either ingest whenever there is a spike in the logs, and when there are fewer logs, we can reduce the ingestion. This approach is helpful for both the organization and me. In terms of metrics showing how Sentinel has helped, as part of log filtering, we have reduced around thirty to thirty-five percent of false-positive incident creation. We have also cleared some audits by enabling log retention in Sentinel, allowing us to pull out data for audits when necessary using both hot retention and cold retention. This has helped the organization as a whole.
Frank Eargle - PeerSpot reviewer
Information Security Engineer at Glasshouse Systems
A highly scalable solution that is easy to manage and super easy to set up
We use Snare for picking up Windows logs, and we used to use it for SQL as well. We had used it for Linux once or twice. We're mainly using it for Windows and Windows flat files The most valuable feature of Snare is flexibility or the ability to filter all things you don't want and don't have…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Sentinel is a tool that, if it's well configured, removes from view all unnecessary information and shows you only needful entries, so you can do your job faster, more conveniently, and with high performance."
"Transactional user information improves security, prevents fraud, and promotes best practices."
"Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network."
"If Sentinel is integrated with Identity Manager and User Application Portal, the solution runs simply perfect!"
"It makes everything easier by automating some tasks and growing with our needs."
"The most valuable feature is the flexible log for identifying security threats inside an application. Sentinel is very good at this."
"The solution's Kusto Query Language (KQL) execution time is pretty good."
"Sentinel has positively impacted my organization by improving monitoring significantly."
"The most valuable feature of Snare is flexibility or the ability to filter all things you don't want and don't have security value."
"Snare has good agents, especially for Windows."
"The best thing about Snare is its format and consistency."
 

Cons

"It is an ancient product."
"I would prefer to extend dashboards part and their functions in Web GUI version, so the charts could be for configurable."
"There are still a few vendor-specific devices for which Sentinel needs to work on integration, such as Netskope devices."
"The dashboard and customer view should be improved."
"There is a need for more flexibility in customization, especially when working with different vendors and platforms."
"Documentation for security aspects could be improved. It is difficult to find clear information about encryption or risks that are addressed."
"I rate Sentinel a six out of ten for scalability."
"The solution does not allow outsourced authorizations."
"Users will initially find it difficult to identify the event types and installation in Snare."
"Snare should modernize its GUI a little bit."
"The solution is now developing a SIEM-like feature on Snare Central Server, but it's not complete yet."
 

Pricing and Cost Advice

"We receive a pricing discount because of our ongoing partnership with Micro Focus."
"The solution’s pricing is aligned with its competitors."
"Sentinel is a subscription-based solution."
"Sentinel's slightly on the expensive side."
"Sentinel is moderately priced."
"We inquired about getting support from the vendor, Micro Focus, but the cost was very high."
"On a scale from one to ten, where one is cheap, and ten is expensive, I rate Snare's pricing a four out of ten."
"Snare is a cheap solution because a lot of customers are using it."
"Snare has reasonable pricing."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Financial Services Firm
16%
Manufacturing Company
10%
Outsourcing Company
10%
Comms Service Provider
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise8
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for NetIQ Sentinel?
My experience with pricing, setup cost, and licensing shows that while it is a little on the higher side, since it is part of a package for all Microsoft products, I feel it is a better choice comp...
What needs improvement with NetIQ Sentinel?
Sentinel needs minimal improvement, though improvements are ongoing. Everything seems to be functioning perfectly, and I don't have any specific inputs for improvements I would like to see in Senti...
What is your primary use case for NetIQ Sentinel?
My main use case for Sentinel is that I'm a subject matter expert for Sentinel, specifically for security incident event and event management. I head the SME for SIEM in LTIMindtree for this curren...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

NetIQ Sentinel, Novell SIEM
No data available
 

Overview

 

Sample Customers

Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Military, Defence and Security Agencies, Banking Finance and Insurance companies, Retail, Health and Utilities.
Find out what your peers are saying about Sentinel vs. Snare and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.