No more typing reviews! Try our Samantha, our new voice AI agent.
Emmanuel-Bentil - PeerSpot reviewer
Managing Director at iMark Consult
Reseller
Top 20
Jun 29, 2026
Struggled with immature cloud analytics but have gained strong endpoint visibility and rollback
Pros and Cons
  • "The AI features of SentinelOne Singularity AI SIEM are absolutely perfect."
  • "Unfortunately, I was not happy with SentinelOne Singularity AI SIEM because it is not mature yet."

What is our primary use case?

We have dealt with SentinelOne Endpoint, and at some point, we also used SentinelOne Singularity AI SIEM, which was introduced somewhere last year. I went on training in South Africa, where there were many questions discussing having one platform that allows control over all endpoints with visibility, which eliminates the need for separate systems. The challenge with SentinelOne Singularity AI SIEM is having an ingester to integrate with it at the syslog level. For some customers, we needed an ingester to integrate with the network devices before we could see them. For the endpoint side, everything was acceptable; we were able to do remediation, ransomware rollback, and everything operates autonomously, so no manual intervention is necessary. In terms of group level, you can assign policies to specific devices in specific environments. Additionally, there was a new introduction to cloud-native apps for cloud security, enabling integration of AWS and Google Suite apps, including Azure platforms, providing visibility, especially for AWS, where we can monitor all Kubernetes clusters and pods, allowing for remediation as vulnerabilities are identified.

What is most valuable?

The AI features of SentinelOne Singularity AI SIEM are absolutely perfect. There are not any issues because there is a game that you play with SentinelOne. This game allows me to drive a proof of concept for customers. When I play the game, SentinelOne provides a tool called Purple AI, which allows for simple queries just like ChatGPT. This means you do not need an expert to understand what is happening around your endpoints and identify threats. I can simply write, 'What happened to my Windows endpoint in the last seventy-two hours?' and it provides all reports and logs. This functionality makes it accessible even for CEOs and decision-makers to understand their environment better, making it an excellent feature for SOC, giving visibility and clarity.

What needs improvement?

I did use the automated workflow feature for a client. The automation allows for configuring all integration with endpoints, as well as SentinelOne Singularity AI SIEM. Unfortunately, I was not happy with SentinelOne Singularity AI SIEM because it is not mature yet. When comparing SentinelOne Singularity AI SIEM to platforms like Elasticsearch or Exabeam, or even QRadar, they are more matured. SentinelOne Singularity AI SIEM is designed to provide an affordable platform integrated with endpoints, eliminating the need for separate SIEM deployments. However, the integration of a log ingester in the cloud makes deployment cumbersome and requires an expert or native system integrator for setup.

SentinelOne Singularity AI SIEM should be separated from the overall platform. If the intention is to make it a complete solution and enable SIEM features, separating it would yield better results. You get a lot of noise when it is combined; separating it would mean clearly identifying logs from the EDR or SDR platform to SentinelOne Singularity AI SIEM. This would help in minimizing confusion and panic for customers facing numerous logs and potential false positives. A separate SIEM would allow clearer visibility, and there is a need for an on-premise option, particularly for organizations with data sovereignty concerns. Many institutions prefer to keep their data on-premise due to regulations, so adding an appliance that firms can integrate into their data centers would be valuable. If larger organizations need a SIEM solution, they will likely turn to QRadar or FortiSIEM instead.

For how long have I used the solution?

I already have experience with SentinelOne because I have been with SentinelOne for the past five years.

Buyer's Guide
SentinelOne Singularity AI SIEM
August 2026
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.

How are customer service and support?

In rating the technical support for SentinelOne, it depends on whether we are discussing EDR or SentinelOne Singularity AI SIEM. I would not rate the entire company uniformly. For the EDR, I might rate it around eight out of ten; for SentinelOne Singularity AI SIEM, I would give it five out of ten or two out of five.

Which other solutions did I evaluate?

Regarding pricing, the pricing of SentinelOne is quite favorable when compared to CrowdStrike. I appreciate the MSSP distribution model. For instance, if I purchase SentinelOne from Exclusive Networks, which I believe is known to you, I can provide it to individuals, allowing them to have SentinelOne installed on their laptops while maintaining the ability to control policies and monitor attacks. The MSSP pricing is negotiable, around thirty-three dollars per endpoint annually. For the reseller level, if support is needed, contacting SentinelOne directly allows me to open a case and access assistance from their engineers, which may cost around fifty dollars per endpoint. Comparatively, SentinelOne is more affordable than CrowdStrike. SentinelOne Singularity AI SIEM pricing also depends on the number of devices onboarded, including switches and firewalls, which all contribute to lowering costs. However, selling a complete cloud solution can be challenging in West Africa due to data sovereignty concerns.

What other advice do I have?

The need for improvement mainly revolves around focus areas. If SentinelOne only concentrates on developed countries, my experience in West Africa suggests disparities. SentinelOne needs to consider implementing an on-premise configuration or introducing a hybrid model. A staging server that sits on-premise allows for better data sovereignty while still using cloud services. If all logs are sent to the SentinelOne cloud, it poses challenges for customers without AWS capabilities.

I would rate SentinelOne Singularity AI SIEM overall at five out of ten. It is not suited for enterprises but works for startups or any environment that relies on cloud resources. My overall review rating for SentinelOne is five out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jun 29, 2026
Flag as inappropriate
PeerSpot user
reviewer2811069 - PeerSpot reviewer
IT Security Analyst at a tech consulting company with 11-50 employees
Real User
Top 5
Mar 23, 2026
AI-driven workflows have transformed incident response speed and reduced false positives
Pros and Cons
  • "After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools."
  • "SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement."

What is our primary use case?

I use SentinelOne Singularity AI SIEM for endpoint security, including EDR and SIEM-based monitoring, as well as for XDR. I monitor endpoints for security reasons and receive alerts when suspicious or malicious activity is detected. When I find anything suspicious or malicious, I investigate it further.

What is most valuable?

I particularly appreciate a feature called Purple AI, which is an AI-based tool that allows us to fetch logs and investigate through a single prompt. It is useful for providing a brief summary of what has happened without needing to review logs in detail. Through this AI capability, we can understand exactly what has been occurring.

There is significant automation we can implement through a feature called hyper-automation. We can automate workflows easily using a drag and drop interface, rather than writing scripts. This makes automation in SentinelOne very straightforward.

I would say the quality is top-notch. It provides perfect summaries, has reduced our response time, and helps us reduce false positives. We receive mostly true positive alerts and do not need to write additional detection rules. SentinelOne Singularity AI SIEM can detect new sophisticated threats and zero-day attacks on its own without requiring rules from us. This automated detection capability is something I truly appreciate.

What needs improvement?

SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement. The interface flickers frequently, and sometimes it does not load properly. When this happens, we have to log out and log back in, or refresh the page before we can see the alerts. Sometimes the interface will be blank. These performance and reliability issues need to be addressed.

For how long have I used the solution?

I have been using SentinelOne Singularity AI SIEM for more than one year.

What do I think about the stability of the solution?

I would rate the stability at six out of ten.

What do I think about the scalability of the solution?

I would rate scalability at seven out of ten. SentinelOne Singularity AI SIEM handles a large environment fairly smoothly and works well. The performance depends on the configuration. If it is properly configured, it works well for large environments as well.

How are customer service and support?

I would rate the technical support at eight out of ten. SentinelOne Singularity AI SIEM has AI-based technical support available. When we have questions or require documentation, we receive it promptly. The support is good.

Which solution did I use previously and why did I switch?

Compared to other tools we have used, such as Sumo Logic, Splunk, and CrowdStrike, those solutions do not have as much AI capability. After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools.

What was our ROI?

SentinelOne Singularity AI SIEM has reduced our response time to true positive alerts by approximately forty percent through automation. For false positive reduction, it has decreased our false positive rate by fifty percent.

Which other solutions did I evaluate?

I can appreciate SentinelOne Singularity AI SIEM primarily for its AI capability. For this reason, we switched to SentinelOne Singularity AI SIEM. It has behavioral AI plus machine learning that has been integrated. We chose SentinelOne Singularity AI SIEM mainly because of its AI capability. It is a unified platform that provides a unified view of security alerts without requiring us to look at other data sources or switch between different tools. This has reduced the time required for faster detection and response.

What other advice do I have?

I would recommend SentinelOne Singularity AI SIEM to other users. Most tools do not have the same level of AI capability. SentinelOne Singularity AI SIEM has Purple AI and hyper-automation features that I can suggest to other users based on these capabilities.

SentinelOne Singularity AI SIEM has improved our SOC's efficiency in investigating alerts and responding to incidents through its AI capability. It provides us a unified view of entire alerts. We do not need to go to other data sources to understand what happened. It connects all the dots and gives us a unified alert view without requiring us to navigate to other tabs. We can see what happened from start to end. Cybersecurity and hacker tactics are constantly evolving, and we are seeing many sophisticated attacks nowadays. SentinelOne Singularity AI SIEM detects these attacks by itself without needing predefined rules, using machine learning and behavioral baselines to detect anomalies and trigger alerts. Additionally, Purple AI automatically provides a summary of incidents explaining what has happened in simple terms without requiring deep investigation into alerts or logs. This explanation of what was abused helps us make faster decisions about whether an incident is truly a threat or a false positive alert.

SentinelOne Singularity AI SIEM has significantly impacted our security tasks and reduced manual effort. We have requirements from clients we provide services for regarding particular alerts or unreported data. We can automate notifications to the customer when these conditions occur without manually creating a ticket. SentinelOne Singularity AI SIEM can automatically notify the user. We also use it for responding to alerts. In some cases, we need to disconnect an endpoint from the network to prevent malicious activity from spreading. We use hyper-automation to automatically disconnect endpoints or remove malicious files if they are present on an endpoint.

I give this product an overall rating of eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Mar 23, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity AI SIEM
August 2026
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
IT Security Consultant at Systemhaus for you GmbH
Real User
Top 5Leaderboard
Mar 2, 2026
AI-driven observability has transformed threat detection and now provides full incident visibility
Pros and Cons
  • "Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly better."
  • "In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier."

What is our primary use case?

Our use case with SentinelOne Singularity AI SIEM is primarily AI observability for a large part. We are using it for SIEM purposes as well. Prior to the inclusion of Purple AI, it was exclusively SIEM.

What is most valuable?

The best features of SentinelOne Singularity AI SIEM are 100% Purple AI.

In addition to that, though somewhat tedious, the implementation of any data you want is a feature of SentinelOne Singularity AI SIEM, and also the option to analyze that via Purple AI to some degree. Additionally, the existence of a large catalog of native integrations is valuable.

Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly improved. We finally have visibility into things that were never visible before. When talking to new customers and onboarding them, it is always apparent that there are so many things in their environment that they never even really knew about and had no visibility into. They previously needed to go through obscure, hard-to-use, and weird tooling to potentially access this information. Having all of that in SentinelOne Singularity AI SIEM makes it so much easier.

What needs improvement?

In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier. I did hear that there is something on the horizon for this, but that is an area that could be made less tedious.

Potentially to some degree, the evaluation of singular events in SentinelOne Singularity AI SIEM could improve. Sometimes they are painting the devil on the wall where there is not really a big issue, just a normal, everyday event. Those are sometimes taken a bit too negatively.

For how long have I used the solution?

I am still using SentinelOne Singularity AI SIEM presently.

What do I think about the stability of the solution?

When it comes to stability, I would give SentinelOne Singularity AI SIEM a nine. There are no really noticeable glitches or bugs. There used to be a few availability issues, but those are essentially mitigated by now. SentinelOne has taken those very seriously and in the past months, which might have been almost a year by now, I have not really noticed any availability issues.

How are customer service and support?

I would rate the technical support of SentinelOne Singularity AI SIEM a nine.

How would you rate customer service and support?

Positive

How was the initial setup?

As for maintenance required with SentinelOne Singularity AI SIEM, I would say it is even easier than the base product because you do not really onboard new data sources that often. If I put it into times a year, I would say it might be twice a year-ish that you need to do maintenance work essentially. Of course, if you want to add new detections or anything, that can be whenever, but I would not really consider that maintenance.

For others looking to implement SentinelOne Singularity AI SIEM, I would recommend starting with a proof of concept. Of course, with a SIEM that is a bit more effort to fully onboard, you might want to get an in-depth demonstration first and see if it meets your needs. Even before the demonstration, ask yourself what you even expect of a SIEM and what points you want from the solution. Once you are in the presentation, you will realize that those can very easily be met and completed with SentinelOne.

Which other solutions did I evaluate?

In comparison, I would assess SentinelOne Singularity AI SIEM favorably to other solutions or vendors such as Splunk, Microsoft, Hunters, Anomali, and Graylog. The nice part about it as well is that you can use AI SIEM standalone. However, the big advantage in my opinion comes from using it with the EDR. If you do that, you just have one of the main issues of SIEMs completely taken care of.

That being the data from the endpoints, in modern SIEMs, you have roughly 80 to 90% of the data is endpoint data. In other SIEMs, you have to pay for those and pay for every bit of data that you put in. With SentinelOne, if it is from the endpoint, you natively have that data and you do not have to pay extra for that, and it is just additional data on top of that. Additionally, combining that with the ability to have all the data in a single data lake means you do not need to use multiple data stores. It is using an open source data format, which is awesome.

What other advice do I have?

My impression of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is great. I am really looking forward to the upcoming feature with agentic incident investigation. If that is actually capable of autonomously investigating incidents across multiple data sources, for example, not just from SentinelOne, it will be transformative. The example I heard recently was an employee of the company opening a normal ticket just stating that their VPN connection is not working. That ticket is also made available to SentinelOne and it will then investigate what is going on with that. In the end, it turned out that this was actually an attack and that employee's VPN connection was hijacked. I am really looking forward to that feature, though it is not here yet, but even right now, it is great.

In terms of assessing the efficiency of SentinelOne Singularity AI SIEM in improving response time to sophisticated threats, you very quickly get an overview of all data and data related to the incident. Even if there is no active incident, you can very quickly get all related information due to the Storylines and Purple AI.

SentinelOne's AI-driven analytics have affected our SOC abilities to reduce false positives, and I would say roughly about 80%.

I would rate this solution a 10 overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Mar 2, 2026
Flag as inappropriate
PeerSpot user
reviewer2835498 - PeerSpot reviewer
Cybersecurity Postsales Engineer at a outsourcing company with 51-200 employees
Real User
Top 5Leaderboard
Jul 23, 2026
AI-driven security workflows have transformed investigations and now reduce incident response times
Pros and Cons
  • "SentinelOne Singularity AI SIEM has improved our overall security posture and is reducing the workload on the SOC team."
  • "SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved."

What is our primary use case?

SentinelOne Singularity AI SIEM's main use case is to enhance cybersecurity by using AI to detect, investigate, and automatically respond across endpoints, cloud, and identities. It helps security teams reduce manual efforts, accelerate incident response, and improve overall security operations.

In my previous role, I used SentinelOne Singularity AI SIEM to investigate endpoint security alerts. Instead of manually using logs from multiple systems, I used the AI-powered investigation features to quickly identify the root cause of suspicious activities. SentinelOne Singularity AI SIEM automatically correlated related events and highlighted the affected endpoints while recommending response actions. We isolated the endpoints with a single click after verifying it was a malicious script, and we remediated the issue much faster than the previous manual process.

What is most valuable?

The best features of SentinelOne Singularity AI SIEM are AI-powered threat detections, unified security data, Purple AI assistant, automated investigations, hyper-automations, and fast threat hunting. These features include centralized log management, Purple AI for natural log investigations, automated alert correlations, and hyper-automations for incident response. These features help security teams detect threats faster, reduce manual effort, minimize false positives, and significantly improve mean time to detect and mean time to respond.

These features significantly improved our SOC workflow. Previously, analysts had to manually collect logs from multiple tools and correlate alerts, which was time-consuming. With SentinelOne Singularity AI SIEM, alerts were automatically correlated into a single incident with an attack timeline, making investigations much faster. Purple AI helped summarize the incident and answer natural language queries, reducing the time spent searching through logs.

SentinelOne Singularity AI SIEM has improved our overall security posture and is reducing the workload on the SOC team. Its AI-driven detection and automated response capabilities help us identify threats faster, reduce false positives, and shorten incident response times. The centralized visibility across endpoints and cloud environments also made investigations more efficient, while automation reduced repetitive manual tasks.

It has improved SOC efficiency by reducing time analysts spend on manual alert investigations and response. Previously, analysts had to collect information from multiple sources and manually correlate events. With SentinelOne Singularity AI SIEM's AI-driven alert prioritization, automated incident correlations, and investigation timelines provide better context quickly. The team can identify the root cause faster, reduce alert fatigue, and take response actions such as isolating affected endpoints more efficiently.

What needs improvement?

SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved. First, the initial setup and integration with some third-party tools could be simpler. Second, more customizable dashboards and reporting would help the management team confirm their needs.

For how long have I used the solution?

I have been using SentinelOne Singularity AI SIEM for the last three years.

What other advice do I have?

My impression of SentinelOne Singularity AI SIEM's AI-driven threat detection capability is very positive. It uses behavioral analysis and machine learning to identify suspicious activity that may not be detected by traditional signature-based methods.

I used SentinelOne Singularity AI SIEM's automated workflow capability to reduce repetitive security tasks. For example, when a high-risk alert was detected, automated workflows helped with actions such as endpoint isolation, alert enrichment, and triggering response processes without requiring manual intervention at every step. This reduced the time analysts spent on routine tasks and has improved consistency in incident handling.

My advice would be to clearly define your security goals and use cases before deploying SentinelOne Singularity AI SIEM. Start with proper endpoint coverage, integrate with your existing security tools, and spend time tuning policies to reduce unnecessary alerts. I would also recommend training the SOC team on the AI investigations and automation features so they can fully benefit from the platform. Finally, continuously review detection results and response processes to ensure the platform is meeting the organization's security needs. I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 23, 2026
Flag as inappropriate
PeerSpot user
reviewer2805261 - PeerSpot reviewer
Cyber Security Engineer at a retailer with 201-500 employees
Real User
Top 5
Mar 6, 2026
Advanced AI detection has reduced false positives and currently protects endpoints from new threats
Pros and Cons
  • "When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware."
  • "It is quite good, but the only downside is that it is costly."

What is our primary use case?

The main use cases for SentinelOne Singularity AI SIEM are endpoint protection and EDRs. When you compare the EDRs with Trend Micro and others, you will find many false positives, but SentinelOne gives you the best protection. It uses its AI to scan and find new malware, how new attackers are behaving, and addresses zero-day attacks as well. It is quite good, but the only downside is that it is costly.

What is most valuable?

The best features in SentinelOne Singularity AI SIEM include AI capabilities; they have two types of AI. First, AI is on the dashboard, which you can interact with, such as asking for logs of the last ten days, and it will provide them to you. This is one type of AI, similar to a chatbot. The other AI operates in the back end to find malware. It employs a combination of AI and ML to check for viruses or any other malicious processes, including fileless attacks.

The impression I have of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is that it is good and working fine, and I have never found any complaints from any customer. The dashboard is also quite simple.

What needs improvement?

When it comes to room for improvement, I would say the analysis page can be improved.

In terms of improvement, you can add more detection features.

For how long have I used the solution?

I have been working with SentinelOne Singularity AI SIEM for almost six months.

What do I think about the stability of the solution?

I have not seen any stability or scalability issues with it; it is usually license-based, so when you are buying, you typically know how much you need.

In terms of performance stability, I have never had any crashes, downtimes, or performance issues.

What do I think about the scalability of the solution?

The scalability of SentinelOne Singularity AI SIEM in adapting to an organization's growing data or complex IT structures is good, but it actually depends on the person who is managing it and how they make the policies; it totally depends on the policies they are making.

How are customer service and support?

My thoughts on the tech support of SentinelOne Singularity AI SIEM are that it is good and AI-based, and the documentation is also good compared to other solutions I have seen.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The benefits of SentinelOne Singularity AI SIEM include that most of the customers who use it upgrade from their existing endpoint solutions. Many are using Trend Micro endpoints, Check Point endpoints, or others, and they are unhappy, especially with solutions such as Kaspersky. When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware.

How was the initial setup?

Regarding the initial setup of SentinelOne Singularity AI SIEM, I can walk you through the deployment process: you can sync your AD, and the agent installation can also be automated. You can push it directly from your Microsoft Active Directory using GPO, which makes it easy. The agent installation can be automated, so I do not think it takes much time. However, since it is an endpoint tool, you have to consider policies for different departments, including allow lists and block lists, so deploying any endpoint does take some time.

What about the implementation team?

We are not directly system integrators of the product, but we sell through Lenovo.

Which other solutions did I evaluate?

Apart from the Harmony, I work with various CloudGuard Check Point products, and I also have a certification for SOCRADAR. I work with SOCRADAR and still have hands-on experience doing POCs and demos with SOCRADAR. I have recently done POCs or demos with SOCRADAR. We are working with an alternate solution for that, and it is a new solution.

What other advice do I have?

SentinelOne Singularity AI SIEM has many features, and my recommendation is to utilize all of them, but people often do not use them all. It would be helpful to automate it or use playbooks to take full advantage of the features. I rate this product a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Last updated: Mar 6, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free SentinelOne Singularity AI SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free SentinelOne Singularity AI SIEM Report and get advice and tips from experienced pros sharing their opinions.