IAM Senior Software Engineer at MGM Resorts International
Real User
Top 20
Sep 2, 2026
I have been attending some sessions to see how we can use CrowdStrike Falcon Next-Gen SIEM more. I appreciate the Charlotte AI, the agentic thing. Probably we will try to see what is going on there. The team is already doing the infrastructure management using CrowdStrike Falcon Next-Gen SIEM. That is not my expertise there, but there is something that I can still let the team know about this new development. I just got to learn about Charlotte AI yesterday in the session, and that is very interesting where you can track the core workstation to actual incident and the adversaries. That is interesting. That is probably something that I want to explore. CrowdStrike Falcon Next-Gen SIEM is a vast tool. It has everything from basic to advanced. The documentation is very vast, so that is one thing that you need to go through and try to understand, because the terminology used is niche. In the majority, this is true. I am actually trying to clear a certification from CrowdStrike, so I am preparing for that. Learning through the documentation is much more useful. It is pretty nice. My overall rating for this solution is ten out of ten.
System Administrator at W. O. Grubb Steel Erection, Inc.
Real User
Top 20
Sep 2, 2026
In an investigation or incident where CrowdStrike Falcon Next-Gen SIEM played a significant role, there was no security incident, but we had plenty of investigative incidents where we were able to pull telemetry from not only the Falcon sensor but also our Microsoft Entra logs, our ExtraHop logs, and our Abnormal Email logs, all integrating together into CrowdStrike Falcon Next-Gen SIEM to get a full, clear picture of what was going on. I do not use automations with CrowdStrike Falcon Next-Gen SIEM. We are not using Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. This has given us visibility where we had none. The expanded usage of CrowdStrike Falcon Next-Gen SIEM is just us using it more, and that process has been very smooth. We are starting to get a few dashboards together and a few saved queries together, and we know what we are looking for a little bit better with our data. I would advise other organizations considering CrowdStrike Falcon Next-Gen SIEM to try it and run a proof of value and notice that the time it takes to return results is seconds compared to minutes with other SIEMs. When you try that once with your data set, you will be hooked. I would rate this product 10 out of 10.
For the integration of Falcon Telemetry with other security data sources within CrowdStrike Falcon Next-Gen SIEM, I have to look into it. I have not tried using Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. I have no information about whether I have been able to consolidate or replace legacy SIEM, SOAR, or other SOC tools. The advice I would give to other organizations considering CrowdStrike Falcon Next-Gen SIEM is that you should choose CrowdStrike. I would rate this product a ten out of ten.
Security Operations at a financial services firm with 5,001-10,000 employees
Real User
Top 10
Sep 2, 2026
We do not use Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. Automations in CrowdStrike Falcon Next-Gen SIEM have increased the confidence my SOC analysts have in making decisions. CrowdStrike Falcon Next-Gen SIEM played a significant role in an investigation or incident by functioning best at responding to incidents relating to specific identity compromise and correlating different data from different sources to make identity-related threats easier to mitigate and identify. My advice to other organizations considering CrowdStrike Falcon Next-Gen SIEM is to not be afraid of the monoculture and to embrace it wholeheartedly. I have given this review an overall rating of eight.
Learn what your peers think about CrowdStrike Falcon Next-Gen SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
CrowdStrike Falcon Next-Gen SIEM is the execution engine of the Agentic SOC, delivering AI-powered detection, investigation, and response across endpoint, cloud, identity, and third-party data. Built on a data fabric designed for AI, it replaces fragmented legacy SIEM architectures with a unified source of security context, helping analysts and AI agents detect and stop threats faster.
What features make CrowdStrike Falcon Next-Gen SIEM stand out?
AI-Powered Data Fabric: Unifies, normalizes,...
I have been attending some sessions to see how we can use CrowdStrike Falcon Next-Gen SIEM more. I appreciate the Charlotte AI, the agentic thing. Probably we will try to see what is going on there. The team is already doing the infrastructure management using CrowdStrike Falcon Next-Gen SIEM. That is not my expertise there, but there is something that I can still let the team know about this new development. I just got to learn about Charlotte AI yesterday in the session, and that is very interesting where you can track the core workstation to actual incident and the adversaries. That is interesting. That is probably something that I want to explore. CrowdStrike Falcon Next-Gen SIEM is a vast tool. It has everything from basic to advanced. The documentation is very vast, so that is one thing that you need to go through and try to understand, because the terminology used is niche. In the majority, this is true. I am actually trying to clear a certification from CrowdStrike, so I am preparing for that. Learning through the documentation is much more useful. It is pretty nice. My overall rating for this solution is ten out of ten.
In an investigation or incident where CrowdStrike Falcon Next-Gen SIEM played a significant role, there was no security incident, but we had plenty of investigative incidents where we were able to pull telemetry from not only the Falcon sensor but also our Microsoft Entra logs, our ExtraHop logs, and our Abnormal Email logs, all integrating together into CrowdStrike Falcon Next-Gen SIEM to get a full, clear picture of what was going on. I do not use automations with CrowdStrike Falcon Next-Gen SIEM. We are not using Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. This has given us visibility where we had none. The expanded usage of CrowdStrike Falcon Next-Gen SIEM is just us using it more, and that process has been very smooth. We are starting to get a few dashboards together and a few saved queries together, and we know what we are looking for a little bit better with our data. I would advise other organizations considering CrowdStrike Falcon Next-Gen SIEM to try it and run a proof of value and notice that the time it takes to return results is seconds compared to minutes with other SIEMs. When you try that once with your data set, you will be hooked. I would rate this product 10 out of 10.
For the integration of Falcon Telemetry with other security data sources within CrowdStrike Falcon Next-Gen SIEM, I have to look into it. I have not tried using Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. I have no information about whether I have been able to consolidate or replace legacy SIEM, SOAR, or other SOC tools. The advice I would give to other organizations considering CrowdStrike Falcon Next-Gen SIEM is that you should choose CrowdStrike. I would rate this product a ten out of ten.
We do not use Charlotte AI or other AI capabilities within CrowdStrike Falcon Next-Gen SIEM. Automations in CrowdStrike Falcon Next-Gen SIEM have increased the confidence my SOC analysts have in making decisions. CrowdStrike Falcon Next-Gen SIEM played a significant role in an investigation or incident by functioning best at responding to incidents relating to specific identity compromise and correlating different data from different sources to make identity-related threats easier to mitigate and identify. My advice to other organizations considering CrowdStrike Falcon Next-Gen SIEM is to not be afraid of the monoculture and to embrace it wholeheartedly. I have given this review an overall rating of eight.