2021-08-30T13:01:00Z

What is a better choice, Splunk or Azure Sentinel?

Why?

NC
Content Manager at PeerSpot (formerly IT Central Station)
  • 0
  • 234
1
PeerSpot user
1 Answer
Real User
Top 5
2021-09-01T19:24:21Z
Sep 1, 2021

It would really depend on (1) which logs you need to ingest and (2) what are your use cases


Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log volume increases. Splunk is good for operations style use cases (NOC), but requires ESS and isn't as easy to use or get data out of for SOC style use cases.


Sentinel is good for endpoint Windows Defender Advanced Edition (extra cost, not the free version), analysis and malware findings, and when the data sources are all Windows events (O365/OneDrive/Email/ADFS), but costs go up substantially if the log sources aren't Microsoft events, and support for non-MSFT log sources is limited.


Neither offers real UEBA capabilities IMO.


Splunk has the add-on (entirely different architecture and systems), for the Caspida UEBA.


MSFT will tout UEBA on Sentinel, but it's endpoint related (not network) and I've yet to see use cases on non-MSFT application data events.

Find out what your peers are saying about Microsoft Sentinel vs. Splunk Enterprise Security and other solutions. Updated: September 2023.
734,678 professionals have used our research since 2012.
Product comparison that may be of interest to you
Related Questions
Ammar Jibarah - PeerSpot reviewer
IT Security at Aramex
Jun 14, 2023
Hello community, We are working on upgrading our SIEM solution and would like to work with Microsoft Sentinel or Palo Alto XSOAR, to be able to combine all on-prem, and cloud app logs into one interface, and be able to benefit from advanced analytics, story building, and automation. I am preparing a POC to try both but would like to hear your opinion based on your experience and knowledge on ...
See 1 answer
AS
Member of the board at Data Security Solutions
Jun 14, 2023
Why not try Logpoint instead?;) 
Shibu Babuchandran - PeerSpot reviewer
Regional Manager/ Service Delivery Manager at a tech services company with 201-500 employees
Jan 20, 2022
Hi dear professionals, How would you compare Securonix and Splunk as a SIEM enterprise solution? 
See 1 answer
Manoj Gautam - PeerSpot reviewer
Practice Lead- Network & Info Security at Inknowtech
Jan 20, 2022
I believe when we built a solution for any customer SOC environment, we need to take a survey of running equipment, their IoS and our product should compatible with their resources , APIs , third party integration, log management and the reporting mechanism should be good enough to understand each and every security aspects.  There are multiple tools are available for the comparison of different SIEM enterprise solution. As per my experience, splunk and arcsight is compatible for most of the customer environment, even though devices are not updated.
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 2, 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to better connect with peers and other independent experts who provide advice without vendor bias. Our users have ranked these solutions according to their valuable features, and discuss which features they like most and why. You can read user reviews for the Top 8 Log Management Tools to help you d...
Moderator
Shibu Babuchandran - PeerSpot reviewer
Regional Manager/ Service Delivery Manager at a tech services company with 201-500 employees
Real User
ExpertModerator
Product Comparisons
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 2, 2022
Top 8 Log Management Tools 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to...
Download Free Report
Download our FREE report comparing Microsoft Sentinel and Splunk Enterprise Security based on reviews, features, and more! Updated: September 2023.
DOWNLOAD NOW
734,678 professionals have used our research since 2012.