Try our new research platform with insights from 80,000+ expert users

Coralogix vs Microsoft Sentinel comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coralogix
Ranking in Security Information and Event Management (SIEM)
22nd
Average Rating
8.4
Reviews Sentiment
6.6
Number of Reviews
13
Ranking in other categories
Application Performance Monitoring (APM) and Observability (21st), Log Management (21st), API Management (15th), Streaming Analytics (15th), Anomaly Detection Tools (1st), AI Observability (18th)
Microsoft Sentinel
Ranking in Security Information and Event Management (SIEM)
4th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
104
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st), Microsoft Security Suite (6th), AI-Powered Cybersecurity Platforms (5th)
 

Mindshare comparison

As of January 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Coralogix is 0.7%, up from 0.3% compared to the previous year. The mindshare of Microsoft Sentinel is 5.0%, down from 7.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
Microsoft Sentinel5.0%
Coralogix0.7%
Other94.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

Naveenkumar Lakshman - PeerSpot reviewer
Presales Engineer at Crayon AS
Centralized monitoring has improved real-time issue tracking and reduced root cause analysis time
One of the best features that Coralogix offers is that it is integration friendly. I can seamlessly work with different cloud providers including AWS, Azure, and GCP. I can monitor Kubernetes or Docker platforms as well, and I can integrate with the DevOps chain including Jenkins and all infrastructure code, Terraform, or Ansible. Coralogix has positively impacted my organization by providing a centralized console to monitor the dashboard, giving me rich flexibility to see different sorts of data that is spread across the logs, metrics, or traces, which are the typical pillars of the observability tool. I have the interface where I can use the drag-and-drop feature, and I can create different types of charts. Mainly, I have the line charts and time series ones that I generally use in many use cases, gauges, tables, pie charts, or markdown widgets. These are the ones generically available, and I can switch between the visualization types. I am getting the underlying query in that and can import and export dashboards built upon the JSON format. I can have my own APIs integrated with my dashboards as well, such as with Terraform, which is useful for scaling across my environments. Regarding root cause analysis, mainly what I can do is correlate across all of the layers because the main logs that I work on are storage-related, including CIFS, NFS, SAN traffic, and the metrics including storage, throughput, or VM resource usage. Being able to view logs, metrics, or traces available, I get all of these in one place, and I can do root cause analysis much quicker.
Kallamuddin Ansari - PeerSpot reviewer
Cyber Security Consultant at ProTechmanize
Centralized monitoring has improved threat response but cost control still needs refinement
Based on real operations used in our corporate IT environment, the key features include log correlation and incident view. Microsoft Sentinel's biggest strength is how it correlates multiple related alerts into a single incident. This significantly reduces alert noise and helps the SOC focus on real threats instead of isolated events. Another valuable feature is KQL-based threat hunting with Kusto Query Language. The flexibility of this language allows us to build custom hunting queries based on our environment's behavior. This is extremely useful for detecting low and slow threats or hidden threats that default rules may miss. Cloud-native scalability and stability is another important feature. Being cloud-native, Microsoft Sentinel scales well for medium to large corporate environments without infrastructure management. Stability has been solid in day-to-day production. SOAR automation using playbooks is a feature we highly recommend. Microsoft Sentinel's SOAR functionality helps automate repetitive SOC tasks like alert enrichment and notification. This saves analyst time and improves response consistency.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Coralogix scales well, and I will rate it nine out of ten."
"The log monitoring is good, and the dashboards that we create are beneficial."
"In my experience, the best feature Coralogix offers is that the dashboard is pretty good."
"The solution offers very good convenience filtering."
"The most valuable feature of Coralogix is that it is a very good vendor for metrics."
"The initial setup is straightforward."
"A non-tech person can easily get used to it."
"For now, we have not experienced any stability issues."
"I've worked on most of the top SIEM solutions, and Sentinel has an edge in most areas. For example, it has built-in SOAR capabilities, allowing you to run playbooks automatically. Other vendors typically offer SOAR as a separate licensed solution or module, but you get it free with Sentinel. In-depth incident integration is available out of the box."
"Another area where it is helping us is in creating a single dashboard for our environment. We can collect all the logs into a log analytics workset and run queries on top of it. We get all the results in the dashboard. Even a layman can understand this stuff. The way Microsoft presents it is really incredible."
"There are a lot of things you can explore as a user. You can even go and actively hunt for threats. You can go on the offensive rather than on the defensive."
"Investigations are something really remarkable. We can drill down right to the raw logs by running different queries and getting those on the console itself."
"It is quite efficient. It helps our clients in identifying their security issues and respond quickly. Our clients want to automate incident response and all those things."
"There are some very powerful features to Sentinel, such as the integration of various connectors. We have a lot of departments that use both IaaS and SaaS services, including M365 as well as Azure services. The ability to leverage connectors into these environments allows for large-scale data injection."
"Log aggregation and data connectors are the most valuable features."
"One of the most valuable features is that it creates a kind of a single pane of glass for organizations that already use Microsoft software. So, when they have things like Microsoft 365, it is very easy for them to kind of plug in or enroll those endpoints into the Azure Sentinel service."
 

Cons

"The user interface could be more intuitive and explanatory."
"The customizable dashboards haven't really helped with my company's efficiency at all, and I think there's room for improvement."
"The documentation of the tool could be improved"
"The user interface is not intuitive, especially when first onboarding, and improvements could be made here."
"We want it to work at what it is expected to work at and not really based on the updated configuration which one developer has decided to change."
"Coralogix's dashboard and search capabilities do not help me in any particular way."
"Coralogix should have some AI capabilities to auto-detect anomalies and provide suggestions. The increasing volume of data and the resulting bandwidth charges are concerns."
"Maybe they could make it more user-friendly."
"Microsoft should improve Sentinel, considering that from the legacy systems, it cannot collect logs."
"The pricing could be improved."
"Microsoft Sentinel should provide an alternative query language to KQL for users who lack KQL expertise."
"In terms of improvements, pricing, licensing, and overall cost could be better."
"There is room for improvement in entity behavior and the integration site."
"As of now, there have been only benefits. However, I am curious about potential AI integration and whether it will be affordable for us because all the compliance costs are rising with all the new features."
"The costs and pricing of Microsoft Sentinel are expensive. That's my biggest complaint, especially from customers who are concerned about the significant expense."
"They can work on the EDR side of things... Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work."
 

Pricing and Cost Advice

"The platform has a reasonable cost. I rate the pricing a three out of ten."
"The cost of the solution is per volume of data ingested."
"We are paying roughly $5,000 a month."
"Currently, we are at a very minimal cost, which is around $400 per month since we have reduced our usage. Initially, we were at $900 per month."
"It is a consumption-based license model. bands at 100, 200, 400 GB per day etc. Azure Sentinel Pricing | Microsoft Azure"
"Sentinel is a pay-as-you-go solution. To use it, you need a Log Analytics workspace. This is where the logs are stored and the cost of Log Analytics is based on gigabytes... On top of that, there is the cost of Sentinel, which is about €2 per gigabyte. If a customer has an M365 E5 license, the logs that come from Microsoft Defender are free."
"Microsoft Sentinel's pricing is relatively expensive and extremely confusing."
"No license is required to make use of Sentinel, but you need to buy products to get the data. In general, the price of those products is comparable to similar products."
"Microsoft is costlier. Some organizations may not be able to afford the cost of Sentinel orchestration and the Log Analytics workspace. The transaction hosting cost is also a little bit on the high side, compared to AWS and GCP."
"Sentinel is expensive relative to other products of the class, so it often isn't affordable for small-scale businesses. However, considering the solution has more extensive capabilities than others, the price is not so high. Pricing is based on GBs of ingested daily data, either by a pay-as-you-go or subscription model."
"Microsoft Sentinel can be costly, particularly for data management."
"Microsoft Sentinel is expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Computer Software Company
10%
Manufacturing Company
8%
Comms Service Provider
6%
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise2
Large Enterprise5
By reviewers
Company SizeCount
Small Business38
Midsize Enterprise22
Large Enterprise45
 

Questions from the Community

What do you like most about Coralogix?
Numerous data monitoring tools are available, but Coralogix somehow fine-tunes our policies and effectively supports our teams.
What is your experience regarding pricing and costs for Coralogix?
To monitor and manage costs associated with Coralogix, I analyze my trend, looking at how the data is being ingested. Generally, it is charged based on what we store, and therefore there are certai...
What needs improvement with Coralogix?
I think Coralogix can be improved with flexible dashboards. Creating specific views, such as saving a dev environment as a separate view rather than adding filters every time, would be great.
Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
 

Comparisons

 

Also Known As

No data available
Azure Sentinel
 

Overview

 

Sample Customers

Payoneer, AGS, Monday.com, Capgemini
Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Find out what your peers are saying about Coralogix vs. Microsoft Sentinel and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.