No more typing reviews! Try our Samantha, our new voice AI agent.

Devo vs Microsoft Sentinel comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.5
Devo enhances data analysis and threat detection cost-effectively, offering scalability, customization, and efficiency in resource allocation.
Sentiment score
6.8
Microsoft Sentinel enhances ROI with faster incident response, automation, and cost efficiency, providing significant operational and security improvements.
If a customer is already using Microsoft’s ecosystem, the ROI can be positive due to seamless integration.
senior cyber security at a tech services company with 201-500 employees
Our MTTR, mean time to response, improved by forty to fifty percent. Earlier, medium-severity incidents took two to three hours to resolve. Now, after Microsoft Sentinel, it is forty to fifty-five minutes.
Cyber Security Consultant at HR Software Solution
We attribute our growth to Sentinel.
Chief Commercial Officer at defend
 

Customer Service

Sentiment score
6.7
Devo's customer service is praised for responsiveness and effectiveness, but some seek better documentation and clarity in ticket handling.
Sentiment score
6.4
Microsoft Sentinel customer service is praised for staff expertise, but premium support is quicker; communication consistency could improve.
I rate the customer support a nine out of ten because of their timely technical guidance and responsiveness during the deployment and troubleshooting periods.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
Both response time and support quality need attention.
Team Lead SOC at a tech services company with 51-200 employees
Microsoft invests significantly in support, which is crucial for companies.
Director de Microsoft y Transformación Digital at Compucad
I believe Microsoft could improve by keeping customer service within the US for Microsoft Sentinel customers who are within state and federal government sectors.
Infosec at a government with 10,001+ employees
Working with a Sentinel engineer helped us tune settings effectively.
Systems Emgineer at a non-profit with 1-10 employees
 

Scalability Issues

Sentiment score
7.0
Devo's cloud-based architecture ensures impressive scalability, efficiently managing large data volumes and integrating users across regions without limitations.
Sentiment score
7.7
Microsoft Sentinel is highly scalable, cloud-native, and integrates easily, but users should consider data ingestion costs.
Devo is a unified SIEM solution designed to handle growing log volumes and enterprise-scale monitoring requirements.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
There is no need to add hardware or redesign infrastructure because it is cloud-native.
Cyber Security Consultant at HR Software Solution
As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.
Systems Emgineer at a non-profit with 1-10 employees
Being a SaaS solution, the scalability of Microsoft Sentinel is robust.
senior cyber security at a tech services company with 201-500 employees
 

Stability Issues

Sentiment score
7.3
Devo is praised for its stability, reliable uptime, proactive support, and effective management of large deployments despite minor issues.
Sentiment score
7.8
Microsoft Sentinel is reliable with high uptime, minor outages, and strong security, despite some customization challenges.
It is stable and reliable for our security operations.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
I have never experienced any downtime, crashes, or performance issues with Microsoft Sentinel because it is SOC as a Service, so it maintains 100% uptime and scaling.
Infosec at a government with 10,001+ employees
In the past two years, our team hasn't encountered any issues with the stability of Microsoft Sentinel from an operations perspective.
Project Executive at synergyc
I need to be aware of deprecated connectors as they may disconnect, but the data continues to be sent with a need for quick adaptation.
senior cyber security at a tech services company with 201-500 employees
 

Room For Improvement

Devo's Activeboards need better customization, integration, UI, and AI capabilities, while cost and usability require attention.
Microsoft Sentinel needs enhancements in integration, usability, performance, automation, and cost management to better serve users and organizations.
This is particularly evident when dealing with failed login attempts and determining true versus false positives.
Strategic Account Executive at a computer software company with 51-200 employees
UI improvements, a simplified dashboard, or an easier reporting workflow could further improve analyst productivity.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
I would appreciate more third-party integrations including Fortinet and others.
Team Lead SOC at a tech services company with 51-200 employees
Log ingestion and retention costs can grow quickly, and understanding which data source is driving cost is not always straightforward.
Cyber Security Consultant at HR Software Solution
We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel.
Systems Emgineer at a non-profit with 1-10 employees
There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing.
senior cyber security at a tech services company with 201-500 employees
 

Setup Cost

Devo offers transparent pricing per gigabyte, with potential metadata charges, including 400-day storage and additional feature benefits.
Microsoft Sentinel's flexible pricing can be costly, but cost-effective within the Microsoft ecosystem with optimization strategies in place.
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps.
Team Lead SOC at a tech services company with 51-200 employees
It has been beneficial that Microsoft Sentinel is included as part of the Microsoft package, making it more cost-effective.
Senior System Administrator at a university with 5,001-10,000 employees
Microsoft Sentinel is not a low-cost SIEM.
Cyber Security Consultant at HR Software Solution
Microsoft Sentinel is provided at no cost, so we didn't have any issues with the cost.
Vice President, Sales, Cybersecurity at a computer software company with 51-200 employees
 

Valuable Features

Devo impresses with real-time analytics, intuitive UI, customization, advanced alerting, cloud-native architecture, and 400 days of data retention.
Microsoft Sentinel enhances security with AI-driven threat detection, automated responses, seamless integration, and efficient threat management through playbooks and analytics.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
Strategic Account Executive at a computer software company with 51-200 employees
When the analyst uses queries to search, it pulls the data quickly, in a second, which aids us greatly with the investigation.
Cyber Security Engineer Ii (Vulnerability & Threat Management) at FICO
It utilizes 400 days of hot data, allowing queries to run very fast and yield results quicker than other tools in terms of security and SIEM capability.
Senior Cloud Engineer at a tech services company with 201-500 employees
Microsoft Sentinel's ability to correlate data from multiple sources and its detection capabilities are essential.
Cost Engineer at a tech vendor with 10,001+ employees
Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence.
Chief Commercial Officer at defend
Microsoft Sentinel's ability to correlate data from multiple sources enhances our threat detection capabilities beyond what is a simple data lake solution by filtering out the noise and consolidating the signal down to a meaningful level that is easier to investigate and see.
Solutions Architect at a tech vendor with 201-500 employees
 

Categories and Ranking

Devo
Ranking in Security Information and Event Management (SIEM)
18th
Average Rating
8.4
Reviews Sentiment
6.5
Number of Reviews
26
Ranking in other categories
Log Management (18th), IT Operations Analytics (7th), AIOps (13th)
Microsoft Sentinel
Ranking in Security Information and Event Management (SIEM)
4th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
108
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (3rd), Microsoft Security Suite (6th), AI-Powered Cybersecurity Platforms (6th)
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Devo is 1.2%, up from 1.1% compared to the previous year. The mindshare of Microsoft Sentinel is 3.9%, down from 6.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Microsoft Sentinel3.9%
Devo1.2%
Other94.9%
Security Information and Event Management (SIEM)
 

Featured Reviews

Usama Khan - PeerSpot reviewer
Team Lead SOC at a tech services company with 51-200 employees
Advanced threat hunting has improved SOC visibility and now supports faster incident response
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM is basically on the AWS cloud. There are specific ports which are enabled on the relay server, which are 514 and 13000, 13151, 152. However, when we talk about databases and custom integrations, there are not default ports in the relay server. No default ports are defined. For JDBC drivers, the port number is 1433, but it is not in the relay server. You have to add it manually. For Oracle RDBMS, the port is 1521, and it is also not there by default. I would appreciate more third-party integrations including Fortinet and others. Machine learning models can also be improved. Playbooks in the SOAR can also be improved. Regarding playbooks for automation, we utilize playbooks for automation in SOAR for automated IOC blocking on a firewall, on a web application firewall, on DNS security, etc. The only option for us to run the playbook is to schedule the job for it. However, if I want to manually run the playbook, there is no option for doing so. This needs improvement.
Kallamuddin Ansari - PeerSpot reviewer
Cyber Security Consultant at HR Software Solution
Centralized monitoring has improved threat response but cost control still needs refinement
Based on real operations used in our corporate IT environment, the key features include log correlation and incident view. Microsoft Sentinel's biggest strength is how it correlates multiple related alerts into a single incident. This significantly reduces alert noise and helps the SOC focus on real threats instead of isolated events. Another valuable feature is KQL-based threat hunting with Kusto Query Language. The flexibility of this language allows us to build custom hunting queries based on our environment's behavior. This is extremely useful for detecting low and slow threats or hidden threats that default rules may miss. Cloud-native scalability and stability is another important feature. Being cloud-native, Microsoft Sentinel scales well for medium to large corporate environments without infrastructure management. Stability has been solid in day-to-day production. SOAR automation using playbooks is a feature we highly recommend. Microsoft Sentinel's SOAR functionality helps automate repetitive SOC tasks like alert enrichment and notification. This saves analyst time and improves response consistency.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
10%
Outsourcing Company
9%
Manufacturing Company
9%
Financial Services Firm
11%
Manufacturing Company
10%
Computer Software Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise5
Large Enterprise12
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise24
Large Enterprise46
 

Questions from the Community

What is your experience regarding pricing and costs for Devo?
The pricing of the product is reasonable if we compare it with other Gartner leading products like Splunk, LogRhythm, Microsoft Sentinel, Google SecOps. Its licensing model is basically on per-day ...
What needs improvement with Devo?
Devo can improve in how its connectors enhance integration with third-party tools. Devo's architecture works by having you deploy a relay server in the data center of the client side and Devo SIEM ...
What is your primary use case for Devo?
I am using Devo myself. Basically, I work at an MSSP, and we provide services to the organization for Security Operation Centers. In our Security Operation Center, we provide the service of SIEM vi...
Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
 

Also Known As

No data available
Azure Sentinel
 

Overview

 

Sample Customers

United States Air Force, Rubrik, SentinelOne, Critical Start, NHL, Panda Security, Telefonica, CaixaBank, OpenText, IGT, OneMain Financial, SurveyMonkey, FanDuel, H&R Block, Ulta Beauty, Manulife, Moneylion, Chime Bank, Magna International, American Express Global Business Travel
Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Find out what your peers are saying about Devo vs. Microsoft Sentinel and other solutions. Updated: June 2026.
908,800 professionals have used our research since 2012.