No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Sentinel vs Tines comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.6
Torq users reported reduced alert management time with automation, enhancing productivity and showing potential for $600,000 annual ROI.
Sentiment score
6.8
Microsoft Sentinel enhances ROI with faster incident response, automation, and cost efficiency, providing significant operational and security improvements.
Sentiment score
6.5
Tines automation reduced analyst needs by 30%, enhancing response time and productivity, with a 20% improved efficiency.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
If a customer is already using Microsoft’s ecosystem, the ROI can be positive due to seamless integration.
senior cyber security at a tech services company with 201-500 employees
Our MTTR, mean time to response, improved by forty to fifty percent. Earlier, medium-severity incidents took two to three hours to resolve. Now, after Microsoft Sentinel, it is forty to fifty-five minutes.
Cyber Security Consultant at HR Software Solution
We attribute our growth to Sentinel.
Chief Commercial Officer at defend
I can speak for fewer employees needed because we used to require many analysts to deal with all the alerts that we were generating, but now we have about 90 to 95% of the alerts already automated through Tines, which requires tremendous time saved and a ton of reduction in the number of analysts required.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
In some domains, we were in a position to actually let go of people, meaning at least two people have been reduced from one team, which saves a lot of cost for the organization.
Head of Cyber Defense Center
We did not see proper value in it, whereas other platforms would have given much higher value for us.
Automation Engineer at a educational organization with 11-50 employees
 

Customer Service

Sentiment score
7.3
Torq offers highly rated customer service, known for quick, effective responses and knowledgeable support, though feature requests may delay.
Sentiment score
6.4
Microsoft Sentinel customer service is praised for staff expertise, but premium support is quicker; communication consistency could improve.
Sentiment score
7.4
Tines' customer service is highly rated for swift AI-powered support and accessible communication, despite not being available 24/7.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Microsoft invests significantly in support, which is crucial for companies.
Director de Microsoft y Transformación Digital at Compucad
I believe Microsoft could improve by keeping customer service within the US for Microsoft Sentinel customers who are within state and federal government sectors.
Infosec at a government with 10,001+ employees
Working with a Sentinel engineer helped us tune settings effectively.
Systems Emgineer at a non-profit with 1-10 employees
Whenever we hit roadblocks or issues with the platform or story, even if it was our mistake, the people from the most senior engineering team of Tines immediately were willing to get on call with us.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
I would rate the customer support a ten on a scale of one to ten.
Head of Cyber Defense Center
The support and engineering team is quick to resolve bugs and respond promptly.
Security Delivery Manager at Accenture
 

Scalability Issues

Sentiment score
6.4
Torq is praised for impressive scalability, adaptability, and effective workflow management, though requires careful management with large workflows.
Sentiment score
7.7
Microsoft Sentinel is highly scalable, cloud-native, and integrates easily, but users should consider data ingestion costs.
Sentiment score
8.2
Tines scales efficiently, managing complex workflows and diverse environments, seamlessly supporting enterprise applications without performance concerns.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
There is no need to add hardware or redesign infrastructure because it is cloud-native.
Cyber Security Consultant at HR Software Solution
As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.
Systems Emgineer at a non-profit with 1-10 employees
Being a SaaS solution, the scalability of Microsoft Sentinel is robust.
senior cyber security at a tech services company with 201-500 employees
It is built for growing teams and has more complex automation capacity.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Whenever this became insufficient, we could easily reach out to the Tines team where they immediately gave us a remedy or fixed the issue.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
From the workloads we have, it can scale for different workflows and add more workflows.
Head of Cyber Defense Center
 

Stability Issues

Sentiment score
6.7
Torq offers high stability and reliability with minimal downtime, quickly resolved issues, and significant improvements over other solutions.
Sentiment score
7.8
Microsoft Sentinel is reliable with high uptime, minor outages, and strong security, despite some customization challenges.
Sentiment score
8.6
Tines is highly reliable with minimal downtime, high accuracy, seamless updates, and consistently supports uninterrupted workflows effectively.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular Developer at Flourish Software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
I have never experienced any downtime, crashes, or performance issues with Microsoft Sentinel because it is SOC as a Service, so it maintains 100% uptime and scaling.
Infosec at a government with 10,001+ employees
In the past two years, our team hasn't encountered any issues with the stability of Microsoft Sentinel from an operations perspective.
Project Executive at synergyc
I need to be aware of deprecated connectors as they may disconnect, but the data continues to be sent with a need for quick adaptation.
senior cyber security at a tech services company with 201-500 employees
The tool is stable up to ninety-nine point nine percent.
Security Delivery Manager at Accenture
Tines is very stable.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
 

Room For Improvement

Torq users request improved AI integration, search functionalities, dashboards, transparency, templates, data manipulation, bulk editing, and playbooks.
Microsoft Sentinel needs enhancements in integration, usability, performance, automation, and cost management to better serve users and organizations.
Tines faces UI challenges, insufficient documentation, and compliance issues, requiring enhanced customization, onboarding, and expansion beyond security applications.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
Log ingestion and retention costs can grow quickly, and understanding which data source is driving cost is not always straightforward.
Cyber Security Consultant at HR Software Solution
We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel.
Systems Emgineer at a non-profit with 1-10 employees
There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing.
senior cyber security at a tech services company with 201-500 employees
Reporting and dashboards could be more advanced for deeper analysis.
Security Delivery Manager at Accenture
The issue with the Implode action is that once we get a certain number of events into the Implode action, we lose context of all the events except the last one that came in, so it is a bit difficult to send data back once it goes through the Implode action.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
I think they need to add more intelligence to the workflow layer because, depending upon what they have right now, it could be possible for Claude or Copilot or ChatGPT to have that feature quickly.
Head of Cyber Defense Center
 

Setup Cost

Torq's pricing is seen as affordable by some, costly by others, but enterprises value its modern features.
Microsoft Sentinel's flexible pricing can be costly, but cost-effective within the Microsoft ecosystem with optimization strategies in place.
Tines is praised for cost-effective integration, ease of use, helpful support, dedicated account managers, and favorable licensing.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
It has been beneficial that Microsoft Sentinel is included as part of the Microsoft package, making it more cost-effective.
Senior System Administrator at a university with 5,001-10,000 employees
Microsoft Sentinel is not a low-cost SIEM.
Cyber Security Consultant at HR Software Solution
Microsoft Sentinel is provided at no cost, so we didn't have any issues with the cost.
Vice President, Sales, Cybersecurity at a computer software company with 51-200 employees
Tines required no setup cost since we just used their cloud tier and built everything with internal engineering resources.
Automation Engineer at a educational organization with 11-50 employees
My experience with pricing, setup cost, and licensing is very good.
Head of Cyber Defense Center
I did not handle the purchasing side, so I did not actually know the exact pricing or the licensing details.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
 

Valuable Features

Torq enhances efficiency by streamlining workflows with AI, automation, and seamless integrations, offering user-friendly customization and scalability.
Microsoft Sentinel enhances security with AI-driven threat detection, automated responses, seamless integration, and efficient threat management through playbooks and analytics.
Tines' API integration offers no-code ease, flexibility, real-time automation, excellent support, and robust app integrations for efficiency.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Microsoft Sentinel's ability to correlate data from multiple sources and its detection capabilities are essential.
Cost Engineer at a tech vendor with 10,001+ employees
Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence.
Chief Commercial Officer at defend
Microsoft Sentinel's ability to correlate data from multiple sources enhances our threat detection capabilities beyond what is a simple data lake solution by filtering out the noise and consolidating the signal down to a meaningful level that is easier to investigate and see.
Solutions Architect at a tech vendor with 201-500 employees
It helps in streamlining our security operations effectively and efficiently without requiring coding knowledge.
Security Delivery Manager at Accenture
What stands out mostly about Tines's features is the integrations. It connects easily with tools such as Slack, emails, and spreadsheets, and it makes data moves automatically without much work.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Tines caught the failure and queued them automatically. We did not lose a single student log.
Automation Engineer at a educational organization with 11-50 employees
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
12
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
Microsoft Sentinel
Ranking in Security Orchestration Automation and Response (SOAR)
2nd
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
108
Ranking in other categories
Security Information and Event Management (SIEM) (4th), Microsoft Security Suite (6th), AI-Powered Cybersecurity Platforms (6th)
Tines
Ranking in Security Orchestration Automation and Response (SOAR)
6th
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
8
Ranking in other categories
Threat Intelligence Platforms (TIP) (11th), AI-Powered Security Automation (2nd), AI IT Support (9th)
 

Mindshare comparison

As of June 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 3.8%, down from 5.5% compared to the previous year. The mindshare of Microsoft Sentinel is 9.8%, down from 18.2% compared to the previous year. The mindshare of Tines is 4.5%, down from 6.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Microsoft Sentinel9.8%
Torq3.8%
Tines4.5%
Other81.9%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AD
Solutions Architect at Swimlane
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
Kallamuddin Ansari - PeerSpot reviewer
Cyber Security Consultant at HR Software Solution
Centralized monitoring has improved threat response but cost control still needs refinement
Based on real operations used in our corporate IT environment, the key features include log correlation and incident view. Microsoft Sentinel's biggest strength is how it correlates multiple related alerts into a single incident. This significantly reduces alert noise and helps the SOC focus on real threats instead of isolated events. Another valuable feature is KQL-based threat hunting with Kusto Query Language. The flexibility of this language allows us to build custom hunting queries based on our environment's behavior. This is extremely useful for detecting low and slow threats or hidden threats that default rules may miss. Cloud-native scalability and stability is another important feature. Being cloud-native, Microsoft Sentinel scales well for medium to large corporate environments without infrastructure management. Stability has been solid in day-to-day production. SOAR automation using playbooks is a feature we highly recommend. Microsoft Sentinel's SOAR functionality helps automate repetitive SOC tasks like alert enrichment and notification. This saves analyst time and improves response consistency.
Shadrach Godwish Chukwu - PeerSpot reviewer
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Automation has replaced repetitive tasks and helps my team organize workflows in real time
Tines is overall good, but the setup can feel a bit technical at first. More templates for common workflows would make it much easier to start quickly without building everything from scratch. I can say that the documentation could be much simpler and mainly example-based, showing real workflows. Faster support responses would also help, especially when someone is building a very complex workflow so they can easily get support responses at any point. The setup time is considerable. It takes time to set it up, and the learning curve is steep. It is not hard once you know it, but getting started takes a whole lot of time and effort and slows new users down considerably. I will heavily dwell on a few things. More ready-made templates would help so you do not always start from scratch. A simpler onboarding flow for new users would also make it much easier to get started very quickly. Better in-app guidance when building workflows would also be helpful.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
10%
Manufacturing Company
10%
Construction Company
9%
Manufacturing Company
11%
Financial Services Firm
11%
Computer Software Company
10%
Government
7%
Financial Services Firm
13%
Manufacturing Company
10%
Insurance Company
7%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise5
Large Enterprise5
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise24
Large Enterprise46
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise4
 

Questions from the Community

What needs improvement with Torq?
I do not dislike anything about Torq because it has satisfied all of our use cases and requirements. We contacted sup...
What is your primary use case for Torq?
Initially, we were using Slack for small automations, such as creating pipelines or shutting down servers. For exampl...
What advice do you have for others considering Torq?
I have been working for five years with experience in the IT field. Torq is very good. It manages everything. I would...
Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel an...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel...
What needs improvement with Tines?
Tines is overall good, but the setup can feel a bit technical at first. More templates for common workflows would mak...
What is your primary use case for Tines?
My main use case for Tines has been automation. My main use has been automating simple workflows, such as moving data...
What advice do you have for others considering Tines?
My advice would be to start simple. The main thing is that you need to build small workflows first. When you build sm...
 

Comparisons

 

Also Known As

No data available
Azure Sentinel
No data available
 

Overview

 

Sample Customers

Information Not Available
Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Information Not Available
Find out what your peers are saying about Microsoft Sentinel vs. Tines and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.