No more typing reviews! Try our Samantha, our new voice AI agent.

SentinelOne Singularity AI SIEM vs SentinelOne Singularity Endpoint comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SentinelOne Singularity AI ...
Ranking in AI Observability
12th
Average Rating
8.6
Reviews Sentiment
6.1
Number of Reviews
5
Ranking in other categories
Security Information and Event Management (SIEM) (14th)
SentinelOne Singularity End...
Ranking in AI Observability
4th
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
244
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Anti-Malware Tools (2nd), Endpoint Detection and Response (EDR) (2nd), Extended Detection and Response (XDR) (2nd), AI-Powered Cybersecurity Platforms (3rd)
 

Mindshare comparison

As of May 2026, in the AI Observability category, the mindshare of SentinelOne Singularity AI SIEM is 1.4%, up from 0.1% compared to the previous year. The mindshare of SentinelOne Singularity Endpoint is 1.6%, down from 7.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AI Observability Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint1.6%
SentinelOne Singularity AI SIEM1.4%
Other97.0%
AI Observability
 

Featured Reviews

Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
AI-driven monitoring has improved real-time threat detection but still needs better automation
I could see some workflows, but I am unable to do automated workflows. For example, some repetitive jobs or repetitive tasks I am doing, but I am trying to have less manual intervention on the front. I am raising some issues that should be resolvable. The SentinelOne team has told me that this can be resolved within a couple of months, but they are saying that it is in future for enhancement and it may take some time. So far, the numbers are great. Regarding disadvantages or areas for improvement, I could say that 35 percent of my manual effort can be detected since I implemented it very recently. I could be able to say my current data talks about only 35 percent, and it may improve further, as I am expecting. But I can only comment based on my alerts and events. The adoption rate will be less compared to other products, as this can be a time-taken process because all my data needs to be offloaded and the system needs to understand my existing alerts, logs, and other things. This will take some more time, probably another month. Another area for improvement is that the product is somewhat expensive. Pricing could be improved as well.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools."
"SentinelOne Singularity AI SIEM's AI-powered analytics does affect our SOC's ability to reduce false positives; that is one of the biggest advantages because the manpower that I have is limited."
"When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware."
"Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly better."
"AI-driven capabilities will give me real-time detection and will protect my autonomous AI interruption."
"It's effectively helped to reduce organizational risk."
"The most valuable feature of SentinelOne Singularity Complete is the STAR Rules."
"Because I have done many deployments for SentinelOne, starting from 500 to 3,000 and 4,000 user customers, I can say that from the deployment perspective, SentinelOne Singularity Endpoint deployment is far more easy and very smooth."
"My advice for others looking into purchasing SentinelOne Singularity Complete is that I would definitely recommend it."
"The most valuable features of SentinelOne are the endpoint detection of threats, and it does not only rely on signatures for detection."
"The security aspect is the most valuable feature for me."
"The 365 management and analytics from the cloud is another great feature."
"For endpoint security, SentinelOne Singularity Endpoint is the best option."
 

Cons

"At the moment, I feel the pricing is a little bit on the higher side, but the tool is positioned in a place where risk is very high, and we do not want to take chances, so we are prepared to pay the premium."
"In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier."
"SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement."
"Another area for improvement is that the product is somewhat expensive. Pricing could be improved as well."
"It is quite good, but the only downside is that it is costly."
"There is an area of improvement is agent health monitoring, which would give us the ability to cap and manage resources used by the SentinelOne agent."
"One area of SentinelOne that definitely has room for improvement is the reporting. The canned reports are clunky and we haven't been able to pull a lot of good information directly from them."
"However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step."
"We'd like to have a network map or scan to cover network security."
"There is not much focus on the on-premise solution as the license cap is so huge for small and medium-sized institutions."
"The maintenance window can be improved because once it happened that I had multiple laptops, and the maintenance window caused a lot of laptops to get stuck in the portal, blocking access."
"The ability to have more direct purchasing for smaller groups and smaller businesses would be great."
"The reporting needs improvement and I would like to see a more granular level of administrative privileges."
 

Pricing and Cost Advice

Information not available
"The price of Singularity Complete compared to some of its competitors is competitive."
"It is very competitive with other solutions that are on the market. At least the last time we renewed, it was very competitive."
"The one I use is $6 a month per device. Some are $4 and there are some that are more than that."
"We pay $30,000 a year for 275 endpoints. We're growing, so I plan to buy another 75 endpoints. There is still a year and a half left in my three-year subscription, so I'm going to increase my endpoint count by 30 percent."
"Its price can be lower because I'm seeing competition from another vendor who beats it on commercials."
"SentinelOne Singularity Complete's price point is excessive compared to the functionality it provides."
"The license is per user."
"The pricing level for this service and application was very interesting for us. I don't know exactly what the price was, but apparently it was a big surprise that the SOC was also included in our pricing model."
report
Use our free recommendation engine to learn which AI Observability solutions are best for your needs.
896,034 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
9%
Construction Company
8%
Comms Service Provider
7%
Healthcare Company
7%
Computer Software Company
10%
Manufacturing Company
8%
Financial Services Firm
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise2
Large Enterprise2
By reviewers
Company SizeCount
Small Business112
Midsize Enterprise60
Large Enterprise84
 

Questions from the Community

What needs improvement with SentinelOne Singularity AI SIEM?
I would not say there is anything that could be better in SentinelOne Singularity AI SIEM; I think we have seen something unique in the product. This product has the potential to add more SOC funct...
What is your primary use case for SentinelOne Singularity AI SIEM?
For us, the use case is primarily to analyze security events that are coming in and also events that are kept over a period of time, to track and use it for investigation and maybe analysis, someti...
What advice do you have for others considering SentinelOne Singularity AI SIEM?
I assess the overall security posture of the company after implementation as positive; I see a big impact on that. I would rate this review as an overall eight.
Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the pricing.
 

Also Known As

No data available
Sentinel Labs, SentinelOne Singularity, Singularity Platform
 

Overview

 

Sample Customers

Information Not Available
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about SentinelOne Singularity AI SIEM vs. SentinelOne Singularity Endpoint and other solutions. Updated: April 2026.
896,034 professionals have used our research since 2012.