No more typing reviews! Try our Samantha, our new voice AI agent.
Hardik Murdia - PeerSpot reviewer
Technical Lead at a tech vendor with 51-200 employees
Real User
Top 5Leaderboard
Jun 8, 2026
AI-driven log searches have reduced investigation time and now prioritize critical security alerts
Pros and Cons
  • "I will strongly recommend this, because after SentinelOne Singularity AI SIEM we have reduced our engineering time to a certain degree as it has helped us to do investigations fast, we get actual alerts that matter and can prioritize them properly, and the monitoring capability is now completely in one single platform so we do not have to go here and there, which has given us good ROI in total."
  • "What I dislike is that the dashboard is very old, so they do not have much capability to be honest."

What is our primary use case?

After a CrowdStrike issue, we began using their cloud security offering. SentinelOne Singularity AI SIEM is more of an integration to their existing cloud security solution. We have been using this particular solution for more than a year, though slightly less than that range.

I am an observability engineer, and this solution is very helpful for security-related needs. When working in a company that handles a lot of data, particularly infrastructure data, you encounter numerous security alerts due to dependencies and security vulnerabilities on infrastructure machines. When we receive this data from different machines, these are signals. When you get this kind of data, it is almost impossible to do it manually in any way or form. What we need is a sampler that samples consistent data. With the AI SIEM on top of SentinelOne Singularity AI SIEM Observability Cloud security solution, we can filter out many things in terms of telemetry data that we receive. The endpoint telemetry is something we actually focus on with this particular solution, followed by the cloud infrastructure logs. We have used Splunk in the past. After a certain time, if you are not on their cloud offering on a very high tier, they will charge you money excessively or they will throttle your application. This is not the case with SentinelOne Singularity AI SIEM. That is a better approach. We also manage Kubernetes containers and environments through this solution. All the pods used to send a lot of telemetry data, and we can easily identify that. The dashboard, though it has some limited functionalities, works extremely well with what they offer. We use it day in and day out.

As we have the enterprise solution for this, we have used it extensively for Kubernetes pods where we have attached certain authentication systems. We have also used it for a lot of network security events when we have to do a compliance report. We have complete automation around it which provides us the reporting and everything at the end of the day. We have integrated it with our data pipelines also, and it helps us there as well.

What is most valuable?

The log segregation is my favorite feature. When you want to search over a very high or extremely long range of logs, it helps you tremendously because it becomes very easy to identify vulnerabilities and issues on the ongoing system. Otherwise, what happens with ELK is it becomes very expensive. With Splunk, though it has a data lake on its own, it requires you a good amount of investment. Though their system is more mature than SentinelOne Singularity AI SIEM, the best part about SentinelOne Singularity AI SIEM is the searching capability they have. It is extremely one of the best in the market right now, from what I remember, because their AI also provides you insights. It tells you what is happening in the system and asks you to check that part or check this part. This provides you with an edge when you are looking for vulnerabilities. In my role as a lead engineer in SRE, my domain is observability. There we have a lot of telemetry data. Telemetry data are metrics, logs, and a lot of other alerts. To identify those parts on the security layer, it is extremely good.

I can talk about the amount of tokens we can use. These are limited, though the searches are very extensive. The actual pricing model is something that is handled by the FinOps team, as I have already mentioned before on one of the products, Cribl. We do not have full visibility and observability and telemetry information, but I can provide you engineering insights. Costing is something that every company has their own FinOps team manage everything. If you want to purchase it, you go through that team. I do not know the enterprise costing for that, but I know that cost for an individual purchase. I think it is justified compared to other peers in the market.

What needs improvement?

What I dislike is that the dashboard is very old, so they do not have much capability to be honest. Dashboard customization is almost nonexistent. What they have is something they offer as standard. They do not have a DataDog style plug and play model where you can add a lot of metrics and it will provide you with them. They basically have pre-built compliance report templates that they just send you, but you do not have a way to customize it further. Currently, as the system is not that mature right now because it has been a very limited offering at the moment for SentinelOne Singularity AI SIEM. Third party integrations are something they lack a lot. I cannot connect it to Grafana or directly to a system which can help me identify things. This is something they lack right now at the moment.

For how long have I used the solution?

We have been using this particular solution for more than a year, though slightly less than that range.

Buyer's Guide
SentinelOne Singularity AI SIEM
July 2026
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,852 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have had no issues to be honest. It was compliant and reliable. I have not even seen much AI hallucinating on top of this. It has provided proper patterns and I do not have any complaints.

These things are properly managed and I do not see a problem to be honest. Though data volumes are really high for logs and other things, it worked well. I will say that even the data lake feature they have, in terms of keeping all the logs intact, those log searches are extremely fast on SentinelOne Singularity AI SIEM, even though the data is very high. Whatever you need, you get it fast as simple as that.

Which solution did I use previously and why did I switch?

We were using something similar before. We were using CrowdStrike extensively for this, but the SIEM approach they have, not the AI feature, is more mature than this. However, due to that outage, our company moved towards SentinelOne Singularity AI SIEM because we had compliance and client issues. Clients specifically asked us to remove CrowdStrike permanently from whatever Windows machines we have for security issues. Something came very strong from one of the companies which we took into account and we changed it across whatever customer we have. We moved with a better alternative. SentinelOne Singularity AI SIEM was relatively a good choice as of now.

How was the initial setup?

The AI integration was pretty straightforward. I did not face any problem. We created some policies and based on those policies, we were able to identify how to integrate it via this. I do not remember the exact steps. I have a document written on it somewhere that I need to pull out. It was a pretty standard thing. You just have to go to some consoles and integrate it based on this. You have to provide the endpoint details and it got integrated very smoothly.

What about the implementation team?

I do not maintain it. My work was just the integration aspect. Maintenance and other aspects are something that one of the other teams manages. These are the security engineers that we have. They actually provide all this information. If you need, I can connect you with them. I can send you their name or information so you can reach out to them.

What was our ROI?

Definitely, that is what I told you. It has given good ROI on that part where our investigation time has reduced to a certain degree. I will say the gains we get are more than fifty percent to be honest. We have reduced almost fifty percent of the dev's time, or not dev, the security engineer's time, SDs, whatever SECs we had. Even my VP of engineering who manages me is one of the guys who manages security. He is very happy with all this investigation time that we have reduced. We have a metric that we track in the company. This actually shows us a good amount of time. Previously it was a continuous problem for us where we had to manage all these things. An engineer had to be there for one of those problems. Now that is gone. We have a little bit more breathing room. It is not completely gone, but it is manageable now.

The sampling happens based on a single line of code. You do not need this one or a similar kind of logs, or some system should not go and sit in the data lakes. The best part about analytics is you do not have to look into anything. Threat hunting, how it works, the experience of the overall threat hunting aspect has actually improved a lot with AI because you do not want to read telemetry data. Who wants to do that? Who has time to do that? Telemetry data are raw data of signals where metrics and logs are coming in. No one wants to read them. The AI helps on top of it and helps you to make sense out of it or provides patterns. You are seeing that pattern or not. These kind of things matter. The best part is it is relatively faster than its peers because even though the data is more, it is relatively faster. I do not know what kind of algorithm they are using in the back end, but it is extremely good to be honest.

I will strongly recommend this. After SentinelOne Singularity AI SIEM, we have reduced our engineering time to a certain degree as it has helped us to do investigations fast. We get actual alerts that matter, and we can prioritize it properly. The monitoring capability is now completely in one single platform. We do not have to go here and there. This actually has given us good ROI in total.

What other advice do I have?

I am an observability engineer, and my current domain is that. SentinelOne Singularity AI SIEM is very helpful for security-related needs. When working in a company that handles a lot of data, particularly infrastructure data, you encounter numerous security alerts due to dependencies and security vulnerabilities on infrastructure machines. When we receive this data from different machines, these are signals. When you get this kind of data, it is almost impossible to do it manually in any way or form. What we need is a sampler that samples consistent data. With the AI SIEM on top of SentinelOne Singularity AI SIEM Observability Cloud security solution, we can filter out many things in terms of telemetry data that we receive. The endpoint telemetry is something we actually focus on with this particular solution, followed by the cloud infrastructure logs. We have used Splunk in the past. After a certain time, if you are not on their cloud offering on a very high tier, they will charge you money excessively or they will throttle your application. This is not the case with SentinelOne Singularity AI SIEM. That is a better approach. We also manage Kubernetes containers and environments through this solution. All the pods used to send a lot of telemetry data, and we can easily identify that. The dashboard, though it has some limited functionalities, works extremely well with what they offer. We use it day in and day out.

I can talk about the amount of tokens we can use. These are limited, though the searches are very extensive. The actual pricing model is something that is handled by the FinOps team, as I have already mentioned before on one of the products, Cribl. We do not have full visibility and observability and telemetry information, but I can provide you engineering insights. Costing is something that every company has their own FinOps team manage everything. If you want to purchase it, you go through that team. I do not know the enterprise costing for that, but I know that cost for an individual purchase. I think it is justified compared to other peers in the market. I would rate this solution a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 8, 2026
Flag as inappropriate
PeerSpot user
Emmanuel-Bentil - PeerSpot reviewer
Managing Director at iMark Consult
Reseller
Top 20
Jun 29, 2026
Struggled with immature cloud analytics but have gained strong endpoint visibility and rollback
Pros and Cons
  • "The AI features of SentinelOne Singularity AI SIEM are absolutely perfect."
  • "Unfortunately, I was not happy with SentinelOne Singularity AI SIEM because it is not mature yet."

What is our primary use case?

We have dealt with SentinelOne Endpoint, and at some point, we also used SentinelOne Singularity AI SIEM, which was introduced somewhere last year. I went on training in South Africa, where there were many questions discussing having one platform that allows control over all endpoints with visibility, which eliminates the need for separate systems. The challenge with SentinelOne Singularity AI SIEM is having an ingester to integrate with it at the syslog level. For some customers, we needed an ingester to integrate with the network devices before we could see them. For the endpoint side, everything was acceptable; we were able to do remediation, ransomware rollback, and everything operates autonomously, so no manual intervention is necessary. In terms of group level, you can assign policies to specific devices in specific environments. Additionally, there was a new introduction to cloud-native apps for cloud security, enabling integration of AWS and Google Suite apps, including Azure platforms, providing visibility, especially for AWS, where we can monitor all Kubernetes clusters and pods, allowing for remediation as vulnerabilities are identified.

What is most valuable?

The AI features of SentinelOne Singularity AI SIEM are absolutely perfect. There are not any issues because there is a game that you play with SentinelOne. This game allows me to drive a proof of concept for customers. When I play the game, SentinelOne provides a tool called Purple AI, which allows for simple queries just like ChatGPT. This means you do not need an expert to understand what is happening around your endpoints and identify threats. I can simply write, 'What happened to my Windows endpoint in the last seventy-two hours?' and it provides all reports and logs. This functionality makes it accessible even for CEOs and decision-makers to understand their environment better, making it an excellent feature for SOC, giving visibility and clarity.

What needs improvement?

I did use the automated workflow feature for a client. The automation allows for configuring all integration with endpoints, as well as SentinelOne Singularity AI SIEM. Unfortunately, I was not happy with SentinelOne Singularity AI SIEM because it is not mature yet. When comparing SentinelOne Singularity AI SIEM to platforms like Elasticsearch or Exabeam, or even QRadar, they are more matured. SentinelOne Singularity AI SIEM is designed to provide an affordable platform integrated with endpoints, eliminating the need for separate SIEM deployments. However, the integration of a log ingester in the cloud makes deployment cumbersome and requires an expert or native system integrator for setup.

SentinelOne Singularity AI SIEM should be separated from the overall platform. If the intention is to make it a complete solution and enable SIEM features, separating it would yield better results. You get a lot of noise when it is combined; separating it would mean clearly identifying logs from the EDR or SDR platform to SentinelOne Singularity AI SIEM. This would help in minimizing confusion and panic for customers facing numerous logs and potential false positives. A separate SIEM would allow clearer visibility, and there is a need for an on-premise option, particularly for organizations with data sovereignty concerns. Many institutions prefer to keep their data on-premise due to regulations, so adding an appliance that firms can integrate into their data centers would be valuable. If larger organizations need a SIEM solution, they will likely turn to QRadar or FortiSIEM instead.

For how long have I used the solution?

I already have experience with SentinelOne because I have been with SentinelOne for the past five years.

How are customer service and support?

In rating the technical support for SentinelOne, it depends on whether we are discussing EDR or SentinelOne Singularity AI SIEM. I would not rate the entire company uniformly. For the EDR, I might rate it around eight out of ten; for SentinelOne Singularity AI SIEM, I would give it five out of ten or two out of five.

Which other solutions did I evaluate?

Regarding pricing, the pricing of SentinelOne is quite favorable when compared to CrowdStrike. I appreciate the MSSP distribution model. For instance, if I purchase SentinelOne from Exclusive Networks, which I believe is known to you, I can provide it to individuals, allowing them to have SentinelOne installed on their laptops while maintaining the ability to control policies and monitor attacks. The MSSP pricing is negotiable, around thirty-three dollars per endpoint annually. For the reseller level, if support is needed, contacting SentinelOne directly allows me to open a case and access assistance from their engineers, which may cost around fifty dollars per endpoint. Comparatively, SentinelOne is more affordable than CrowdStrike. SentinelOne Singularity AI SIEM pricing also depends on the number of devices onboarded, including switches and firewalls, which all contribute to lowering costs. However, selling a complete cloud solution can be challenging in West Africa due to data sovereignty concerns.

What other advice do I have?

The need for improvement mainly revolves around focus areas. If SentinelOne only concentrates on developed countries, my experience in West Africa suggests disparities. SentinelOne needs to consider implementing an on-premise configuration or introducing a hybrid model. A staging server that sits on-premise allows for better data sovereignty while still using cloud services. If all logs are sent to the SentinelOne cloud, it poses challenges for customers without AWS capabilities.

I would rate SentinelOne Singularity AI SIEM overall at five out of ten. It is not suited for enterprises but works for startups or any environment that relies on cloud resources. My overall review rating for SentinelOne is five out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jun 29, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity AI SIEM
July 2026
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,852 professionals have used our research since 2012.
reviewer2811069 - PeerSpot reviewer
IT Security Analyst at a tech consulting company with 11-50 employees
Real User
Top 5Leaderboard
Mar 23, 2026
AI-driven workflows have transformed incident response speed and reduced false positives
Pros and Cons
  • "After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools."
  • "SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement."

What is our primary use case?

I use SentinelOne Singularity AI SIEM for endpoint security, including EDR and SIEM-based monitoring, as well as for XDR. I monitor endpoints for security reasons and receive alerts when suspicious or malicious activity is detected. When I find anything suspicious or malicious, I investigate it further.

What is most valuable?

I particularly appreciate a feature called Purple AI, which is an AI-based tool that allows us to fetch logs and investigate through a single prompt. It is useful for providing a brief summary of what has happened without needing to review logs in detail. Through this AI capability, we can understand exactly what has been occurring.

There is significant automation we can implement through a feature called hyper-automation. We can automate workflows easily using a drag and drop interface, rather than writing scripts. This makes automation in SentinelOne very straightforward.

I would say the quality is top-notch. It provides perfect summaries, has reduced our response time, and helps us reduce false positives. We receive mostly true positive alerts and do not need to write additional detection rules. SentinelOne Singularity AI SIEM can detect new sophisticated threats and zero-day attacks on its own without requiring rules from us. This automated detection capability is something I truly appreciate.

What needs improvement?

SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement. The interface flickers frequently, and sometimes it does not load properly. When this happens, we have to log out and log back in, or refresh the page before we can see the alerts. Sometimes the interface will be blank. These performance and reliability issues need to be addressed.

For how long have I used the solution?

I have been using SentinelOne Singularity AI SIEM for more than one year.

What do I think about the stability of the solution?

I would rate the stability at six out of ten.

What do I think about the scalability of the solution?

I would rate scalability at seven out of ten. SentinelOne Singularity AI SIEM handles a large environment fairly smoothly and works well. The performance depends on the configuration. If it is properly configured, it works well for large environments as well.

How are customer service and support?

I would rate the technical support at eight out of ten. SentinelOne Singularity AI SIEM has AI-based technical support available. When we have questions or require documentation, we receive it promptly. The support is good.

Which solution did I use previously and why did I switch?

Compared to other tools we have used, such as Sumo Logic, Splunk, and CrowdStrike, those solutions do not have as much AI capability. After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools.

What was our ROI?

SentinelOne Singularity AI SIEM has reduced our response time to true positive alerts by approximately forty percent through automation. For false positive reduction, it has decreased our false positive rate by fifty percent.

Which other solutions did I evaluate?

I can appreciate SentinelOne Singularity AI SIEM primarily for its AI capability. For this reason, we switched to SentinelOne Singularity AI SIEM. It has behavioral AI plus machine learning that has been integrated. We chose SentinelOne Singularity AI SIEM mainly because of its AI capability. It is a unified platform that provides a unified view of security alerts without requiring us to look at other data sources or switch between different tools. This has reduced the time required for faster detection and response.

What other advice do I have?

I would recommend SentinelOne Singularity AI SIEM to other users. Most tools do not have the same level of AI capability. SentinelOne Singularity AI SIEM has Purple AI and hyper-automation features that I can suggest to other users based on these capabilities.

SentinelOne Singularity AI SIEM has improved our SOC's efficiency in investigating alerts and responding to incidents through its AI capability. It provides us a unified view of entire alerts. We do not need to go to other data sources to understand what happened. It connects all the dots and gives us a unified alert view without requiring us to navigate to other tabs. We can see what happened from start to end. Cybersecurity and hacker tactics are constantly evolving, and we are seeing many sophisticated attacks nowadays. SentinelOne Singularity AI SIEM detects these attacks by itself without needing predefined rules, using machine learning and behavioral baselines to detect anomalies and trigger alerts. Additionally, Purple AI automatically provides a summary of incidents explaining what has happened in simple terms without requiring deep investigation into alerts or logs. This explanation of what was abused helps us make faster decisions about whether an incident is truly a threat or a false positive alert.

SentinelOne Singularity AI SIEM has significantly impacted our security tasks and reduced manual effort. We have requirements from clients we provide services for regarding particular alerts or unreported data. We can automate notifications to the customer when these conditions occur without manually creating a ticket. SentinelOne Singularity AI SIEM can automatically notify the user. We also use it for responding to alerts. In some cases, we need to disconnect an endpoint from the network to prevent malicious activity from spreading. We use hyper-automation to automatically disconnect endpoints or remove malicious files if they are present on an endpoint.

I give this product an overall rating of eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Mar 23, 2026
Flag as inappropriate
PeerSpot user
IT Security Consultant at Systemhaus for you GmbH
Real User
Top 5Leaderboard
Mar 2, 2026
AI-driven observability has transformed threat detection and now provides full incident visibility
Pros and Cons
  • "Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly better."
  • "In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier."

What is our primary use case?

Our use case with SentinelOne Singularity AI SIEM is primarily AI observability for a large part. We are using it for SIEM purposes as well. Prior to the inclusion of Purple AI, it was exclusively SIEM.

What is most valuable?

The best features of SentinelOne Singularity AI SIEM are 100% Purple AI.

In addition to that, though somewhat tedious, the implementation of any data you want is a feature of SentinelOne Singularity AI SIEM, and also the option to analyze that via Purple AI to some degree. Additionally, the existence of a large catalog of native integrations is valuable.

Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly improved. We finally have visibility into things that were never visible before. When talking to new customers and onboarding them, it is always apparent that there are so many things in their environment that they never even really knew about and had no visibility into. They previously needed to go through obscure, hard-to-use, and weird tooling to potentially access this information. Having all of that in SentinelOne Singularity AI SIEM makes it so much easier.

What needs improvement?

In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier. I did hear that there is something on the horizon for this, but that is an area that could be made less tedious.

Potentially to some degree, the evaluation of singular events in SentinelOne Singularity AI SIEM could improve. Sometimes they are painting the devil on the wall where there is not really a big issue, just a normal, everyday event. Those are sometimes taken a bit too negatively.

For how long have I used the solution?

I am still using SentinelOne Singularity AI SIEM presently.

What do I think about the stability of the solution?

When it comes to stability, I would give SentinelOne Singularity AI SIEM a nine. There are no really noticeable glitches or bugs. There used to be a few availability issues, but those are essentially mitigated by now. SentinelOne has taken those very seriously and in the past months, which might have been almost a year by now, I have not really noticed any availability issues.

How are customer service and support?

I would rate the technical support of SentinelOne Singularity AI SIEM a nine.

How would you rate customer service and support?

Positive

How was the initial setup?

As for maintenance required with SentinelOne Singularity AI SIEM, I would say it is even easier than the base product because you do not really onboard new data sources that often. If I put it into times a year, I would say it might be twice a year-ish that you need to do maintenance work essentially. Of course, if you want to add new detections or anything, that can be whenever, but I would not really consider that maintenance.

For others looking to implement SentinelOne Singularity AI SIEM, I would recommend starting with a proof of concept. Of course, with a SIEM that is a bit more effort to fully onboard, you might want to get an in-depth demonstration first and see if it meets your needs. Even before the demonstration, ask yourself what you even expect of a SIEM and what points you want from the solution. Once you are in the presentation, you will realize that those can very easily be met and completed with SentinelOne.

Which other solutions did I evaluate?

In comparison, I would assess SentinelOne Singularity AI SIEM favorably to other solutions or vendors such as Splunk, Microsoft, Hunters, Anomali, and Graylog. The nice part about it as well is that you can use AI SIEM standalone. However, the big advantage in my opinion comes from using it with the EDR. If you do that, you just have one of the main issues of SIEMs completely taken care of.

That being the data from the endpoints, in modern SIEMs, you have roughly 80 to 90% of the data is endpoint data. In other SIEMs, you have to pay for those and pay for every bit of data that you put in. With SentinelOne, if it is from the endpoint, you natively have that data and you do not have to pay extra for that, and it is just additional data on top of that. Additionally, combining that with the ability to have all the data in a single data lake means you do not need to use multiple data stores. It is using an open source data format, which is awesome.

What other advice do I have?

My impression of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is great. I am really looking forward to the upcoming feature with agentic incident investigation. If that is actually capable of autonomously investigating incidents across multiple data sources, for example, not just from SentinelOne, it will be transformative. The example I heard recently was an employee of the company opening a normal ticket just stating that their VPN connection is not working. That ticket is also made available to SentinelOne and it will then investigate what is going on with that. In the end, it turned out that this was actually an attack and that employee's VPN connection was hijacked. I am really looking forward to that feature, though it is not here yet, but even right now, it is great.

In terms of assessing the efficiency of SentinelOne Singularity AI SIEM in improving response time to sophisticated threats, you very quickly get an overview of all data and data related to the incident. Even if there is no active incident, you can very quickly get all related information due to the Storylines and Purple AI.

SentinelOne's AI-driven analytics have affected our SOC abilities to reduce false positives, and I would say roughly about 80%.

I would rate this solution a 10 overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Last updated: Mar 2, 2026
Flag as inappropriate
PeerSpot user
reviewer2835498 - PeerSpot reviewer
Cybersecurity Postsales Engineer at a outsourcing company with 51-200 employees
Real User
Top 5
Jul 23, 2026
AI-driven security workflows have transformed investigations and now reduce incident response times
Pros and Cons
  • "SentinelOne Singularity AI SIEM has improved our overall security posture and is reducing the workload on the SOC team."
  • "SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved."

What is our primary use case?

SentinelOne Singularity AI SIEM's main use case is to enhance cybersecurity by using AI to detect, investigate, and automatically respond across endpoints, cloud, and identities. It helps security teams reduce manual efforts, accelerate incident response, and improve overall security operations.

In my previous role, I used SentinelOne Singularity AI SIEM to investigate endpoint security alerts. Instead of manually using logs from multiple systems, I used the AI-powered investigation features to quickly identify the root cause of suspicious activities. SentinelOne Singularity AI SIEM automatically correlated related events and highlighted the affected endpoints while recommending response actions. We isolated the endpoints with a single click after verifying it was a malicious script, and we remediated the issue much faster than the previous manual process.

What is most valuable?

The best features of SentinelOne Singularity AI SIEM are AI-powered threat detections, unified security data, Purple AI assistant, automated investigations, hyper-automations, and fast threat hunting. These features include centralized log management, Purple AI for natural log investigations, automated alert correlations, and hyper-automations for incident response. These features help security teams detect threats faster, reduce manual effort, minimize false positives, and significantly improve mean time to detect and mean time to respond.

These features significantly improved our SOC workflow. Previously, analysts had to manually collect logs from multiple tools and correlate alerts, which was time-consuming. With SentinelOne Singularity AI SIEM, alerts were automatically correlated into a single incident with an attack timeline, making investigations much faster. Purple AI helped summarize the incident and answer natural language queries, reducing the time spent searching through logs.

SentinelOne Singularity AI SIEM has improved our overall security posture and is reducing the workload on the SOC team. Its AI-driven detection and automated response capabilities help us identify threats faster, reduce false positives, and shorten incident response times. The centralized visibility across endpoints and cloud environments also made investigations more efficient, while automation reduced repetitive manual tasks.

It has improved SOC efficiency by reducing time analysts spend on manual alert investigations and response. Previously, analysts had to collect information from multiple sources and manually correlate events. With SentinelOne Singularity AI SIEM's AI-driven alert prioritization, automated incident correlations, and investigation timelines provide better context quickly. The team can identify the root cause faster, reduce alert fatigue, and take response actions such as isolating affected endpoints more efficiently.

What needs improvement?

SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved. First, the initial setup and integration with some third-party tools could be simpler. Second, more customizable dashboards and reporting would help the management team confirm their needs.

For how long have I used the solution?

I have been using SentinelOne Singularity AI SIEM for the last three years.

What other advice do I have?

My impression of SentinelOne Singularity AI SIEM's AI-driven threat detection capability is very positive. It uses behavioral analysis and machine learning to identify suspicious activity that may not be detected by traditional signature-based methods.

I used SentinelOne Singularity AI SIEM's automated workflow capability to reduce repetitive security tasks. For example, when a high-risk alert was detected, automated workflows helped with actions such as endpoint isolation, alert enrichment, and triggering response processes without requiring manual intervention at every step. This reduced the time analysts spent on routine tasks and has improved consistency in incident handling.

My advice would be to clearly define your security goals and use cases before deploying SentinelOne Singularity AI SIEM. Start with proper endpoint coverage, integrate with your existing security tools, and spend time tuning policies to reduce unnecessary alerts. I would also recommend training the SOC team on the AI investigations and automation features so they can fully benefit from the platform. Finally, continuously review detection results and response processes to ensure the platform is meeting the organization's security needs. I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 23, 2026
Flag as inappropriate
PeerSpot user
reviewer2805261 - PeerSpot reviewer
Cyber Security Engineer at a retailer with 201-500 employees
Real User
Top 5
Mar 6, 2026
Advanced AI detection has reduced false positives and currently protects endpoints from new threats
Pros and Cons
  • "When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware."
  • "It is quite good, but the only downside is that it is costly."

What is our primary use case?

The main use cases for SentinelOne Singularity AI SIEM are endpoint protection and EDRs. When you compare the EDRs with Trend Micro and others, you will find many false positives, but SentinelOne gives you the best protection. It uses its AI to scan and find new malware, how new attackers are behaving, and addresses zero-day attacks as well. It is quite good, but the only downside is that it is costly.

What is most valuable?

The best features in SentinelOne Singularity AI SIEM include AI capabilities; they have two types of AI. First, AI is on the dashboard, which you can interact with, such as asking for logs of the last ten days, and it will provide them to you. This is one type of AI, similar to a chatbot. The other AI operates in the back end to find malware. It employs a combination of AI and ML to check for viruses or any other malicious processes, including fileless attacks.

The impression I have of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is that it is good and working fine, and I have never found any complaints from any customer. The dashboard is also quite simple.

What needs improvement?

When it comes to room for improvement, I would say the analysis page can be improved.

In terms of improvement, you can add more detection features.

For how long have I used the solution?

I have been working with SentinelOne Singularity AI SIEM for almost six months.

What do I think about the stability of the solution?

I have not seen any stability or scalability issues with it; it is usually license-based, so when you are buying, you typically know how much you need.

In terms of performance stability, I have never had any crashes, downtimes, or performance issues.

What do I think about the scalability of the solution?

The scalability of SentinelOne Singularity AI SIEM in adapting to an organization's growing data or complex IT structures is good, but it actually depends on the person who is managing it and how they make the policies; it totally depends on the policies they are making.

How are customer service and support?

My thoughts on the tech support of SentinelOne Singularity AI SIEM are that it is good and AI-based, and the documentation is also good compared to other solutions I have seen.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The benefits of SentinelOne Singularity AI SIEM include that most of the customers who use it upgrade from their existing endpoint solutions. Many are using Trend Micro endpoints, Check Point endpoints, or others, and they are unhappy, especially with solutions such as Kaspersky. When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware.

How was the initial setup?

Regarding the initial setup of SentinelOne Singularity AI SIEM, I can walk you through the deployment process: you can sync your AD, and the agent installation can also be automated. You can push it directly from your Microsoft Active Directory using GPO, which makes it easy. The agent installation can be automated, so I do not think it takes much time. However, since it is an endpoint tool, you have to consider policies for different departments, including allow lists and block lists, so deploying any endpoint does take some time.

What about the implementation team?

We are not directly system integrators of the product, but we sell through Lenovo.

Which other solutions did I evaluate?

Apart from the Harmony, I work with various CloudGuard Check Point products, and I also have a certification for SOCRADAR. I work with SOCRADAR and still have hands-on experience doing POCs and demos with SOCRADAR. I have recently done POCs or demos with SOCRADAR. We are working with an alternate solution for that, and it is a new solution.

What other advice do I have?

SentinelOne Singularity AI SIEM has many features, and my recommendation is to utilize all of them, but people often do not use them all. It would be helpful to automate it or use playbooks to take full advantage of the features. I rate this product a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Last updated: Mar 6, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free SentinelOne Singularity AI SIEM Report and get advice and tips from experienced pros sharing their opinions.
Updated: July 2026
Buyer's Guide
Download our free SentinelOne Singularity AI SIEM Report and get advice and tips from experienced pros sharing their opinions.