What is our primary use case?
After a CrowdStrike issue, we began using their cloud security offering. SentinelOne Singularity AI SIEM is more of an integration to their existing cloud security solution. We have been using this particular solution for more than a year, though slightly less than that range.
I am an observability engineer, and this solution is very helpful for security-related needs. When working in a company that handles a lot of data, particularly infrastructure data, you encounter numerous security alerts due to dependencies and security vulnerabilities on infrastructure machines. When we receive this data from different machines, these are signals. When you get this kind of data, it is almost impossible to do it manually in any way or form. What we need is a sampler that samples consistent data. With the AI SIEM on top of SentinelOne Singularity AI SIEM Observability Cloud security solution, we can filter out many things in terms of telemetry data that we receive. The endpoint telemetry is something we actually focus on with this particular solution, followed by the cloud infrastructure logs. We have used Splunk in the past. After a certain time, if you are not on their cloud offering on a very high tier, they will charge you money excessively or they will throttle your application. This is not the case with SentinelOne Singularity AI SIEM. That is a better approach. We also manage Kubernetes containers and environments through this solution. All the pods used to send a lot of telemetry data, and we can easily identify that. The dashboard, though it has some limited functionalities, works extremely well with what they offer. We use it day in and day out.
As we have the enterprise solution for this, we have used it extensively for Kubernetes pods where we have attached certain authentication systems. We have also used it for a lot of network security events when we have to do a compliance report. We have complete automation around it which provides us the reporting and everything at the end of the day. We have integrated it with our data pipelines also, and it helps us there as well.
What is most valuable?
The log segregation is my favorite feature. When you want to search over a very high or extremely long range of logs, it helps you tremendously because it becomes very easy to identify vulnerabilities and issues on the ongoing system. Otherwise, what happens with ELK is it becomes very expensive. With Splunk, though it has a data lake on its own, it requires you a good amount of investment. Though their system is more mature than SentinelOne Singularity AI SIEM, the best part about SentinelOne Singularity AI SIEM is the searching capability they have. It is extremely one of the best in the market right now, from what I remember, because their AI also provides you insights. It tells you what is happening in the system and asks you to check that part or check this part. This provides you with an edge when you are looking for vulnerabilities. In my role as a lead engineer in SRE, my domain is observability. There we have a lot of telemetry data. Telemetry data are metrics, logs, and a lot of other alerts. To identify those parts on the security layer, it is extremely good.
I can talk about the amount of tokens we can use. These are limited, though the searches are very extensive. The actual pricing model is something that is handled by the FinOps team, as I have already mentioned before on one of the products, Cribl. We do not have full visibility and observability and telemetry information, but I can provide you engineering insights. Costing is something that every company has their own FinOps team manage everything. If you want to purchase it, you go through that team. I do not know the enterprise costing for that, but I know that cost for an individual purchase. I think it is justified compared to other peers in the market.
What needs improvement?
What I dislike is that the dashboard is very old, so they do not have much capability to be honest. Dashboard customization is almost nonexistent. What they have is something they offer as standard. They do not have a DataDog style plug and play model where you can add a lot of metrics and it will provide you with them. They basically have pre-built compliance report templates that they just send you, but you do not have a way to customize it further. Currently, as the system is not that mature right now because it has been a very limited offering at the moment for SentinelOne Singularity AI SIEM. Third party integrations are something they lack a lot. I cannot connect it to Grafana or directly to a system which can help me identify things. This is something they lack right now at the moment.
For how long have I used the solution?
We have been using this particular solution for more than a year, though slightly less than that range.
What do I think about the stability of the solution?
We have had no issues to be honest. It was compliant and reliable. I have not even seen much AI hallucinating on top of this. It has provided proper patterns and I do not have any complaints.
These things are properly managed and I do not see a problem to be honest. Though data volumes are really high for logs and other things, it worked well. I will say that even the data lake feature they have, in terms of keeping all the logs intact, those log searches are extremely fast on SentinelOne Singularity AI SIEM, even though the data is very high. Whatever you need, you get it fast as simple as that.
Which solution did I use previously and why did I switch?
We were using something similar before. We were using CrowdStrike extensively for this, but the SIEM approach they have, not the AI feature, is more mature than this. However, due to that outage, our company moved towards SentinelOne Singularity AI SIEM because we had compliance and client issues. Clients specifically asked us to remove CrowdStrike permanently from whatever Windows machines we have for security issues. Something came very strong from one of the companies which we took into account and we changed it across whatever customer we have. We moved with a better alternative. SentinelOne Singularity AI SIEM was relatively a good choice as of now.
How was the initial setup?
The AI integration was pretty straightforward. I did not face any problem. We created some policies and based on those policies, we were able to identify how to integrate it via this. I do not remember the exact steps. I have a document written on it somewhere that I need to pull out. It was a pretty standard thing. You just have to go to some consoles and integrate it based on this. You have to provide the endpoint details and it got integrated very smoothly.
What about the implementation team?
I do not maintain it. My work was just the integration aspect. Maintenance and other aspects are something that one of the other teams manages. These are the security engineers that we have. They actually provide all this information. If you need, I can connect you with them. I can send you their name or information so you can reach out to them.
What was our ROI?
Definitely, that is what I told you. It has given good ROI on that part where our investigation time has reduced to a certain degree. I will say the gains we get are more than fifty percent to be honest. We have reduced almost fifty percent of the dev's time, or not dev, the security engineer's time, SDs, whatever SECs we had. Even my VP of engineering who manages me is one of the guys who manages security. He is very happy with all this investigation time that we have reduced. We have a metric that we track in the company. This actually shows us a good amount of time. Previously it was a continuous problem for us where we had to manage all these things. An engineer had to be there for one of those problems. Now that is gone. We have a little bit more breathing room. It is not completely gone, but it is manageable now.
The sampling happens based on a single line of code. You do not need this one or a similar kind of logs, or some system should not go and sit in the data lakes. The best part about analytics is you do not have to look into anything. Threat hunting, how it works, the experience of the overall threat hunting aspect has actually improved a lot with AI because you do not want to read telemetry data. Who wants to do that? Who has time to do that? Telemetry data are raw data of signals where metrics and logs are coming in. No one wants to read them. The AI helps on top of it and helps you to make sense out of it or provides patterns. You are seeing that pattern or not. These kind of things matter. The best part is it is relatively faster than its peers because even though the data is more, it is relatively faster. I do not know what kind of algorithm they are using in the back end, but it is extremely good to be honest.
I will strongly recommend this. After SentinelOne Singularity AI SIEM, we have reduced our engineering time to a certain degree as it has helped us to do investigations fast. We get actual alerts that matter, and we can prioritize it properly. The monitoring capability is now completely in one single platform. We do not have to go here and there. This actually has given us good ROI in total.
What other advice do I have?
I am an observability engineer, and my current domain is that. SentinelOne Singularity AI SIEM is very helpful for security-related needs. When working in a company that handles a lot of data, particularly infrastructure data, you encounter numerous security alerts due to dependencies and security vulnerabilities on infrastructure machines. When we receive this data from different machines, these are signals. When you get this kind of data, it is almost impossible to do it manually in any way or form. What we need is a sampler that samples consistent data. With the AI SIEM on top of SentinelOne Singularity AI SIEM Observability Cloud security solution, we can filter out many things in terms of telemetry data that we receive. The endpoint telemetry is something we actually focus on with this particular solution, followed by the cloud infrastructure logs. We have used Splunk in the past. After a certain time, if you are not on their cloud offering on a very high tier, they will charge you money excessively or they will throttle your application. This is not the case with SentinelOne Singularity AI SIEM. That is a better approach. We also manage Kubernetes containers and environments through this solution. All the pods used to send a lot of telemetry data, and we can easily identify that. The dashboard, though it has some limited functionalities, works extremely well with what they offer. We use it day in and day out.
I can talk about the amount of tokens we can use. These are limited, though the searches are very extensive. The actual pricing model is something that is handled by the FinOps team, as I have already mentioned before on one of the products, Cribl. We do not have full visibility and observability and telemetry information, but I can provide you engineering insights. Costing is something that every company has their own FinOps team manage everything. If you want to purchase it, you go through that team. I do not know the enterprise costing for that, but I know that cost for an individual purchase. I think it is justified compared to other peers in the market. I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.