The automated workflow feature impacts my security tasks and manual efforts significantly. Downtime is not necessarily required in scenarios where a particular system has to be isolated. Whether it is a server or a normal endpoint, if an application server faces downtime, the situation differs from a normal endpoint. If an application server needs to be contained, the customer will obviously experience downtime. The consolidation of multiple tools with SentinelOne Singularity AI SIEM impacts SOC operations positively concerning cost and staffing needs. While I am unsure about staffing because it depends on daily occurrences, it definitely makes work easier for the team. For example, without it, a person can hardly handle two or three threats a day, but with SentinelOne Singularity AI SIEM, they can handle around 10 to 12 threats daily, which makes it much more efficient. SentinelOne Singularity AI SIEM is quite affordable. My overall review rating for this product is 9 out of 10.
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
Real User
Top 5
Jun 15, 2026
We have used the automated workflow feature of SentinelOne Singularity AI SIEM and are still working on it. We started implementing automated workflows almost three months ago. The automated configuration is not a one-time setup, as we are continuously making changes and modifications over time. I assess the overall security posture of our organization after implementing SentinelOne Singularity AI SIEM as significantly improved. We have developed a security posture that has definitely reached the benchmark. Previously, we were using Secureworks XDR, which is also a very good solution. We ran both solutions in parallel and discovered that Secureworks had almost a ten minute gap in identifying issues compared to SentinelOne, with a five to eight minute difference between the two platforms. The issue with Secureworks XDR is that it was not taking action because their playbooks were not efficient enough, partially because they were integrating with SentinelOne. In contrast, SentinelOne has local integration, so it immediately takes action and responds on the endpoint with automation. If any threat or suspicious activity is detected on any endpoint or server, SentinelOne immediately takes action at the same time. We have definitely increased our security posture. I would rate SentinelOne Singularity AI SIEM overall as 8.5 out of ten. There are still certain things we are evaluating, so we maintain the rating of 8.5. I am basing this rating on three main factors: the quality of support, the frequency and quality of updates, and the integration and update capabilities. In terms of threat detection, response, and log collection, SentinelOne Singularity AI SIEM is excellent. We do not have any issues with those areas. SentinelOne Singularity AI SIEM's AI-driven analytics have positively affected our SOC's ability to reduce false positives. We initially encountered false positives, but after configuration and adjustment, it performed much better for us. We now experience very low rates of false positives. Consolidating multiple tools into SentinelOne Singularity AI SIEM has positively impacted our SOC's operational costs. We now manage our EDR, MDR, view logs, and handle automation all from one consolidated console from SentinelOne Singularity AI SIEM. The consolidation has also reduced our SOC's operational costs and staffing needs. We are also taking SOC services from SentinelOne itself. SentinelOne has a dedicated SOC service that handles our SOC operations. SentinelOne Singularity AI SIEM's scalability in adapting to our organization's growing data and complex IT structures is flexible. We have not faced any scalability issues so far. Perhaps after one or two years we can discuss challenges we may have encountered, but as of now we have not faced anything related to scalability. We currently have five administrators managing this product, each with different roles and responsibilities. Within our structure, we have multiple entities, and we can create entity-wise administrators, which works very well for us. More than 2,500 users in our company are using this product. One issue we are facing is that SentinelOne's support team, as part of Amazon, works on updates on Sundays at the weekend. However, Sunday is the first working day for the Middle East region, particularly in Saudi Arabia. We have requested them to address tenant-related issues during our working hours. They are considering this request, and once Amazon establishes operations in Saudi Arabia, our tenant will be shifted to the kingdom and this issue will be resolved. I would also like to mention the maintenance window for upgrades, which is an area that could be improved. My overall rating for SentinelOne Singularity AI SIEM is 8.5 out of ten.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
Real User
Top 5
May 28, 2026
Correlation, alerting, reporting, and helping with the AI-based alerts generated by the AI are the usual use cases. The parsing is already built into SentinelOne Singularity AI SIEM. There is no challenge with operations because there are very good training portals where the people learn and perform the operation actively, and there is super training available on the SentinelOne portal through the SentinelOne Training University. I provide this review with an overall rating of ten out of ten.
Group Chief Information Officer at NeST Information Technologies Pvt Ltd
Real User
Top 5
Mar 27, 2026
I assess the overall security posture of the company after implementation as positive; I see a big impact on that. I would rate this review as an overall eight.
IT Security Analyst at a tech consulting company with 11-50 employees
Real User
Top 5
Mar 23, 2026
I would recommend SentinelOne Singularity AI SIEM to other users. Most tools do not have the same level of AI capability. SentinelOne Singularity AI SIEM has Purple AI and hyper-automation features that I can suggest to other users based on these capabilities. SentinelOne Singularity AI SIEM has improved our SOC's efficiency in investigating alerts and responding to incidents through its AI capability. It provides us a unified view of entire alerts. We do not need to go to other data sources to understand what happened. It connects all the dots and gives us a unified alert view without requiring us to navigate to other tabs. We can see what happened from start to end. Cybersecurity and hacker tactics are constantly evolving, and we are seeing many sophisticated attacks nowadays. SentinelOne Singularity AI SIEM detects these attacks by itself without needing predefined rules, using machine learning and behavioral baselines to detect anomalies and trigger alerts. Additionally, Purple AI automatically provides a summary of incidents explaining what has happened in simple terms without requiring deep investigation into alerts or logs. This explanation of what was abused helps us make faster decisions about whether an incident is truly a threat or a false positive alert. SentinelOne Singularity AI SIEM has significantly impacted our security tasks and reduced manual effort. We have requirements from clients we provide services for regarding particular alerts or unreported data. We can automate notifications to the customer when these conditions occur without manually creating a ticket. SentinelOne Singularity AI SIEM can automatically notify the user. We also use it for responding to alerts. In some cases, we need to disconnect an endpoint from the network to prevent malicious activity from spreading. We use hyper-automation to automatically disconnect endpoints or remove malicious files if they are present on an endpoint. I give this product an overall rating of eight out of ten.
My impression of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is great. I am really looking forward to the upcoming feature with agentic incident investigation. If that is actually capable of autonomously investigating incidents across multiple data sources, for example, not just from SentinelOne, it will be transformative. The example I heard recently was an employee of the company opening a normal ticket just stating that their VPN connection is not working. That ticket is also made available to SentinelOne and it will then investigate what is going on with that. In the end, it turned out that this was actually an attack and that employee's VPN connection was hijacked. I am really looking forward to that feature, though it is not here yet, but even right now, it is great. In terms of assessing the efficiency of SentinelOne Singularity AI SIEM in improving response time to sophisticated threats, you very quickly get an overview of all data and data related to the incident. Even if there is no active incident, you can very quickly get all related information due to the Storylines and Purple AI. SentinelOne's AI-driven analytics have affected our SOC abilities to reduce false positives, and I would say roughly about 80%. I would rate this solution a 10 overall.
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
SentinelOne Singularity AI SIEM offers comprehensive security information and incident management designed to enhance threat detection, response, and investigation capabilities within enterprise environments.SentinelOne Singularity AI SIEM is known for its robust capabilities in the realm of cybersecurity, providing organizations with an advanced tool to combat modern threats. The platform integrates machine learning and artificial intelligence to automate threat identification and streamline...
The automated workflow feature impacts my security tasks and manual efforts significantly. Downtime is not necessarily required in scenarios where a particular system has to be isolated. Whether it is a server or a normal endpoint, if an application server faces downtime, the situation differs from a normal endpoint. If an application server needs to be contained, the customer will obviously experience downtime. The consolidation of multiple tools with SentinelOne Singularity AI SIEM impacts SOC operations positively concerning cost and staffing needs. While I am unsure about staffing because it depends on daily occurrences, it definitely makes work easier for the team. For example, without it, a person can hardly handle two or three threats a day, but with SentinelOne Singularity AI SIEM, they can handle around 10 to 12 threats daily, which makes it much more efficient. SentinelOne Singularity AI SIEM is quite affordable. My overall review rating for this product is 9 out of 10.
We have used the automated workflow feature of SentinelOne Singularity AI SIEM and are still working on it. We started implementing automated workflows almost three months ago. The automated configuration is not a one-time setup, as we are continuously making changes and modifications over time. I assess the overall security posture of our organization after implementing SentinelOne Singularity AI SIEM as significantly improved. We have developed a security posture that has definitely reached the benchmark. Previously, we were using Secureworks XDR, which is also a very good solution. We ran both solutions in parallel and discovered that Secureworks had almost a ten minute gap in identifying issues compared to SentinelOne, with a five to eight minute difference between the two platforms. The issue with Secureworks XDR is that it was not taking action because their playbooks were not efficient enough, partially because they were integrating with SentinelOne. In contrast, SentinelOne has local integration, so it immediately takes action and responds on the endpoint with automation. If any threat or suspicious activity is detected on any endpoint or server, SentinelOne immediately takes action at the same time. We have definitely increased our security posture. I would rate SentinelOne Singularity AI SIEM overall as 8.5 out of ten. There are still certain things we are evaluating, so we maintain the rating of 8.5. I am basing this rating on three main factors: the quality of support, the frequency and quality of updates, and the integration and update capabilities. In terms of threat detection, response, and log collection, SentinelOne Singularity AI SIEM is excellent. We do not have any issues with those areas. SentinelOne Singularity AI SIEM's AI-driven analytics have positively affected our SOC's ability to reduce false positives. We initially encountered false positives, but after configuration and adjustment, it performed much better for us. We now experience very low rates of false positives. Consolidating multiple tools into SentinelOne Singularity AI SIEM has positively impacted our SOC's operational costs. We now manage our EDR, MDR, view logs, and handle automation all from one consolidated console from SentinelOne Singularity AI SIEM. The consolidation has also reduced our SOC's operational costs and staffing needs. We are also taking SOC services from SentinelOne itself. SentinelOne has a dedicated SOC service that handles our SOC operations. SentinelOne Singularity AI SIEM's scalability in adapting to our organization's growing data and complex IT structures is flexible. We have not faced any scalability issues so far. Perhaps after one or two years we can discuss challenges we may have encountered, but as of now we have not faced anything related to scalability. We currently have five administrators managing this product, each with different roles and responsibilities. Within our structure, we have multiple entities, and we can create entity-wise administrators, which works very well for us. More than 2,500 users in our company are using this product. One issue we are facing is that SentinelOne's support team, as part of Amazon, works on updates on Sundays at the weekend. However, Sunday is the first working day for the Middle East region, particularly in Saudi Arabia. We have requested them to address tenant-related issues during our working hours. They are considering this request, and once Amazon establishes operations in Saudi Arabia, our tenant will be shifted to the kingdom and this issue will be resolved. I would also like to mention the maintenance window for upgrades, which is an area that could be improved. My overall rating for SentinelOne Singularity AI SIEM is 8.5 out of ten.
Correlation, alerting, reporting, and helping with the AI-based alerts generated by the AI are the usual use cases. The parsing is already built into SentinelOne Singularity AI SIEM. There is no challenge with operations because there are very good training portals where the people learn and perform the operation actively, and there is super training available on the SentinelOne portal through the SentinelOne Training University. I provide this review with an overall rating of ten out of ten.
I assess the overall security posture of the company after implementation as positive; I see a big impact on that. I would rate this review as an overall eight.
I would recommend SentinelOne Singularity AI SIEM to other users. Most tools do not have the same level of AI capability. SentinelOne Singularity AI SIEM has Purple AI and hyper-automation features that I can suggest to other users based on these capabilities. SentinelOne Singularity AI SIEM has improved our SOC's efficiency in investigating alerts and responding to incidents through its AI capability. It provides us a unified view of entire alerts. We do not need to go to other data sources to understand what happened. It connects all the dots and gives us a unified alert view without requiring us to navigate to other tabs. We can see what happened from start to end. Cybersecurity and hacker tactics are constantly evolving, and we are seeing many sophisticated attacks nowadays. SentinelOne Singularity AI SIEM detects these attacks by itself without needing predefined rules, using machine learning and behavioral baselines to detect anomalies and trigger alerts. Additionally, Purple AI automatically provides a summary of incidents explaining what has happened in simple terms without requiring deep investigation into alerts or logs. This explanation of what was abused helps us make faster decisions about whether an incident is truly a threat or a false positive alert. SentinelOne Singularity AI SIEM has significantly impacted our security tasks and reduced manual effort. We have requirements from clients we provide services for regarding particular alerts or unreported data. We can automate notifications to the customer when these conditions occur without manually creating a ticket. SentinelOne Singularity AI SIEM can automatically notify the user. We also use it for responding to alerts. In some cases, we need to disconnect an endpoint from the network to prevent malicious activity from spreading. We use hyper-automation to automatically disconnect endpoints or remove malicious files if they are present on an endpoint. I give this product an overall rating of eight out of ten.
My impression of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is great. I am really looking forward to the upcoming feature with agentic incident investigation. If that is actually capable of autonomously investigating incidents across multiple data sources, for example, not just from SentinelOne, it will be transformative. The example I heard recently was an employee of the company opening a normal ticket just stating that their VPN connection is not working. That ticket is also made available to SentinelOne and it will then investigate what is going on with that. In the end, it turned out that this was actually an attack and that employee's VPN connection was hijacked. I am really looking forward to that feature, though it is not here yet, but even right now, it is great. In terms of assessing the efficiency of SentinelOne Singularity AI SIEM in improving response time to sophisticated threats, you very quickly get an overview of all data and data related to the incident. Even if there is no active incident, you can very quickly get all related information due to the Storylines and Purple AI. SentinelOne's AI-driven analytics have affected our SOC abilities to reduce false positives, and I would say roughly about 80%. I would rate this solution a 10 overall.