Clients can use SentinelOne Singularity AI SIEM for endpoint security solutions, and apart from that, we currently have something called prompt security where it is helping us to enhance control over the AI prompts given by end-users. Some end-users tend to feed sensitive data to AI tools like Claude, Gemini, and ChatGPT. We have not implemented it yet, but we have provided a POC for agnostic prompt security. AI-driven Threat Detection capability is crucial because attackers have started conducting attacks using AI patterns. They analyze the patterns of defending solutions, and based on the defense architecture, they generate the payload according to the environment. To detect those kinds of payloads, we need AI-based threat detection to sense whether they come from a single source or distinct sources, where these kinds of prompts and malicious payloads are being generated. Real-time monitoring is a must-have functionality for any product, and SentinelOne Singularity AI SIEM has the same response. We can create rules for peculiar situations we encounter, and if those rules get triggered, the system can automatically help isolate or contain that system while providing us alerts at the same time. This way, if a particular user reports not being able to reach anything, we can quickly understand that SentinelOne Singularity AI SIEM has isolated their system.
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
Real User
Top 5
Jun 15, 2026
The primary use cases for SentinelOne Singularity AI SIEM are that we are using it as a replacement for Secureworks. We migrated to and switched to SentinelOne.
Vice President Cyber Security Practice Head at orbit techsol w pvt.ltd
Real User
Top 5
May 28, 2026
We discuss with customers whether they want to go on a cloud or on-premises for the usual use cases of SentinelOne Singularity AI SIEM that I work with mostly. If a customer has a SentinelOne EDR, the EPS we do not count. The rest of the things we can integrate on a cloud. Correlation, alerting, reporting, and helping with the AI-based alerts generated by the AI are the usual use cases. The parsing is already built into SentinelOne Singularity AI SIEM.
Group Chief Information Officer at NeST Information Technologies Pvt Ltd
Real User
Top 5
Mar 27, 2026
For us, the use case is primarily to analyze security events that are coming in and also events that are kept over a period of time, to track and use it for investigation and maybe analysis, sometimes even forensics.
IT Security Analyst at a tech consulting company with 11-50 employees
Real User
Top 5
Mar 23, 2026
I use SentinelOne Singularity AI SIEM for endpoint security, including EDR and SIEM-based monitoring, as well as for XDR. I monitor endpoints for security reasons and receive alerts when suspicious or malicious activity is detected. When I find anything suspicious or malicious, I investigate it further.
I am using SentinelOne Singularity AI SIEM as a customer only, and I have taken it very recently. I am using it to get visibility of investigating my alerts based on the alert events received from my endpoints. For AI-driven applications, I want to have end-to-end visibility, which is where the observability piece comes in. I am using it primarily for the AI part, as this product will cover my real-time data detections. I am planning on implementing it for my AI-driven applications.
Learn what your peers think about SentinelOne Singularity AI SIEM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Our use case with SentinelOne Singularity AI SIEM is primarily AI observability for a large part. We are using it for SIEM purposes as well. Prior to the inclusion of Purple AI, it was exclusively SIEM.
SentinelOne Singularity AI SIEM offers comprehensive security information and incident management designed to enhance threat detection, response, and investigation capabilities within enterprise environments.SentinelOne Singularity AI SIEM is known for its robust capabilities in the realm of cybersecurity, providing organizations with an advanced tool to combat modern threats. The platform integrates machine learning and artificial intelligence to automate threat identification and streamline...
Clients can use SentinelOne Singularity AI SIEM for endpoint security solutions, and apart from that, we currently have something called prompt security where it is helping us to enhance control over the AI prompts given by end-users. Some end-users tend to feed sensitive data to AI tools like Claude, Gemini, and ChatGPT. We have not implemented it yet, but we have provided a POC for agnostic prompt security. AI-driven Threat Detection capability is crucial because attackers have started conducting attacks using AI patterns. They analyze the patterns of defending solutions, and based on the defense architecture, they generate the payload according to the environment. To detect those kinds of payloads, we need AI-based threat detection to sense whether they come from a single source or distinct sources, where these kinds of prompts and malicious payloads are being generated. Real-time monitoring is a must-have functionality for any product, and SentinelOne Singularity AI SIEM has the same response. We can create rules for peculiar situations we encounter, and if those rules get triggered, the system can automatically help isolate or contain that system while providing us alerts at the same time. This way, if a particular user reports not being able to reach anything, we can quickly understand that SentinelOne Singularity AI SIEM has isolated their system.
The primary use cases for SentinelOne Singularity AI SIEM are that we are using it as a replacement for Secureworks. We migrated to and switched to SentinelOne.
We discuss with customers whether they want to go on a cloud or on-premises for the usual use cases of SentinelOne Singularity AI SIEM that I work with mostly. If a customer has a SentinelOne EDR, the EPS we do not count. The rest of the things we can integrate on a cloud. Correlation, alerting, reporting, and helping with the AI-based alerts generated by the AI are the usual use cases. The parsing is already built into SentinelOne Singularity AI SIEM.
For us, the use case is primarily to analyze security events that are coming in and also events that are kept over a period of time, to track and use it for investigation and maybe analysis, sometimes even forensics.
I use SentinelOne Singularity AI SIEM for endpoint security, including EDR and SIEM-based monitoring, as well as for XDR. I monitor endpoints for security reasons and receive alerts when suspicious or malicious activity is detected. When I find anything suspicious or malicious, I investigate it further.
I am using SentinelOne Singularity AI SIEM as a customer only, and I have taken it very recently. I am using it to get visibility of investigating my alerts based on the alert events received from my endpoints. For AI-driven applications, I want to have end-to-end visibility, which is where the observability piece comes in. I am using it primarily for the AI part, as this product will cover my real-time data detections. I am planning on implementing it for my AI-driven applications.
Our use case with SentinelOne Singularity AI SIEM is primarily AI observability for a large part. We are using it for SIEM purposes as well. Prior to the inclusion of Purple AI, it was exclusively SIEM.