I would like to see broader third-party integration and easier troubleshooting for log sources. I would like to see more customization in dashboards and reporting, especially for SOC-specific metrics and management summaries. This would bring more flexibility in configuring alerts and log source views.
The main improvement area is deeper customization. It would be helpful to have more flexibility for creating custom detection rules, dashboards, and alert workflows based on specific organizational requirements. I would also like to see more integrations and advanced investigation capabilities over time. Another area would be improving the reporting and customization options. More detailed reports, better visibility into investigation timelines, and easier customization of alerts would make Huntress Managed SIEM even more useful for day-to-day SOC operations. I would like to see more advanced dashboard customization, additional third-party integrations, and more granular control over alert rules and workflows. Better reporting and automation options would also make it more useful for SOC environments.
Huntress Managed SIEM has areas for improvement regarding more log sources. They are working on connecting more sources to the right format for events, such as a Fortinet firewall, but we use other firewalls as well, so that could use some development. The deployment of Huntress Managed SIEM is somewhat complex compared to ITDR and EDR, as those are just click, click, click, and next, next, finish, while SIEM requires some form of configuration. Additionally, a Huntress agent is needed within the same network as the firewall to collect those logs, so it would be a great addition if they could make it possible to log events directly from a Fortinet FortiGate firewall to Huntress Managed SIEM.
Technology Operations Specialist at a tech vendor with 5,001-10,000 employees
Real User
Top 10
Aug 20, 2026
Areas where Huntress Managed SIEM could improve include automated alert triage, events, threat intelligence context, endpoint visibility, detection and response workflows, log correlation, incident timeliness, integration with existing security tools, and reduced alert fatigue. One area where Huntress Managed SIEM could improve is customization. More flexibility around dashboards, reporting, alert tuning, and detection rules would be useful for teams with more specialized security requirements. I would also appreciate the continued expansion of integrations with third-party security and infrastructure tools. Improving these areas would give security teams more control over how they organize and investigate the data while still keeping the managed experience simple. Another improvement would be more granular control over alert prioritization and notification settings. It would be helpful to have more flexibility in defining what gets escalated based on our specific environment and risk profile. More detailed reporting and customizable dashboards would also make it easier to communicate trends and incident activity to different stakeholders. Continued expansion of integrations would be beneficial as well, especially for teams managing a broader security stack.
Huntress Managed SIEM can be improved with more integrations; that would always be great. The custom ones that you can create are good, but having more native ones would be even better. Regarding Huntress Managed SIEM's AI capabilities, I think its governance and security are pretty good. I think Huntress Managed SIEM's AI capabilities are still in its early stages, so it probably will need some improvement over time, but I think that's something that will get better as it's around longer and improved. My experience with the behavioral analytics feature in Huntress Managed SIEM is that I think it's pretty effective at surfacing suspicious activity.
Huntress Managed SIEM could do better in terms of improved UI and also in terms of making it more simple for users. The main area for improvement is making the UI more simple.
I have not run into a situation where there has been a problem, and even when I have reached out to customer technical support, they have been able to immediately address any problems that I have encountered.
Huntress Managed SIEM can be improved by adding the ability to have multiple endpoints delivering SIEM log collectors to a single cloud agent. There are no other improvements needed for Huntress Managed SIEM beyond what I have mentioned.
I believe Huntress Managed SIEM could be improved by increasing integrations with non-Microsoft solutions as this would broaden its appeal. A broader out-of-the-box solution for diverse environments including IoT, Mac OS, and Linux servers would be valuable. I would rate Huntress Managed SIEM an eight because a couple of things could be changed, such as having more integrations with non-Microsoft systems, improved customization on the dashboard, and enhanced reporting in the threat intelligence updates. Being unable to click on new niche variants of threats is another point I would mention, but overall an eight out of ten is a good score because I think it is a very well-priced solution for its capabilities and all the positives I have outlined. The eight rating is primarily influenced by those integration and customization points I mentioned, which are the main requests from customers.
Director, Engineering & Services Professional at a computer software company with 51-200 employees
Reseller
Top 20
Dec 3, 2025
I would appreciate more features in the stack. I would like Huntress MDR and SIEM to integrate with EDRs like SentinelOne to combine that level of intelligence and information into their stack so that they can leverage whatever protections the client has and gather that intelligence to help with the MDR side. Regarding the SIEM, I would like to see more features added. I would appreciate the capability of setting our own alerting based on certain triggers within the logs so that we can compete and fill a void that their SIEM has compared to other SIEMs in the industry such as Perch Security for ConnectWise.
Huntress Managed SIEM delivers advanced threat detection and response capabilities tailored for Security Information and Event Management. It addresses cybersecurity challenges with automated monitoring and actionable insights. Huntress Managed SIEM stands out by offering comprehensive security event monitoring designed for modern cybersecurity landscapes. It identifies potential threats and vulnerabilities, ensuring actionable data for quicker response. Its integration capabilities with...
I would like to see broader third-party integration and easier troubleshooting for log sources. I would like to see more customization in dashboards and reporting, especially for SOC-specific metrics and management summaries. This would bring more flexibility in configuring alerts and log source views.
The main improvement area is deeper customization. It would be helpful to have more flexibility for creating custom detection rules, dashboards, and alert workflows based on specific organizational requirements. I would also like to see more integrations and advanced investigation capabilities over time. Another area would be improving the reporting and customization options. More detailed reports, better visibility into investigation timelines, and easier customization of alerts would make Huntress Managed SIEM even more useful for day-to-day SOC operations. I would like to see more advanced dashboard customization, additional third-party integrations, and more granular control over alert rules and workflows. Better reporting and automation options would also make it more useful for SOC environments.
Huntress Managed SIEM has areas for improvement regarding more log sources. They are working on connecting more sources to the right format for events, such as a Fortinet firewall, but we use other firewalls as well, so that could use some development. The deployment of Huntress Managed SIEM is somewhat complex compared to ITDR and EDR, as those are just click, click, click, and next, next, finish, while SIEM requires some form of configuration. Additionally, a Huntress agent is needed within the same network as the firewall to collect those logs, so it would be a great addition if they could make it possible to log events directly from a Fortinet FortiGate firewall to Huntress Managed SIEM.
Areas where Huntress Managed SIEM could improve include automated alert triage, events, threat intelligence context, endpoint visibility, detection and response workflows, log correlation, incident timeliness, integration with existing security tools, and reduced alert fatigue. One area where Huntress Managed SIEM could improve is customization. More flexibility around dashboards, reporting, alert tuning, and detection rules would be useful for teams with more specialized security requirements. I would also appreciate the continued expansion of integrations with third-party security and infrastructure tools. Improving these areas would give security teams more control over how they organize and investigate the data while still keeping the managed experience simple. Another improvement would be more granular control over alert prioritization and notification settings. It would be helpful to have more flexibility in defining what gets escalated based on our specific environment and risk profile. More detailed reporting and customizable dashboards would also make it easier to communicate trends and incident activity to different stakeholders. Continued expansion of integrations would be beneficial as well, especially for teams managing a broader security stack.
Huntress Managed SIEM can be improved with more integrations; that would always be great. The custom ones that you can create are good, but having more native ones would be even better. Regarding Huntress Managed SIEM's AI capabilities, I think its governance and security are pretty good. I think Huntress Managed SIEM's AI capabilities are still in its early stages, so it probably will need some improvement over time, but I think that's something that will get better as it's around longer and improved. My experience with the behavioral analytics feature in Huntress Managed SIEM is that I think it's pretty effective at surfacing suspicious activity.
Huntress Managed SIEM could do better in terms of improved UI and also in terms of making it more simple for users. The main area for improvement is making the UI more simple.
I have not run into a situation where there has been a problem, and even when I have reached out to customer technical support, they have been able to immediately address any problems that I have encountered.
Huntress Managed SIEM can be improved by adding the ability to have multiple endpoints delivering SIEM log collectors to a single cloud agent. There are no other improvements needed for Huntress Managed SIEM beyond what I have mentioned.
I did not find anything for improvement; Huntress Managed SIEM is a completely perfect and stable product.
I believe Huntress Managed SIEM could be improved by increasing integrations with non-Microsoft solutions as this would broaden its appeal. A broader out-of-the-box solution for diverse environments including IoT, Mac OS, and Linux servers would be valuable. I would rate Huntress Managed SIEM an eight because a couple of things could be changed, such as having more integrations with non-Microsoft systems, improved customization on the dashboard, and enhanced reporting in the threat intelligence updates. Being unable to click on new niche variants of threats is another point I would mention, but overall an eight out of ten is a good score because I think it is a very well-priced solution for its capabilities and all the positives I have outlined. The eight rating is primarily influenced by those integration and customization points I mentioned, which are the main requests from customers.
I would appreciate more features in the stack. I would like Huntress MDR and SIEM to integrate with EDRs like SentinelOne to combine that level of intelligence and information into their stack so that they can leverage whatever protections the client has and gather that intelligence to help with the MDR side. Regarding the SIEM, I would like to see more features added. I would appreciate the capability of setting our own alerting based on certain triggers within the logs so that we can compete and fill a void that their SIEM has compared to other SIEMs in the industry such as Perch Security for ConnectWise.
There should be better exclusions of log types and the ability to exclude specific types of logs that might be using a lot of data.