Talk to us
by MicrosoftTechBag Intel Page

Microsoft Sentinel

The SIEM your Microsoft logs are already free on — Microsoft Sentinel is a cloud-native SIEM billed on the data you ingest, not per seat. Azure Activity, Microsoft 365 audit logs and Defender XDR alerts ingest free; everything else runs ~$4.30/GB, or ~$2.96 on a commitment.

Microsoft logs ingest free · the rest per GBSIEM + XDR in one Defender queueHonest vs Splunk · we sell that too

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
What it is
SaaS only, on Azure
Cloud-native SIEM
The bill
not per seat
Per GB ingested
Analyst standing
2025 MQ for SIEM
Gartner Leader
Honest note
escalate fast
Third-party ingest costs

Data residency & processing — not the same question

Stored in

Central India · Jio India West · Jio India Central

Same region as the Log Analytics workspace. Data lake: Central India.

Processed in

A US region

Microsoft documents that workspaces outside Europe, Israel and China are processed in the US.

If your obligation is worded as storing data in India, an India region meets it. If your regulator, board or contract speaks about processing or cross-border transfer, settle that before the PoC — the full answer is in the FAQ. Source: Microsoft’s geographical availability and data residency documentation.

Quick answer

Microsoft Sentinel is Microsoft’s cloud-native SIEM (security information and event management) — the system that collects logs from every corner of your estate, correlates them into incidents, and gives your SOC one place to hunt and respond. It is delivered only as SaaS on Azure, runs on a Log Analytics workspace, and is queried with KQL. Two things define it in 2026. First, the money: Sentinel is billed on DATA INGESTED, not per user or per device — pay-as-you-go is about $4.30/GB (~₹361) in East US, dropping to an effective ~$2.96/GB (~₹249) at the 100 GB/day commitment tier, with a data lake tier for high-volume, low-value logs at roughly $0.05/GB to ingest and $0.026/GB/month to store on a 6:1 compression basis. Azure Activity logs, Microsoft 365 audit logs and Defender XDR alerts are free, which is why Microsoft-heavy estates see a bill far below the raw log volume. Second, the portal move: Microsoft Sentinel is being consolidated into the Microsoft Defender portal, and after 31 March 2027 it will NOT be supported in the Azure portal at all — every existing customer has to plan that transition, and it is the single most important fact on the table for anyone buying or renewing right now. Microsoft was named a Leader in the 2025 Gartner Magic Quadrant for SIEM, alongside Google Security Operations. The honest scope: Sentinel is the natural choice if your estate is already Microsoft — the free first-party connectors and native Defender XDR correlation are genuinely hard to match — but ingest costs from noisy third-party sources (firewalls, proxies, NDR) can escalate fast and unpredictably, and Splunk still leads on raw search power and detection-engineering flexibility for mature teams. TechBag sells Splunk too, and will model the real GB/day bill before you commit, in INR with GST. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Microsoft Sentinel — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Microsoft Sentinel (cloud-native SIEM)
Vendor
Microsoft (Microsoft Security)
Category
SIEM + SOAR + UEBA — security operations
Priced on
GB of data INGESTED per day (not per user/device)
Entry rate
~$4.30/GB PAYG · ~$2.96/GB at 100 GB/day commit
Free sources
Azure Activity, M365 audit, Defender XDR alerts
Free retention
90 days included, then charged
The deadline
Azure portal retires 31 March 2027 — Defender portal only
Data residency
Stored: Central India, Jio India West/Central
Data processing
US region for Indian workspaces — read the FAQ
Query language
KQL (Kusto Query Language)
In India via
TechBag — ingest modelling, GST invoicing
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Microsoft’s cloud-native SIEM — it collects logs from across your estate, correlates them into incidents, and gives the SOC one place to hunt and respond. SaaS on Azure, queried with KQL.

A traditional SIEM bill vs Sentinel’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolMicrosoft Sentinel
Pricing axisPer device or per userPer GB ingested per day
Microsoft logsPaid like any other sourceAzure Activity, M365, XDR alerts free
High-volume logsFull rate or drop themData lake tier at a fraction of analytics
InfrastructureServers, storage, upgradesSaaS on Azure — nothing to run
SIEM and XDRTwo consoles, manual correlationOne incident queue in Defender
RetentionPriced from day one90 days included, then charged
Honest caveat—Third-party ingest escalates the bill
Best fit—Microsoft-standardised estates

The SIEM of choice for Microsoft estates — for non-Microsoft log volume, on-prem or air-gapped, weigh Splunk or Elastic (TechBag sells Splunk).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The foundation

Log Analytics workspace

The store

Sentinel is switched on top of an Azure Monitor Log Analytics workspace — that workspace is where your data actually lives, and it is why Sentinel and Log Analytics charges can appear as separate line items on older classic pricing. The first 90 days of retention are included.

02
The ingest

Data connectors

The intake

Hundreds of connectors pull logs in — first-party Microsoft sources (Entra, Defender XDR, Azure Activity, M365) plus syslog/CEF, AWS, GCP and third-party appliances. Whether a source is free or paid is the single biggest driver of your bill.

03
The brain

Analytics rules & Fusion

The detection

Scheduled KQL rules, near-real-time rules and Microsoft's multistage attack detection turn raw events into alerts and incidents. Note: once you move to the Defender portal, the Defender XDR correlation engine takes over incident grouping from Fusion.

04
The economics

Data lake tier

The cheap seats

A low-cost tier for high-volume, low-value logs — ingest around $0.05/GB, storage around $0.026/GB/month billed on a uniform 6:1 compression rate, and queries charged per GB scanned. This is how you keep firewall and proxy logs without paying analytics rates for them.

05
The future

Defender portal & MCP

The console

Sentinel is consolidating into the Microsoft Defender portal for unified SIEM + XDR operations, and now exposes an MCP server so AI agents can query the data lake and graph. The Azure portal experience retires on 31 March 2027.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Connectors

Hundreds of data connectors

First-party Microsoft sources, syslog/CEF, AWS, GCP and third-party appliances.

Collect
Free sources

Free first-party ingest

Azure Activity, M365 audit logs and Defender XDR alerts ingest at no charge.

Collect
Data lake

Data lake tier

High-volume, low-value logs at roughly $0.05/GB ingest and $0.026/GB/month storage.

Collect
Transform

Ingest-time transformation

Redact, split, filter and normalise data as it lands — the main lever on your bill.

Detect
Analytics rules

Scheduled & near-real-time rules

KQL-driven detections plus hundreds of out-of-the-box templates from the Content hub.

Detect
UEBA

User & Entity Behaviour Analytics

Behavioural baselining across identities and hosts to surface anomalies rules miss.

Detect
Hunting

Advanced hunting (KQL)

Query the whole estate proactively; bookmarks and hunts preserve investigation context.

Detect
Threat intel

Threat intelligence

Ingest indicators, match them against your telemetry, and use the free MDTI feed.

Respond
SOAR

Playbooks (Logic Apps)

Automated response built on Azure Logic Apps — billed separately from Sentinel.

Respond
Automation

Automation rules

Route, tag, assign and close incidents automatically without writing a playbook.

Respond
XDR correlation

Unified SecOps with Defender

In the Defender portal, Sentinel and Defender XDR incidents merge into one queue.

Respond
AI & MCP

Security Copilot & MCP server

Generative-AI triage plus an MCP server exposing the data lake and graph to AI agents.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Microsoft Security (official)·Overview

Microsoft Sentinel: The AI-ready security platform

The platform vision, explained by Microsoft.

Microsoft Security (official)·Data lake

Introduction to Microsoft Sentinel data lake

The low-cost tier that changes SIEM economics.

Microsoft Security (official)·Cost

Cost management in Microsoft Sentinel data lake

Controlling the bill — the buying decision.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Microsoft Sentinel

AI works best where the work already happens.

Here’s what genuinely sets Sentinel apart (and where Splunk or Elastic may fit better).

01

The bill is ingest, not seats — and Microsoft logs are free

Every SIEM is priced on data volume, but the detail that decides Sentinel's economics is which sources are free. Azure Activity logs, Office 365 audit logs (SharePoint, Exchange, Teams) and security alerts from the whole Defender XDR family ingest at no charge. For an organisation already standardised on Microsoft 365 and Azure, that means a large share of the telemetry a SOC actually wants is free to collect, and you pay mainly for the third-party sources you add. This is the single strongest financial argument for Sentinel, and it is a real one rather than a marketing claim — Microsoft documents the free data types explicitly. The corollary matters just as much: if your noisiest logs come from non-Microsoft firewalls, proxies and network sensors, none of that discount applies to you, and the bill is set by whatever those devices emit.

02

The data lake tier fixed the worst part of SIEM economics

The oldest problem in SIEM is that you are forced to choose between keeping a log and affording it. Compliance says retain everything; the analytics rate says retain nothing you do not need to alert on. Sentinel's data lake tier is the structural answer: high-volume, low-value logs go into a tier that ingests at roughly $0.05/GB and stores at roughly $0.026/GB/month, billed on a uniform 6:1 compression rate — so 600 GB of raw data bills as 100 GB — with KQL querying built in and charged per GB scanned. You keep the firewall and proxy data for the auditor and the incident responder without paying analytics rates for logs nobody writes a detection against. Getting the tiering right is most of the work in controlling a Sentinel bill, and it is exactly the modelling TechBag does before you sign.

03

One incident queue across SIEM and XDR

Sentinel's native tie to Defender XDR is the operational argument. In the Defender portal, alerts from Sentinel analytics rules and alerts from Defender XDR land in one unified incident queue, correlated by Defender's own engine rather than sitting in two consoles waiting for an analyst to notice they are the same attack. Entity pages for users, devices and IP addresses merge Sentinel and Defender data into a single view, and advanced hunting queries span both. For a SOC that already runs Defender for Endpoint, Defender for Office 365 and Entra ID Protection, this removes the integration work that a third-party SIEM makes you do and maintain. It is also why the portal transition below is not merely a UI change.

04

The deadline you must plan around: 31 March 2027

This is the most important fact for anyone buying or renewing Sentinel right now, and it deserves to be stated plainly rather than buried. Microsoft Sentinel will no longer be supported in the Azure portal after 31 March 2027; all customers move to the Microsoft Defender portal. Microsoft says the transition itself carries no extra cost and billing is unchanged, but the operational changes are real and worth scoping early: the Fusion correlation rule is disabled in favour of the Defender XDR engine, some automation-rule conditions behave differently, Workspace Manager is not available, incidents created through the API or manually do not sync to the Defender portal, and the IdentityInfo table stops supporting table-level RBAC. If you have built automation against any of those, plan the migration rather than discovering it at the deadline.

05

The honest caveat — third-party ingest is where budgets break

Being honest, and TechBag sells Splunk too: Sentinel's cost advantage is conditional on your estate being Microsoft-shaped. The free first-party connectors are genuinely valuable, but the moment your highest-volume sources are non-Microsoft — network firewalls, web proxies, NDR sensors, custom application logs — you are paying analytics rates on the noisiest data you own, and Sentinel bills can escalate quickly and less predictably than an EPS-based or capacity-based model. Splunk remains ahead on raw search power, detection-engineering flexibility and handling genuinely diverse telemetry at scale, which is why mature detection teams still choose it. QRadar's EPS-based pricing is more predictable for regulated buyers who need to forecast a number. And Sentinel is SaaS-only on Azure, so if you have a hard on-premises or air-gapped requirement, it is simply not a candidate.

06

The honest positioning

Microsoft Sentinel is the right SIEM for organisations already standardised on Microsoft 365 and Azure that want SIEM and XDR in one console, value free first-party telemetry, and can use the data lake tier to keep high-volume logs affordably. It is a 2025 Gartner Magic Quadrant Leader and the fastest-growing enterprise SIEM. It is the wrong choice if your log volume is dominated by non-Microsoft sources, if you need on-premises or air-gapped deployment, or if you have a mature detection-engineering team whose value comes from Splunk's search flexibility. TechBag sells Splunk as well, and the useful thing we do here is model your actual GB/day by source before you commit — the number that decides this, and the one vendors are slowest to help you calculate. Quoted in INR with GST.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

361 /GB
Pay-as-you-go analytics rate (~$4.30/GB, East US)
Microsoft pricing*
249 /GB
Effective rate at the 100 GB/day commitment (~$2.96/GB)
Microsoft pricing*
90 days
Retention included at no extra charge
Microsoft docs
6:1 compression
Data lake storage billing basis
Microsoft docs
10 GB/day free
First 31 days, on the free trial
Microsoft docs
2027
Azure portal retires 31 March
The deadline

What your Microsoft Sentinel rollout looks like

Day 0Free

Model the ingest

Inventory your log sources and estimate GB/day for each, separating free first-party Microsoft sources from paid third-party ones. This number decides everything. TechBag does this modelling free.

Week 1–2Deploy

Workspace & connectors

Stand up the Log Analytics workspace, connect the free Microsoft sources first, then add third-party feeds deliberately — deciding analytics tier versus data lake tier per table.

Week 3–6Tune

Detections & automation

Enable Content hub rule templates, tune out the noise, build automation rules and playbooks, and set retention per table rather than globally.

Month 2+Operate

Defender portal & steady state

Operate in the Defender portal ahead of the 31 March 2027 Azure retirement, review the bill monthly against the model, and re-tier tables as volumes change.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.4
280+ reviews*
88% would recommend
Integration (Microsoft estate)4.7
Detection & hunting4.4
Scalability4.5
Cost predictability3.9
5
55%
4
32%
3
9%
2
3%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Our Microsoft logs — Entra, M365 audit, Defender alerts — ingest free, which meant most of what our SOC actually watches cost us nothing to collect. That changed the business case completely.
Head of SecOps
Banking
Financial Services
One incident queue across Sentinel and Defender XDR is the real win. We stopped correlating by hand across two consoles, and mean time to triage dropped noticeably.
SOC Lead
Financial Services
Insurance
The data lake tier let us finally keep twelve months of firewall logs for the auditor without paying analytics rates on data nobody writes a detection against.
Security Architect
Insurance
Technology
KQL is genuinely powerful once your team learns it, and the Content hub templates gave us a working detection set on day one rather than month three.
Detection Engineer
Technology
Retail
Honest warning: our first month's bill was double the estimate because nobody modelled the proxy logs. Get the ingest tiering right before you turn connectors on, not after.
IT Director
Retail
Manufacturing
We had automation built on Fusion and the Workspace Manager. The Defender portal move meant reworking it — worth scoping that migration early rather than at the deadline.
Security Engineer
Manufacturing
IT Services
For a mixed estate with heavy non-Microsoft network gear, we ran the numbers and Splunk was the better fit. TechBag told us that straight even though they sell Sentinel.
CISO
IT Services
BFSI
As an Indian enterprise, having TechBag model the GB/day by source in INR before we committed was the difference between a predictable budget and a surprise.
Head of Infrastructure
BFSI
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Microsoft SentinelThis page

Gartner MQ Leader 2025 — this page.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
Microsoft SentinelThis page

Deep on Microsoft data; ingest cost varies elsewhere.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Microsoft Sentinel vs the field

The SIEM leaders — honest lanes; the edge is free first-party ingest + one incident queue with Defender. Deepest search, or on-prem? Splunk. We say so (and sell it).

DimensionMicrosoft SentinelSplunk Enterprise SecurityIBM QRadarGoogle Security OperationsElastic Security
PositionCloud-native SIEM for Microsoft estatesThe search-power incumbentThe regulated-industry stalwartCloud-agnostic security analyticsOpen, ELK-based
Pricing axisPer GB ingested per dayWorkload or ingest — historically costlyEPS-based — predictable to forecastFlat per-employee-ish, volume-agnosticResource-based; free self-managed tier
Microsoft-estate integrationNative; first-party logs freeGood connectors, paid ingestConnectors, no native tieConnectors, no native tieConnectors, no native tie
Search & detection engineeringKQL — powerful, Azure-shapedSPL — still the benchmarkAQL, strong OOTB contentYARA-L, very large scaleLucene/ES|QL, very flexible
Deployment modelSaaS only, on AzureCloud, on-prem or hybridCloud or on-premSaaS only, on Google CloudCloud, on-prem, air-gapped
Cost predictabilityVaries with log volume — model it firstHistorically the expensive optionEPS licensing forecasts cleanlyVolume-agnostic pricingSelf-managed cost is controllable
Long-term log retentionData lake tier at ~$0.026/GB/moAvailable, priced accordinglyAvailable12 months hot by defaultFrozen/searchable snapshots
SOAR & automationPlaybooks on Logic Apps (billed separately)Splunk SOAR (own product)QRadar SOARNative SOAR includedBasic; often paired with a SOAR
AI in the SOCSecurity Copilot + MCP server for agentsCisco AI Assistantwatsonx-assistedGemini-poweredElastic AI Assistant
The thing to plan aroundAzure portal retires 31 Mar 2027Cisco integration reshaping roadmapSaaS assets sold to Palo Alto; XSIAM migrationGoogle Cloud dependencyYou run and tune it yourself
Best fitMicrosoft-standardised estatesMature detection-engineering teamsRegulated buyers needing forecastable costHuge volume, cloud-agnosticBudget-constrained or air-gapped
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Microsoft Sentinel fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Microsoft Sentinel if…

  • Your estate is already Microsoft 365 and Azure — first-party logs ingest free
  • You want SIEM and XDR in one incident queue in the Defender portal
  • You need to keep high-volume logs affordably via the data lake tier
  • You want SaaS with no SIEM infrastructure to run, patch or scale

Choose Splunk if…

  • You have a mature detection-engineering team whose value is search flexibility across genuinely diverse data (TechBag sells it)

Choose IBM QRadar if…

  • You are regulated and need EPS-based pricing you can forecast — but note the SaaS assets moved to Palo Alto and migration to Cortex XSIAM is the path

Choose Google Security Operations if…

  • Your log volume is enormous and you want pricing that does not scale with it, on a cloud-agnostic platform

Choose Elastic Security if…

  • You need on-premises or air-gapped deployment, or your team already runs the ELK stack and wants to keep control of cost

Microsoft Sentinel is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What will your ingest actually cost?

Sentinel bills on data ingested, so this is the only sum that matters. The baseline puts every GB on the analytics tier at pay-as-you-go (~$4.30/GB). The optimised figure moves your low-value logs to the data lake tier (~$0.05/GB) and prices the rest at the 100 GB/day commitment rate (~$2.96/GB) once you qualify. Microsoft’s published East US rates at ~₹84/USD; regional rates differ and Microsoft calls them estimates, not quotes. Excludes Logic Apps, Functions and Copilot, which bill separately.

100
5 GB2,000 GB
40%
0%80%

Free first-party sources — Azure Activity, Microsoft 365 audit logs and Defender XDR alerts — are excluded from both figures, so count only your billable GB. The commitment rate applies at 100 GB/day and above. Illustrative: your TechBag quote models your real sources.

Everything on analytics tier, pay-as-you-go
₹1,31,83,800
Saved by tiering + committing
₹76,77,264
₹3,83,86,320 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Sentinel is billed on data ingested per day, not per user or device — so the only figure that matters is your GB/day, by source. Rates below are Microsoft’s published East US figures (converted at ~₹84/USD) and vary by region; Microsoft describes them as estimates, not quotes. TechBag models your real ingest before you commit and quotes in INR with GST.

Analytics tier — pay-as-you-go

~$4.30per GB ingested

Best for starting out or low volume

  • ~$4.30/GB ≈ ₹361/GB ingested (East US)
  • 90 days retention included, then charged
  • No commitment; switch to a tier any time

Analytics tier — commitment

~$2.96per GB, effective at 100 GB/day

Best above ~69 GB/day

  • ~$2.96/GB ≈ ₹249/GB at the 100 GB/day tier (~31% off)
  • Tiers run to 50,000 GB/day (~$2.05/GB at the top)
  • Break-even vs pay-as-you-go is ~69 GB/day

Data lake tier

~$0.05per GB ingested

Best for high-volume, low-value logs

  • ~$0.05/GB ≈ ₹4/GB to ingest; ~$0.026/GB/month to store
  • Storage billed on a 6:1 compression basis
  • KQL queries ~$0.005/GB scanned

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Ingest volume

What is your GB/day by source, and which of those sources are free first-party Microsoft logs?

2
Tiering

Which tables belong in the analytics tier and which in the cheaper data lake tier? This is the main cost lever.

3
Commitment

Does your volume justify a commitment tier? The break-even against pay-as-you-go is roughly 69 GB/day for the 100 GB commit.

4
Retention

How long must each data type be kept for compliance, given 90 days is included and the rest is charged?

5
The deadline

What is your plan for the 31 March 2027 Azure portal retirement, and what automation depends on Fusion or Workspace Manager?

6
Residency

Does your obligation speak about STORING data in India or PROCESSING it there? Sentinel stores in Central India / Jio India regions but processes in a US region — settle which one your regulator means before the PoC.

7
Hidden costs

Have you priced Logic Apps playbooks, Azure Functions connectors and Security Copilot SCUs separately from Sentinel itself?

8
Honest fit

If your highest-volume logs are non-Microsoft, have you compared Splunk or an EPS-priced option? TechBag advises across both.

9
Commercials

Have you modelled the annual bill in INR with GST, including growth in log volume?

FAQ

Questions buyers ask

Microsoft Sentinel is Microsoft's cloud-native SIEM — security information and event management — the system that collects security logs from across your estate, correlates them into incidents, and gives a security operations team one place to detect, hunt and respond. It is delivered only as SaaS on Azure infrastructure, runs on top of an Azure Monitor Log Analytics workspace, and is queried using KQL (Kusto Query Language). Beyond core SIEM it includes UEBA (user and entity behaviour analytics), SOAR-style automation through playbooks built on Azure Logic Apps, threat intelligence ingestion, and a Content hub of hundreds of ready-made detection rules and workbooks. Microsoft was named a Leader in the 2025 Gartner Magic Quadrant for SIEM, alongside Google Security Operations. Two structural facts matter more than the feature list. First, it is billed on data ingested rather than per user or per device, and a set of first-party Microsoft sources — Azure Activity logs, Office 365 audit logs, and security alerts from the Defender XDR family — ingest at no charge, which is why Microsoft-heavy estates see a much smaller bill than their raw log volume suggests. Second, Sentinel is consolidating into the Microsoft Defender portal, and after 31 March 2027 it will not be supported in the Azure portal at all. TechBag sells Splunk as well, so the advice you get here is about fit, not allegiance.

Ready to evaluate Microsoft Sentinel?

Model your real GB/day by source before you commit, plan the 31 March 2027 Defender portal move, or get an honest Sentinel-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.