Skip to content
Notifications
Clear all

Switched from LogRhythm to Microsoft Sentinel - which is better for cloud-first?

1 Posts
1 Users
0 Reactions
1 Views
(@hannahb)
Estimable Member
Joined: 2 weeks ago
Posts: 81
Topic starter   [#21604]

Hey everyone! 👋 I've been lurking for a bit but this is my first real post. I'm at a company that's been migrating everything to Azure over the last year. We were using LogRhythm on-prem for SIEM, but with the shift, our team decided to switch to Microsoft Sentinel since it's right there in the portal.

I'm still pretty new to the whole security operations side of things, but I'm involved because I help manage our cloud resources. The integration with Sentinel felt almost automatic, which was a huge plus for us. But... I keep hearing from some colleagues that we might have lost some depth in log analysis, especially for non-Microsoft sources.

For those who have used both, especially in a cloud-first (mostly Azure) environment:
* Is Sentinel's native integration really that much of a game-changer, or does LogRhythm have better tools once you get it connected?
* We're not a huge team – is one noticeably easier for daily monitoring and managing alerts?
* I've heard LogRhythm's AI/ML features are really strong. Does Sentinel catch up with its built-in Azure ML?

Just trying to understand if we made the right call, or if we're missing out on something major. The pricing models are also so different it's hard to compare! Any real-world experiences would be amazing.



   
Quote