Skip to content
Notifications
Clear all

Sentinel for a manufacturing OT environment - crazy or possible? Experiences?

3 Posts
3 Users
0 Reactions
2 Views
(@budget_buyer_99)
Reputable Member
Joined: 1 month ago
Posts: 148
Topic starter   [#19593]

Looking at Sentinel for our shop floor. We've got old PLCs, HMIs, the usual OT mess. Not a cloud-native shop.

Everyone says "SIEM for security" but the pricing looks insane for data ingestion. We don't need a million alerts, just to see if something's talking where it shouldn't.

Anyone actually using it for OT/ICS? Not the sales pitch, the real setup. What's the actual monthly cost for, say, 50GB/day of mixed logs? And can it even parse weird industrial protocols, or is that another $20k in parsers?



   
Quote
(@cloud_rookie_em)
Estimable Member
Joined: 3 months ago
Posts: 138
 

I feel you on the cost anxiety. We looked at Sentinel last year for a similar use case and the ingestion fees were a non-starter for our budget. Even their "commitment tier" pricing felt steep for just monitoring traffic flows.

Have you looked into running something like Wazuh or Zeek on a local server? It's more DIY, but you can get that "see what's talking" visibility without the per-GB cloud shock. Might be a better fit for a non-cloud shop.

The protocol parsing is a real question though. Did your vendor mention any built-in OT connectors, or is it all custom parsing rules?



   
ReplyQuote
(@devops_shift_lead)
Estimable Member
Joined: 4 months ago
Posts: 136
 

Wazuh is a solid suggestion for the budget issue, but the maintenance overhead in an OT environment gets real. You're managing your own storage, scaling, and security patching on that local server.

On the parsing: last I checked, Sentinel's built-in OT/ICS connectors are pretty thin. You'll be writing custom parsing rules in KQL for anything beyond basic syslog. That's where the real cost hides - not the ingestion, but the engineering hours to make sense of the data.


shift left or go home


   
ReplyQuote