Skip to content
Notifications
Clear all

Top SIEM for a finance firm under 100 users - Sentinel compared

4 Posts
4 Users
0 Reactions
2 Views
(@cloud_infra_rookie)
Honorable Member
Joined: 1 month ago
Posts: 224
Topic starter   [#7672]

Hi everyone, I'm new to the cloud and security side of things. I've been mostly working with AWS basics and Terraform.

My team is looking at SIEM options for our small finance company (under 100 users). Microsoft Sentinel keeps coming up, but I'm trying to understand how it really compares to other tools like maybe Splunk or even open source options.

For a finance firm, we need strong compliance (like PCI DSS) and good threat detection. Cost is a big factor at our size.

Could someone break down Sentinel's pros and cons for a small setup? Especially:
- Is it manageable for a beginner infra person?
- How does the pricing with Log Analytics work for a small user base?
- Any gotchas or things you wish you knew before starting?

I'm trying to learn if it's the right "beginner-friendly" path or if we should look elsewhere. Thanks for any insights! 😊



   
Quote
(@billyj)
Reputable Member
Joined: 1 week ago
Posts: 137
 

You're right to zero in on cost and manageability. For a shop under 100 users, Sentinel's biggest hurdle is its pricing architecture, which is ingestion-based on the Log Analytics workspace. You can easily blow past budget with verbose logs if you're not meticulous with filtering from day one. For PCI DSS, the built-in compliance workbooks are decent, but the real detection strength comes from custom analytics rules, which is not beginner-friendly.

On your point about it being a "beginner-friendly" path, I'd push back slightly. If you're already in the Azure ecosystem, the integration is seamless and that reduces operational overhead. But if you're not, you're suddenly managing Azure tenants, log ingestion pipelines, and KQL queries. That's a steep climb compared to a more packaged, appliance-style solution.

I'd suggest you run a 30-day POC with your actual log sources and watch the daily GB ingestion like a hawk. That's the only way to model true cost. The gotcha is that turning on all the recommended Microsoft security connectors will ingest far more than you anticipate.



   
ReplyQuote
(@latency_llama)
Estimable Member
Joined: 3 months ago
Posts: 83
 

The beginner-friendly question is a trap. It's not about being easy to start, it's about what you're starting. You're not just learning a SIEM, you're signing up for Azure Monitor, Log Analytics, and KQL as your new full-time hobbies. If your team's skills are in AWS and Terraform, you're now maintaining a separate cloud tenant and ingestion pipelines across providers, which is its own special kind of operational tax.

On cost, the previous post nailed the ingestion risk. For 100 users, the raw log volume might seem trivial until you realize every authenticated event, firewall flow, and DNS query from your cloud environment wants a ticket to the Log Analytics party. Your first bill will be a fascinating lesson in data filtering. The PCI DSS workbooks are checklists, not a detection engine. You'll need to build that, which means writing and maintaining KQL analytics rules. That's not beginner work, that's a junior security analyst role.

You might look at a managed SOC service that bundles a SIEM, or even a platform like Wazuh if you have the appetite to run it. Sentinel makes sense if you're already neck-deep in Azure and have someone who enjoys writing queries for a living. Otherwise, you're buying a very expensive on-ramp to a different cloud.


P99 or bust.


   
ReplyQuote
(@infra_architect_rebel)
Estimable Member
Joined: 3 months ago
Posts: 122
 

The POC advice is good, but the "appliance-style solution" comparison is the wrong target. That's just another kind of vendor lock-in with its own operational tax.

Sentinel's real problem for a 100-person shop isn't just the Azure overhead. It's that you're buying a battleship to patrol a pond. You'll spend more time and money tuning ingestion and KQL for a tiny signal volume than you would just running a simpler stack.

The cost surprise isn't about the connectors, it's about the default tables like SecurityEvent and CommonSecurityLog. Ingest everything? Your bill is toast.


Simplicity is the ultimate sophistication


   
ReplyQuote