We're a 200-person shop with a 60/40 split between Azure and on-prem VMware. Need to replace our legacy SIEM. Top contenders are Palo Alto Cortex XSIAM and Microsoft Sentinel.
Primary evaluation criteria:
* **Cost control:** Predictable ingestion and retention pricing. On-prem log source costs are a concern.
* **Hybrid connectivity:** Agent vs. gateway performance for non-Azure resources.
* **SOAR integration:** Need to automate responses across both cloud and on-prem systems.
* **Vendor lock-in:** How much of the stack *requires* other vendor services (M365, Azure, Palo firewalls)?
Initial findings:
* Sentinel's cost model feels opaque once you factor in Data Collection Rules and workspace fees.
* Cortex's licensing seems all-inclusive, but the initial quote was steep.
* Sentinel's native integration with Defender suite is a plus, but we don't run a full Microsoft stack.
* Our team has more Azure experience than Palo Alto.
Looking for real-world experience on operational overhead and true total cost.
Trust but verify.
I'm an SRE at a mid-sized fintech running about 70% Azure, 30% bare metal, and I've maintained both Sentinel and Cortex XDR/SIEM for different security use-cases over the last three years.
1. **Cost Predictability**
Sentinel's cost is a trap. You pay for ingestion per GB, workspace, and for Azure Monitor data collection rules. Non-Azure log sources require Azure Arc agents or syslog forwarders, which add compute overhead. Monthly bills can swing 30% easily. Cortex's pricing is all-inclusive for ingestion and retention, but the entry point is high. If you're under 50 GB/day, Sentinel might appear cheaper, but past that threshold, Cortex becomes more linear.
2. **Hybrid Agent Overhead**
Sentinel's Azure Monitor Agent (AMA) for Windows/Linux on-prem requires a lightweight Arc-connected VM. In my env, this added about 5-8% CPU overhead per monitored server. The syslog gateway option is simpler for network devices. Cortex's connector is a single, heavier agent that does both log collection and endpoint security. It consumed roughly 12-15% CPU on busy servers, but you get more data context.
3. **SOAR and Automation Boundaries**
Sentinel's Logic Apps are Azure-native. To run a playbook against an on-prem system, you need a hybrid runbook worker inside your network, which is another VM to manage. Cortex's XSOAR is self-contained and can deploy lightweight workers anywhere. If your automation targets are mostly Azure services, Sentinel is easier. If you're running scripts against on-prem firewalls or VMs, Cortex's model is cleaner.
4. **Vendor Lock-in Reality**
Sentinel is a gateway drug. Advanced features like UEBA, incident timelines, and entity behavior analytics require you to also license Microsoft 365 Defender and Azure Defender. Without them, you get a basic SIEM. Cortex doesn't require their firewalls, but to get full value from their threat intelligence, you're pushed toward their ecosystem. Sentinel's lock-in is deeper because it's tied to your Azure tenant and identity stack.
I'd pick Cortex if your top priority is predictable cost and your playbooks need to touch on-prem systems equally. I'd pick Sentinel if your team's Azure skills are strong and you're planning to adopt more Microsoft security products. To decide, tell us your average daily log volume and what percentage of your automation targets are outside Azure.