Listing Thumbnail

    SentinelOne Singularity AI SIEM, Hyperautomation, Purple AI & Observo AI

     Info
    Sold by: SentinelOne 
    Deployed on AWS
    SentinelOne Singularity AI SIEM revolutionizes your security operations on AWS. Eliminate the skyrocketing ingestion costs and data overloads of legacy SIEMs by utilizing Observo AI to filter data volumes. This provides a deeper, richer dataset, enabling smarter and more accurate detections, accelerated generative AI investigations, and precise responses with Singularity Hyperautomation. AI SIEM is fundamentally shifting the role of security analyst from manual, repetitive tasks to strategic defense. Empower your team to accelerate investigations and mitigate critical risks with a fast, scalable, and intelligent SIEM built for the Autonomous SOC.
    4.2

    Overview

    Play video

    SentinelOne Singularity AI SIEM is a cloud-native SaaS solution that revolutionizes security operations by unifying cutting-edge generative and agentic AI with advanced hyperautomation. This fundamentally shifts the security analyst's role from repetitive, manual tasks to strategic threat analysis and proactive defense, enabling teams to operate with unprecedented speed and efficiency.

    Unlike legacy SIEMs, our platform is built on an open, unified data lake designed for the scale and speed of modern cloud environments. It processes rich, unfiltered data to deliver autonomous threat mitigation, drastically reducing alert fatigue and mean time to resolution (MTTR) for AWS customers.

    Key Features & Benefits

    Autonomous & Agentic AI: Critical threats are autonomously mitigated by our AI, seamlessly augmenting human analysts for effective threat hunting and investigations.

    Hyperautomation Workflows: Streamline security operations with no-code automation to design and deploy workflows that automate triage, investigation, and response processes.

    Observo AI for Data Optimization: Our integration gives you an AI-native pipeline that ingests, enriches, and optimizes data before it reaches the SIEM. This reduces ingestion costs by ensuring you only pay for critical security posture data.

    Purple AI for Accelerated SecOps: Our generative AI analyst is built into the platform to reduce manual effort. It provides instant summaries and automates threat hunting with natural language to accelerate investigations.

    Seamless AWS Integrations

    SentinelOne Singularity AI SIEM is designed to integrate seamlessly into your AWS security ecosystem, providing enhanced visibility and simplified operations.

    Amazon Security Lake: Ingest high-fidelity security data from SentinelOne and other sources into Amazon Security Lake for a unified view, simplifying compliance and enabling in-depth threat hunting.

    AWS Security Hub: Automatically send and receive security findings, allowing for centralized management and a comprehensive security posture assessment across your entire AWS environment.

    Amazon GuardDuty: Enhance your threat detection by correlating SentinelOne data with findings from GuardDuty, gaining a deeper understanding of malicious activity in your AWS accounts.

    AWS AppFabric: Get a unified, contextualized view of user activity across your SaaS applications and your AWS environment, improving your ability to detect and respond to insider threats and compromised accounts.

    NEW - AWS Security Incident Response: Manage security incident response across AWS environments within Hyperautomation's no-code canvas, adding context from both external and internal sources and reducing MTTR.

    Experience the Autonomous SOC

    Break free from the limitations of legacy SIEMs and empower your security team to focus on what matters most. With SentinelOne Singularity AI SIEM on AWS, you can achieve faster threat detection, more efficient investigations, and a stronger security posture.

    Highlights

    • 100x faster than legacy SIEM
    • 50% lower operational costs and 246% ROI compared to legacy SIEM
    • 99% reduction in risk exposure, and 80% faster threat detection compared to AI SIEM

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    SentinelOne Singularity AI SIEM, Hyperautomation, Purple AI & Observo AI

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Contact us for pricing
    Daily ingestion starting from $721
    $125,000.00

    Vendor refund policy

    Contact us for refund questions or concerns.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Support is available for these solutions via telephone or our customer support portal. Contact: 1-855-868-3733 General Inquiries: sales@sentinelone.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.2
    14 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    43%
    50%
    0%
    7%
    0%
    9 AWS reviews
    |
    5 external reviews
    External reviews are from PeerSpot .
    Dev Reshwal

    Automation has reduced workload and real-time monitoring provides faster incident response

    Reviewed on Jul 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    In my daily work, the main use case for SentinelOne Singularity AI SIEM  is creating rules, fine-tuning, source recording, rule creations, and when any alerts are triggered. We can raise them to the client side, continuously monitoring any alerts. We can raise them to the client side for early resolution, also creating the dashboards, checking the logs, and agents installation. Those are the day-to-day tasks in our SIEM  tool.

    Alert fighting is a specific example of a recent situation where I used SentinelOne Singularity AI SIEM  for one of these tasks. Sometimes multiple alerts are triggered in the SIEM . At that time, we analyze what type of alert it is, whether it is a true positive or false positive. That is challenging for me.

    Our day-to-day tasks include alert raising, continuous monitoring, raising the alerts, dashboard managing, creating the dashboard, rule creating, and decoder creating. If there is any requirement from the client side, we will also do these types of activities, creating any new rule.

    When I have those multiple alerts and I need to figure out if they are true positives or false positives, I usually check in Deep Visibility if it belongs to any suspicious fields or anything malicious, or if it is a true positive belonging to our organization. I also check if it belongs to any suspicious sites, IPs, or IOCs such as malicious IPs or malicious hashes, or if it belongs to any malicious paths. I will check the source, the destination, and what it is doing. We can check if the path belongs to a genuine path or a suspicious path. We will do that type of analysis and then I will specify if it belongs to a true positive or a false positive. We can follow those types of steps.

    What is most valuable?

    SentinelOne Singularity AI SIEM offers the best features that belong to the AI. This includes automated alerts. We can also do the automated alerts on these fields. I can create multiple types of use cases. It means we will create multiple types of use cases for our requirements. For example, if we have blocked any suspicious or malicious app in the environment, we can block these. That is a best feature, and Purple AI  is also a best feature in SentinelOne Singularity AI SIEM tools. Deep Visibility is also a best feature because we can check multiple types of activity, such as what it is doing, what activities it is currently performing, and what the steps are. There are multiple types of best features in there.

    I will give an example of how Deep Visibility has helped me in my investigations or daily work. If any suspicious or malicious malware types of alerts are triggered in SentinelOne Singularity AI SIEM, then I will check the source of this with the help of Deep Visibility. Deep Visibility is basically for when any alerts are triggered on any endpoint. You can see what types of activity are being done, what is being downloaded, and what types of history there are. You can check the source, the destination, and what systems are doing this activity. I will check that type of feature in Deep Visibility.

    SentinelOne Singularity AI SIEM has impacted my organization positively because I am observing some improvement. There are multiple tool alerts in our organization, but SentinelOne Singularity AI SIEM feature is real-time monitoring and real-time threat detection. With the help of our and the client's organization, it is secure. There are improvements. Those types of improvements are better for securing our organization from anything suspicious or any malicious types of alerts.

    There are faster response times available with SentinelOne Singularity AI SIEM. Also, there is the automation alert. We can set any parameter on SentinelOne Singularity AI SIEM source, and it will automatically raise an alert to the client side. We can also integrate that type of feature with SentinelOne Singularity AI SIEM. With the help of alert raising, there is the fastest way to raise an alert. That is the best feature and there is a very big improvement.

    What needs improvement?

    SentinelOne Singularity AI SIEM is the best, but sometimes the dashboards are a little simple compared to other tools. The custom dashboard is not available in their features. Therefore, I would suggest adding the custom dashboard for any of our requirements.

    The AI-driven analytics from SentinelOne Singularity AI SIEM has not affected our ability to reduce false positives.

    SentinelOne Singularity AI SIEM has affected my SOC's efficiency in investigating alerts and responding to incidents. If we receive any alerts, we can observe what activity is being done. We can see if it is malicious or something suspicious, or a true positive. We can analyze the path, the hash, and whether the signature is verified or not. We can see if it is an alert triggered by any engine. We can see the source of this. We will do that type of analysis and raise it to the client side. Also, if I identify anything suspicious or malicious in the alert, I will forcefully kill and quarantine it immediately.

    For how long have I used the solution?

    I have been working in my current field for the last two years and five months.

    What do I think about the stability of the solution?

    SentinelOne Singularity AI SIEM is stable.

    What do I think about the scalability of the solution?

    The pricing for SentinelOne Singularity AI SIEM is best, and it has very easy features for understanding. There are multiple tools with various types of features, but SentinelOne Singularity AI SIEM provides some features, maybe fewer features, but they are very useful features. We can say that to the client. Also, the integration parts are easy. It is cloud-based, and there are multiple automation activities also being done. It is an easy way to work, and minimum workers are needed. SentinelOne Singularity AI SIEM is doing multiple types of activities because there are automated tools with AI features. There are also Deep Visibility and multiple Purple AI  types. It has multiple best features. We can suggest those types of things to the client for purchasing SentinelOne Singularity AI SIEM.

    I will give SentinelOne Singularity AI SIEM a ten out of ten on scalability.

    I rate SentinelOne Singularity AI SIEM a ten out of ten because there are the best features in there. There are multiple types of features such as auto-raising, automation, AI features, and the Deep Visibility feature. There is an improvement in our organization to be faster to secure our organization's safety. That is why I will give it a ten out of ten. The integration part is also best. It is a ten out of ten from my side. That is why I give it a ten out of ten.

    How are customer service and support?

    The customer support for SentinelOne Singularity AI SIEM is also the best because we have raised tickets to the support center multiple times. The support team gives an immediate answer, within ten to fifteen minutes. They also schedule calls and troubleshoot the alerts and solve the issue. The support team is very best.

    I rate the customer support for SentinelOne Singularity AI SIEM a ten out of ten.

    Which solution did I use previously and why did I switch?

    In our organization, we previously used the CrowdStrike solution.

    We switched from CrowdStrike to SentinelOne Singularity AI SIEM because our organization is an MSSP  organization. That means I provide services to the client. We had twenty to thirty clients in our organization that we managed. Twenty-seven or twenty-eight clients were using SentinelOne Singularity AI SIEM, but only one or two clients were on CrowdStrike. Their client also switched to SentinelOne Singularity AI SIEM. That is why, at this time, we are only managing SentinelOne Singularity AI SIEM.

    How was the initial setup?

    The integration part for SentinelOne Singularity AI SIEM is very easy. Any fresher can easily do this. The agent installation is also so easy. Within one to two minutes, we can install SentinelOne Singularity AI SIEM agents in the environment or client environment network. It is the best, fastest installation.

    What was our ROI?

    I have seen a return on investment with SentinelOne Singularity AI SIEM. The tool also saves our money and time. The pricing is very medium, and time is also saved because there are automation features available. That is why multiple alerts are raised by the automated process. In those times, manual alerts are less frequent compared to other tools. It is helpful. Sometimes, in our organization, two people are working on these AI-driven features in SentinelOne Singularity AI SIEM. But when the automation features are started, one person can also manage the console. It is money saved, and the automation and those types of activities are doing the automated alerts. One person is only managing and checking if the alerts are going properly. That is why it is also money-saving. It is a money-saving tool, and the pricing is also low. Any small or startup organization can also buy it easily.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for SentinelOne Singularity AI SIEM is that the setups are very easy for any fresher. Any basic knowledge can also do the setups. Regarding the pricing, it is not heavy. It is in the middle, not high, not low. Any small organization can also purchase this. Compared to another SIEM tool's pricing, the pricing is the best, from my side.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity AI SIEM, I did not evaluate other options because SentinelOne Singularity AI SIEM is the best according to me. We have used other tools, but SentinelOne Singularity AI SIEM has multiple types of features and it is an easy-to-understand tool. That is why I am choosing SentinelOne Singularity AI SIEM.

    What other advice do I have?

    The accuracy and reliability of output from SentinelOne Singularity AI SIEM are very high. SentinelOne Singularity AI SIEM is very accurate. It is also very reliable. We have not found any glitching. It is faster, and it also has real-time threat hunting and real-time detection. That is the capability in there.

    The real-time monitoring feature of SentinelOne Singularity AI SIEM helps with Deep Visibility. If any malicious or suspicious alerts are triggered, I will check the alert. We can analyze this alert with the help of Deep Visibility. We can see its source, its destination, what it is trying to do, and if the path is genuine or not. We receive the alerts and we can do this type of investigation. Then, if anything malicious happens, we can raise it to the client side for notification purposes. We can say we observed this type of alert at this time, and it is this type of malicious activity.

    My impression of the AI-driven threat detection capabilities of SentinelOne Singularity AI SIEM is that it is the best feature because multiple alerts can be happening, but the AI-driven features immediately block them. Any alerts are blocked before they happen. And it gives the action, such as killing and quarantining the threat.

    I give SentinelOne Singularity AI SIEM an overall rating of ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    reviewer2873466

    Centralized monitoring has transformed investigations and now reduces incident response time

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for SentinelOne Singularity AI SIEM  is centralized log management, threat detection and correlation for incident investigation, automated response, cloud security monitoring, and endpoint plus SIM correlations.

    My primary use case for SentinelOne Singularity AI SIEM  is centralized security monitoring and incident investigation. I ingest logs from Microsoft Entra ID , Active Directory, Microsoft 365, firewall, VPNs, and SentinelOne EDR into the AI SIEM . Instead of checking each platform individually, I use SIEM  to correlate events, identify suspicious activity, and investigate incidents from a single console.

    What is most valuable?

    The best features SentinelOne Singularity AI SIEM offers include centralized log management, AI-powered threat detection, Purple AI , AI Security  Assistant, unified investigation timeline, and threat hunting. Hyper automation, fast search and investigation, cloud, and identity visibility are also standout features.

    Out of those features, the centralized console is the one I find myself using the most, and it has made a big difference in my daily work.

    SentinelOne Singularity AI SIEM has positively impacted my organization by improving visibility, reducing investigation time, and helping the security team respond to incidents faster.

    What needs improvement?

    Overall, SentinelOne Singularity AI SIEM is a strong platform, but there are a few areas where it could be improved. One area is customization. While it provides many built-in decorations and dashboards, creating highly customized decoration rules and reports can sometimes require additional efforts. Another area is third-party integrations. Although it integrates with many security products, expanding native integration and simplifying onboarding for less common vendors would make deployment easier.

    From a usability perspective, I think the platform could make advanced investigation more intuitive. New analysts can face a learning curve when building complex searches, custom detection rules, or dashboards. Improving the user experience with more guided workflow templates and contextual recommendations would help teams become productive more quickly.

    For how long have I used the solution?

    I have been using SentinelOne Singularity AI SIEM for about one year.

    What do I think about the stability of the solution?

    In my experience, SentinelOne Singularity AI SIEM has been a stable platform. It has been reliable for day-to-day SOC operations, including log ingestion, real-time monitoring, threat detection, and incident investigation.

    What do I think about the scalability of the solution?

    In my experience, SentinelOne Singularity AI SIEM is highly scalable. As my organization grows, it is able to ingest and analyze logs for additional cloud services, identity providers, and network devices without requiring major changes to my security operations. This makes it well-suited for organizations with hybrid or multi-cloud environments.

    I would rate the scalability of SentinelOne Singularity AI SIEM very high. It is designed to handle growing log volumes and supports environments that include on-premises infrastructure, cloud services, endpoints, identity platforms, and network devices.

    How are customer service and support?

    My experience with the support has been very responsive and knowledgeable, particularly for technical issues and troubleshooting. I would rate the customer support eight out of ten.

    Which solution did I use previously and why did I switch?

    I previously used another SIM solution. The main reason for moving to SentinelOne was to improve centralized visibility, simplify security options, and take advantage of AI-driven event correlations. With the previous solution, investigation often required switching between multiple tools and manually correlating events.

    How was the initial setup?

    Overall, my experience with pricing, setup cost, and licensing has been positive. While SentinelOne Singularity AI SIEM is an enterprise-grade platform and not the lowest cost option, I think the pricing is reasonable considering the capabilities it provides. Features such as centralized log management, AI-driven analytics, automated workflow, and integrated security options can reduce operational overhead and improve SOC efficiency, which helps justify the investment.

    What was our ROI?

    I have seen a positive return on investment primarily through operational efficiency rather than reducing headcount. The biggest measurable benefit has been the reduction in investigation time. Before using SentinelOne Singularity AI SIEM, investigating a moderately complex alert took around thirty to sixty minutes because analysts had to collect logs from multiple security tools. With centralized log management and AI-driven correlation, I can often understand the scope of an incident in about ten to fifteen minutes.

    What's my experience with pricing, setup cost, and licensing?

    Overall, my experience with pricing, setup cost, and licensing has been positive. While SentinelOne Singularity AI SIEM is an enterprise-grade platform and not the lowest cost option, I think the pricing is reasonable considering the capabilities it provides. Features such as centralized log management, AI-driven analytics, automated workflow, and integrated security options can reduce operational overhead and improve SOC efficiency, which helps justify the investment.

    Which other solutions did I evaluate?

    I considered other enterprise SIEM platforms such as Sentinel , Splunk, Enterprise Security, IBM, and Google Security Operations . I evaluated them based on integration with my existing environment, AI-assisted threat detection, scalability, ease of investigation, automation capabilities, and total cost of ownership. SentinelOne stood out because of its strong integration between EDR and AI SIEM, centralized visibility, and AI-driven event correlations.

    What other advice do I have?

    My advice would be to spend time planning the deployment and identifying the log resources that provide the most value. SentinelOne Singularity AI SIEM is most effective when it is integrated with key systems such as Entra ID, 365, VPN, and endpoints. I would rate this product eight out of ten overall.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Vanshikas Vanshikas

    Centralized security data has improved AI-driven threat correlation and faster incident response

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    SentinelOne Singularity AI SIEM  serves as our centralized platform for security data across our environments, enabling real-time threat detection and accelerated incident response. I use it to collect and analyze logs from endpoints, cloud workloads, identity providers, firewalls, and SaaS applications.

    We initially used SentinelOne Singularity AI SIEM  to identify and investigate a potential account compromise. The platform correlated unusual login activities from our identity provider, multiple authentication attempts, and suspicious PowerShell execution on an endpoint. Rather than having analysts manually check logs from different tools, the AI SIEM  automatically connected these events into a single incident. This allowed our SOC team to quickly determine that the credentials were compromised and isolate the affected endpoint.

    Our primary use case focuses on improving SOC efficiency by centralizing security telemetry and using AI to correlate alerts from endpoints, cloud identity, and network sources. Instead of investigating isolated alerts, analysts receive prioritized incidents with the full attack timeline. This helps reduce alert fatigue, speed up investigations, and enable faster response to threats such as phishing, credential compromise, and lateral movement.

    What is most valuable?

    The best feature is that it collects and correlates logs, which is very helpful. We also use it for AI-powered investigations. The platform provides unified visibility, AI-driven alert correlations, threat hunting, automated response, and AI-driven data pipelines. These are the features I found most valuable.

    We have been using the AI-driven alert correlation feature extensively. Without AI-driven alert correlation, an employee clicking on a phishing email could exploit our entire organization. The AI automatically recognizes that all of these events are connected because they involve the same user, endpoint, and timeframe. We use it when somebody receives a phishing email or clicks a link, credentials are used from an unusual location, PowerShell is launched, connections are made to a malicious server, and persistence attempts occur. The correlation feature helps us identify and correlate these attacks, determine where the attack started, and find the threat so we can fix it.

    The platform brings together AI, automation, and unified visibility in a way that helps security teams work more efficiently. Rather than switching between multiple tools and manually correlating alerts, analysts can investigate incidents from a single console with AI-assisted context. Features such as automated alert correlation, threat hunting, and response workflows help reduce investigation time and improve overall SOC productivity.

    One of the biggest positive impacts has been improved operational efficiency for the security team. By centralizing telemetries from multiple sources and using AI to correlate related alerts, we have reduced the time spent on manual investigation. Analysts can focus on higher priority incidents. We have also noticed faster incident detection and response, better visibility across endpoints, cloud, and identity environments, as well as improved collaboration because everyone works from the same incident view.

    What needs improvement?

    Overall, SentinelOne Singularity AI SIEM  is a very strong platform, but there are a few areas where I would like to see improvements. The AI-generated investigations can occasionally require manual validation for complex incidents. Increasing the precision and explainability of AI recommendations would be valuable. I would also appreciate even broader out-of-the-box integrations with third-party security tools and more pre-built detections and response playbooks. Additionally, making dashboards and reporting even more customizable would help organizations tailor the platform to different teams and executive reporting needs.

    SentinelOne Singularity AI SIEM is a very strong platform, so I do not have much to suggest for improvement. Those are the main areas I would highlight. Overall, the platform is quite mature, and the improvements I would like to see are more about enhancing usability than addressing major shortcomings. Continued investigation into AI accuracy and explainability, additional native integrations with third-party tools, richer pre-built automation playbooks, and more flexible dashboards and reporting would be beneficial.

    For how long have I used the solution?

    I have been working in this field for one year.

    What do I think about the stability of the solution?

    I have experienced no issues with SentinelOne Singularity AI SIEM. It is the best product I have ever used. The platform has been very stable in my experience. I have worked with it, and it is very handy, easy to manage, and excellent with its AI-driven capabilities.

    What do I think about the scalability of the solution?

    From what I have seen, I have not personally encountered scalability issues, so I cannot point to any specific challenge in a production environment. As with any enterprise SIEM, the main considerations tend to be planning data ingestion, tuning detection rules to minimize noise, and integrating new data sources as the environment expands. Those are common operational considerations rather than unique limitations of the platform.

    How are customer service and support?

    I have not reached out to customer support yet and have not experienced it directly. However, I have heard from my organization that their customer support is very good. Several of my colleagues have spoken with customer support, and their experience was great.

    Which solution did I use previously and why did I switch?

    I have only worked with SentinelOne Singularity AI SIEM because I have recently started working. I have seven to eight months of experience, so I have never used any different solution.

    How was the initial setup?

    My advice would be to plan the deployment carefully, integrate all relevant security data sources, and invest time in tuning detection and automation. SentinelOne Singularity AI SIEM delivers the most value when AI supports experienced analysts by reducing manual work and improving investigation speed rather than operating without human oversight.

    What about the implementation team?

    My organization is currently a partner of SentinelOne.

    What was our ROI?

    I cannot provide verified metrics because I was not directly involved in measuring ROI, so I would not want to speculate. My experience is that the value comes from improved analyst productivity, faster investigations, and reduced operational overhead rather than a specific percentage of cost savings.

    What's my experience with pricing, setup cost, and licensing?

    We actually had a great experience with pricing, setup cost, and licensing. I was not directly involved in pricing or contract negotiation, so I cannot comment on exact licensing costs. My understanding is that SentinelOne offers enterprise licensing based on factors such as the product selected, deployment size, and required capabilities. The platform appears to provide good value because it consolidates multiple security functions into a single platform.

    Which other solutions did I evaluate?

    I was not directly involved in the product evaluation or selection process, so I cannot accurately state which vendors were formally evaluated. In general, organizations looking at AI-powered SIEM solutions consider options such as Microsoft Sentinel , Google Security Operations , IBM, Falcon  Next-Gen SIEM, and Microsoft Defender. However, I have not worked on those solutions, so I only have knowledge of SentinelOne Singularity AI SIEM.

    What other advice do I have?

    AI-driven analytics can reduce false positives by providing better context and correlating related alerts into meaningful incidents. This helps analysts spend less time investigating false activity and more time responding to genuine threats.

    My impression is that the AI-driven threat detection capabilities are one of the platform's key strengths. Overall, I have a positive impression. The AI-driven threat detection helps identify suspicious behavior, correlate related events into meaningful insights, and prioritize higher-risk threats. This enables analysts to investigate and respond more quickly while reducing alert fatigue. Human validation is still important, but the AI provides valuable decision support.

    From my perspective, SentinelOne Singularity AI SIEM appears very suited for organizations with growing data volumes and increasingly complex IT environments. The visibility to ingest and correlate telemetry from endpoints, cloud workloads, identity systems, and third-party security tools provides a centralized view as the environment expands. Real-time monitoring impacts our threat identification process significantly.

    Based on its capability, SentinelOne Singularity AI SIEM can improve SOC efficiency by correlating alerts, summarizing incidents, and helping analysts prioritize genuine threats. This reduces manual investigation and enables faster incident response while analysts still validate the AI's recommendations for critical decisions.

    I think SentinelOne has taken a strong approach to AI governance and security. The platform uses AI to assist analysts with tasks such as alert correlation, investigations, and incident summarization while still allowing human analysts to validate findings before taking actions. From a governance perspective, having role-based access control, audit logs, and centralized visibility helps organizations maintain oversight. It is important to have clear governance policies, regularly review AI-generated recommendations, and ensure automated response workflows are appropriately validated.

    Overall, I would rate the accuracy and reliability of the AI capabilities as good. The AI is effective at correlating related alerts, summarizing incidents, and helping analysts prioritize investigations, which can significantly reduce manual effort. However, AI outputs should not be treated as infallible, and for higher impact security decisions, it is still important for analysts to validate the AI findings and recommendations. I would rate this review as an eight out of ten overall.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Ayman Said

    Unified monitoring has improved threat response and reduced false positives across our devices

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have been working with SentinelOne Singularity AI SIEM  for four years.

    What is most valuable?

    The best features of SentinelOne Singularity AI SIEM  include its user-friendly interface, ease of deployment, and ease of use. It is also easy to control the devices, as we block USB on all machines. You can export the configuration of machines and have very good visibility of the instance. The reports are excellent.

    SentinelOne Singularity AI SIEM  has impacted my organization positively and it was a very good solution.

    What needs improvement?

    SentinelOne Singularity AI SIEM  can improve in the area of XDR , especially in the integration between SentinelOne and other solutions and components in the network, as it was not working well with the Fortinet firewall. The API and the integration between each other is not working well at this time, and they are promising to work on this area, but they have not done that effectively.

    What do I think about the stability of the solution?

    We did not face any downtime with SentinelOne Singularity AI SIEM.

    What do I think about the scalability of the solution?

    SentinelOne Singularity AI SIEM is scalable in terms of adapting to my organization's growing data.

    What about the implementation team?

    Around six to eight engineers were involved in the process of migration, working on this project.

    I was personally involved in the project.

    What was our ROI?

    SentinelOne Singularity AI SIEM has impacted my operational costs positively, and I think we made a good deal with them because we are a big group and have a big account, so we got a good deal with SentinelOne.

    What's my experience with pricing, setup cost, and licensing?

    The licensing cost for SentinelOne Singularity AI SIEM is a little bit high compared with the others, but it is worth it. It deserves the prices and is value for money; it is not very expensive according to the services that they are giving us.

    What other advice do I have?

    For the implementation and deployment of SentinelOne Singularity AI SIEM for the whole solution, it takes about months as we made a migration from EDR to another for 3,000 users across Egypt and GCC, so it takes a lot of efforts.

    I assess the efficiency of SentinelOne Singularity AI SIEM in improving my response time to sophisticated threats as very fast and very good.

    For false positive incidents, SentinelOne Singularity AI SIEM manages these situations very well, and when we are facing someone uploading a false positive file, we can deal with these situations very well. You can easily go into the interface and mark this as a false positive, and I can recover the deleted or false positive files or anything like that.

    AI-driven analytics of SentinelOne Singularity AI SIEM helped me to reduce false positives.

    I assess the real-time monitoring feature of SentinelOne Singularity AI SIEM as very good and very responsive. Monitoring is working well, and it has a fast response to any threat; it does not take more than a few seconds to detect any threat and send a request for action. So it is very good.

    For the automated workflow feature of SentinelOne Singularity AI SIEM, we did not try it.

    I rate this product an 8 out of 10.

    GANESAN K

    AI-driven security has transformed threat response and now empowers faster incident resolution

    Reviewed on Jul 08, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Clients can use SentinelOne Singularity AI SIEM  for endpoint security solutions, and apart from that, we currently have something called prompt security where it is helping us to enhance control over the AI prompts given by end-users. Some end-users tend to feed sensitive data to AI tools like Claude, Gemini , and ChatGPT. We have not implemented it yet, but we have provided a POC for agnostic prompt security.

    AI-driven Threat Detection capability is crucial because attackers have started conducting attacks using AI patterns. They analyze the patterns of defending solutions, and based on the defense architecture, they generate the payload according to the environment. To detect those kinds of payloads, we need AI-based threat detection to sense whether they come from a single source or distinct sources, where these kinds of prompts and malicious payloads are being generated.

    Real-time monitoring is a must-have functionality for any product, and SentinelOne Singularity AI SIEM  has the same response. We can create rules for peculiar situations we encounter, and if those rules get triggered, the system can automatically help isolate or contain that system while providing us alerts at the same time. This way, if a particular user reports not being able to reach anything, we can quickly understand that SentinelOne Singularity AI SIEM  has isolated their system.

    What is most valuable?

    With the help of this tool, the response time to sophisticated threats has improved significantly, and it recently cuts the MTTR time using Purple AI  by 40%.

    SentinelOne Singularity AI SIEM  allows us to use natural language; we do not need knowledge of scripting or querying languages to correlate threats. We can search in normal, plain, simple English. For example, if I want to check the detections regarding a particular threat in a particular attack surface, I only need to provide it in plain, simple English, and Purple AI  will generate a query and summarize the results for that. It has made my job much easier, both for myself and for the SOC teams. With minimal effort, we can get the queries asked by the auditors or forensics teams.

    AI analytics reduces the manual tasks and helps us prioritize critical and immediate threats that need to be addressed. The analytical part mainly provides clarity on what we should focus on, which threats to investigate, or if we need to report it or whitelist false positives. These kinds of tasks are largely automated and taken care of.

    Knowing which threat we need to look at first based on its criticality makes it easier for us to address it. Getting to the problem is one thing, and with Purple AI, we are able to get answers without using complex queries; we just search for what we are looking for, and it generates the corresponding steps right in the console, which helps us respond to critical threats on an immediate basis.

    After implementing SentinelOne Singularity AI SIEM, we can see that we have visibility over all the applications on our endpoints, and it helps us identify which of those applications are more vulnerable or critical, whether high or medium. These kinds of visibilities are available, allowing us to proactively protect the endpoint and our infrastructure.

    What needs improvement?

    They could expand more integrations for other third-party products that are not currently available. Those are areas they can improve or have yet to improve.

    For example, we have firewall integrations, so if we integrate our firewalls, we will be able to have a log view of the traffic. If traffic is coming from the firewall, we can see from which side a particular threat is coming. Currently, they support only FortiNet, Cisco, and Palo Alto. However, many of our clients use SonicWall firewalls, which are not in SentinelOne Singularity AI SIEM marketplace. They could add SonicWall because it is also a global product that needs to be included.

    SentinelOne Singularity AI SIEM is pretty good compared to Charlotte AI  from CrowdStrike. However, if it could provide more information on IOA, that would be beneficial. While SentinelOne Singularity AI SIEM does provide those details, leveraging that information to proactively check our systems for vulnerabilities would be better. In Charlotte AI , those functionalities are available. Therefore, the prompt can be improved, and provide more information on the attackers and attacks we are facing. Indicators of compromise are one thing, but IOA is another critical aspect that needs to be taken care of to help organizations proactively improve their cyber defenses against evolving attacks, as many attacks are happening globally. The same attacks may come to India or target our organization as well; thus improving on the IOA part would be beneficial.

    For how long have I used the solution?

    I have been working with SentinelOne Singularity AI SIEM for around three to four years.

    What do I think about the stability of the solution?

    SentinelOne Singularity AI SIEM is 99% stable with no glitches as of now.

    What do I think about the scalability of the solution?

    The product is pretty much scalable.

    How are customer service and support?

    Customer support could be better. Customer support could be better because it is frequently transferred to various agents. This is just one particular case, and I do not want to elaborate further.

    How was the initial setup?

    The deployment process with SentinelOne Singularity AI SIEM is somewhat complicated. Until some versions, we had scenarios where we needed to reboot machines, impacting deployment. However, with upgraded versions, we can now install the agent without any reboot, showing that they have improved that aspect.

    What was our ROI?

    For instance, if you are getting attacked and you use a brand other than SentinelOne Singularity AI SIEM, you will need to contact the OEM for recovery, which takes time. In contrast, with SentinelOne Singularity AI SIEM, we have a rollback option with just an automated click. If the data gets encrypted, it automatically rolls back. This functionality minimizes downtime and the impact of the attack. Looking at that perspective—post-attack damage control—the ROI is better. Using SentinelOne Singularity AI SIEM, data retrieval happens at a much faster rate, allowing production to continue without impact.

    What other advice do I have?

    The automated workflow feature impacts my security tasks and manual efforts significantly.

    Downtime is not necessarily required in scenarios where a particular system has to be isolated. Whether it is a server or a normal endpoint, if an application server faces downtime, the situation differs from a normal endpoint. If an application server needs to be contained, the customer will obviously experience downtime.

    The consolidation of multiple tools with SentinelOne Singularity AI SIEM impacts SOC operations positively concerning cost and staffing needs. While I am unsure about staffing because it depends on daily occurrences, it definitely makes work easier for the team. For example, without it, a person can hardly handle two or three threats a day, but with SentinelOne Singularity AI SIEM, they can handle around 10 to 12 threats daily, which makes it much more efficient. SentinelOne Singularity AI SIEM is quite affordable. My overall review rating for this product is 9 out of 10.

    View all reviews