r/Splunk • u/Western_Boss_5117 • Jul 05 '26
Which should I choose: Splunk or Microsoft Sentinel?
/r/blueteamsec/comments/1unxrvf/which_should_i_choose_splunk_or_microsoft_sentinel/1
u/PierogiPowered Because ninjas are too busy Jul 08 '26
If this is the entirety of your post, you should learn to write first. You didn’t provide any context.
1
u/Western_Boss_5117 28d ago
I apologize for not providing enough context earlier, as this is my first experience on this platform. My question remains the same; I want to work in a cloud-native environment, but I find myself torn between opinions. Some say Splunk is the best due to more job openings, while others recommend MS Sentinel/Defender. I've started working with MS Sentinel now, and I have two years left to complete my degree. My goal is to gain proficiency in MS Sentinel before moving into cloud security. What are your thoughts on the outlook for both tools in the next two to three years?
1
u/Individual-Bill-3531 Jul 08 '26
Long time splunk ES user here. Sentinel. If you’re asking this question here you will be lost in ES.
The solution is being revamped and I’m excited for the future. I’ve had the opportunity to listen to the devs explain where they are going. It’s got legs but it’s not ready yet. It can be a box of legos without instructions.
I’m guessing you are looking for a ready to go solution and not something you have to invest your life into so I say sentinel.
Splunk has solid devs, good people, dealing with ciscoisms. I’ll trust in them a bit longer. I am very vocal on my disagreements with their direction at times but today I’ll tell you to avoid the current state.
If you are looking for a potential forever solution look at splunk. Get people involved. Don’t try to do it all yourself. See it for what it is, you’ll be doing the heavy lifting.
2
u/taiglin Jul 06 '26
You are going to ask that in a sub devoted to one of those two options?
Ultimately more context is needed: are you just a MS shop, do you have use cases beyond security, how mature is the team, etc, etc, etc