Atlas Fold / SIEM

SIEM, unfolded.

Security information & event management

Atlas Fold / SIEM / First edition

Security information & event management

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Comparable offerings and editions; exclude managed service comparisons.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Microsoft Sentinel (medium confidence) has the highest documented score (5.0) for Operational maturity among assessed offerings in this comparison group.

Microsoft Sentinel (medium confidence) and Google Security Operations SIEM (medium confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings. 1 offering remains unknown for this dimension.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Microsoft Sentinel: no unknown dimensions.
  • Splunk Enterprise Security: Shipped innovation, Ecosystem & integration, Operator enablement
  • Google Security Operations SIEM: Ecosystem & integration, Governance & control

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Microsoft Sentinel · Microsoft

Microsoft Sentinel cloud SIEM (Microsoft Defender portal; remaining Azure portal support until 31 March 2027). Not Defender XDR as a whole, not Security Copilot, and not Microsoft Sentinel MCP or graph as the scored offering. · Assessed 2026-09-21 · Research preview

Operational maturity

Do current public docs describe a complete ingest-detect-investigate-incident loop as operator procedures, not marketing claims?

Documented-evidence stage of a shipped SIEM operating loop from collection through detection, investigation, and incident or case handling. Anchors describe presence of documented procedures, not observed quality or efficacy. A gap in public docs is unknown (null), not stage 0.

Documented cloud SIEM loop of connectors, KQL analytics rules, incidents, hunting, and automation rules. Ordinary baseline includes ASIM normalization and incident correlation. Data-lake tiering is preview and Fusion is unavailable on the evaluated Defender-portal path, so those are not scored as differentiation.

Score5.0 / 5.0medium confidence

Rationale and sources

The incident, hunting and automation loop is supplemented by Content hub lifecycle procedures, shipped Log Analytics retention settings, connector-health monitoring and scheduled/NRT rule execution and change audit. This completes anchor 5 as a documentation stage. Health support has connector-specific limits; preview lake workflows are excluded.

Constraints

  • Evaluated offering is Microsoft Sentinel cloud SIEM, not Microsoft Defender XDR, Security Copilot, or the Sentinel MCP/graph platform extras.
  • After 31 March 2027 Sentinel is documented as Defender-portal only; Azure portal remains documented until then.
  • Analytics-tier tables are required for analytics rules, hunting queries, parsers, playbooks, watchlists, and workbooks; lake-only tables do not run those SIEM features.
  • Fusion and Microsoft-security incident-creation rules are documented as unavailable after Defender-portal onboarding or Defender XDR incident integration.
  • Data-lake onboarding, graph, and some table-management experiences are documented with preview labels.
  • Playbooks are Azure Logic Apps with separate roles and resource-group permissions; they are not included merely by enabling Sentinel.
  • Connector support may be Microsoft, partner, or community; a connector listing is not evidence of complete parsing for every source version.
  • Connector-health tables cover supported connector types rather than every integration. Azure Lighthouse does not alone grant all customer connector deployment rights; GDAP and tenant-specific permissions may be required.

Sources

0–5 rubric anchors

  • 0 — Public documentation states that the offering does not provide a SIEM ingest-detect-investigate-incident operating loop.
  • 1 — Documentation describes collecting security telemetry and searching stored events.
  • 2 — Documentation describes scheduled or streaming detections that create alerts from queried telemetry.
  • 3 — Documentation describes aggregating alerts into incidents or cases with assignment, status, and review of contributing events.
  • 4 — Documentation describes operator workflows for grouping or enriching incidents, hunting related activity, and documented automation of incident handling under operator-defined conditions.
  • 5 — Documentation describes the stage-4 loop plus SIEM content lifecycle, data-tier or retention operations, and health or audit of collection and detection execution as shipped operator procedures.
Assessed offerings inSIEM platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Microsoft Sentinel5.0 (medium)3.0 (medium)5.0 (medium)5.0 (medium)4.0 (medium)4.0 (medium)
Splunk Enterprise Security3.0 (medium)Unknown3.0 (low)Unknown2.0 (medium)Unknown
Google Security Operations SIEM3.7 (medium)3.0 (medium)4.0 (medium)UnknownUnknown3.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

Cohort siem-platforms compares SIEM platform offerings and named editions only. Managed detection and response, MSSP operating models, and SOAR-only products are out of cohort scope even when a vendor sells them alongside SIEM.

Anchors are documented-evidence stages, not observed product quality, efficacy, or completeness. Stage 0 is only for affirmative documented absence of the scoped capability. Missing public docs, failed fetches, gated docs, or preview/Pre-GA-only procedures are unknown (null), never zero.

Shipped innovation stage 3 is the ordinary current SIEM baseline: ingest with normalization, risk or correlation, investigation, incident or case handling, and retention. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline. Preview, Pre-GA, edition-unavailable paths, AI branding, and unique-market-first claims are excluded from stage 4+. Undifferentiated ordinary SIEM work is scored 3 with no novelty claim, or null if the full baseline is not documented.

This edition researches Microsoft Sentinel, Splunk Enterprise Security and Google Security Operations. Other field-guide offerings remain unassessed. Coverage is a research sample, not evidence of market leadership.

ibm-qradar remains unassessed as the continuing IBM self-managed QRadar SIEM. Retired QRadar cloud / QRadar SaaS is not treated as a live cloud SIEM pilot. Palo Alto Networks acquisition of QRadar SaaS assets does not make Cortex XSIAM a scored substitute in this file.

Google SecOps Standard includes base SOAR. Reviewed legacy case procedures support the baseline case workflow; package-wide permissions and connector/content pairing remain gaps. Enhanced Cases is Pre-GA and excluded.

Scope limitation: Microsoft publishes both a Sentinel SIEM and a Sentinel 'platform' (data lake, graph, MCP). Conservative interpretation: score cloud SIEM incident/automation procedures; do not score MCP, Security Copilot, agentic defense, preview data-lake management, or Fusion (unavailable after Defender-portal onboarding) as innovation.

Detailed Splunk Enterprise Security 8 procedure pages were inaccessible during review. Product pages and available search excerpts support limited, low-confidence judgments; unsupported control and integration details remain unknown.

Confidence is at most medium because this is public-documentation research, not a lab or customer-tenant assessment. Splunk cells use low confidence because inference from snippets and product pages is material.

Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.

All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • Cohort siem-platforms compares SIEM platform offerings and named editions only. Managed detection and response, MSSP operating models, and SOAR-only products are out of cohort scope even when a vendor sells them alongside SIEM.
  • Anchors are documented-evidence stages, not observed product quality, efficacy, or completeness. Stage 0 is only for affirmative documented absence of the scoped capability. Missing public docs, failed fetches, gated docs, or preview/Pre-GA-only procedures are unknown (null), never zero.
  • Shipped innovation stage 3 is the ordinary current SIEM baseline: ingest with normalization, risk or correlation, investigation, incident or case handling, and retention. Stage 4 requires a genuinely different shipped operator workflow beyond that baseline. Preview, Pre-GA, edition-unavailable paths, AI branding, and unique-market-first claims are excluded from stage 4+. Undifferentiated ordinary SIEM work is scored 3 with no novelty claim, or null if the full baseline is not documented.
  • This edition researches Microsoft Sentinel, Splunk Enterprise Security and Google Security Operations. Other field-guide offerings remain unassessed. Coverage is a research sample, not evidence of market leadership.
  • ibm-qradar remains unassessed as the continuing IBM self-managed QRadar SIEM. Retired QRadar cloud / QRadar SaaS is not treated as a live cloud SIEM pilot. Palo Alto Networks acquisition of QRadar SaaS assets does not make Cortex XSIAM a scored substitute in this file.
  • Google SecOps Standard includes base SOAR. Reviewed legacy case procedures support the baseline case workflow; package-wide permissions and connector/content pairing remain gaps. Enhanced Cases is Pre-GA and excluded.
  • Scope limitation: Microsoft publishes both a Sentinel SIEM and a Sentinel 'platform' (data lake, graph, MCP). Conservative interpretation: score cloud SIEM incident/automation procedures; do not score MCP, Security Copilot, agentic defense, preview data-lake management, or Fusion (unavailable after Defender-portal onboarding) as innovation.
  • Detailed Splunk Enterprise Security 8 procedure pages were inaccessible during review. Product pages and available search excerpts support limited, low-confidence judgments; unsupported control and integration details remain unknown.
  • Confidence is at most medium because this is public-documentation research, not a lab or customer-tenant assessment. Splunk cells use low confidence because inference from snippets and product pages is material.
  • Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.
  • All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

SIEM platforms

Comparable offerings and editions; exclude managed service comparisons.

Find your next idea.

Tip: press / to open search. Escape closes this window.