Home › Blog

The Amazing Rise of Microsoft Fentanyl— I mean, Sentinel Back in the day, we didn’t call i

The Amazing Rise of Microsoft Fentanyl—
I mean, Sentinel

Back in the day, we didn’t call it SIEM.
We called it ArcSight. And like all “legacy meds,” it came with side-effects: complex rule writing, heavyweight licensing, and dashboards that looked like a 90s rave gone wrong.

Then came Microsoft with its shiny little pill: Sentinel.

A miracle cure, they said.

Cloud-born, AI-enhanced, plug-and-play connectors. A controlled substance for CISOs desperate for coverage and compliance. And like fentanyl, it spread fast.

Suddenly the market was hooked.

CFOs whispering: “It’s cheaper than Splunk.”

Consultants murmuring: “Don’t resist—migrate.”

Ex-ArcSight experts like me?

Watching entire SIEM empires collapse overnight.

Sentinel isn’t evil.
It’s just addictive.
Every analytic rule, every workbook, every connector gives you that dopamine hit of “coverage achieved.”
Until you realise—like all dependencies- you’re the one being consumed.

I was an ArcSight expert.
I saw what it displaced.
Now I see the future written in Azure blue.

And here’s the twist:
I love the damn thing.
It’s amazing at what it is and what it does - integrate seamlessly with the enterprise stack of choice: Microsoft.
And I expect it to persist for a long, long time.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing