
DataSet (by SentinelOne)
Log monitoring software
Log analysis software
DevSecOps software
Monitoring software
- Features
- Ease of use
- Ease of management
- Quality of support
- Affordability
- Market presence
Take the quiz to check if DataSet (by SentinelOne) and its alternatives fit your requirements.
Pay-as-you-go
Small
Medium
Large
- Information technology and software
- Construction
- Healthcare and life sciences
What is DataSet (by SentinelOne)
DataSet is a cloud-based data lake and log analytics product from SentinelOne that centralizes security, IT, and application telemetry for search, investigation, and retention. It is used by security operations and IT/DevSecOps teams to ingest and analyze high-volume logs and events across endpoints, cloud workloads, and third-party sources. The product emphasizes scalable storage and fast querying to support threat hunting, incident investigation, and operational analytics, and it is commonly positioned as the data foundation for SentinelOne’s broader analytics and response workflows.
Centralized log and event lake
DataSet provides a single repository for storing and querying diverse telemetry, including security events and operational logs. This supports cross-source investigations where analysts need to correlate activity across endpoints, cloud environments, and other tools. Centralization can reduce the need to maintain multiple separate log stores for different teams and use cases.
Security-focused investigation workflows
The product is designed to support threat hunting and incident investigation use cases, aligning log analytics with security operations needs. It fits naturally into workflows where detection, triage, and investigation rely on historical event context. For organizations already standardizing on SentinelOne, DataSet can reduce integration overhead between telemetry storage and security analytics.
Scalable ingestion and retention model
DataSet is built to ingest large volumes of telemetry and retain it for later analysis, which is important for investigations that require historical lookback. A data-lake approach can be more flexible than fixed schemas when onboarding new log sources. This helps teams expand coverage over time without redesigning storage for each new data type.
Best fit within SentinelOne stack
DataSet is most straightforward to adopt when an organization already uses SentinelOne products and workflows. Teams that want a vendor-neutral observability platform may find the surrounding ecosystem and integrations less broad than platforms built primarily for general-purpose monitoring. This can increase effort when standardizing across heterogeneous toolchains.
Observability depth may vary
While DataSet supports log analytics, organizations seeking deep application performance monitoring features (for example, full APM with extensive tracing and code-level diagnostics) may need additional tooling. The product’s primary orientation is security and event analytics rather than end-to-end application observability. This can limit its role as a single platform for all monitoring disciplines.
Cost and governance complexity
Data-lake style ingestion and long retention can become expensive and require careful governance as data volumes grow. Teams typically need to manage source onboarding, parsing/normalization, retention policies, and access controls to keep usage predictable. Without disciplined controls, query performance and spend can be harder to manage at scale.
Plan & Pricing
Pricing model: Pay-as-you-go (consumption-based) Price: $0.99 per GB per day (billed annually). 30 days retention included by default. What’s included: Unlimited users, unlimited data sources, unlimited queries, unlimited dashboards, unlimited real-time alerts, unlimited support, enterprise-grade security. Notes: Minimum volume required (not specified on site). Volume discounts available for higher ingestion volumes. Consumption-based (no-commitment) option available where customers pay only for ingested data. Example costs (illustrative):
- 1 GB/day average = $0.99 per day (billed annually)
- 10 GB/day average = $9.90 per day (billed annually)
Contact: For custom quotes, longer retention, and enterprise terms contact sales.
Seller details
SentinelOne, Inc.
Mountain View, CA, USA
2013
Public
https://www.sentinelone.com/
https://x.com/SentinelOne
https://www.linkedin.com/company/sentinelone/