ServiceNow SecOps is a SOAR product, not a SIEM like Azure Sentinel. You can use Azure Sentinel to do the detection of events and then pass that information into ServiceNow to manage the incidents. From the ServiceNow Security Operations documentation: ServiceNow® Security Operations is a security orchestration, automation, and response (SOAR) engine built on the Now Platform. Designed to help security and IT teams respond faster and more efficiently to incidents and vulnerabilities, Security Operations uses intelligent workflows, automation, and a deep connection with Security Operations and IT to streamline response.