USM Anywhere vs VMware Aria Operations for Logs comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

USM Anywhere
Ranking in Log Management
17th
Average Rating
8.4
Number of Reviews
113
Ranking in other categories
Security Information and Event Management (SIEM) (13th), Endpoint Detection and Response (EDR) (31st), Compliance Management (8th)
VMware Aria Operations for ...
Ranking in Log Management
9th
Average Rating
8.2
Number of Reviews
24
Ranking in other categories
No ranking in other categories
 

Market share comparison

As of June 2024, in the Log Management category, the market share of USM Anywhere is 0.8% and it decreased by 76.7% compared to the previous year. The market share of VMware Aria Operations for Logs is 1.2% and it decreased by 51.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
Security Information and Event Management (SIEM)
1.3%
Endpoint Detection and Response (EDR)
0.2%
No other categories found
 

Featured Reviews

JV
Aug 1, 2022
Useful highlighted known vulnerabilities, full network viability, and beneficial reports
I have used AT&T AlienVault USM for Log collection and management, priority, and incident analysis AT&T AlienVault USM has helped our organization by highlighting known vulnerabilities in our network and full visibility of our network to figure out if there is anything that we are not aware of.…
AS
Feb 23, 2024
Offers real-time monitoring and tracks resource usage to ensure efficient compute resource allocation, provides valuable insights into the virtual environment but limitations in full-stack visibility
VMware Aria is suitable for infrastructure visibility, but for a comprehensive overview that includes applications and services, other tools are required. The monitoring landscape is getting bigger. When it comes to infrastructure monitoring, we need more visibility. VMware needs to integrate more related applications and third-party products. That would make it more appealing to an audience beyond the VMware team. Let me explain the scenario: Suppose I have a third-party product deployed on top of VMware, like Red Hat OpenShift containers. I generate a report using vROps, and it gives me recommendations related to OpenShift. But I can't apply those recommendations directly because Red Hat (or any third-party vendor) has its own resource management approach. This creates a conflict. The VMware team, limited to their view of VMware, might think vROps or Aria recommendations are the gospel. But the respective application's monitoring and operations team has a different perspective on resource management. This disagreement leads to operational conflicts. Now, I understand you can't completely blame VMware for that; each vendor has its own way of doing things. But VMware should somehow bridge this gap. The recommendations coming out of vROps or Aria need to be agreeable to others.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Allowed us to help our customers satisfy compliance needs around logging and monitoring."
"The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful."
"The setup is very easy and straightforward."
"The best thing about AlienVault USM is it being a “Jack-of-All Trades” solution. It provides SIEM, HIDS/NIDS, FIM, NetFlow, Asset Management, Vulnerability Management, etc., under one USM platform. None of the commercial SIEM vendors like ArcSight, McAfee, etc., can boast of such a diverse feature set."
"Our main focus was intrusion detection, alerts, and correlation. It's easy to use AlienVault and integrate it with other alert tools because it includes lots of connectors. Either the tool is already there, or AlienVault will write an API for us if they don't have a connector for the solution that is providing the logs."
"Its powerful correlation engine helps reduce time in manually correlating events."
"The best feature of this product is the ease of use. It is extremely easy to set up and get going. This is a very useful tool for a small organization."
"This solution can identify many threats inside the organization (compromised endpoints, configuration issues), as well as "outside" threats (botnets, network scanners, web-attacks, etc)."
"One of the things I like about it is its interface. When it comes to generating reports on VMs and stuff, it's very quick. This is very handy for the technical team, who need to generate reports quickly. So that's really good."
"The events are notably more descriptive, aiding in security and event analysis. We've also integrated Sky Collector, providing valuable insights and solutions for troubleshooting."
"The root cause analysis feature is very valuable."
"I like the interface."
"It is very scalable and can handle a large workload."
"Our current costs are too high, and this tool will help us to better optimize our infrastructure."
"It gives the customer a quick overview, so they don't have to dig. There's a clear dashboard with many sensors in a single space. He gets a helicopter view of his environment, but he can investigate further if there are serious issues. It's pretty user-friendly."
"What I like is that you can have different storage locations for different applications."
 

Cons

"Their threat intelligence platform needs to be broadened. They should integrate it with more threat intelligence platforms. For the threat feed that they get from open intelligence, I would like them to add a few premium threat intelligence platforms. They can provide a bundle in which AlienVault has the threat intelligence background of other premium products."
"I've been told that AlienVault doesn't have a full version of NES running in there, but I'm not sure if that's accurate or if my engineer made it that way. I'm not sure he was completely honest either because we had NES in the environment before. Those tools could be improved because AlienVault is a SIEM, and it added all these other features."
"Support can be slow at times, but the quality is high. Posted knowledge base articles could use improvement."
"The one thing I continue to dislike about the USM is the limitation on reports."
"Its reporting tools need improvements. It would be good if they can provide integration with other ticketing systems. Currently, we only have integration with Slack and Jira. It is also a bit slow, and its replication engine can be improved."
"More complimentary training needs to be done for use with this tool. If you get into a bind, then it will cost you."
"AT&T AlienVault USM can improve searchable data. It should be available for more than 90 days. If you need more than 90 days of data, you have to put a request and they give you raw data, which is not easy to search. A good addition would be to allow users to search data older than 90 days."
"It was easy on PoC, but when we got to the product it was different story. We had to learn the product again and got feeling that the PoC was a different product."
"In vRealize login files, we have limitations regarding log partitions."
"The monitoring landscape is getting bigger. When it comes to infrastructure monitoring, we need more visibility. VMware needs to integrate more related applications and third-party products. That would make it more appealing to an audience beyond the VMware team."
"The dashboard needs to be improved because this is what I need to monitor my infrastructure."
"The pricing of the solution could be improved."
"They should improve their web interface to make it more user-friendly."
"I think that it should be able to integrate with other third-party backup and recovery solutions, more that it does now."
"What I'd like to improve in vRealize Log Insight is the licensing model. VMware provides vRealize Log Insight along with the VMware Cloud Foundation, but customers who would like to go for the native VMware would have to procure vRealize Log Insight separately. Today, vRealize Log Insight is offered on two different licenses, one is based on the number of VMs, and the other is based on the number of physical codes on the machine. If VMware can provide a bundle offer for customers who procure more than ten licenses, where you can have an option to run, for example, three hundred machines on vRealize Log Insight with no extra cost, this would encourage more people to adopt the solution. What I'd like to see in the next release of vRealize Log Insight is for a cloud option to be available, which would be a pay-as-you-go licensing model that would allow me to pick and choose what I'll monitor. For example, I have one thousand and three hundred critical servers, and the seven hundred servers for basic development, I don't want to monitor on vRealize Log Insight today, so I should be able to pick what I need to monitor on the solution and only pay for that specific instance. If VMware can apply these changes, it would help VMware customers to procure more or adopt more of vRealize Log Insight even in smaller projects."
"The tool is expensive."
 

Pricing and Cost Advice

"It allows you to do a lot with a small price tag... The pricing is the best on the market."
"Negotiate the best package for your environment."
"Its price is in the medium to upper range."
"Use an MSSP instead. It is much cheaper."
"QRadar, ArcSight and Splunk are some of the most expensive SIEM products out there in the market and not everyone has the budget to buy them. In such cases, AV USM is a very cost effective alternative."
"AlienVault is certainly not nearly as expensive as Splunk or QRadar. It's decently priced, but I don't have the exact figure."
"It is a product that is priced in a medium range, making it neither a cheap nor a costly product."
"We pay around $12,000 a year including storage."
"Pricing is good because it is part of the suite package. It comes in a bundle for us."
"The license cost for any other monitoring tool is too high compared to this product."
"Pricing could always be lower. If it were free, I would be more satisfied."
"The product's price is reasonable, but when it comes to SQL licensing, it's a bit expensive."
"I am not sure what the exact cost is. However, I believe the vRealize suite costs $2,500.00 per year."
"The licensing cost for vRealize Log Insight is a little higher, so in terms of cost, it all depends upon what kind of environment you have. If you have a complete virtualized environment, or at least you're using a ninety-five percent virtualized environment, then vRealize Log Insight will play a very good role because it is a VMware component, so it has very tight integration with other VMware components and systems. This means you don't have to procure any other monitoring and management tool, and you don't need a separate automation tool. vRealize Log Insight will have an upper hand if your environment is purely virtualized on VMware. If you're using a mix of physical and virtual components, for example, a 50:50 ratio, then you need to have a third-party component to manage overall monitoring."
"The pricing has been updated recently."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Government
8%
Educational Organization
8%
Financial Services Firm
7%
Government
15%
Financial Services Firm
14%
Computer Software Company
14%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about AT&T AlienVault USM?
The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful.
What is your experience regarding pricing and costs for AT&T AlienVault USM?
It is a product that is priced in a medium range, making it neither a cheap nor a costly product.
What needs improvement with AT&T AlienVault USM?
The vulnerability scanning feature is one of the areas where the product has certain shortcomings and needs to improve. The tool has vulnerability scanning, but it is not that efficient. A mobile a...
What do you like most about vRealize Log Insight?
The events are notably more descriptive, aiding in security and event analysis. We've also integrated Sky Collector, providing valuable insights and solutions for troubleshooting.
What is your experience regarding pricing and costs for vRealize Log Insight?
The product's price is reasonable, but when it comes to SQL licensing, it's a bit expensive. So, it's expensive, not extremely expensive. I would rate the pricing a two out of ten, with ten being v...
What needs improvement with vRealize Log Insight?
In terms of vOps, we use templates for optimization to monitor heavy hitters on storage and CPU resources. In the VMware environment, one area for improvement is the handling of VM failovers due to...
 

Also Known As

AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
vRealize Log Insight
 

Learn More

Video not available
 

Overview

 

Sample Customers

Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Wildlands Adventure Zoo, Medic Mobile, IBM, Seventy Seven Energy, Baystate Health, Osis, Oxford University, Columbia University, Siemens, Cardinal Health, Ashdod Port, Vasakronan, Sydney Adventist Hospital, University of Derby
Find out what your peers are saying about USM Anywhere vs. VMware Aria Operations for Logs and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.