Try our new research platform with insights from 80,000+ expert users
ICT Consultant at N3tcom
Real User
Responsive support, helpful vulnerability assessment, and useful network awareness
Pros and Cons
  • "The most valuable features of AlienVault OSSIM are vulnerability assessment, network intrusion detection system, response to critical events, and awareness of the whole network."
  • "AlienVault OSSIM on-premise version is more difficult to implement than the cloud version. Additionally, they should add integration between several different environments at once and improve their online knowledge base."

What is our primary use case?

I use AlienVault OSSIM for the protection of our customers and to find critical events. 

There are two different versions of AlienVault OSSIM, one is on-premise and the other is cloud.

What is most valuable?

The most valuable features of AlienVault OSSIM are vulnerability assessment, network intrusion detection system, response to critical events, and awareness of the whole network.

What needs improvement?

AlienVault OSSIM on-premise version is more difficult to implement than the cloud version. Additionally, they should add integration between several different environments at once and improve their online knowledge base.

For how long have I used the solution?

I have been using AlienVault OSSIM for three years.

Buyer's Guide
AlienVault OSSIM
November 2024
Learn what your peers think about AlienVault OSSIM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.

What do I think about the stability of the solution?

The older versions of AlienVault OSSIM were not stable, but the latest version was better.

I rate the stability of AlienVault OSSIM a four out of five.

What do I think about the scalability of the solution?

I rate the scalability of AlienVault OSSIM a four out of five.

We have three people who use this solution in my company.

How are customer service and support?

The support from AlienVault OSSIM is good, they are responsive.

I rate the support from AlienVault OSSIM a five out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of AlienVault OSSIM was easy. However, I have many years of experience in the field of network administration. The process took one day to complete.

What about the implementation team?

We did the implementation of AlienVault OSSIM, we are all certified. We have five engineers that did the implementation of the solution.

What's my experience with pricing, setup cost, and licensing?

The price of AlienVault OSSIM is too high sometimes for us to present to our customers. The price should be lower. We are on a three-year license to use the solution. We had to pay extra for the support.

What other advice do I have?

We have two people that do the maintenance for the solution.

I rate AlienVault OSSIM an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer735291 - PeerSpot reviewer
HEAD OF ENGINEERING at a insurance company with 201-500 employees
Real User
Top 20
Stable, scalable, and useful reporting
Pros and Cons
  • "The paid version of the solution has reporting and better scalability options."
  • "When comparing AlienVault OSSIM to other solutions it looks a bit outdated. Additionally, they need to improve their integration."

What is our primary use case?

I have deployed AlienVault OSSIM in a couple of small environments for monitoring.

What is most valuable?

The paid version of the solution has reporting and better scalability options.

What needs improvement?

When comparing AlienVault OSSIM to other solutions it looks a bit outdated. Additionally, they need to improve their integration.

For how long have I used the solution?

I have been using AlienVault OSSIM for approximately seven years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The free version is lacking some of the scalability options.

Which solution did I use previously and why did I switch?

I have used QRadar and ArcSight.

How was the initial setup?

The configuration of the solution is difficult. There are videos we can watch but we do not have time to watch videos. We want there to be better documentation that we can use.

What's my experience with pricing, setup cost, and licensing?

We are using a free version of the solution. If you purchase a license there are more features available but the price is a little high. The solution should be cheaper to allow more customers to be able to afford it.

Which other solutions did I evaluate?

I have evaluated ELK Stack and Security Onion.

What other advice do I have?

I rate AlienVault OSSIM an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
AlienVault OSSIM
November 2024
Learn what your peers think about AlienVault OSSIM. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,562 professionals have used our research since 2012.
reviewer2401791 - PeerSpot reviewer
ICT Support Analyst at a tech services company with 1-10 employees
Real User
Top 20
Has a robust threat intelligence feature along with efficient asset grouping functionality
Pros and Cons
  • "It has helped us remediate threats in the past by providing significant events that assisted in identifying suspicious activities, such as logins from multiple countries."
  • "I suggest more in-built rules based on modern threats and environments to make it a more competitive solution."

What is our primary use case?

The primary use case is threat detection. We have configured various rules to monitor the environment for any suspicious activity.

What needs improvement?

Collecting logs can sometimes be tedious, especially compared to my experience with Microsoft Sentinel.

I suggest more in-built rules based on modern threats and environments to make it a more competitive solution.

For how long have I used the solution?

I have been using AlienVault OSSIM for six months.

What other advice do I have?

I find the overall threat intelligence feature robust and the asset grouping feature, allows us to correlate events with entire asset groups.

It has helped us remediate threats in the past by providing significant events that assisted in identifying suspicious activities, such as logins from multiple countries.

The asset discovery functionality, once set up, automatically identifies all devices on the network. It aids compliance efforts and helps us understand the network's device landscape.

While integration is possible with other tools like EDR and Cisco Office 365 Defender ATP, it is not as fast or easy as integrating with Microsoft products.

I recommend it, particularly for medium to large companies with complex IT infrastructures.

Overall, I rate the product an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
PeerSpot user
Development Manager at a tech services company with 51-200 employees
Real User
A free solution with an easy installation, but the system is slow
Pros and Cons
  • "The initial setup was straightforward. I didn't have any problems."
  • "It's under heavy traffic. If you have heavy traffic, the system is slow."

What is our primary use case?

I primarily use the solution for securing my traffic and the SIEM.

What is most valuable?

The fact that it is free is the most valuable aspect of the solution.

What needs improvement?

It's under heavy traffic. If you have heavy traffic, the system is slow. 

For how long have I used the solution?

I've been using the solution for two years.

What do I think about the scalability of the solution?

The scalability of the solution is okay. We have about 100 users right now.

How are customer service and technical support?

Technical support is fine, but if you have a problem, for example, if you have to decode or fix some bugs, you have to manage it yourself.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

The initial setup was straightforward. I didn't have any problems.

What about the implementation team?

I implemented the solution myself.

What's my experience with pricing, setup cost, and licensing?

The solution is free to use.

Which other solutions did I evaluate?

We didn't evaluate other options before choosing this solution.

What other advice do I have?

The installation is easy, but it's not very compatible with some of our other solutions. Still, it's okay, it's very good. It integrates well with ELK.

I would rate the solution six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1140594 - PeerSpot reviewer
Director at a tech services company with 51-200 employees
Real User
Very good out-of-the-box, pre-integrated features, which save us time
Pros and Cons
  • "Inbuilt IDS, inbuilt integration with threat intelligence platform and with vulnerability assessment modules."
  • "Lacking in depth of reporting."

What is our primary use case?

This product would typically be used by a client who would be looking at dipping his feet into the SIEM space and understanding how to go about setting up an SOC without putting in a large up-front investment. I'm the director of our company and we are partners with AlienVault. 

What is most valuable?

The solution offers great models with good integration and this is one of the out-of-the-box features which you're able to easily enable and get it up and running. It's a big plus for the product, because you don't have to bother your head about doing the integrations.

Other good features include an inbuilt IDS, an inbuilt integration with their own threat intelligence platform which is the OTX, and integration with the vulnerability assessment modules.

What needs improvement?

I believe this solution still has a way to go. From a management console perspective and the maturity of the dashboards, I would probably put it slightly behind some of the other players that have been in the market for ages. The leading vendors of SIEM already have a very mature user interface with evolved dashboards and reporting mechanisms. There is a lot of depth in that, but not everybody is looking for that. If your requirements are functional and you're looking for something that's easily deployable and simple to understand and manage, without the necessity of a very large team, I would choose this solution. 

An additional feature I'd like to see would be an increase in the depth of reporting. IBM has AI enabled dashboards which are supposed to be intuitive. They are difficult to configure and that's a problem, but they are very rich in terms of the information that they provide. There is a lot of granular detail and different ways in which you can slice and dice and present the same data. I would also like to see the product handle larger scale deployments and more third party integrations.

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

This is a stable solution. 

What do I think about the scalability of the solution?

It's scalable, but AlienVault is not an enterprise class solution in the sense that it cannot go beyond 15000 EPS, which limits the market that it can address. That's a drawback, but expansion might not be what the company wants and they're happy to remain in the 2000 to 3000 EPS range, in which case it's a great product for its market. 

How are customer service and technical support?

We don't use the support very much as we manage to deal with most issues in-house. The technical support they provide is okay. We haven't had too many problems but my reference point might be slightly slanted, because we don't have such a large installed base.

How was the initial setup?

The initial setup is relatively straightforward and doesn't take much time. AlienVault has its own vulnerability module and its own OTX feed. All of these are pre-integrated which makes for a speedy deployment. The issue is that these days nobody employs SIEM alone. It needs to be able to correlate information not only from its own data sources, but also from third-party data sources, like vulnerability tools, like threat intelligence feeds, like forensic data, and these third party integrations add to implementation time. Each situation is different and deployment time depends on the scale of the infrastructure. 

What other advice do I have?

Most of the SOC or SIEM enterprise class products are very expensive, whereas with OSSIM you can start out with a smaller setup and then expand as you wish. It's great because you get a pre-integrated, ready to run platform, which you can deploy. You don't have to bother about the integrations too much. This platform provides an adequate level of experience for that kind of an integrated intelligence gathering in any IT setup at a reasonable cost. It makes the entry easier for somebody who's not so well versed in these technologies and so on. I think that's the principal use case for AlienVault's product line.

Make sure to choose the right partner to do the implementation. It's important that they know and understand the technology. They should have a very good understanding of the tool as well as an understanding of the security and operations space so that they are able to deliver on what you want to achieve as an outcome. 

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Head of Infrastructure at Pearl Data Direct
Real User
Community forums provide good support, but it is not user-friendly and the correlation engine needs improvement
Pros and Cons
  • "The most valuable feature is the logging capability."
  • "The correlation engine needs to be improved."

What is our primary use case?

We are using this solution for collecting logs. We are not correlating or assessing any user behavior analytics (UBA). 

What is most valuable?

The most valuable feature is the logging capability.

What needs improvement?

The correlation engine needs to be improved.

The interface is not user-friendly, which is an area for improvement.

For how long have I used the solution?

I have been using this solution for one year.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

This is certainly a scalable product.

How are customer service and technical support?

The Community version does not have any technical support.

We have been able to resolve some issues through the community forums.

Which solution did I use previously and why did I switch?

Previously, we did not use another similar product.

What's my experience with pricing, setup cost, and licensing?

We are using the community version, which can be used for free.

Which other solutions did I evaluate?

We have decided to implement a fully-featured SIEM solution that has all of the features, including UBA.

What other advice do I have?

Because we are using the community version, we were unable to explore features such as behavior analytics.

I would rate this solution a five out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AlienVault OSSIM Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free AlienVault OSSIM Report and get advice and tips from experienced pros sharing their opinions.