No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs Sentinel comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
Sentinel
Ranking in Security Information and Event Management (SIEM)
15th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.2%, down from 3.1% compared to the previous year. The mindshare of Sentinel is 2.7%, down from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Sentinel2.7%
AlienVault OSSIM1.2%
Other96.1%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
PT
Senior Specialist at a tech vendor with 10,001+ employees
Improved incident monitoring has reduced false positives and supports audit-ready reporting
The best features Sentinel offers, in my experience, include the filtering features and the ability to run KQL queries so that I can understand what table has what and when the last log has been monitored and reported. Sentinel has positively impacted my organization by improving monitoring significantly. As a pay-as-you-go service, we are ingesting logs as needed. When the pay-as-you-go service is enabled, we can either ingest whenever there is a spike in the logs, and when there are fewer logs, we can reduce the ingestion. This approach is helpful for both the organization and me. In terms of metrics showing how Sentinel has helped, as part of log filtering, we have reduced around thirty to thirty-five percent of false-positive incident creation. We have also cleared some audits by enabling log retention in Sentinel, allowing us to pull out data for audits when necessary using both hot retention and cold retention. This has helped the organization as a whole.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"There are a lot of people you will find using OSSIM since they are also offering OTX as a service"
"Its user-friendliness is the most valuable. It is very easy to use and explore. The dashboard is very well packaged and integrated. You don't have to spend a lot of time in configuring it and checking out the RPM etc. It is also free and very powerful."
"The most valuable features of AlienVault OSSIM are vulnerability assessment, network intrusion detection system, response to critical events, and awareness of the whole network."
"You can customize the dashboards as well as the reporting."
"Most of the SOC or SIEM enterprise class products are very expensive, whereas with OSSIM you can start out with a smaller setup and then expand as you wish."
"The most valuable feature is the logging capability."
"AlienVault OSSIM's GUI is very user-friendly."
"What I like about this product, is that it is a fully-fledged solution."
"Sentinel has positively impacted my organization by improving monitoring significantly."
"The stability is phenomenal and we never had any issues with downtime or even had to restart."
"One of the most valuable features is the business intelligence engine. It's very important because it keeps track of everything that's happening and alerts us if something is different than expected. The first time I used it, I was shocked at how well it performed. Another valuable feature that I think makes this product worth the price you pay for it is that it connects to basically every system that provides some form of logging, and it's very easy to set up what triggers this."
"If Sentinel is integrated with Identity Manager and User Application Portal, the solution runs simply perfect!"
"It makes everything easier by automating some tasks and growing with our needs."
"Sentinel gave us logs to tell us what's going right and wrong in your environment so we could secure the network."
"The solution lets us get all the logs properly and regularly monitor customer infrastructure."
"Novell SIEM was my second technology of this kind."
 

Cons

"We need more dashboards and we need more customization for dashboards."
"It's under heavy traffic. If you have heavy traffic, the system is slow."
"It's so hard to configure and explore something new on it. It is not easy to find the steps we need to follow in order to use the solution effectively."
"AlienVault OSSIM is costly."
"The user interface could be improved."
"It takes some time. It does not give me a prompt response for any such [malicious] traffic. It takes time to get that alert from the AlienVault system."
"I would advise others to not implement it for any enterprise-level organization."
"The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale."
"The web interface needs to be improved, as it has a java-based way to call its controls."
"The dashboard and customer view should be improved."
"Creating a drag-and-drop dashboard or workbook in Sentinel is a little more complex compared to other tools like LogRhythm and IBM QRadar."
"This product's connection to certain types of cloud systems could be improved. We can do Microsoft, Google, and Amazon, but there are a lot of other things happening in the cloud that we do not connect well enough to. This product could be improved with better connection to cloud-based solutions."
"The solution does not allow outsourced authorizations."
"It's probably not a product that I would recommend to anyone."
"There are still a few vendor-specific devices for which Sentinel needs to work on integration, such as Netskope devices."
"There is no integration in the web-side of the tool."
 

Pricing and Cost Advice

"The tool's licensing costs are yearly."
"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"OSSIM is open source, and USM is the paid license. So, if you want, you can switch to USM. There you will have to buy a license, and they have a support team that helps you out on issues you face."
"I used the paid version of the tool and found it to be expensive. It has been a while since I changed to Securonix. I will have to check whether AlienVault charges per device, user, or log."
"AlienVault OSSIM is expensive compared to its competitors."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"The solution is open source, so it's free to use."
"AlienVault OSSIM is free."
"We receive a pricing discount because of our ongoing partnership with Micro Focus."
"Sentinel is a subscription-based solution."
"Sentinel's slightly on the expensive side."
"Sentinel is moderately priced."
"We inquired about getting support from the vendor, Micro Focus, but the cost was very high."
"The solution’s pricing is aligned with its competitors."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,262 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
15%
Financial Services Firm
8%
University
7%
Manufacturing Company
7%
Outsourcing Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise8
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
What is your primary use case for AlienVault OSSIM?
This solution is very similar to most of the other MSSPs that you would find out there. When I look at use cases, AlienVault was initially aimed at small to medium businesses. It grew, and that was...
What is your experience regarding pricing and costs for NetIQ Sentinel?
My experience with pricing, setup cost, and licensing shows that while it is a little on the higher side, since it is part of a package for all Microsoft products, I feel it is a better choice comp...
What needs improvement with NetIQ Sentinel?
Sentinel needs minimal improvement, though improvements are ongoing. Everything seems to be functioning perfectly, and I don't have any specific inputs for improvements I would like to see in Senti...
What is your primary use case for NetIQ Sentinel?
My main use case for Sentinel is that I'm a subject matter expert for Sentinel, specifically for security incident event and event management. I head the SME for SIEM in LTIMindtree for this curren...
 

Also Known As

OSSIM
NetIQ Sentinel, Novell SIEM
 

Overview

 

Sample Customers

Council Rock School District
Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Find out what your peers are saying about AlienVault OSSIM vs. Sentinel and other solutions. Updated: September 2026.
914,262 professionals have used our research since 2012.