Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Network and Security Engineer at a tech services company with 11-50 employees
Real User
We are able to get alerts perfectly with FIM and VA features
Pros and Cons
  • "This is a USM, so being able to get all the features under one roof makes it a good product with good new features."
  • "We are able to get alerts perfectly with FIM and VA features."
  • "Pay attention to false-positive event automatic correlations."

What is our primary use case?

This has an OTX feed. With it, we are able to get notifications about every incident that happens.

By forwarding device logs, we are able to get alerts perfectly with FIM and VA features.

How has it helped my organization?

We are the Partners in Sri Lanka. We are doing deployments in Sri Lanka, Maldives, and Bangladesh. 

This is a USM, so being able to get all the features under one roof makes it a good product with good new features.

What is most valuable?

Unified Security Manager (USM). In every SIEM, having only SIEM features (log management, alerting, notifications, etc.) is typical. Here we can get file integrity monitoring and a vulnerability assessment tool together with SIEM

I have never seen a tool like this.

What needs improvement?

The Log Management and configuration of email notifications should be user-friendly. Pay attention to false-positive event automatic correlations. 

Buyer's Guide
USM Anywhere
November 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.

Yes.

60.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No, we did not have issues with stability.

What do I think about the scalability of the solution?

No, we did not have issues with scalability.

How are customer service and support?

Good. They have technically fluent engineers there.

Which solution did I use previously and why did I switch?

Yes. We switched because this is a USM (SIEM, FIM, and VA tool in one product) and the price.

How was the initial setup?

The initial setup is straightforward, but some features are little bit difficult.

What about the implementation team?

We are the partners in Sri Lanka. Therefore, we are directly involved with implementations.

What's my experience with pricing, setup cost, and licensing?

It has good pricing.

Which other solutions did I evaluate?

We evaluated EventTracker.

What other advice do I have?

Our customers have good references about AlienVault.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are partners in Sri Lanka
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you Kalana for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
IT Security Analyst at a tech services company with 10,001+ employees
Real User
Report modules now allow us to get a visualization of the activity of the main assets.
Pros and Cons
  • "OTX is a great module that lets staff maintain and monitor updates regarding events in the infrastructure and takes decision to improve the security perimeter."

    What is most valuable?

    OTX is a great module that lets staff maintain and monitor updates regarding events in the infrastructure and takes decision to improve the security perimeter.

    How has it helped my organization?

    Report modules now allows us to get a visualization of the activity of the main assets to continue the business and lets us take decisions to the stakeholders.

    What needs improvement?

    Report modules now lets us get a visualization of the activity of the main assets to continue to improve the business and reduce the risk of failures.

    For how long have I used the solution?

    Around 2 years ago and It allowed me to grow not only technologically but also it has helped me to improve process in attention to information security events in the company.

    What was my experience with deployment of the solution?

    Yes, but it was with integration with other devices but the AlienVault TAC did a great job to resolve the problems.

    What do I think about the stability of the solution?

    Honestly this solution was very stable and there were no problems whatsoever

    What do I think about the scalability of the solution?

    I have not had the opportunity to do an implementation of scalability, but, with the experience with 2 years ago managed the solution, I don't believe we will have problems to deploy.

    How is customer service and technical support?

    Customer Service:

    The service was excellent and always showing excellent treatment and availability.

    Technical Support:

    The service is excellent the support requested really is quick and very efficient

    How was the initial setup?

    It was way very fast and straightforward, thanks to the great supported gave fot the AlienVault TAC

    What about the implementation team?

    This integration was made with both teams, and I think the deploy was very easy due the great knowledge of vendor team, them gave us a great explanation about of the all modules and the best practice to deploy the solutions.

    What was our ROI?

    It has not yet been measured.

    What's my experience with pricing, setup cost, and licensing?

    Considering the scalability with the other solutions in the market, I think this solution really have a great price to all size of medium and big enterprise.

    Which other solutions did I evaluate?

    Yes, I did, the solution considered was HPE and Splunk

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Thank you Ruben for your comments & insightful feedback!

    Buyer's Guide
    USM Anywhere
    November 2024
    Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
    824,067 professionals have used our research since 2012.
    PeerSpot user
    IT Security Engineer II at a retailer with 5,001-10,000 employees
    Vendor
    Provides a single pane of glass that shows threats that are in the environment.

    What is most valuable?

    The dashboard.

    How has it helped my organization?

    The single pane of glass that shows threats that are in the environment.

    What needs improvement?

    Sub menus: Sometimes you really have to drill down to get to where you want to go.

    For how long have I used the solution?

    We have been using this solution for three years.

    What was my experience with deployment of the solution?

    I did not encounter any issues with deployment.

    What do I think about the stability of the solution?

    There were stability issues due to lack of memory.

    What do I think about the scalability of the solution?

    I did not encounter any issues with scalability.

    How are customer service and technical support?

    Customer Service:

    I would rate customer service as excellent.

    Technical Support:

    I would rate technical support as excellent.

    Which solution did I use previously and why did I switch?

    We did not use a previous solution.

    How was the initial setup?

    The setup was straightforward.

    What about the implementation team?

    We did the implementation in-house.

    What was our ROI?

    The ROI was priceless.

    What's my experience with pricing, setup cost, and licensing?

    N/A.

    Which other solutions did I evaluate?

    We used other solutions, but they couldn't compare: QRadar, Splunk, ArcSight and LogRhythm. All were way too expensive compared to AlienVault USM.

    What other advice do I have?

    All companies should buy an AlienVault SIEM. It is well worth the investment

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Kevin - I appreciate you taking time to provide your feedback on USM.

    Sales Solutions Engineer at a tech services company with 201-500 employees
    Reseller
    Easy to deploy and flexible enough to create your own plugins
    Pros and Cons
    • "This solution can identify many threats inside the organization (compromised endpoints, configuration issues), as well as "outside" threats (botnets, network scanners, web-attacks, etc)."
    • "It would be nice to see some machine learning and monitoring of the configuration in network devices."

    What is our primary use case?

    The primary use cases for this solution are log management, security events correlation, and any other enterprise use cases for SIEM (new plugins development, correlation rules development, risk assessment, and asset management).

    How has it helped my organization?

    This solution can identify many threats inside the organization, like compromised endpoints, configuration issues, as well as "outside" threats (botnets, network scanners, web-attacks, etc). During the first two weeks post-deployment, our client's cybersecurity certainly improves by using AT&T AlienVault USM.

    What is most valuable?

    The features that we have found most valuable are the out-of-box vulnerability scanner, Network IDS, Host IDS, Netflow Monitoring, and more than four thousand pre-installed correlation rules.

    What needs improvement?

    Having automatic agent deployment would be a great feature. It would be nice to see some machine learning and monitoring of the configuration in network devices.

    For how long have I used the solution?

    One to three years.

    How was the initial setup?

    This solution is very easy to deploy and integrates comfortably with data sources. AT&T AlienVault USM has a user-friendly engine for custom plugins development, so you can develop your own plugin for your own application without any problems.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Aurhorized distributor
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Denys - I appreciate your time & feedback!

    PeerSpot user
    DevOps Engineer at Two Hat Security
    Consultant
    The vulnerability scanner keeps our environment always updated about security threats

    What is our primary use case?

    Our initial need which brought us to acquire this solution was to be in compliance with GDPR requirements. Our environment is cloud-based (specifically AWS).

    How has it helped my organization?

    Beyond provided us with an IDS as was our initial need, but AlienVault gave us more useful resources, as SIEM, and as a vulnerability scanner (the last, one of my favourite resources).

    What is most valuable?

    My favourite one is the vulnerability scanner because while using it, our environment is always updated about security threats.

    What needs improvement?

    Taking into account that server access credentials are controlled by the tool, some more management-focused actions could be performed from AlienVault.

    For how long have I used the solution?

    Less than one year.
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Erlon - thank you for your feedback & comments!

    kr1spy84 - PeerSpot reviewer
    Security Systems Administrator at VERTICAL SCREEN, INC
    User
    We develop additional rules and scripts to make it more usable. It provides a checklist answer when using SIEM. I believe we are on the verge of outgrowing this platform.
    Pros and Cons
    • "AlienVault provides a checklist answer when using SIEM."
    • "We develop additional rules and scripts to make it more usable."

    What is our primary use case?

    This is a jack of all trades (master of none) SIEM/IDS/vulnerability management/OSSEC/NetFlow solution. We use it primarily as a SIEM and IDS solution.

    How has it helped my organization?

    AlienVault provides a checklist answer when using SIEM. We currently develop additional rules and scripts to make it more usable, but the overall solution is lackluster.

    What is most valuable?

    IDS is a nice capability to have. In the past, I have implemented standalone Suricata sensors and having this bundled in is very helpful. OTX is good when implemented correctly.

    What needs improvement?

    Many of the tasks on features are useless in our situation. NetFlow is worthless.  Many of the built-in correlation engine solutions are just okay.

    For how long have I used the solution?

    One to three years.

    What's my experience with pricing, setup cost, and licensing?

    The vulnerability management solution is worse than buying a Nessus Professional license.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Hi I'm the Customer Programs Manager here at AlienVault and would like to first say "thank you" for taking time to provide your candid feedback in the product review. I'd like to get a conversation going between you and our team here to see if we can resolve some of the issues you've raised in your review. If you're open to it, please reach out to me at tandrews@alienvault.com and I"ll be happy to set up a call with the appropriate team(s) to discuss. Thank you in advance for your time and consideration.

    PeerSpot user
    CEO at a tech services company with 1-10 employees
    Reseller
    Enabled us to create an SOC on a budget with smaller than usual staff requirements
    Pros and Cons
    • "The AlienVault solution has enabled us to create a SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers."
    • "We would like more plugins. This being the main point of improvement which would benefit the users."

    What is our primary use case?

    As a cyber security company, we have used AlienVault to set the foundations of our security solutions offerings.

    Giving our customers all the services that they require via a single console environment, either self-managed or managed by ourselves, enabling companies with little to no IT department to have an all-in-one security compliance and reporting solution.

    How has it helped my organization?

    The AlienVault solution has enabled us to create an SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers.

    What is most valuable?

    The below features are what make the solution so powerful, particularly saving time and money (most importantly):
    • Real-time email alerts
    • Event correlations
    • Log management
    • System monitoring
    • Network monitoring
    • Uptime monitoring
    • OTX threat intelligence
    • Vulnerability scanning/reporting
    • Compliance reporting

    What needs improvement?

    All products have room for improvement. AlienVault is always looking at ways to improve their solution. 

    We would like more plugins. This being the main point of improvement which would benefit the users.

    For how long have I used the solution?

    Less than one year.
    Disclosure: My company has a business relationship with this vendor other than being a customer: MSSP/Reseller
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Thank you Scott for your time to review AlienVault USM and for your candid feedback!

    PeerSpot user
    Head of MSS Platform and Product Management at a tech services company with 51-200 employees
    Consultant
    Allows for a lot of out-of-the-box features but it does not have APIs
    Pros and Cons
    • "It allows for a lot of out-of-the-box features: vuln scanning, HIDS/HIPS, and IDS."
    • "Asset discovery seems to be good."
    • "It would be hard for any legitimate MSSP to use it."

    What is our primary use case?

    • Supporting an MSSP.
    • Supporting clients with minimum on-premise install.
    • We are rolling out a USM appliance.

    How has it helped my organization?

    It allows for a lot of out-of-the-box features: vuln scanning, HIDS/HIPS, and IDS. The Suricata rule set is pretty lame

    What is most valuable?

    Asset discovery seems to be good. Nice that everything is bundled.  

    What needs improvement?

    Scaling, and it has no APIs! 

    It would be hard for any legitimate MSSP to use it.  

    For how long have I used the solution?

    Still implementing.

    What's my experience with pricing, setup cost, and licensing?

    The price point is good.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Thank you Brian for your time to review AlienVault USM and for your candid feedback! If you'd like to set up some time to speak with the team about the issues you've raised, I'd be happy to facilitate that on your behalf. Please reach out to me at: tandrews@alienvault.com. Thank you in advance for your time and consideration!

    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
    Updated: November 2024
    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.