Try our new research platform with insights from 80,000+ expert users
PeerSpot user
IT Security Engineer II at a retailer with 5,001-10,000 employees
Vendor
Provides a single pane of glass that shows threats that are in the environment.

What is most valuable?

The dashboard.

How has it helped my organization?

The single pane of glass that shows threats that are in the environment.

What needs improvement?

Sub menus: Sometimes you really have to drill down to get to where you want to go.

For how long have I used the solution?

We have been using this solution for three years.

Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.

What was my experience with deployment of the solution?

I did not encounter any issues with deployment.

What do I think about the stability of the solution?

There were stability issues due to lack of memory.

What do I think about the scalability of the solution?

I did not encounter any issues with scalability.

How are customer service and support?

Customer Service:

I would rate customer service as excellent.

Technical Support:

I would rate technical support as excellent.

Which solution did I use previously and why did I switch?

We did not use a previous solution.

How was the initial setup?

The setup was straightforward.

What about the implementation team?

We did the implementation in-house.

What was our ROI?

The ROI was priceless.

What's my experience with pricing, setup cost, and licensing?

N/A.

Which other solutions did I evaluate?

We used other solutions, but they couldn't compare: QRadar, Splunk, ArcSight and LogRhythm. All were way too expensive compared to AlienVault USM.

What other advice do I have?

All companies should buy an AlienVault SIEM. It is well worth the investment

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Kevin - I appreciate you taking time to provide your feedback on USM.

PeerSpot user
SOC Lead / Sr. SOC Analyst at a tech services company with 501-1,000 employees
MSP
Out of the box features for easy asset discovery, vulnerability scans, IDS setup are all beneficial.

What is most valuable?

AlienVault out of the box features for easy asset discovery, vulnerability scans, IDS setup are all beneficial, but the best feature we find most valuable is the main dashboard for how the information is bubbled up and presented to us.

How has it helped my organization?

With AlienVault we have been able to reduce lag times by not having to invest into specialized research for which we rely on AlienVault Security Labs and OTX (Open Threat Exchange).

What needs improvement?

With all the great features AlienVault has to offer, it would be nice to see improved search query functionality, similar to ELK stack.

For how long have I used the solution?

18 months+

What was my experience with deployment of the solution?

Easy setup out of the box as it comes as a virtual appliance. 

What do I think about the stability of the solution?

Solid platform built on debian system.

What do I think about the scalability of the solution?

Haven't been able to break it yet.

How is customer service and technical support?

5 Stars

Disclosure: My company has a business relationship with this vendor other than being a customer: We are a part of the MSSP program.
PeerSpot user
it_user3405 - PeerSpot reviewer
it_user3405Partner at a tech services company with 51-200 employees
Real User

I would like to see root cause analysis and big data relationships as part of the overall solution.

Also, the query should feed into a larger data matrix of solutions where they feed into machine learning solutions to address the problem - intelligent situational awareness.

See all 2 comments
Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
it_user466524 - PeerSpot reviewer
Senior Infrastructure Analyst at a pharma/biotech company with 1,001-5,000 employees
Vendor
Provides a single way to analyze traffic and threats on our network.

What is most valuable?

Enabling visibility of traffic on our network, merging of multiple systems reporting and analysis and clear method to highlight potential issues.

How has it helped my organization?

Previously we had no single way to analyze traffic and threats on our network, relying instead on multiple, independent systems. We can now correlate reported threats and anomalies to better determine what threats we face.

What needs improvement?

The configuration is somewhat complex and the interface a bit non-intuitive. Whilst very useful for reporting, interpretation of the results can be difficult: improved features to help with this would be welcome.

For how long have I used the solution?

I've been using it for six months.

What do I think about the stability of the solution?

We’ve had 100% uptime since installation.

What do I think about the scalability of the solution?

We have not had any requirements to change the scope of the installation since first deployment.

How are customer service and technical support?

Good. Initial help with deployment was excellent, and the facility to create a tunnel for tech support personnel to troubleshoot system is very useful.

Which solution did I use previously and why did I switch?

We didn't have anything like AlienVault previously.

How was the initial setup?

It's fairly complex. There is quite a bit of additional config required in order to get the most from the system. A base config allows for monitoring, but to get the most, you need to add plugins for various systems on your network: this config is somewhat complex and requires a good knowledge of how AV works.

What's my experience with pricing, setup cost, and licensing?

Unless you have a small network, you really need the unlimited endpoint license, which is the most expensive option. Best to negotiate to get this version, otherwise scalability will be an issue (unless your total number of endpoints in under approx. 100).

Which other solutions did I evaluate?

We also looked at Tripwire.

What other advice do I have?

The initial onboarding during the trial period, including assisted setup, was most useful. Ensure you get the most from this, as if you require further setup assistance, it comes under (paid-for) professional services. AV is a very useful tool, but must be configured correctly in order to get the most out of it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Alan - thank you for your thoughtful feedback & comments.

Sales Solutions Engineer at a tech services company with 201-500 employees
Reseller
Easy to deploy and flexible enough to create your own plugins
Pros and Cons
  • "This solution can identify many threats inside the organization (compromised endpoints, configuration issues), as well as "outside" threats (botnets, network scanners, web-attacks, etc)."
  • "It would be nice to see some machine learning and monitoring of the configuration in network devices."

What is our primary use case?

The primary use cases for this solution are log management, security events correlation, and any other enterprise use cases for SIEM (new plugins development, correlation rules development, risk assessment, and asset management).

How has it helped my organization?

This solution can identify many threats inside the organization, like compromised endpoints, configuration issues, as well as "outside" threats (botnets, network scanners, web-attacks, etc). During the first two weeks post-deployment, our client's cybersecurity certainly improves by using AT&T AlienVault USM.

What is most valuable?

The features that we have found most valuable are the out-of-box vulnerability scanner, Network IDS, Host IDS, Netflow Monitoring, and more than four thousand pre-installed correlation rules.

What needs improvement?

Having automatic agent deployment would be a great feature. It would be nice to see some machine learning and monitoring of the configuration in network devices.

For how long have I used the solution?

One to three years.

How was the initial setup?

This solution is very easy to deploy and integrates comfortably with data sources. AT&T AlienVault USM has a user-friendly engine for custom plugins development, so you can develop your own plugin for your own application without any problems.

Disclosure: My company has a business relationship with this vendor other than being a customer: Aurhorized distributor
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Denys - I appreciate your time & feedback!

PeerSpot user
CEO at a tech services company with 1-10 employees
Reseller
Enabled us to create an SOC on a budget with smaller than usual staff requirements
Pros and Cons
  • "The AlienVault solution has enabled us to create a SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers."
  • "We would like more plugins. This being the main point of improvement which would benefit the users."

What is our primary use case?

As a cyber security company, we have used AlienVault to set the foundations of our security solutions offerings.

Giving our customers all the services that they require via a single console environment, either self-managed or managed by ourselves, enabling companies with little to no IT department to have an all-in-one security compliance and reporting solution.

How has it helped my organization?

The AlienVault solution has enabled us to create an SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers.

What is most valuable?

The below features are what make the solution so powerful, particularly saving time and money (most importantly):
  • Real-time email alerts
  • Event correlations
  • Log management
  • System monitoring
  • Network monitoring
  • Uptime monitoring
  • OTX threat intelligence
  • Vulnerability scanning/reporting
  • Compliance reporting

What needs improvement?

All products have room for improvement. AlienVault is always looking at ways to improve their solution. 

We would like more plugins. This being the main point of improvement which would benefit the users.

For how long have I used the solution?

Less than one year.
Disclosure: My company has a business relationship with this vendor other than being a customer: MSSP/Reseller
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you Scott for your time to review AlienVault USM and for your candid feedback!

Vendor
We haven't suffered a true breach, but it has helped identify weaknesses.

What is most valuable?

SIEM capabilities, vulnerability scanning, asset discovery/management features.

How has it helped my organization?

Increased visibility, threat detection.

What needs improvement?

The web UI can be clunky at times, with poor error handling. Updates need more QC before release.

For how long have I used the solution?

One year.

What was my experience with deployment of the solution?

Deployment has always been smooth.

What do I think about the stability of the solution?

No, it has been quite stable.

What do I think about the scalability of the solution?

Nothing except for networking challenges.

How are customer service and technical support?

Customer Service:

Seven out of 10.

Technical Support:

Seven out of 10. First level of support is hit and miss, but higher level support technicians are great.

Which solution did I use previously and why did I switch?

No, we started with OSSIM and then bought USM.

How was the initial setup?

Very straightforward if you're prepared. Just deploy the OVA template and follow the instructions and you're up in less than an hour.

What about the implementation team?

In-house.

What was our ROI?

I can't say.

What's my experience with pricing, setup cost, and licensing?

The asset licenses are misleading. You can have as many as you want in AV and have NIDS work on all of them. The limit is more about logs and plugins for the assets.

Which other solutions did I evaluate?

No.

What other advice do I have?

It's a good solution and has a promising future.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
IT Security Analyst at a tech services company with 10,001+ employees
Real User
Report modules now allow us to get a visualization of the activity of the main assets.
Pros and Cons
  • "OTX is a great module that lets staff maintain and monitor updates regarding events in the infrastructure and takes decision to improve the security perimeter."

    What is most valuable?

    OTX is a great module that lets staff maintain and monitor updates regarding events in the infrastructure and takes decision to improve the security perimeter.

    How has it helped my organization?

    Report modules now allows us to get a visualization of the activity of the main assets to continue the business and lets us take decisions to the stakeholders.

    What needs improvement?

    Report modules now lets us get a visualization of the activity of the main assets to continue to improve the business and reduce the risk of failures.

    For how long have I used the solution?

    Around 2 years ago and It allowed me to grow not only technologically but also it has helped me to improve process in attention to information security events in the company.

    What was my experience with deployment of the solution?

    Yes, but it was with integration with other devices but the AlienVault TAC did a great job to resolve the problems.

    What do I think about the stability of the solution?

    Honestly this solution was very stable and there were no problems whatsoever

    What do I think about the scalability of the solution?

    I have not had the opportunity to do an implementation of scalability, but, with the experience with 2 years ago managed the solution, I don't believe we will have problems to deploy.

    How is customer service and technical support?

    Customer Service:

    The service was excellent and always showing excellent treatment and availability.

    Technical Support:

    The service is excellent the support requested really is quick and very efficient

    How was the initial setup?

    It was way very fast and straightforward, thanks to the great supported gave fot the AlienVault TAC

    What about the implementation team?

    This integration was made with both teams, and I think the deploy was very easy due the great knowledge of vendor team, them gave us a great explanation about of the all modules and the best practice to deploy the solutions.

    What was our ROI?

    It has not yet been measured.

    What's my experience with pricing, setup cost, and licensing?

    Considering the scalability with the other solutions in the market, I think this solution really have a great price to all size of medium and big enterprise.

    Which other solutions did I evaluate?

    Yes, I did, the solution considered was HPE and Splunk

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    Thank you Ruben for your comments & insightful feedback!

    it_user672663 - PeerSpot reviewer
    Information Security Analyst at a insurance company
    Vendor
    Some of the valuable features are log aggregation, correlation, and threat intel.

    What is most valuable?

    Log aggregation, correlation, and threat intel.

    How has it helped my organization?

    AlienVault has streamlined our security functions by combining several different functions into one package.

    What needs improvement?

    I think expanding their vendor-specific plugins would beneficial.

    For how long have I used the solution?

    We have been using this solution for one year.

    What was my experience with deployment of the solution?

    I did not encounter any issues with deployment.

    What do I think about the stability of the solution?

    I did not encounter any issues with stability.

    What do I think about the scalability of the solution?

    I did not encounter any issues with scalability.

    How are customer service and technical support?

    Customer Service:

    Their support is good and their response time is prompt.

    Technical Support:

    I would rate them as very knowledgeable.

    Which solution did I use previously and why did I switch?

    We did not use a previous solution.

    How was the initial setup?

    It was very straightforward. The setup was basically install the VM, setup network monitoring/syslog, and watch the data flow.

    What about the implementation team?

    Our implementation was in-house.

    What was our ROI?

    It's hard to calculate ROI on a prevention mechanism, as the variables of a prevented incident are unknown.

    What's my experience with pricing, setup cost, and licensing?

    They are very affordable and flexible in their licensing model.

    Which other solutions did I evaluate?

    We evaluated HPE ArcSight, IBM QRadar, LogRhythm, Splunk, and SolarWinds.

    What other advice do I have?

    I would highly recommend the customer training courses. They are very helpful.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at AlienVault
    Real User

    thank you for your time and your comments.

    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2024
    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.