Try our new research platform with insights from 80,000+ expert users
it_user484692 - PeerSpot reviewer
Security Consultant at a tech consulting company with 51-200 employees
Consultant
We have noticed outdated Java and Flash versions due to the snort rules included in the appliance.

What is most valuable?

AlienVault provides excellent visibility into your network by combining centralized logging, host-based IDS and network IDS. This enables me to detect quite a lot of potential issues that have gone through AlienVault's correlation engine and our own policies.

How has it helped my organization?

On several occasions we have detected attacks (DDoS) just as they are starting and have been able to rapidly mitigate them. We have also noticed outdated Java and Flash versions due to the snort rules included in the appliance.

What needs improvement?

The biggest improvement they could do is to provide full support for IPv6 addressing. It currently has quite lightweight support for IPv6 addresses in the sense that it will record the source/destination addresses in all cases, but currently trying to search with IPv6 addresses is not possible and thus makes our lives harder.

For how long have I used the solution?

Including my experience with the previous version (v4) I have two years of professional experience with AlienVault.

Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.

What was my experience with deployment of the solution?

We have not faced any large issues with the deployment.

What do I think about the stability of the solution?

We have not faced any large issues with the stability.

What do I think about the scalability of the solution?

The only issues is related to the volume of alarms in a system - the UI/UX for working with a large mass - starting with several hundred alarms is suboptimal. I am hesitant to mention this as it is easily solved in the future by small UI changes.

How are customer service and support?

All of the bug reports have been sent to AlienVault and have been handled with skill. At least once we got to talk to their experts who worked with us to debug the cases in our environment.

How was the initial setup?

There are many steps, but the steps are not complex. The biggest hurdle in the deployment/setup phase is usually gathering the actual information (assets details, services, policies) about the environment, not the installation itself.

What about the implementation team?

Our team did the implementation. If you have experience implementing a SIEM solution then you can implement this yourselves, otherwise you should get an external team do it. The issue is not with the technical skills needed for the actual implementation, but the knowledge needed to know what to include, what policies to write, and what not to include.

What's my experience with pricing, setup cost, and licensing?

For licensing you will need to contact an AlienVault reseller as it is comprised of (roughly) how many events per second you are processing, how many assets you are adding, and in how many physical locations.

Which other solutions did I evaluate?

I was not part of the process. I have heard that our team had tried other products, but mostly the cost was prohibitive in those alternatives.

What other advice do I have?

As this is a product that will give you a lot of visibility into everything you can throw at it, it is good to note that you should have good working relations with the *people* in charge of the assets you have visibility over (e.g. with network mirroring).

You will get alarms about a plethora of things you couldn't have imagined, things that people have forgotten, that have been misconfigured and that are under attack. You will need to explain the remedies and mitigations to people. And that is possibly the biggest hurdle. This product will not help you if you cannot fix the problems it finds.

It may not have the same abilities as most tools off-the-shelf but it has the best bang for buck. Unless you already have a high-quality SOC operation running, you will be able to handle probably all of your SIEM needs with AlienVault for a few years with a fraction of the price of other more complete solutions.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

thank you for your review!

it_user123747 - PeerSpot reviewer
Chief Security Officer at a financial services firm with 501-1,000 employees
Vendor
​The integration of IDS and OSSEC is valuable as it enables correlation between Network IDS events and host system event logs

What is most valuable?

The integration of IDS and OSSEC is valuable as it enables correlation between Network IDS events and host system event logs.

How has it helped my organization?

AlienVault USM has improved how we manage events and incidents in our infrastructure. With AlienVault we are able to respond to incidents and take necessary action faster than we could before without the solution in place.

What needs improvement?

Some customizations with the integration between AlienVault components have room for improvement and enabling users with WebUI interfaces instead of having to edit configuration files on the system to achieve certain actions would be a good improvement.

For how long have I used the solution?

Three years.

What do I think about the stability of the solution?

No issues with instability has been encountered in our environment.

What do I think about the scalability of the solution?

No issues with scalability has been encountered in our environment.

How are customer service and technical support?

The AlienVault Technical support is good and has helped out several time with some really specific configurations in our environment.

Which solution did I use previously and why did I switch?

We used an outsourced MSSP solution but we needed to get the solution in-house in order to better integrate with our datacenters and systems and comply with financial regulatory and PCI-DSS requirements.

How was the initial setup?

The initial setup was straightforward and quite easy to setup. Requires Linux knowledge to manage but given that we use Linux for our critical infrastructure services it was no problem for us.

What's my experience with pricing, setup cost, and licensing?

We chose AlienVault partly do the the many features and functionalities that was bundled with the product to the pricing and licensing models that was offered. Many other solutions did not have the full spectrum of features but was significantly more expensive so we would have been forced to get additional solutions to cover all our requirements. With AlienVault we got a all-in-one solution that covered our needs.

Which other solutions did I evaluate?

We had a look at the current offerings at that time, including Tripwire, McAfee, SourceFire, etc., but concluded that we would get the best-bang-for-the-bucks with AlienVault solution

What other advice do I have?

As with any Security solution, you still need to have knowledgeable people to manage the solution and the solution is not a silver-bullet that takes care of all your issues without being properly managed. Make sure you have the necessary knowledge and headcount to use the solution before implementing this or any other solution. With Security, the most of the cost is in OPEX, not CAPEX, so make sure you have the necessary expertise to operate the solution as efficiently as possible.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

thanks for your feedback.

Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
it_user752880 - PeerSpot reviewer
Security Analyst at a tech services company with 1-10 employees
User
Its powerful correlation engine helps reduce time in manually correlating events
Pros and Cons
  • "Its powerful correlation engine helps reduce time in manually correlating events."
  • "The only complex area of the setup was writing the custom scripts."
  • "It should be able to communicate with other security solutions to stop threats."

How has it helped my organization?

Its powerful correlation engine helps reduce time in manually correlating events.

What is most valuable?

  • Alarms
  • Correlation

What needs improvement?

It should be able to communicate with other security solutions to stop threats.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

How are customer service and technical support?

Customer Service:

I would rate customer service as a nine out of 10.

Technical Support:

I would rate technical support as a nine out of 10.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

The only complex area of the setup was writing the custom scripts.

What about the implementation team?

We use both a vendor team and an in-house team for implementation.

What was our ROI?

The ROI is quite good.

What's my experience with pricing, setup cost, and licensing?

Use an MSSP instead. It is much cheaper.

Which other solutions did I evaluate?

We did not evaluate other options.

What other advice do I have?

It is quite awesome.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for your time to review AlienVault USM and for your candid feedback!

ICT Consultant at N3tcom
Real User
Highly stable, easy to use, and simple implementation
Pros and Cons
  • "The most valuable features of AT&T AlienVault USM are the ease of management and knowledge of what is on the network of my customers. It's easy to understand the problems, and management our alarms and events."
  • "The price of AT&T AlienVault USM could be reduced."

What is our primary use case?

We are using AT&T AlienVault USM for collecting the events, generating alarms, and events management.

What is most valuable?

The most valuable features of AT&T AlienVault USM are the ease of management and knowledge of what is on the network of my customers. It's easy to understand the problems, and management our alarms and events.

What needs improvement?

The price of AT&T AlienVault USM could be reduced.

For how long have I used the solution?

I have been using AT&T AlienVault USM for approximately two years.

What do I think about the stability of the solution?

I am satisfied with the stability of AT&T AlienVault USM.

I rate the stability of AT&T AlienVault USM a five out of five.

What do I think about the scalability of the solution?

AT&T AlienVault USM is scalable enough for our needs.

How was the initial setup?

The initial setup of AT&T AlienVault USM was easy. Which involved all the configurations of correlation rules, and other elements for customer problems management. The full implementation took approximately two days.

What about the implementation team?

I did the implementation of AT&T AlienVault USM with a colleague.

What's my experience with pricing, setup cost, and licensing?

AT&T AlienVault USM is an expensive solution and we pay for the license and the support separately. We paid for the license and support for three years.

What other advice do I have?

I would recommend this solution to others.

We do not use all the features of the solution.

I rate AT&T AlienVault USM an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
DevOps Engineer at Two Hat Security
Consultant
The vulnerability scanner keeps our environment always updated about security threats

What is our primary use case?

Our initial need which brought us to acquire this solution was to be in compliance with GDPR requirements. Our environment is cloud-based (specifically AWS).

How has it helped my organization?

Beyond provided us with an IDS as was our initial need, but AlienVault gave us more useful resources, as SIEM, and as a vulnerability scanner (the last, one of my favourite resources).

What is most valuable?

My favourite one is the vulnerability scanner because while using it, our environment is always updated about security threats.

What needs improvement?

Taking into account that server access credentials are controlled by the tool, some more management-focused actions could be performed from AlienVault.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Erlon - thank you for your feedback & comments!

PeerSpot user
Network and Security Engineer at a tech services company with 51-200 employees
Real User
It has powerful threat detection, incident response, and compliance management
Pros and Cons
  • "It has powerful threat detection, incident response, and compliance management."
  • "AlienVault has an advanced component within one package. With this, we can cover more area with one solution."
  • "AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive."

What is our primary use case?

AlienVault Unified Security Management (USM) has powerful threat detection, incident response, and compliance management. We can use this across cloud, on-premise and hybrid environments. 

The reason to use USM is that it has the following components in its package: 

  • Asset Discovery
  • Vulnerability Assessment
  • Intrusion Detection
  • Behavioral Monitoring
  • SIEM & Log Management.

How has it helped my organization?

AlienVault has an advanced component within one package. With this, we can cover more area with one solution. 

As a example, it has vulnerability assessment component built-in. From this, we can do the vulnerability assessment easily and we do not have to buy another solution for the vulnerability assessment. It is easy to use and we can take better advantage from an all-in-one solution like USM. 

What is most valuable?

AlienVault USM has a vulnerability assessment feature and only one SIEM feature compared to other SIEM solutions. 

What needs improvement?

AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive.

For how long have I used the solution?

Less than one year.

What other advice do I have?

It is the most valuable tool that I have seen of the SIEM solutions.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner in Sri Lanka.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you Tharaka for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
Head of IT at a consultancy with 201-500 employees
Consultant
We use the HIDS to monitor our servers, which track user account locks and logon failures

What is most valuable?

  • Network monitoring
  • SIEM

How has it helped my organization?

We have much greater visibility in what is happening on our network.

What needs improvement?

Backup, restore, and upgrade - some menu options are a bit convoluted.

For how long have I used the solution?

Six months.

What was my experience with deployment of the solution?

No.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Customer Service:

Excellent, every contact with customer services, support, and training has been superb.

Technical Support:

Excellent - very good, comprehensive, and knowledgeable staff.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

Yes - simple deployment in VM, worked the first time.

What about the implementation team?

In-house.

What was our ROI?

Difficult to answer - specifically, this was a new product for us to increase and improve upon security.

What's my experience with pricing, setup cost, and licensing?

We did market research, web reviews, etc. We spoke to a number of vendors (LogRhythm, etc.), but we felt that AlienVault was the best value and most comprehensive for our organisation's size.

Which other solutions did I evaluate?

Yes, LogRhythm, and Splunk.

What other advice do I have?

We are very happy. The training was excellent, and the interaction with AlienVault is first rate - real leader in customer service, the OTX pulse feature is very useful.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
Security Analyst at a tech services company
Consultant
Quickly got insight into my environment

How has it helped my organization?

Quickly got insight into my environment.

What is most valuable?

Deployment was very easy. I got my servers and devices reporting very quickly.

What needs improvement?

It would be great if there was a feature to add in watch lists, like McAfee or QRadar have -- to keep track of IPs, domain, etc. that I have identified as being malicious.

Also, being able to connect into other TAXII/STIX feeds other than OTX.

How are customer service and technical support?

Customer Service:

Excellent. Customer service was very responsive.

Technical Support:

Excellent. Support was very responsive.

Which solution did I use previously and why did I switch?

Yes, McAfee ESM. Even after upgrading to Version 10, the interface was still hard to navigate through and did not work on every browser. Writing effective rules was difficult.

How was the initial setup?

Very straightforward.

What about the implementation team?

In-house.

What's my experience with pricing, setup cost, and licensing?

Very reasonable and for the value of the product, we couldn't ask for better pricing.

Which other solutions did I evaluate?

We did a SIEM solution comparison with McAfee ESM, IBM QRadar, and Fortinet.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you Tim for your time to review AlienVault USM and for your candid feedback!

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.