- Correlation
- Customization
InfoSec at a tech services company with 1,001-5,000 employees
Cost effective solution.
AlienVault is a full featured cost effective SIEM that provides quality threat intelligence for a lot less than the competition. I knocked off a point [from my rating] for the learning curve compared to some of the competition and another point for the lack of native user behavior analytics but for the money you really can't do any better.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a tech company with 51-200 employees
It has a lot of capabilities, but make sure there’s someone that can devote daily time to it.
What is most valuable?
How has it helped my organization?
No, but that’s not really their fault, rather ours. I think this has a lot of valuable functions that really could be leveraged quite nicely.
What needs improvement?
They have the advantage of having a large community that uses the free version, and they really could use this as a sort of beta testing population for new releases. Yet, a lot of the releases break things that are used. I think they need to do more QA before releases. For example, I have custom rules written for the Suricata function. Some releases ago, there was a code change and now every single update requires that I reinstall the custom rules, and I am still waiting for the fix. They need to either stop allowing customization (which would be a mistake) or they need to embrace that a majority of their customer base does this and put in safe guards. I understand putting in limits to what’s supported, but simple things like this are part of the appeal of the product. Another example is that a few releases back, they broke the Nagios availability monitoring portion. All the functionality to watch your systems is there, and of course, I used it. When it broke, support told me it was really only meant to watch the AlienVault system itself, yet the entire interface is there, the options to enable the monitoring on hosts is there. I believe, first of all, that what I was told was wrong as availability monitoring is one of the core functions AlienVault touts, and secondly, that they need to be more careful with testing before releasing updates. It took like twp more updates before the functionality was restored.
For how long have I used the solution?
I've used it for three years.
What do I think about the stability of the solution?
Some, but they are hard to pin down. This is a system that has a lot of things that can stop working, and unless you are paying close attention, to the background processes, you would never realize it.
How are customer service and technical support?
Some people are excellent, and others not so much. They also seem to sometimes have conflicting information. I often rely more on the community for answers than I do on support, depending on the issue.
Which solution did I use previously and why did I switch?
We didn't have anything in place previously.
How was the initial setup?
We had a consultant that was provided by AlienVault, which was great. Otherwise, it would have been a little confusing and though they have made improvements in the documentation, it was horrible initially.
What's my experience with pricing, setup cost, and licensing?
Fair for all of the capabilities it has.
Which other solutions did I evaluate?
We looked at some but I can't remember which ones.
What other advice do I have?
It has a lot of capabilities, but make sure there’s someone that can devote daily time to it and that there is buy in from all segments, or a majority of the capabilities become pointless.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
USM Anywhere
November 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
824,067 professionals have used our research since 2012.
Director of Information Technology at a healthcare company with 51-200 employees
Simplified log analysis and log management.
Valuable Features
Alerts derived from logs.
Improvements to My Organization
Simplified log analysis and log management.
Room for Improvement
More information about what the alerts mean and how they are derived would be useful when determining their significance. Support is good to provide this information though.
Use of Solution
>12 months
Stability Issues
No.
Customer Service and Technical Support
Excellent.
Initial Setup
Fairly straightforward. It does take some time to tune the system to your environment – to prevent getting alerts on activity your find acceptable in your environment.
Pricing, Setup Cost and Licensing
They do give discounts towards the end of quarters if your renewal is due.
Other Advice
You will wonder how you lived without it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
ICT Consultant at N3tcom
Highly stable, easy to use, and simple implementation
Pros and Cons
- "The most valuable features of AT&T AlienVault USM are the ease of management and knowledge of what is on the network of my customers. It's easy to understand the problems, and management our alarms and events."
- "The price of AT&T AlienVault USM could be reduced."
What is our primary use case?
We are using AT&T AlienVault USM for collecting the events, generating alarms, and events management.
What is most valuable?
The most valuable features of AT&T AlienVault USM are the ease of management and knowledge of what is on the network of my customers. It's easy to understand the problems, and management our alarms and events.
What needs improvement?
The price of AT&T AlienVault USM could be reduced.
For how long have I used the solution?
I have been using AT&T AlienVault USM for approximately two years.
What do I think about the stability of the solution?
I am satisfied with the stability of AT&T AlienVault USM.
I rate the stability of AT&T AlienVault USM a five out of five.
What do I think about the scalability of the solution?
AT&T AlienVault USM is scalable enough for our needs.
How was the initial setup?
The initial setup of AT&T AlienVault USM was easy. Which involved all the configurations of correlation rules, and other elements for customer problems management. The full implementation took approximately two days.
What about the implementation team?
I did the implementation of AT&T AlienVault USM with a colleague.
What's my experience with pricing, setup cost, and licensing?
AT&T AlienVault USM is an expensive solution and we pay for the license and the support separately. We paid for the license and support for three years.
What other advice do I have?
I would recommend this solution to others.
We do not use all the features of the solution.
I rate AT&T AlienVault USM an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Network and Security Consultant SI at a tech services company
We can gather all data from different devices, analyze theme and extract the correct information.
What is most valuable?
SIEM, Event Correlation and the Vulnerability Scanner.
How has it helped my organization?
Reduced the number of the false alarms generated by other devices. With AlienVault we can gather all data from different devices, analyze theme and extract the correct information.
What needs improvement?
Plugins: most plugins are not up to date with the newer versions of products.
For how long have I used the solution?
Since 2013
How are customer service and technical support?
We had problems with the MySQL database, but the technical support is very helpful. I'd give them a 9/10.
Which solution did I use previously and why did I switch?
Yes, But AlienVault is the more appropriate solution, it's flexible, Linux based, and contains a large number of open source solutions.
How was the initial setup?
Simple.
What about the implementation team?
A vendor team, don't install the solution in a virtual platform except VMware ESXi. We had a long story with AlienVault with a Proxmox Virtual Environment.
What other advice do I have?
It's a powerfull solution and contain more features than other products.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a tech services company with 1-10 employees
Its powerful correlation engine helps reduce time in manually correlating events
Pros and Cons
- "Its powerful correlation engine helps reduce time in manually correlating events."
- "The only complex area of the setup was writing the custom scripts."
- "It should be able to communicate with other security solutions to stop threats."
How has it helped my organization?
Its powerful correlation engine helps reduce time in manually correlating events.
What is most valuable?
- Alarms
- Correlation
What needs improvement?
It should be able to communicate with other security solutions to stop threats.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
How are customer service and technical support?
Customer Service:
I would rate customer service as a nine out of 10.
Technical Support:
I would rate technical support as a nine out of 10.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
The only complex area of the setup was writing the custom scripts.
What about the implementation team?
We use both a vendor team and an in-house team for implementation.
What was our ROI?
The ROI is quite good.
What's my experience with pricing, setup cost, and licensing?
Use an MSSP instead. It is much cheaper.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
It is quite awesome.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT/IS Officer - Marketing Director at a tech services company with 51-200 employees
It Has Become an Invaluable Asset for Our Small Organization
What is our primary use case?
Working as the CIO for a small community bank, resources for staffing and manpower can be limited. AlienVault helps to simplify the management of Information Security and helps me to detect threats and manage alerts with ease!
How has it helped my organization?
AlienVault gave our organization a centralized tool to manage our security with its intrusion detection, asset management, vulnerability assessments, along with all of its other features, it has become an invaluable asset for our small organization.
What is most valuable?
We have found the AIO USM the most valuable because of its centralized grouping of all of the tools necessary to manage our security in an "All In One" solution. Of its parts, the scheduled vulnerability assessment tool has been helpful as a preventative measure to help keep ahead of security threats!
What needs improvement?
As with many of its users, I have submitted suggestions in the past and AlienVault has seemed to listen to suggestions from its users and have implemented them every time. I am happy with the product as it is today.
For how long have I used the solution?
Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Engineer at a energy/utilities company with 501-1,000 employees
Due to the logger feature, everything is centralized on the AlientVault Server.
Valuable Features:
Event Correlation is the most valuable feature for every SIEM. AlienVault has ISO 27001 compliance which is very helpful for the companies looking to have the ISO 27001 certification.
Improvements to My Organization:
As it includes a logger feature for gathering all logs from all devices (network devices, servers, hosts etc.) it has basically become the only software that we look at when we have a problem. We don’t need to search from one device to another as it’s all centralized on the same AlienVault Server which enables us to save time and become more efficient at work.
Room for Improvement:
As it includes multiple security softwares, the installation and configuration takes a lot of time. It would be good if they could work on that but the time is understandable given all the features AlienVault offers.
Other Advice:
It’s a very good SIEM with plenty of functionalities which helped improve our KPI.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Exabeam
ManageEngine Log360
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- What Questions Should I Ask Before Buying SIEM?
- RSA-EMC vs. other SIEM products?
Thank you for your feedback & comments!