- Correlation
- Customization
Security Analyst at a tech company with 51-200 employees
It has a lot of capabilities, but make sure there’s someone that can devote daily time to it.
What is most valuable?
How has it helped my organization?
No, but that’s not really their fault, rather ours. I think this has a lot of valuable functions that really could be leveraged quite nicely.
What needs improvement?
They have the advantage of having a large community that uses the free version, and they really could use this as a sort of beta testing population for new releases. Yet, a lot of the releases break things that are used. I think they need to do more QA before releases. For example, I have custom rules written for the Suricata function. Some releases ago, there was a code change and now every single update requires that I reinstall the custom rules, and I am still waiting for the fix. They need to either stop allowing customization (which would be a mistake) or they need to embrace that a majority of their customer base does this and put in safe guards. I understand putting in limits to what’s supported, but simple things like this are part of the appeal of the product. Another example is that a few releases back, they broke the Nagios availability monitoring portion. All the functionality to watch your systems is there, and of course, I used it. When it broke, support told me it was really only meant to watch the AlienVault system itself, yet the entire interface is there, the options to enable the monitoring on hosts is there. I believe, first of all, that what I was told was wrong as availability monitoring is one of the core functions AlienVault touts, and secondly, that they need to be more careful with testing before releasing updates. It took like twp more updates before the functionality was restored.
For how long have I used the solution?
I've used it for three years.
Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
Some, but they are hard to pin down. This is a system that has a lot of things that can stop working, and unless you are paying close attention, to the background processes, you would never realize it.
How are customer service and support?
Some people are excellent, and others not so much. They also seem to sometimes have conflicting information. I often rely more on the community for answers than I do on support, depending on the issue.
Which solution did I use previously and why did I switch?
We didn't have anything in place previously.
How was the initial setup?
We had a consultant that was provided by AlienVault, which was great. Otherwise, it would have been a little confusing and though they have made improvements in the documentation, it was horrible initially.
What's my experience with pricing, setup cost, and licensing?
Fair for all of the capabilities it has.
Which other solutions did I evaluate?
We looked at some but I can't remember which ones.
What other advice do I have?
It has a lot of capabilities, but make sure there’s someone that can devote daily time to it and that there is buy in from all segments, or a majority of the capabilities become pointless.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Engineer at a energy/utilities company with 501-1,000 employees
Due to the logger feature, everything is centralized on the AlientVault Server.
Valuable Features:
Event Correlation is the most valuable feature for every SIEM. AlienVault has ISO 27001 compliance which is very helpful for the companies looking to have the ISO 27001 certification.
Improvements to My Organization:
As it includes a logger feature for gathering all logs from all devices (network devices, servers, hosts etc.) it has basically become the only software that we look at when we have a problem. We don’t need to search from one device to another as it’s all centralized on the same AlienVault Server which enables us to save time and become more efficient at work.
Room for Improvement:
As it includes multiple security softwares, the installation and configuration takes a lot of time. It would be good if they could work on that but the time is understandable given all the features AlienVault offers.
Other Advice:
It’s a very good SIEM with plenty of functionalities which helped improve our KPI.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
IT Security Architect at a healthcare company with 1,001-5,000 employees
I can see all HIDS and IDS events in one place. Setup is complex when playing with custom plugins.
What is most valuable?
The SIEM part where I can see all HIDS and IDS events in one place alongwith the correlation directives.
How has it helped my organization?
We have a better detection rate for malware and other cyber-attacks. Really helps when USM integrated in the incident response plan.
What needs improvement?
- Database query speed when dealing with millions of events per day
- Reports customization and types
- Dashboards TV modes (SOC surveillance monitors)
For how long have I used the solution?
I've been using it for three years.
What do I think about the stability of the solution?
I've experienced frequent slowness, and we had to downgrade to filter out many logs.
What do I think about the scalability of the solution?
The AIO is not fast enough for a network over 100 EPS, so you have to go with a dedicated server option for better speed.
How are customer service and technical support?
7/10
Which solution did I use previously and why did I switch?
We had nothing in place prior to this.
How was the initial setup?
It's complex when playing with custom plugins.
What's my experience with pricing, setup cost, and licensing?
The price is low, and it's good quality but require effort.
Which other solutions did I evaluate?
There were no other options looked at.
What other advice do I have?
To take full advantage of the product you have to work under the hood.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT/IS Officer - Marketing Director at a tech services company with 51-200 employees
It Has Become an Invaluable Asset for Our Small Organization
What is our primary use case?
Working as the CIO for a small community bank, resources for staffing and manpower can be limited. AlienVault helps to simplify the management of Information Security and helps me to detect threats and manage alerts with ease!
How has it helped my organization?
AlienVault gave our organization a centralized tool to manage our security with its intrusion detection, asset management, vulnerability assessments, along with all of its other features, it has become an invaluable asset for our small organization.
What is most valuable?
We have found the AIO USM the most valuable because of its centralized grouping of all of the tools necessary to manage our security in an "All In One" solution. Of its parts, the scheduled vulnerability assessment tool has been helpful as a preventative measure to help keep ahead of security threats!
What needs improvement?
As with many of its users, I have submitted suggestions in the past and AlienVault has seemed to listen to suggestions from its users and have implemented them every time. I am happy with the product as it is today.
For how long have I used the solution?
Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Assistant at a financial services firm with 51-200 employees
I can monitor less things and just read reports or alarms.
What is most valuable?
The customizable reports
How has it helped my organization?
I can monitor less things and just read reports or alarms.
What needs improvement?
I don't have any, as I've been pretty satisfied with the product.
For how long have I used the solution?
1 Year
What was my experience with deployment of the solution?
No, it was pretty smooth. There's a little bit of a learning curve out the gate, but they have lots of help available.
What do I think about the stability of the solution?
No
What do I think about the scalability of the solution?
Just learning the language, it's a new product, and it takes time to learn all of it's capabilities.
How are customer service and technical support?
Customer Service:
10, they have great customer Service
Technical Support:10
Which solution did I use previously and why did I switch?
We had a MARs and it was EOF.
How was the initial setup?
It was pretty straightforward, you take a class and then you get extra help. There wasn't any confusion.
What about the implementation team?
In-house.
What was our ROI?
N/A
What's my experience with pricing, setup cost, and licensing?
It's worth it!
Which other solutions did I evaluate?
Yes, but I wasn't apart of the research team.
What other advice do I have?
I'm glad we purchased it, wished we would have gone with outside monitoring instead of inhouse an there is a lot to learn. Great product though.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Good security management capabilities but the interface needs to be more user-friendly
Pros and Cons
- "The most valuable feature of this solution is security management for PCI DSS."
- "This solution could be easier to use."
What is our primary use case?
This is a SIEM solution that our customers use in an on-premises deployment.
What is most valuable?
The most valuable feature of this solution is security management for PCI DSS.
What needs improvement?
This solution could be easier to use. It is hard for some people to understand, and they need to get training and certification just to understand what it's showing them.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
In terms of stability, I would give it fifty percent.
What do I think about the scalability of the solution?
The scalability of this solution is good.
We have a large number of customers who use this product on a daily basis.
How are customer service and technical support?
Technical support is very good from their side.
How was the initial setup?
The initial setup of this solution is a bit complex. Specifically, it is the way that it integrates with other products.
What about the implementation team?
We deployed this solution in-house.
What other advice do I have?
This is a good product but it can be made more user-friendly.
I would rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
IT Officer with 51-200 employees
Visibility For Your Network and To Find Bottlenecks
How has it helped my organization?
Recently, we used the NetFlow capability to find a bottleneck in the network and the offending computer.
What is most valuable?
The most valuable aspect of AlienVault is the visibility into the network. You have the capability to gather logs from multiple sources and easily see what is going on in the network.
What needs improvement?
It is a lot of work to get the software configured and set up properly.
What do I think about the stability of the solution?
There were some issues with the reporting functions. AlienVault corrected that problem in a new update.
How are customer service and technical support?
Customer Service:
The customer service department is very responsive to questions.
Technical Support:
The technical support team is very knowledgeable. It is helpful that they are able to have remote support sessions to review the problem.
Which solution did I use previously and why did I switch?
No.
What about the implementation team?
We deployed this system in-house. We are not a fan of moving things to cloud-based solutions.
What's my experience with pricing, setup cost, and licensing?
The engineering support that is provided by AlienVault upon first installation was excellent! They went way above and beyond what I was expecting.
Which other solutions did I evaluate?
We evaluated the popular SIEM tools Splunk, LogRhythm, and SolarWinds. AlienVault provided the most features for the price point.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Expert at a tech services company
Provides threat detection powered by signatures and advanced correlation rules.
What is most valuable?
Threat detection powered by signatures and advanced correlation rules.
How has it helped my organization?
It helps to identify external and internal security threats to the organization, on time.
What needs improvement?
- Accuracy of threat detection
- Advance reporting
- Reliable asset and vulnerability management feature
For how long have I used the solution?
We have been using this solution for three years.
What was my experience with deployment of the solution?
I did not encounter any issues with deployment.
What do I think about the stability of the solution?
I did not encounter any issues with stability.
What do I think about the scalability of the solution?
I did not encounter any issues with scalability.
How are customer service and technical support?
Customer Service:
Excellent.
Technical Support:We received average support. As observed, the support engineers take a long time for issue resolution.
Which solution did I use previously and why did I switch?
I have not used any other solutions before.
How was the initial setup?
The setup was simple and straightforward.
What about the implementation team?
We had an in-house implementation.
What was our ROI?
It has not yet been measured.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing are at its best in the market when compared with other vendor's SIEM products.
Which other solutions did I evaluate?
We evaluated ArcSight, RSA Security Analytics, and Splunk.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Exabeam
ManageEngine Log360
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
Thank you for the feedback you've provided on your experience with using USM.