We use it for the intrusion protection on our firewall. It's monitoring all our incoming traffic from the outside world through a firewall.
VP IT Operations at a financial services firm with 51-200 employees
Enables us to search for critical vulnerabilities in our network
What is our primary use case?
How has it helped my organization?
Previous to this, we really didn't have any protection, any intrusion system in place. It's made me more comfortable, since I'm in charge of IT for this company. I sleep better at night.
Using the solution, we have been able to look for critical vulnerabilities in our network. Thankfully, we haven't found any. It takes just a couple of hours.
What is most valuable?
The most valuable feature is what it can block, what it can prevent from coming in.
What needs improvement?
The only that I can think of is that is not ideal is sending Windows Server logs to their device, to the system. That has to be done on each server. I don't know if they have changed that.
Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
It's very scalable.
How are customer service and support?
Tech support is very good. They usually respond very quickly.
Which solution did I use previously and why did I switch?
This is the first solution of its kind for us.
How was the initial setup?
The initial setup was pretty straightforward. The deployment took about a day. In terms of our implementation strategy, we have the cloud version. You create a VM in your system, it communicates with the cloud, and then you just log in through the cloud.
What's my experience with pricing, setup cost, and licensing?
It's very reasonably priced. It was one of the lowest among the ones I looked at. Licensing is pretty flexible. They can do a two-year or a three-year, even a one-year, perhaps.
Which other solutions did I evaluate?
I looked at two others but I don't remember their names.
What other advice do I have?
Compare it to the other vendors in the field, some of the top vendors. Make sure it fits your needs. It's more for a mid-sized company or a small company, not a large enterprise.
Regarding using it for discovering assets in our network which do not belong, our network isn't that big so we really don't use it for that. We also don't use the solution for compliance with regulations.
When it comes to staff using the solution, at the moment it is me and a monitoring service. We're the only ones who log into the solution. As for deployment, one person could probably do it because they help you deploy it. I did the deployment myself, with AlienVault. For maintenance, if you have a monitoring service that's fine, but if you're doing it yourself, you probably need somebody monitoring the log. When there's an incident, you probably need one or two other people.
I would rate it a nine out of ten. It does what we need and it's reliable.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Director Of Information Technology at a tech services company with 51-200 employees
Allows us to roll out log management on clients and servers, host-based IDS, and network-based IDS.
Pros and Cons
- "The best feature of this product is the ease of use. It is extremely easy to set up and get going. This is a very useful tool for a small organization."
- "I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job."
How has it helped my organization?
This has helped improve our overall IT security by allowing us to implement a full suite of security tools that allows us to roll out log management on clients and servers, host-based IDS, and network-based IDS. It also provides vulnerability scanning; however, we use a separate product for that.
What is most valuable?
The best feature of this product is the ease of use. It is extremely easy to set up and get going. This is a very useful tool for a small organization.
What needs improvement?
I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues; the product scales very easy.
How are customer service and technical support?
Customer Service:
I would rate customer service an 8/10. I've received calls from customer service a few times a month and it gets a little overbearing, especially when you are busy, as IT professionals are.
Technical Support:
I would rate technical support a 9/10.
Which solution did I use previously and why did I switch?
This was our first solution for HIDS, NIDS, and log management.
How was the initial setup?
The initial setup was straightforward. I simply followed the steps in the setup wizard and the steps provided by technical support, and I had a trial version (later converted to paid version with additional steps) set up in about an hour or less.
What about the implementation team?
This was set up in-house.
What was our ROI?
It is really hard to put a number on ROI but I will say that AlienVault has allowed us to close the gap on security alert timing and we can respond to incidents in a much more timely fashion which, to me, is much more valuable than a number.
What's my experience with pricing, setup cost, and licensing?
AlienVault is flexible on their pricing for unlimited licenses.
Which other solutions did I evaluate?
We evaluated Splunk as well. AlienVault was a much cheaper solution and required less time to be rolled out. Splunk is a much more difficult product to work with and almost requires a dedicated employee to manage.
What other advice do I have?
I highly recommend AlienVault USM for anybody that is seeking a SIEM solution that is easy to implement and easy to manage. It works very well for small- and medium-size businesses.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
USM Anywhere
December 2024
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
An all-in-one package for monitoring components across the network
Pros and Cons
- "In terms of monitoring, my best feature would be the monitoring of components across the network. It monitors the respective nodes and any new node that comes onto the network and provides reports. The reporting dashboards are really helpful for management in terms of making decisions around patch management."
- "I've been using it just for my own personal upskilling in terms of how the product works. At the moment, it is pretty straightforward and simple, and it is working how it is supposed to. The feedback would come once it is deployed to customer sites. They'll be using it on a more frequent basis, and that's when the feedback would come in terms of the areas in which they're facing issues or are looking for simplicity."
What is our primary use case?
General use cases would be for patch management and vulnerability management. The devices that are on the network may need patching if they're outdated. For any device or node that has entered the network and may be considered a threat, the HTTPS ports and different nodes need to be monitored for incoming and outgoing traffic. We could put in security rules for monitoring the actual devices down to the USP level, and we can also get the vulnerability information from OSX, and then provide that information to the IT teams.
In terms of the version, usually, when the updates come, the updates need to be aggregated to the customer, but at this moment in time, I am yet to secure a customer in that space due to the current COVID crisis in the country, across the Pacific, and globally.
In terms of deployment, the endpoints are on-premise, but it would be cloud-based in terms of the platform. So, it could be both depending on the customer. They would either have cloud or hybrid.
What is most valuable?
In terms of monitoring, my best feature would be the monitoring of components across the network. It monitors the respective nodes and any new node that comes onto the network and provides reports. The reporting dashboards are really helpful for management in terms of making decisions around patch management.
It is an all-in-one package. In terms of the selling points, to the best of my knowledge, it has eight different selling points or eight features, and they're all interlinked, which most of the infrastructure setups here do not have. They have separate systems for monitoring the networks. So, USM can cater based on those eight capabilities.
What needs improvement?
I've been using it just for my own personal upskilling in terms of how the product works. At the moment, it is pretty straightforward and simple, and it is working how it is supposed to. The feedback would come once it is deployed to customer sites. They'll be using it on a more frequent basis, and that's when the feedback would come in terms of the areas in which they're facing issues or are looking for simplicity.
For how long have I used the solution?
I have been using this solution for the last eight to 10 months.
What do I think about the stability of the solution?
So far, I haven't seen any patches or updates from the partner or the OTX site to show any issues in terms of stability. Based on the frequency of the updates, at the moment, it seems stable.
What do I think about the scalability of the solution?
It is easy to scale. It comes with all features, as opposed to separate individual modules. To my knowledge, you can scale it for your organization as and when there is a requirement or the organization grows. So, in terms of scalability, there is no problem. After you get it up and running, as the organization grows, the engines will be able to pick up that information.
It is really good for medium and large companies, but it can also be used for small organizations. Instead of deploying it to a small organization, you could provide a service where it is not on the customer site, and you basically link into your nodes for small customers. So, you install it for medium and large customers, and for small customers, you install it on your premise, and then you sell the individual features that they may request.
How are customer service and technical support?
I have not been in touch with their technical support. I deal with the technical account manager. When I read up the information and there is something that I'm not sure about, I check my resources and see what's available online. If none of the available resources are helpful, I reach out to my account manager who then puts me in touch with the technical team. I presume that if we encounter any issues in deployment, it would be based on a customer's demography or the setup.
How was the initial setup?
If you're not familiar with it from a tech perspective, it might be confusing for you, but from what I've seen and based on my experience, it is pretty simple and straightforward.
The user guides are also very helpful if you hit any roadblocks. It is very straightforward in terms of the instructions to set it up, but you should have minimum tech experience in understanding the documentation, which is fair enough and good because you don't want it to be too simple to set up that companies would say, "Well, we don't need IT if anybody can do this." So, you'd need some technical background to at least understand the documentation or the user guide.
I've only installed it for myself. It took a short amount of time to get it up and running. The deployment duration would depend on a customer's infrastructure size and the number of nodes that a customer has. It will also depend on the data collection that the agents or the engines need to do to protect the information and then put it in its database.
What's my experience with pricing, setup cost, and licensing?
Its price is in the medium to upper range.
What other advice do I have?
I would definitely recommend this solution, but I would also do a pre-assessment of the organizational setup and infrastructure. I'm a reseller, and it is obviously my top priority that we sell the product
If you look at the Gartner Magic Quadrants, you will see AlienVault is up there in the upper right quadrant, which makes it one of the top recommended solutions. That is the reason for my partnership with AT&T Cybersecurity for the product.
I would rate AT&T AlienVault USM a nine out of 10. No solution is 100% perfect.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Buyer & Operations Specialist at Nth Generation Computing
I've found the vulnerability assessment very valuable because it identifies vulnerabilities and AWS configuration issues
What is our primary use case?
We have used AlienVault for our security monitoring for threat protection and compliance management. We've seen an improvement against malware and viruses. It has definitely eased our concerns so we can focus on other things.
How has it helped my organization?
AlienVault is very user-friendly. We've had a great experience with asset discovery, compliance reporting, endpoint detection and response. Our team uses the network infrastructure monitoring as well.
What is most valuable?
- In my experience, I've found the vulnerability assessment very valuable because it identifies vulnerabilities and AWS configuration issues, so we are less likely to have potential risks.
- The compliance reporting is also valuable for reporting purposes.
What needs improvement?
The only recommended changes I can think of is to have the ability to filter logs. Also, being able to navigate the dashboard. That seems to have been quite a challenge.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
There are multiple functions of this product, the stability and availability are awesome.
What do I think about the scalability of the solution?
The scalability of this solution is exceptional. I believe it's very reliable and dependable.
Which solution did I use previously and why did I switch?
I'm not familiar with what was used prior to AlienVault nor the reason the switch was made. I'm just very pleased.
How was the initial setup?
Yes, our team did not have any issues with the initial setup of AlienValut and its functions.
What about the implementation team?
In-house.
What was our ROI?
The return on investment is great. I feel this product is well worth the price for all the functions and performance it can provide.
What's my experience with pricing, setup cost, and licensing?
I advise others on the pricing and licensing. I research to find the best pricing for the value of the products as well as register all licensing.
Which other solutions did I evaluate?
No, our tech department did the evaluating of all the options and chose AlienVault.
What other advice do I have?
AlienVault is an amazing product that I would highly recommend.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at a tech services company with 10,001+ employees
We have been able to ensure the health of our servers
Pros and Cons
- "As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business."
- "Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour."
- "For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier."
What is our primary use case?
We use the appliance in a few of ways: monitoring network behaviour, asset discovery, and running vulnerability scans. We can monitor the availability of servers and any particular software. As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business.
How has it helped my organization?
We have been able to ensure the health of our servers. We can also use vulnerability scans to ensure our system is as good as it could be.
Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour. The ranking can be modified to allow us to apply a standard rule and also be customized, which suits our business needs.
What is most valuable?
I have used the asset discovery and the vulnerability scans the most. As a system administrator, it is important that we are prepared for any eventualities. I also like how you can use the hardware “out-of-the-box”, or using logs you can actually customise the performance to fit your environment and needs.
What needs improvement?
For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
Which solution did I use previously and why did I switch?
We did not have any sustainable solution, previously.
What's my experience with pricing, setup cost, and licensing?
Use the AlienVault team. They are helpful and the documentation that they provide is second to none.
Which other solutions did I evaluate?
We checked out several competitors. For what it can do and the cost, it was the best SIEM tool!
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IS Manager at a financial services firm with 501-1,000 employees
It has allowed us to centralize our logging. We had used previous products and found AlienVault centralized the logging for our security.
Pros and Cons
- "We had used previous products and found AlienVault centralized the logging for our security."
- "There are many reports included but would be nice to have better access to the data."
How has it helped my organization?
It has allowed us to centralize our logging. We had used previous products and found AlienVault centralized the logging for our security. Additionally, we are better able to meet our compliance needs.
What is most valuable?
We use several features extensively. Logging, vulnerability scanning, file integrity monitoring, and threat information.
What needs improvement?
I would like to see some better ways to report on the information. There are many reports included but would be nice to have better access to the data. Customizations are possible but don't always allow us to report on what we need.
What do I think about the stability of the solution?
We have a new remote sensor sending a large amount of data. We have seen some slowness but the sensor is new and we tracked down the slowness to network connectivity. The server has handled all we could throw at it.
What do I think about the scalability of the solution?
Working well with everything we have sent to it.
How are customer service and technical support?
Customer Service:
I have enjoyed working with the client support folks. I have had really good experiences with them even having them help with plugins when they weren't working.
Technical Support:
Very good.
Which solution did I use previously and why did I switch?
ManageEngine Event Log Analyzer
How was the initial setup?
The wizard setup was great and helped deployment go well.
What about the implementation team?
Received training and did in-house. Also had some follow-up consulting that helped to do a health check on the system that was very valuable. Consultants did a great job of helping us become more comfortable.
What was our ROI?
Not measured.
What's my experience with pricing, setup cost, and licensing?
Look at other products and AlienVault will have you coming back as it did us.
Which other solutions did I evaluate?
Yes, many other vendors - its been a while so I don't remember them all.
What other advice do I have?
No, good solid product
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Analyst at a financial services firm with 201-500 employees
You can customize the "Overview" dashboard to you or your company's needs.
What is most valuable?
AlienVault's "Overview" dashboard makes it very easy to see everything going on in your network that needs your immediate attention. You can easily customize the dashboard to you or your company's needs.
How has it helped my organization?
I now have the ability to report all vulnerabilities and threats hitting our network to upper management in an easy-to-understand format.
What needs improvement?
Offer solutions based on a PoC (Proof of Concept) to fit each company's specific needs, rather than letting the company guess or piece together the solution they need.
For how long have I used the solution?
I have used it for six months.
What was my experience with deployment of the solution?
We have not encountered any deployment issues; the setup was very easy and support was by my side to assist me with any issues that arose.
What do I think about the stability of the solution?
We have encountered stability issues; we have a high volume of logs passing through our SIEM and the default configuration couldn't handle all the data. Working with support, we were able to remediate all the crashes we were having.
What do I think about the scalability of the solution?
We have encountered scalability issues. We had to keep changing our configuration or updating our storage capabilities as we added more logs.
How are customer service and technical support?
Customer Service:
Customer service is 8/10.
Technical Support:Technical support is 9/10. Engineers are very knowledgeable about their product!
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
The setup was very straightforward. AlienVault provides simple, step-by-step instructions for each of their products!
What about the implementation team?
As a single Analyst, I was able to implement this product very easily.
What was our ROI?
At this time, it is too early to tell ROI.
What's my experience with pricing, setup cost, and licensing?
Know your capabilities and storage needs before negotiating a price! Make sure you ask about log storage options before purchase.
Which other solutions did I evaluate?
Before choosing, we evaluated other options. We were looking at Splunk and Rapid7.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at a financial services firm with 201-500 employees
The alarms dashboard shows any threats that may need further investigation.
Pros and Cons
- "The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
- "The vulnerability reporting needs to have options to be able to sort or customize the output."
How has it helped my organization?
AlienVault has brought more awareness to the activity on our network. Security risks are identified and addressed to reduce any possible security breach.
What is most valuable?
Alarms dashboard shows immediately any threats that may need further investigation. The vulnerability scanning is helpful to identify the areas that need patching or fixes installed.
What needs improvement?
The vulnerability reporting needs to have options to be able to sort or customize the output. It is helpful to look at the vulnerability and how many hosts have it, in addition to being able to look at an individual host to see what vulnerabilities it has.
What do I think about the stability of the solution?
We did not encounter any stability issues. AlienVault seems to be pretty solid and we have not had any issues with it being unavailable.
What do I think about the scalability of the solution?
We have not encountered any scalability issues. We have a fairly simple deployment with only one sensor, so it was straightforward.
How are customer service and technical support?
Customer Service:
Customer service is very good.
Technical Support:
Technical support is very good. They have always been prompt to address an issue and stuck with it until resolution.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
Initial setup was very straightforward; few configuration settings and it was pulling in logs.
What about the implementation team?
An in-house team implemented it.
What was our ROI?
ROI is a difficult one to measure for this. It helps us cover a compliance need as well as provides us a means to be aware of any possible threats and vulnerabilities.
What's my experience with pricing, setup cost, and licensing?
Pricing is very competitive with other products and you get much more functionality from AlienVault. The vulnerability scanning and threat intelligence offers additional tools that others don't have.
Which other solutions did I evaluate?
We looked at a couple of other products before choosing AlienVault. We looked at LogRhythm and EventTracker.
What other advice do I have?
If you take the training virtually, make sure you can dedicate the week with uninterrupted time. The training is quite in-depth and you want to have your undivided attention on it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Laurie, awesome to hear you're having a great experience with the product! We hear you loud and clear on the need to extend our reporting capabilities, especially around vulnerability management. I'll try to keep you in the loop as we look to roll out new features to this area of the product. Thanks again for the feedback and for being a customer. We truly appreciate your business!
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Exabeam
ManageEngine Log360
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
Thank you so much Lorenzo for taking time to share your experience & feedback!