What is our primary use case?
Our customers have three use cases, Log aggregation, correlation, and the SIEM functionalities.
Our customers are mostly in the finance and banking sectors.
What is most valuable?
Log aggregation and alarms are the most useful for security for our customers. It collects logs from various log sources in the corporate network and then gives you actionable intel on the collected logs.
The second feature is SIEM capabilities. It's an umbrella set for what SIEM does.
The asset discovery and inventory capabilities in USM Anywhere is quite good because it helps to discover all assets and IP addresses on the corporate network.
USM Anywhere uses artificial intelligence to enhance threat detection.
What needs improvement?
The only issue that you need to bypass is the issue with integration with some other log sources, some other application security applications.
The issue is still present. The process of collecting logs from applications that do not have an alien app or alien routes can be made a little bit better. Once there is no alien app, it's always very difficult to collect logs from third-party applications.
So, the process of collecting logs from third-party applications is something that needs to be improved.
Also, when it comes to parsing of some logs, I've worked with another solution that has a custom parsing feature that can assist you in creating the custom parsing rule by yourself. But for any of those, USM needs to reach out to the engineering team, which takes months to come up with.
There is room for improvement in Log parsing. So when there are logs that are being parsed, we need to create a custom parsing rule to correctly parse some event logs. I've worked with a solution that has a feature that helps you to create custom parsing rules. But for enablement, we need to escalate to their engineering team, which takes months before they can respond and give you that parsing rule.
For how long have I used the solution?
I have been using it for three years.
What do I think about the stability of the solution?
Many times I've noticed issues with stability. Mostly, it's quite stable, though. It's stable. But when you overload it a little, or access it, depending on the storage capacity.
I would rate the stability an eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. We have small, we have medium, and we have enterprise banks as our customers.
How are customer service and support?
The customer service and support respond fast and we jump on sessions fast, unlike some other vendors that can be slow to join a session.
How would you rate customer service and support?
How was the initial setup?
I would rate my experience with the initial setup an eight out of ten, with ten being easy. It can be public cloud, private cloud, or on-premises. It depends on the customer.
For most customers, I deploy more on-prem than on cloud.
The deployment time really depends on the customer and how responsive they are. But with everything, it could take up to two weeks, working every day, to fully deploy the solution and update it all.
To fully integrate, it depends on the organization. It depends on the log sources that should be integrated. But mostly, if you dedicate every day to deployment, it shouldn't last more than a week.
What was our ROI?
It's saved security costs. It's saved costs in terms that when the solution is not in place and the customer gets hacked, they lose finances. So the solution has helped the customers not to get hacked. So, it has saved costs.
What's my experience with pricing, setup cost, and licensing?
The price is really variable depending on what tier the customer is subscribing to. I think USM Anywhere recently started a 125, a 250, and then 500 and 1000 tier. So it depends on the organization, but it's affordable for most customers.
What other advice do I have?
Overall, I would rate it an eight out of ten. I would recommend it because it is a good solution. It's easy to navigate. It's flexible.
Which deployment model are you using for this solution?
On-premises
*Disclosure: My company has a business relationship with this vendor other than being a customer.