No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
35th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (36th)
 

Mindshare comparison

As of October 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.2%, down from 2.9% compared to the previous year. The mindshare of NetWitness Platform is 1.2%, up from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
AlienVault OSSIM1.2%
NetWitness Platform1.2%
Other97.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
reviewer1130436 - PeerSpot reviewer
Information Technology Security and Infrastructure Expert at a government with 201-500 employees
Helps to deal with potential attacks and is available at a reasonable price
My company has had many benefits from the use of the product in the last eight years. The tool has streamlined our company's incident response process since it serves as a log repository, which allows us to correlate events and access different technology stacks. In our company, we were able to actually find some potential attacks, so it has been very helpful. The tool's integration capability isn't so great. In my company, we managed to integrate it with our Microsoft Azure Subscription, after which we managed to integrate it with other tools. You will face a lot of difficulties if you want to integrate it with your database monitoring tool, PAM solutions, or IAM products. The product has done well overall for my company's teams to deal with their workflow efficiency. I would not recommend the product to others. I rate the tool a seven out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"OSSIM is the only solution that includes the large number of modules that we need: a vulnerability scanner, a network IDS system, a host IDS system."
"The threat alerts it gives me from time to time on harmful code within the network, or if they are generating any network traffic, are very useful."
"The threat policies of the solution are always very advanced and the best in the market, and they are very persistent in terms of keeping up with security protocols."
"The initial setup was straightforward. I didn't have any problems."
"The paid version of the solution has reporting and better scalability options."
"I have deployed it widely because I find that it gives value for money."
"The dashboard is the solution's most valuable aspect; it brings everything into one central point where I can actually look at it and go, "Okay, I understand what's going on," and the solution works well and allows me to have visibility into anomalous events."
"The most valuable feature is the logging capability."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"Overall, this is a good solution with suitable features and it very well fits our needs."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"Once it is deployed and you are used to it, you can do whatever you want."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
"The most valuable feature is the hunting ability to work in a CERT."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
 

Cons

"GUI could be improved."
"It takes some time. It does not give me a prompt response for any such [malicious] traffic. It takes time to get that alert from the AlienVault system."
"When comparing AlienVault OSSIM to other solutions it looks a bit outdated. Additionally, they need to improve their integration."
"We need more dashboards and we need more customization for dashboards."
"ArcSight works better than AlienVault right now."
"The user interface could be improved."
"I would advise others to not implement it for any enterprise-level organization."
"The initial setup was not so easy, partly because the documentation was not up to date."
"But the 11.3 version is a complete disaster. You cannot analyze anything."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"Advance monitoring and alerting feature is not stable (Event Stream Analysis)."
"RSA NetWitness Logs and Packets is far behind the competition."
"I am not happy with the RSA support. Sometimes they can be really annoying because it takes so long to get the support that you need."
"The implementation needs assistance."
"They should implement algorithms to digest that data and produce additional, more advanced reporting, alerting and support of internal security teams."
"Security needs improvement. We would still like to know how the traffic is entering the organization."
 

Pricing and Cost Advice

"I used the paid version of the tool and found it to be expensive. It has been a while since I changed to Securonix. I will have to check whether AlienVault charges per device, user, or log."
"AlienVault OSSIM is free."
"The tool's licensing costs are yearly."
"The solution is open source, so it's free to use."
"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"AlienVault pricing is the best. Whatever cost you are paying, you are getting a return on every penny... It's not like your IBM, your QRadar, or Splunk, where the cost is too high."
"AlienVault OSSIM is expensive compared to its competitors."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"The product is expensive."
"It’s cheaper to run virtual machines in a VMware environment."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Compared to the competition, the is price is not that high."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"This is a pricey solution; it's not cheap."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Comms Service Provider
14%
Manufacturing Company
9%
Financial Services Firm
8%
University
8%
Construction Company
12%
Financial Services Firm
11%
Comms Service Provider
10%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
What is your primary use case for AlienVault OSSIM?
This solution is very similar to most of the other MSSPs that you would find out there. When I look at use cases, AlienVault was initially aimed at small to medium businesses. It grew, and that was...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

OSSIM
RSA Security Analytics
 

Overview

 

Sample Customers

Council Rock School District
Los Angeles World Airports, Reply
Find out what your peers are saying about AlienVault OSSIM vs. NetWitness Platform and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.