AlienVault OSSIM vs Trellix ESM comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
11th
Average Rating
7.4
Number of Reviews
28
Ranking in other categories
No ranking in other categories
Trellix ESM
Ranking in Security Information and Event Management (SIEM)
17th
Average Rating
7.4
Number of Reviews
34
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 4.3%, up from 1.8% compared to the previous year. The mindshare of Trellix ESM is 0.4%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
No other categories found
 

Featured Reviews

Aman Aijaz - PeerSpot reviewer
Jun 28, 2023
An easy-to-scale open-source solution used for monitoring events on devices
The area for improvement is a lot. When I started using it on our enterprise side, the issue we faced was, for example, if we were running at that time on AlienVault OSSIM v5.7.4. So, for some orders, we had to install some packages, and when we tried installing that package, some dependencies got upgraded to a new version. Now once that dependency got upgraded, the SQL, since you might be aware that OSSIM uses SQL database, now SQL and all the dependency in everything was not on the same version, and that caused the database to crash. The aforementioned area should be eased out by upgrading the patches and upgrading dependencies. This kind of thing is a disadvantage of OSSIM, and I would like them to work on this. But I have also raised service requests many times and gave it a push on the community section too. However, since it is a local source, they don't reply much over there. That is why I don't like to work on OSSIM because it is unpredictable. Once the storage goes above 50 percent, it starts behaving unpredictably. If you get stuck with a situation, then you need to drill a lockdown into that. Sometimes you get no luck. Then you have to just reimage the server with the new fresh OS of AlienVault. As for additional features, not much because if you move to the newer version, it is kind of getting more stable. But, to make my life easier, then I would say try to give more features. I know it's open source, so they also cannot provide me with more features. But still, if they can provide me with more features because right now it's becoming old. Right now, we are even moving from SIEM to Security Data Lake. So when we move to it, this will be literally outdated. No one can even expect anything out of it. The way security is moving, it will be outdated very soon. They have to also provide something new to keep this going for the future also.
Daniel Durian - PeerSpot reviewer
Dec 6, 2022
Provides visibility of all the traffic within the company infrastructure
The primary use case of the solution is central log management for the company. It allows us to see all the traffic coming in and going out to and from the internet. It provides various views from the firewall and web application firewall and event logs from the endpoint. The command view will tell…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"You can customize the dashboards as well as the reporting."
"The solution has a very good open source community, and whenever we have problems, we are always able to resolve it online."
"The most valuable features of this solution are the data correlation and vulnerability assessment."
"The most valuable feature is the logging capability."
"AlienVault OSSIM's GUI is very user-friendly."
"The solution is free to use."
"The solution is very stable. Compared to Qradar and Splunk, it's very stable."
"The paid version of the solution has reporting and better scalability options."
"The most valuable feature is the correlation rules."
"The most valuable feature is the capability to correlate different events from different platforms that we feed into it."
"It is a good central viewpoint for issues. These can then be investigated in more detail on the subnet server(s)/endpoints."
"We are now able to completely monitor our environment so we can review what is there, which is a big win for us."
"It can be easily deployed with the other solutions."
"The solution's technical support is great."
"It is easy to use and deploy. It comes with user-friendly manuals."
"The most valuable feature is for the security operation center because it provides visibility of all traffic within the company infrastructure."
 

Cons

"When comparing AlienVault OSSIM to other solutions it looks a bit outdated. Additionally, they need to improve their integration."
"The incidence reporting could be better."
"We need more dashboards and we need more customization for dashboards."
"AlienVault OSSIM is costly."
"The initial setup was a bit complex. You've got to do a lot of reading. It's not an intuitive implementation."
"They can add more compliance templates."
"The price of this solution is very high and it could be cheaper."
"The solution needs more integration with cyber intelligence systems."
"We cannot add new data sources to the most recent version."
"It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI."
"The user interface could be more user-friendly."
"Product currently requires Flash."
"I would like to see fingerprint recognition included in the next release of this solution."
"There's no software support from McAfee."
"There are some banking and transactional cases that are local, South America transactions. I would like to see them add features that can be used locally, to make those transactions more reliable."
"The only issue I have with McAfee is the amount of computer resources that it takes... it's definitely impacting some of the other applications that are running on a computer at the same time."
 

Pricing and Cost Advice

"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"The tool's licensing costs are yearly."
"OSSIM is free."
"OSSIM is open source, and USM is the paid license. So, if you want, you can switch to USM. There you will have to buy a license, and they have a support team that helps you out on issues you face."
"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"We are using the community version, which can be used for free."
"AlienVault OSSIM is free."
"AlienVault pricing is the best. Whatever cost you are paying, you are getting a return on every penny... It's not like your IBM, your QRadar, or Splunk, where the cost is too high."
"The pricing is fair."
"The price of McAfee ESM is higher than some of the other solutions. There are additional features that can be added at an additional fee."
"We renew our license annually."
"The licensing cost is based on EPS."
"You should buy the distributed option instead of the all-in-one for environments with more than 1000 end points."
"The cost is dependent on the customer's environment and requirements."
"We pay for our licensing fees on a yearly basis, and there are no costs in addition to the standard licensing fees."
"The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
8%
Educational Organization
8%
Government
8%
Educational Organization
73%
Computer Software Company
5%
Financial Services Firm
4%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with AlienVault OSSIM?
Collecting logs can sometimes be tedious, especially compared to my experience with Microsoft Sentinel. I suggest more in-built rules based on modern threats and environments to make it a more comp...
What do you like most about McAfee ESM?
The solution's technical support is great.
What is your experience regarding pricing and costs for McAfee ESM?
The product is slightly expensive. They offer some discount on the purchase of a certain number of nodes. They should give some concession on the license renewal as well.
What needs improvement with McAfee ESM?
The integration capabilities of Trellix ESM with SaaS solutions are an area of concern where improvements are needed. When you continue to add solutions from other vendors, you need to look at the ...
 

Also Known As

OSSIM
McAfee ESM, NitroSecurity, McAfee Enterprise Security Manager
 

Learn More

Video not available
 

Overview

 

Sample Customers

Council Rock School District
San Francisco Police Credit Union, Wªstenrot Gruppe, Volusion, California Department of Corrections & Rehabilitation, Government of New Brunswick, State of Colorado, Macquarie Telecom, Texas Tech University Health Sciences Center, Cologne Bonn Airport
Find out what your peers are saying about AlienVault OSSIM vs. Trellix ESM and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.