AlienVault OSSIM vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
11th
Average Rating
7.4
Number of Reviews
28
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Security Information and Event Management (SIEM)
13th
Average Rating
8.4
Number of Reviews
113
Ranking in other categories
Log Management (18th), Endpoint Detection and Response (EDR) (31st), Compliance Management (9th)
 

Mindshare comparison

As of July 2024, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 4.3%, up from 1.8% compared to the previous year. The mindshare of USM Anywhere is 0.8%, down from 2.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
Log Management
0.5%
Endpoint Detection and Response (EDR)
0.4%
 

Featured Reviews

Aman Aijaz - PeerSpot reviewer
Jun 28, 2023
An easy-to-scale open-source solution used for monitoring events on devices
The area for improvement is a lot. When I started using it on our enterprise side, the issue we faced was, for example, if we were running at that time on AlienVault OSSIM v5.7.4. So, for some orders, we had to install some packages, and when we tried installing that package, some dependencies got upgraded to a new version. Now once that dependency got upgraded, the SQL, since you might be aware that OSSIM uses SQL database, now SQL and all the dependency in everything was not on the same version, and that caused the database to crash. The aforementioned area should be eased out by upgrading the patches and upgrading dependencies. This kind of thing is a disadvantage of OSSIM, and I would like them to work on this. But I have also raised service requests many times and gave it a push on the community section too. However, since it is a local source, they don't reply much over there. That is why I don't like to work on OSSIM because it is unpredictable. Once the storage goes above 50 percent, it starts behaving unpredictably. If you get stuck with a situation, then you need to drill a lockdown into that. Sometimes you get no luck. Then you have to just reimage the server with the new fresh OS of AlienVault. As for additional features, not much because if you move to the newer version, it is kind of getting more stable. But, to make my life easier, then I would say try to give more features. I know it's open source, so they also cannot provide me with more features. But still, if they can provide me with more features because right now it's becoming old. Right now, we are even moving from SIEM to Security Data Lake. So when we move to it, this will be literally outdated. No one can even expect anything out of it. The way security is moving, it will be outdated very soon. They have to also provide something new to keep this going for the future also.
JV
Aug 1, 2022
Useful highlighted known vulnerabilities, full network viability, and beneficial reports
I have used AT&T AlienVault USM for Log collection and management, priority, and incident analysis AT&T AlienVault USM has helped our organization by highlighting known vulnerabilities in our network and full visibility of our network to figure out if there is anything that we are not aware of.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is free to use."
"Asset discovery is good."
"You can customize the dashboards as well as the reporting."
"The initial setup was straightforward. I didn't have any problems."
"AlienVault OSSIM is an enterprise solution that sells easily. It is rated highly by organizations."
"OSSIM is the only solution that includes the large number of modules that we need: a vulnerability scanner, a network IDS system, a host IDS system."
"The paid version of the solution has reporting and better scalability options."
"The open vault component and the checking of vulnerabilities are the most valuable features. The page management helps with this. If you know how your device is vulnerable at least you can do something about it."
"We're using it more for reporting, that's all. We're using it to help our customers to pass any kind of audits that they receive."
"It allows you to define what alerts you want to see, or not to see, as well as if you want them grouped, or ungrouped."
"The USM is a work horse, no matter what devices or the number of logs we throw at it, the system processes them in real time, correlates the events, and alerts on only events that need human review."
"The ease of implementation is the most valuable feature."
"The most valuable feature of this solution is security management for PCI DSS."
"Every activity on the firewall is recorded, and notifications are sent with this solution."
"Vulnerability scanning helped out shortcomings of what was not patched in the past and what needed to be patched. This assisted with fine tuning the environment for compliance."
"The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
 

Cons

"AlienVault OSSIM gives unwanted notifications."
"AlienVault OSSIM is costly."
"The correlation engine needs to be improved."
"The solution needs more integration with cyber intelligence systems."
"It's so hard to configure and explore something new on it."
"I don't like to work on OSSIM because it is unpredictable."
"There needs to be more support or some kind of training program so users can self-learn the system more effectively."
"I would like the solution to be able to integrate with my firewall, my IDS and my Honeypot solutions so that it can provide real-time reporting as things occur and then have alert sent to me on my phone when suspicious activity is happening."
"The other thing is the agent is OSSEC. They needed to create its own agent to help to find threats on the devices that it happens to be installed."
"We've had some stability problems, not a lot, but a few. Updates seem to be the worst. That seems to be when the stability problems come up."
"The solution already has quite good tools, however, they need better integration tools for linking with Office 365, Google Suite, and so on."
"The only room for improvement I can mention is the initial installation procedures. I found that the online installation instructions for the product were missing important details, they lacked necessary steps."
"The solution is a bit complicated. It could be simplified quite a bit."
"We would like more plugins. This being the main point of improvement which would benefit the users."
"As this software is in the cloud, you do not have control on updates and general changes which are happening."
"I've been told that AlienVault doesn't have a full version of NES running in there, but I'm not sure if that's accurate or if my engineer made it that way. I'm not sure he was completely honest either because we had NES in the environment before. Those tools could be improved because AlienVault is a SIEM, and it added all these other features."
 

Pricing and Cost Advice

"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"AlienVault OSSIM is free."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"OSSIM is open source, and USM is the paid license. So, if you want, you can switch to USM. There you will have to buy a license, and they have a support team that helps you out on issues you face."
"AlienVault OSSIM is expensive compared to its competitors."
"We are using a free version of the solution. If you purchase a license there are more features available but the price is a little high. The solution should be cheaper to allow more customers to be able to afford it."
"OSSIM is free."
"The solution is open source, so it's free to use."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"Use an MSSP instead. It is much cheaper."
"Its price is much lower than McAfee ESM."
"We ran a few PoCs. The price and feature set were the best with AlienVault."
"AlienVault is certainly not nearly as expensive as Splunk or QRadar. It's decently priced, but I don't have the exact figure."
"Its price is in the medium to upper range."
"The pricing is a good value. The key thing is that for the new product, the licensing of it, is subscription-based and it's based on data. Clients need to be really careful when thinking about that, because odds are they're going to need to put a lot more data into it than what they initially estimate, which is going to drive their subscription costs up."
"Do the one month trial and try to work out the kinks during it, as it has free support and service hours."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
8%
Educational Organization
8%
Government
8%
Computer Software Company
18%
Educational Organization
8%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with AlienVault OSSIM?
Collecting logs can sometimes be tedious, especially compared to my experience with Microsoft Sentinel. I suggest more in-built rules based on modern threats and environments to make it a more comp...
What do you like most about AT&T AlienVault USM?
The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful.
What is your experience regarding pricing and costs for AT&T AlienVault USM?
It is a product that is priced in a medium range, making it neither a cheap nor a costly product.
What needs improvement with AT&T AlienVault USM?
The vulnerability scanning feature is one of the areas where the product has certain shortcomings and needs to improve. The tool has vulnerability scanning, but it is not that efficient. A mobile a...
 

Also Known As

OSSIM
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Learn More

 

Overview

 

Sample Customers

Council Rock School District
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about AlienVault OSSIM vs. USM Anywhere and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.