No more typing reviews! Try our Samantha, our new voice AI agent.

LevelBlue USM Anywhere vs LogLogic comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 24, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LevelBlue USM Anywhere
Ranking in Log Management
28th
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (37th), Compliance Management (14th)
LogLogic
Ranking in Log Management
50th
Ranking in Security Information and Event Management (SIEM)
47th
Average Rating
6.0
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Log Management category, the mindshare of LevelBlue USM Anywhere is 1.4%, up from 0.4% compared to the previous year. The mindshare of LogLogic is 1.0%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
USM Anywhere1.4%
LogLogic1.0%
Other97.6%
Log Management
 

Featured Reviews

Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…
it_user126030 - PeerSpot reviewer
Senior ICT Solutions Expert at a comms service provider with 1,001-5,000 employees
I've evaluated Splunk and IBM Q1 but LogLogic is the best choice for log management. SIEM functionality needs improvement.
If you are searching for log management solution, LogLogic is probably the best choice. The SIEM functionality is not at that level, and I suggest instead to choose another SIEM solution (eg: IBM Q1). In my experience, a good practice is to separate log management from SIEM in a way that they are two separate systems.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The UI is clean and easy to use."
"The other big selling feature for us was its integration capabilities with all the other security-based products."
"Implementation took few days and it's easy to complete the task within the given project time line."
"AlientVault has helped us in improving our visualization and incident response during cybersecurity situations."
"The solution also provides basic log storage options for periods of 15, 30, and 90 days."
"The best thing about AlienVault USM is it being a Jack-of-All Trades solution, providing SIEM, HIDS/NIDS, FIM, NetFlow, Asset Management, Vulnerability Management, and more under one USM platform, which none of the commercial SIEM vendors like ArcSight or McAfee can boast of with such a diverse feature set."
"AlienVault provided the best bang for buck."
"The solution has all the features that we need, however they do not work correctly."
"If you are searching for log management solution, LogLogic is probably the best choice."
"Having logs in a central location helps with troubleshooting, forensic investigations, and legal investigations."
 

Cons

"It needs to be easier to deploy switch monitoring."
"The only that I can think of is that is not ideal is sending Windows Server logs to their device, to the system."
"The Log Management and configuration of email notifications should be user-friendly."
"AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive."
"The AT&T AlienVault USM is okay, but the relational database is not very good for large amounts of data. For example, many logs cannot be processed. It has been very slow for the queries and some data which are large, it is not very good in this case."
"There were deployment issues. At the time, it was right after USM Anywhere had been released, and not all of the documentation was posted."
"Taking into account that server access credentials are controlled by the tool, some more management-focused actions could be performed from AlienVault."
"Reporting still needs a lot of work, especially on the vulnerability side."
"Customer Service: On a scale of 1-5, 0. They say the right things but don't deliver when it counts."
"Definitely SIEM – other vendors have gone a lot further in developing SIEM functionality and made a lot more in this area."
 

Pricing and Cost Advice

"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"It has good pricing."
"So far, it has been a good solution for a tight budget."
"Its price is in the medium to upper range."
"They charge a license based on the storage. ATT AlienVault USM is a less expensive solution than IBM QRadar."
"AlienVault is certainly not nearly as expensive as Splunk or QRadar. It's decently priced, but I don't have the exact figure."
"It allows you to do a lot with a small price tag... The pricing is the best on the market."
"It is affordable, and it also has many features that the premium products such as ArcSight and QRadar have. It is a very good platform for a SIEM solution. Everything is included in the price."
Information not available
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
914,351 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
20%
Outsourcing Company
18%
Comms Service Provider
8%
Manufacturing Company
7%
Construction Company
20%
Comms Service Provider
20%
Financial Services Firm
16%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
No data available
 

Questions from the Community

What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
Ask a question
Earn 20 points
 

Also Known As

AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
No data available
 

Overview

 

Sample Customers

Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Astrium, Cerner, Children's Hospital, Effiage, Lavego, Plantronics, Skipton Building Society, The Body Shop, The Lowry, University of Manitoba
Find out what your peers are saying about LevelBlue USM Anywhere vs. LogLogic and other solutions. Updated: September 2026.
914,351 professionals have used our research since 2012.