No more typing reviews! Try our Samantha, our new voice AI agent.

LevelBlue USM Anywhere vs Logsign Next-Gen SIEM comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 24, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LevelBlue USM Anywhere
Ranking in Log Management
28th
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (37th), Compliance Management (14th)
Logsign Next-Gen SIEM
Ranking in Log Management
46th
Ranking in Security Information and Event Management (SIEM)
45th
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of LevelBlue USM Anywhere is 1.5%, up from 1.0% compared to the previous year. The mindshare of Logsign Next-Gen SIEM is 1.1%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
USM Anywhere1.5%
Logsign Next-Gen SIEM1.1%
Other97.4%
Security Information and Event Management (SIEM)
 

Featured Reviews

Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…
Thanuja Karunarathne - PeerSpot reviewer
Engineer at Connex Information Technologies
Real-time monitoring and analytics are very easy and fast and very easy to use
The alerting and real-time analytics helped the security team. They are using a Hadoop database, so real-time monitoring and analytics are very easy and fast. Queries return results quickly and in very small time. It has full automation and automated SIEM responses. We are currently only testing Logsign, but in a few months, we plan to integrate our servers, routers, firewalls, and endpoints into our company's Logsign instance. Then, we can manage everything using Logsign.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AlienVault is the more appropriate solution, it's flexible, Linux based, and contains a large number of open source solutions."
"This solution can completely detect and prevent incidents on your network."
"Using the communication within the security device, it is easier to create plugins."
"The most valuable feature in AT&T AlienVault USM is the reporting."
"We have a better detection rate for malware and other cyber-attacks, and it really helps when USM is integrated in the incident response plan."
"The setup of AlienVault is extremely easy; it is very simple to understand for someone who is trying a SIEM solution for the first time, and the integration of servers and other devices is extremely easy, as it is a piece of cake where you just double-click and start, and you are up and running."
"We find AlienVault to have the best price to performance value."
"It has allowed us to see what is happening on our servers."
"The most valuable features of Logsign SIEM are its cloud capabilities, alerting functionality, integration with Elastic Search, and configuration options."
"Logsign provides sample logs within the product, allowing users to see how logs will appear before integration, which is a valuable feature for testing and understanding log formats."
"It has full automation and automated SIEM responses."
 

Cons

"Its reporting tools need improvements."
"Their threat intelligence platform needs to be broadened. They should integrate it with more threat intelligence platforms. For the threat feed that they get from open intelligence, I would like them to add a few premium threat intelligence platforms. They can provide a bundle in which AlienVault has the threat intelligence background of other premium products."
"The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing."
"There is room for improvement in Log parsing."
"IPv6 not supported Correlate with external logs from other sources makes little bit difficult to work"
"I think plugin management should be self-service on AlienVault USM. The other product is self-service but on the USM side. You have to submit a ticket then AT&T creates and updates the plugins."
"I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job."
"Although they use machine learning, the algorithms that they use are graph-based."
"I hope they address the pricing model for Logsign Next-Gen SIEM, especially regarding regional variations. The pricing should not differ based on the country of operation as it can lead to dissatisfaction among customers. A fixed pricing structure would be more favorable for us. I would also suggest enhancing the GUI interface and adding features similar to xFi Exchange from IBM Pure. This would streamline operations and save time for analysts."
"AI and machine learning need to be developed. If they develop those features, I think everything will be fine."
"Improvements needed in Logsign SIEM are providing specific security alerts that can be filtered and configured more effectively."
 

Pricing and Cost Advice

"AlienVault is certainly not nearly as expensive as Splunk or QRadar. It's decently priced, but I don't have the exact figure."
"QRadar, ArcSight and Splunk are some of the most expensive SIEM products out there in the market and not everyone has the budget to buy them. In such cases, AV USM is a very cost effective alternative."
"It's very reasonably priced. It was one of the lowest among the ones I looked at. Licensing is pretty flexible. They can do a two-year or a three-year, even a one-year, perhaps."
"Pricing is very competitive with other products and you get much more functionality from AlienVault."
"The licensing fees are dependent on usage."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"They are a little more expensive than Microsoft."
"The pricing is a good value. The key thing is that for the new product, the licensing of it, is subscription-based and it's based on data. Clients need to be really careful when thinking about that, because odds are they're going to need to put a lot more data into it than what they initially estimate, which is going to drive their subscription costs up."
"Compared to other SIEMs, it has low pricing."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
20%
Outsourcing Company
18%
Comms Service Provider
8%
Financial Services Firm
7%
Comms Service Provider
14%
Financial Services Firm
12%
Construction Company
8%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
No data available
 

Questions from the Community

What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
Ask a question
Earn 20 points
 

Also Known As

AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
No data available
 

Overview

 

Sample Customers

Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Turkish Petroleum, Tırsan, DP World, SAC American Colleges, Robert College, Unlu&Co, UniCo Insurance Company, ETSTur, CK Energy, UEDAS Energy, Wilo, Eurocross Assistance, Deloitte Turkey, Incı GS Yuasa, Pappara, Bilgi University, Anadolu University, İstanbul University, The Ministry of Energy and Natural Resources, TRT, Anadolu Media Agency, Ministry of Family, Labour and Social Services, Ispark, Spor AS and wide range of enterprises in different industries. 
Find out what your peers are saying about LevelBlue USM Anywhere vs. Logsign Next-Gen SIEM and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.