Try our new research platform with insights from 80,000+ expert users

Logstash vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Logstash
Ranking in Log Management
25th
Average Rating
9.4
Reviews Sentiment
6.4
Number of Reviews
4
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Log Management
46th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Security Information and Event Management (SIEM) (31st), Endpoint Detection and Response (EDR) (52nd), Compliance Management (13th)
 

Mindshare comparison

As of July 2025, in the Log Management category, the mindshare of Logstash is 0.6%, up from 0.4% compared to the previous year. The mindshare of USM Anywhere is 0.4%, down from 0.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Mustafa Husny - PeerSpot reviewer
Helps to collect logs from various data sources, including hardware
I use Logstash primarily for connecting logs from hardware. This is the main use case. The second use case involves making correlations between logs from various sources.  I can collect logs from various data sources, including hardware. The product needs to improve its compatibility.  I rate…
Kris Nawani - PeerSpot reviewer
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I can collect logs from various data sources, including hardware."
"The transformation means we ship the logs in the way that we want them to be presented in Kibana, which is the main function we use Logstash for."
"Logstash has numerous plugins for inputs and outputs, allowing it to work well in environments that do not contain other Elastic components."
"We have three or four Logstash servers for high availability."
"Everything aligns well with improving our organization."
"The ease of implementation is the most valuable feature."
"We're using it more for reporting, that's all. We're using it to help our customers to pass any kind of audits that they receive."
"The dashboards are very descriptive and contain just the right amount of information. The activity alarms and events contain a plethora of data that is very descriptive and useful."
"We are able to get alerts perfectly with FIM and VA features."
"The vulnerability manager and the file integration are very good."
"The AlienVault solution has enabled us to create a SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers."
"I can easily check (in one place) all the logs and data in relation to attacks. It also gives me an overview if a server is not configured properly."
"The main menu: You can see everything there, what is happening on the servers, and in the logs, you can view more details of each event."
 

Cons

"We still have a problem with importing the log system."
"Almost all the research can be very bad. We still have a problem with importing the log system."
"The product needs to improve its compatibility."
"An enhancement we could implement is the ability to cluster Logstash to exist in more than one node."
"Elastic does not provide proper support for Logstash worldwide, and I rate their technical support as one out of ten."
"Its reporting tools need improvements. It would be good if they can provide integration with other ticketing systems. Currently, we only have integration with Slack and Jira. It is also a bit slow, and its replication engine can be improved."
"Windows log collection works with HIDS, but documentation is sparse and confusing."
"We develop additional rules and scripts to make it more usable."
"I've been using it just for my own personal upskilling in terms of how the product works. At the moment, it is pretty straightforward and simple, and it is working how it is supposed to. The feedback would come once it is deployed to customer sites. They'll be using it on a more frequent basis, and that's when the feedback would come in terms of the areas in which they're facing issues or are looking for simplicity."
"AlienVault needs to continue to integrate with other third-party technologies that clients want to have monitored."
"Reporting is convoluted and difficult at times, although they claim to have hundreds of pre-built reports, very few of them are actually useful for anything but what the USM is doing."
"AlienVault cannot automatically respond to threats like other SIEM solutions, such as Sentinel and LogRhythm. Most of our clients are far away, so it's often challenging to handle alerts when they come up on our dashboard."
"Plugins could be better utilized, as some of them do not recognize all logs."
 

Pricing and Cost Advice

Information not available
"Its price is much lower than McAfee ESM."
"Use the AlienVault team. They are helpful and the documentation that they provide is second to none."
"Negotiate the best package for your environment."
"​The price point is good.​"
"AT&T AlienVault USM is an expensive solution and we pay for the license and the support separately. We paid for the license and support for three years."
"Its price is in the medium to upper range."
"They charge a license based on the storage. ATT AlienVault USM is a less expensive solution than IBM QRadar."
"AlienVault is flexible on their pricing for unlimited licenses."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
861,524 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
12%
Government
9%
Educational Organization
6%
Computer Software Company
19%
Financial Services Firm
10%
Comms Service Provider
9%
Educational Organization
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Logstash?
I can collect logs from various data sources, including hardware.
What needs improvement with Logstash?
An enhancement we could implement is the ability to cluster Logstash to exist in more than one node.
What is your primary use case for Logstash?
A use case for using Logstash that we have involves integration servers that log in files in a non-transformed way. We have more than four servers that log in files, and when we have an issue, we c...
What do you like most about AT&T AlienVault USM?
The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful.
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
 

Comparisons

 

Also Known As

No data available
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Information Not Available
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about Logstash vs. USM Anywhere and other solutions. Updated: July 2025.
861,524 professionals have used our research since 2012.