No more typing reviews! Try our Samantha, our new voice AI agent.

Security Onion vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Security Onion
Ranking in Log Management
27th
Average Rating
7.6
Reviews Sentiment
5.5
Number of Reviews
3
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Log Management
36th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Security Information and Event Management (SIEM) (31st), Endpoint Detection and Response (EDR) (41st), Compliance Management (13th)
 

Mindshare comparison

As of April 2026, in the Log Management category, the mindshare of Security Onion is 2.6%, down from 5.7% compared to the previous year. The mindshare of USM Anywhere is 1.0%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
Security Onion2.6%
USM Anywhere1.0%
Other96.4%
Log Management
 

Featured Reviews

Jörg Kippe - PeerSpot reviewer
Scientist at a educational organization with 10,001+ employees
A mature and affordable solution that is easy to install and easy to update
The product takes time to learn, it's not that easy. In the beginning we had a lot of questions. If you want to use such a tool in an real (industrial) environment, you have to ask how to get the network data. Can we do a full packet capture? Can we provide agents to our end systems? There are no simple solutions to these questions. It's a general problem when running such systems in an industrial environment.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"Security Onion is the most mature solution in the market."
"We use Security Onion for internal vulnerability assessment."
"The solution has all the features that we need, however they do not work correctly."
"We have benefited greatly due to gaining the visibility we need for different instances."
"Phishing sites were detected and it secured the environment from the upcoming threat."
"AlienVault is a full featured cost effective SIEM that provides quality threat intelligence for a lot less than the competition."
"The main menu: You can see everything there, what is happening on the servers, and in the logs, you can view more details of each event."
"Using the communication within the security device, it is easier to create plugins."
"SIEM log collection is great, and all of the rules that support updates with maintenance."
"The asset management functionality (active and passive scans) is also really important. You can't protect what you do not know about, so having an inventory of all your devices and software is critical to a security management program."
 

Cons

"The product is not easy to learn."
"Security Onion's user interface could be improved."
"The initial setup of the solution is a little bit difficult."
"The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing."
"The GUI needs to improve because it's not user-friendly."
"Reporting and Windows log collection is the biggest drawback."
"There were stability issues due to lack of memory."
"Source material on the forums to be more up-to-date with the changes happening within the product."
"The solution is very user-friendly, but the dashboard could be improved as well as the level of customization."
"Search performance can be slow. The Raw Logs feature is painfully slow."
"Customer service is 4/10 - they need to provide faster responses to emails."
 

Pricing and Cost Advice

"Security Onion is a free solution."
"It is an open-source solution."
"Security Onion is an open-source solution."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"Do the one month trial and try to work out the kinks during it, as it has free support and service hours."
"It's affordable for most customers."
"AT&T AlienVault USM is an expensive solution and we pay for the license and the support separately. We paid for the license and support for three years."
"QRadar, ArcSight and Splunk are some of the most expensive SIEM products out there in the market and not everyone has the budget to buy them. In such cases, AV USM is a very cost effective alternative."
"​The price point is good.​"
"Use an MSSP instead. It is much cheaper."
"The ROI is quite good."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
886,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
University
12%
Government
11%
Comms Service Provider
10%
Computer Software Company
7%
Construction Company
21%
Financial Services Firm
10%
Computer Software Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

Ask a question
Earn 20 points
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
 

Also Known As

No data available
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Information Not Available
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about Security Onion vs. USM Anywhere and other solutions. Updated: April 2026.
886,858 professionals have used our research since 2012.