Try our new research platform with insights from 80,000+ expert users

Security Onion vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Security Onion
Ranking in Log Management
19th
Average Rating
7.6
Reviews Sentiment
5.5
Number of Reviews
3
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Log Management
40th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Security Information and Event Management (SIEM) (29th), Endpoint Detection and Response (EDR) (53rd), Compliance Management (14th)
 

Mindshare comparison

As of October 2025, in the Log Management category, the mindshare of Security Onion is 4.5%, down from 5.4% compared to the previous year. The mindshare of USM Anywhere is 0.5%, down from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
Security Onion4.5%
USM Anywhere0.5%
Other95.0%
Log Management
 

Featured Reviews

Jörg Kippe - PeerSpot reviewer
A mature and affordable solution that is easy to install and easy to update
The product takes time to learn, it's not that easy. In the beginning we had a lot of questions. If you want to use such a tool in an real (industrial) environment, you have to ask how to get the network data. Can we do a full packet capture? Can we provide agents to our end systems? There are no simple solutions to these questions. It's a general problem when running such systems in an industrial environment.
Kris Nawani - PeerSpot reviewer
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Security Onion is the most mature solution in the market."
"We use Security Onion for internal vulnerability assessment."
"The most valuable feature of Security Onion for security monitoring is its ability to find infected ports."
"We are able to get alerts perfectly with FIM and VA features."
"The asset discovery and inventory capabilities in USM Anywhere is quite good."
"The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful."
"The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
"The solution also provides basic log storage options for periods of 15, 30, and 90 days."
"As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business."
"Allowed us to help our customers satisfy compliance needs around logging and monitoring."
"The solution is stable."
 

Cons

"Security Onion's user interface could be improved."
"The initial setup of the solution is a little bit difficult."
"The product is not easy to learn."
"The AT&T AlienVault USM is okay, but the relational database is not very good for large amounts of data. For example, many logs cannot be processed. It has been very slow for the queries and some data which are large, it is not very good in this case."
"Adding a parsing interface for the customers would make AT&T AlienVault USM better."
"The reporting is mediocre and is something that needs to be improved."
"The solution already has quite good tools, however, they need better integration tools for linking with Office 365, Google Suite, and so on."
"AlienVault needs to continue to integrate with other third-party technologies that clients want to have monitored."
"More complimentary training needs to be done for use with this tool. If you get into a bind, then it will cost you."
"Different functions to customize reports should be added."
"We develop additional rules and scripts to make it more usable."
 

Pricing and Cost Advice

"It is an open-source solution."
"Security Onion is an open-source solution."
"Security Onion is a free solution."
"AT&T AlienVault USM is an expensive solution and we pay for the license and the support separately. We paid for the license and support for three years."
"We ran a few PoCs. The price and feature set were the best with AlienVault."
"It is affordable, and it also has many features that the premium products such as ArcSight and QRadar have. It is a very good platform for a SIEM solution. Everything is included in the price."
"Do the one month trial and try to work out the kinks during it, as it has free support and service hours."
"QRadar, ArcSight and Splunk are some of the most expensive SIEM products out there in the market and not everyone has the budget to buy them. In such cases, AV USM is a very cost effective alternative."
"We pay around $12,000 a year including storage."
"Negotiate the best package for your environment."
"So far, it has been a good solution for a tight budget."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
869,760 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
University
11%
Computer Software Company
11%
Comms Service Provider
11%
Government
10%
Computer Software Company
16%
Comms Service Provider
11%
Financial Services Firm
7%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business64
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What do you like most about Security Onion?
The most valuable feature of Security Onion for security monitoring is its ability to find infected ports.
What is your experience regarding pricing and costs for Security Onion?
Security Onion is an open-source solution. On a scale from one to ten, where ten is expensive and one is cheap, I rate the solution's pricing a six out of ten.
What needs improvement with Security Onion?
The initial setup of the solution is a little bit difficult.
What do you like most about AT&T AlienVault USM?
The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that the product has with third-party applications are useful.
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
 

Also Known As

No data available
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Information Not Available
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about Security Onion vs. USM Anywhere and other solutions. Updated: September 2025.
869,760 professionals have used our research since 2012.