Try our new research platform with insights from 80,000+ expert users
it_user672663 - PeerSpot reviewer
Information Security Analyst at a insurance company
Vendor
Some of the valuable features are log aggregation, correlation, and threat intel.

What is most valuable?

Log aggregation, correlation, and threat intel.

How has it helped my organization?

AlienVault has streamlined our security functions by combining several different functions into one package.

What needs improvement?

I think expanding their vendor-specific plugins would beneficial.

For how long have I used the solution?

We have been using this solution for one year.

Buyer's Guide
USM Anywhere
June 2025
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,711 professionals have used our research since 2012.

What was my experience with deployment of the solution?

I did not encounter any issues with deployment.

What do I think about the stability of the solution?

I did not encounter any issues with stability.

What do I think about the scalability of the solution?

I did not encounter any issues with scalability.

How are customer service and support?

Customer Service:

Their support is good and their response time is prompt.

Technical Support:

I would rate them as very knowledgeable.

Which solution did I use previously and why did I switch?

We did not use a previous solution.

How was the initial setup?

It was very straightforward. The setup was basically install the VM, setup network monitoring/syslog, and watch the data flow.

What about the implementation team?

Our implementation was in-house.

What was our ROI?

It's hard to calculate ROI on a prevention mechanism, as the variables of a prevented incident are unknown.

What's my experience with pricing, setup cost, and licensing?

They are very affordable and flexible in their licensing model.

Which other solutions did I evaluate?

We evaluated HPE ArcSight, IBM QRadar, LogRhythm, Splunk, and SolarWinds.

What other advice do I have?

I would highly recommend the customer training courses. They are very helpful.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

thank you for your time and your comments.

it_user671703 - PeerSpot reviewer
Sr. Networking & EMS Analyst
Vendor
Provides a good platform to start looking at the traffic on your network.

What is most valuable?

Event monitoring and vulnerability scanning have been a huge benefit to us.

How has it helped my organization?

It provides a good platform to start looking at the traffic on your network.

What needs improvement?

Most of the troubleshooting requires going through the Linux command line and bypassing the GUI. We have a wide variety of users with different technical expertise. For some, any amount of command line troubleshooting scares them away from products.

For how long have I used the solution?

We have been using this solution for a year.

What was my experience with deployment of the solution?

Our deployment was rather unique and is pushing the limitations of the architecture that we chose. Given from what I have learned, if you have large deployments of the separate networks, then do not attempt to use remote sensors on those network segments.

What do I think about the stability of the solution?

Many of the patches typically have some bugs that we end up finding. We ended up implementing a deployment in our lab so as to fully test it internally, before patching.

What do I think about the scalability of the solution?

The system is quite scalable however, it is best to understand the limitations of the different architectures offered.

How are customer service and technical support?

Customer Service:

The customer service is excellent, we have quick and knowledgeable help on all our calls.

Technical Support:

The support team is also excellent with very knowledgeable engineers.

Which solution did I use previously and why did I switch?

This was our first solution for this type of security appliance.

How was the initial setup?

The initial setup was straightforward, but adding in more sensors made it a bit more complex.

What about the implementation team?

We had vendor help for the initial setup, however, the additional sensor expansion was in-house.

What was our ROI?

We quickly found some issues after deploying and have used the vulnerability scanner to verify patches are properly applied in the environment.

What's my experience with pricing, setup cost, and licensing?

If you expect to have a significant amount of devices on a sensor, then look at the cost/performance of going to a full server.

Which other solutions did I evaluate?

We evaluated LogRhythm and QRadar.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thanks Chris for your feedback & comments!

See all 2 comments
Buyer's Guide
USM Anywhere
June 2025
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,711 professionals have used our research since 2012.
PeerSpot user
Director Of Information Technology at a tech services company with 51-200 employees
Real User
Allows us to roll out log management on clients and servers, host-based IDS, and network-based IDS.
Pros and Cons
  • "The best feature of this product is the ease of use. It is extremely easy to set up and get going. This is a very useful tool for a small organization."
  • "I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job."

How has it helped my organization?

This has helped improve our overall IT security by allowing us to implement a full suite of security tools that allows us to roll out log management on clients and servers, host-based IDS, and network-based IDS. It also provides vulnerability scanning; however, we use a separate product for that.

What is most valuable?

The best feature of this product is the ease of use. It is extremely easy to set up and get going. This is a very useful tool for a small organization.

What needs improvement?

I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job.

What do I think about the stability of the solution?

We have not encountered any stability issues.

What do I think about the scalability of the solution?

We have not encountered any scalability issues; the product scales very easy.

How are customer service and technical support?

Customer Service:

I would rate customer service an 8/10. I've received calls from customer service a few times a month and it gets a little overbearing, especially when you are busy, as IT professionals are.

Technical Support:

I would rate technical support a 9/10.

Which solution did I use previously and why did I switch?

This was our first solution for HIDS, NIDS, and log management.

How was the initial setup?

The initial setup was straightforward. I simply followed the steps in the setup wizard and the steps provided by technical support, and I had a trial version (later converted to paid version with additional steps) set up in about an hour or less.

What about the implementation team?

This was set up in-house.

What was our ROI?

It is really hard to put a number on ROI but I will say that AlienVault has allowed us to close the gap on security alert timing and we can respond to incidents in a much more timely fashion which, to me, is much more valuable than a number.

What's my experience with pricing, setup cost, and licensing?

AlienVault is flexible on their pricing for unlimited licenses.

Which other solutions did I evaluate?

We evaluated Splunk as well. AlienVault was a much cheaper solution and required less time to be rolled out. Splunk is a much more difficult product to work with and almost requires a dedicated employee to manage.

What other advice do I have?

I highly recommend AlienVault USM for anybody that is seeking a SIEM solution that is easy to implement and easy to manage. It works very well for small- and medium-size businesses.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Brett - thank you so much for taking time to provide your comments & feedback.

See all 2 comments
PeerSpot user
IT Security Analyst at a financial services firm with 201-500 employees
Vendor
You can customize the "Overview" dashboard to you or your company's needs.

What is most valuable?

AlienVault's "Overview" dashboard makes it very easy to see everything going on in your network that needs your immediate attention. You can easily customize the dashboard to you or your company's needs.

How has it helped my organization?

I now have the ability to report all vulnerabilities and threats hitting our network to upper management in an easy-to-understand format.

What needs improvement?

Offer solutions based on a PoC (Proof of Concept) to fit each company's specific needs, rather than letting the company guess or piece together the solution they need.

For how long have I used the solution?

I have used it for six months.

What was my experience with deployment of the solution?

We have not encountered any deployment issues; the setup was very easy and support was by my side to assist me with any issues that arose.

What do I think about the stability of the solution?

We have encountered stability issues; we have a high volume of logs passing through our SIEM and the default configuration couldn't handle all the data. Working with support, we were able to remediate all the crashes we were having.

What do I think about the scalability of the solution?

We have encountered scalability issues. We had to keep changing our configuration or updating our storage capabilities as we added more logs.

How are customer service and technical support?

Customer Service:

Customer service is 8/10.

Technical Support:

Technical support is 9/10. Engineers are very knowledgeable about their product!

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

The setup was very straightforward. AlienVault provides simple, step-by-step instructions for each of their products!

What about the implementation team?

As a single Analyst, I was able to implement this product very easily.

What was our ROI?

At this time, it is too early to tell ROI.

What's my experience with pricing, setup cost, and licensing?

Know your capabilities and storage needs before negotiating a price! Make sure you ask about log storage options before purchase.

Which other solutions did I evaluate?

Before choosing, we evaluated other options. We were looking at Splunk and Rapid7.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Lucas - I appreciate you taking time to provide your experience of using AlienVault USM.

See all 2 comments
PeerSpot user
Professor at a university with 201-500 employees
Vendor
It is set up as a dashboard in the security lab. Students can view and analyze the monitoring techniques of the product.

What is most valuable?

AlienVault is used in a classroom setting at Pittsburgh Technical College, which brings industry tools from the college classroom back into the field. We have several employers in the area that use AV so student acclimation to the product is key. AV is set up as a dashboard in the security lab where students can view and analyze the monitoring techniques of the product. If an event happens, they can process an analytical step to provide remediation.

How has it helped my organization?

Students becoming acclimated to the product can go out into the field and have first-hand knowledge on how to use a USM or SIEM product. This is a win-win solution for the vendor and future employers.

For how long have I used the solution?

The school has used the product for over a year.

What was my experience with deployment of the solution?

We were attempting to push HIDS on the domain controllers, and ran into an initial problem. This problem was immediately solved by the AV service technician that was able to remote in and fix the problem.

What do I think about the stability of the solution?

One of the problems we had with stability was a problem of our own. We were running AV on a VLAN that students were able to run DHCP servers, which caused our own problems.

How are customer service and technical support?

Customer Service:

We have had several tickets open with AV and they are prompt in their service time.

Technical Support:

Technical support is prompt in acknowledging your needs and reply with a message that a service technician will be with you shortly. They make every attempt possible to work with your schedule.

Which solution did I use previously and why did I switch?

A direct competitor to AV is IBM QRadar, which is also used in the classroom environment.

How was the initial setup?

The setup was straightforward. We installed AV to vSphere ESXi as a virtual appliance deployed as an OVA template.

What was our ROI?

The ROI is unmeasured since we are an academic partner; there is no way of knowing how much positive impact the product will attain from students getting first-hand knowledge of an industry product before they go out into the field upon graduation.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are an academic partner.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Philip - thanks so much for your comments & feedback on your experience with AlienVault USM.

See all 2 comments
PeerSpot user
System Administrator at a financial services firm with 201-500 employees
Vendor
The alarms dashboard shows any threats that may need further investigation.
Pros and Cons
  • "The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
  • "The vulnerability reporting needs to have options to be able to sort or customize the output."

How has it helped my organization?

AlienVault has brought more awareness to the activity on our network. Security risks are identified and addressed to reduce any possible security breach.

What is most valuable?

Alarms dashboard shows immediately any threats that may need further investigation. The vulnerability scanning is helpful to identify the areas that need patching or fixes installed.

What needs improvement?

The vulnerability reporting needs to have options to be able to sort or customize the output. It is helpful to look at the vulnerability and how many hosts have it, in addition to being able to look at an individual host to see what vulnerabilities it has.

What do I think about the stability of the solution?

We did not encounter any stability issues. AlienVault seems to be pretty solid and we have not had any issues with it being unavailable.

What do I think about the scalability of the solution?

We have not encountered any scalability issues. We have a fairly simple deployment with only one sensor, so it was straightforward.

How are customer service and technical support?

Customer Service:

Customer service is very good.

Technical Support:

Technical support is very good. They have always been prompt to address an issue and stuck with it until resolution.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

Initial setup was very straightforward; few configuration settings and it was pulling in logs.

What about the implementation team?

An in-house team implemented it.

What was our ROI?

ROI is a difficult one to measure for this. It helps us cover a compliance need as well as provides us a means to be aware of any possible threats and vulnerabilities.

What's my experience with pricing, setup cost, and licensing?

Pricing is very competitive with other products and you get much more functionality from AlienVault. The vulnerability scanning and threat intelligence offers additional tools that others don't have.

Which other solutions did I evaluate?

We looked at a couple of other products before choosing AlienVault. We looked at LogRhythm and EventTracker.

What other advice do I have?

If you take the training virtually, make sure you can dedicate the week with uninterrupted time. The training is quite in-depth and you want to have your undivided attention on it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user723714 - PeerSpot reviewer
it_user723714Product Manager at a tech vendor with 201-500 employees
Real User

Laurie, awesome to hear you're having a great experience with the product! We hear you loud and clear on the need to extend our reporting capabilities, especially around vulnerability management. I'll try to keep you in the loop as we look to roll out new features to this area of the product. Thanks again for the feedback and for being a customer. We truly appreciate your business!

See all 3 comments
PeerSpot user
Tech Support Engineer at a tech services company with 501-1,000 employees
MSP
Offers an Open Threat Exchange for IP reputation and vulnerability scanning.

What is most valuable?

  • Open Threat Exchange (for IP reputation)
  • Vulnerability scanning
  • Quick APT phishing-related threat detection

How has it helped my organization?

  • Phishing sites were detected and it secured the environment from the upcoming threat.
  • Vulnerability scanner OpenVas is very useful for knowing current vulnerabilities present in system and taking preventive action.

What needs improvement?

  • IPv6 not supported
  • Correlate with external logs from other sources makes little bit difficult to work

For how long have I used the solution?

I have been using it for one year.

What was my experience with deployment of the solution?

It works well when you have minimum required setup as per AlienVault documentation.

What do I think about the stability of the solution?

Stability issues happen only when you do not have sufficient hardware as the primary requirement.

What do I think about the scalability of the solution?

It scales well.

How are customer service and technical support?

Customer Service:

Customer service is 7 out of 10.

Technical Support:

Technical support is 10 out of 10.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

Initial setup was straightforward and simple.

What about the implementation team?

An in-house team implemented it.

What was our ROI?

It is providing good ROI.

What's my experience with pricing, setup cost, and licensing?

It is cheaper and more valuable compared to other reputable SIEMs.

Which other solutions did I evaluate?

Before choosing this product, we did not evaluate other options.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user723714 - PeerSpot reviewer
it_user723714Product Manager at a tech vendor with 201-500 employees
Real User

Thank you so much for the feedback! I did want to let you konw that we're currently working on IPv6 support and have just rolled out a Custom Plugin Builder to make onboarding custom log sources more efficient. Please keep in touch with how the product is working for you!

See all 3 comments
it_user604401 - PeerSpot reviewer
AVP & Information Security Officer at a financial services firm with 501-1,000 employees
Real User
Automated alarms help identify what is happening on your network that should be investigated.

What is most valuable?

The automated alarms have been very helpful in identifying what is happening on your network that should be investigated.

How has it helped my organization?

It has helped us keep an eye on Admin activity on the network and in our directory.

What needs improvement?

The way it identifies systems can use some improvement. It has a hard time differentiating between versions of Windows.

For how long have I used the solution?

I have used it for two years.

What was my experience with deployment of the solution?

Deployment was extremely smooth.

What do I think about the stability of the solution?

The system has been very stable.

What do I think about the scalability of the solution?

We have a small network. So far, we have had no issues with scale.

How are customer service and technical support?

Customer Service:

Customer service is excellent, very responsive, and they know their product.

Technical Support:

Technical support is excellent so far.

Which solution did I use previously and why did I switch?

This was the solution selected after evaluating several competing products; no SIEM prior to this deployment.

How was the initial setup?

Initial setup was very straightforward.

What about the implementation team?

We did the initial implementation and then had a vendor fine tune it with us. The vendor was very well qualified.

What's my experience with pricing, setup cost, and licensing?

Licensing and pricing was one of the primary reasons for selecting this solution. Since no one has an unlimited budget, consider your needs and get the most bang for your buck.

Which other solutions did I evaluate?

Before choosing this product, we evaluated other options. We were leaning heavily towards AccelOps but had worries about their viability as a business.

What other advice do I have?

If you are considering this solution, I highly recommend that you have someone in-house who is familiar with Unix/Linux. The underpinnings of this solution is *nix. It will make deployment and ongoing maintenance much easier.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you so much for your comments & thoughtful feedback.

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.