Try our new research platform with insights from 80,000+ expert users
it_user467397 - PeerSpot reviewer
IT Security Administrator at a local government with 501-1,000 employees
Vendor
The basic setup was straightforward. I'd like to see built in support to detect more security incidents.

What is most valuable?

  • Security alarms
  • Log collection

How has it helped my organization?

We now get a better view into what is happening on our network and to the servers than previously.

What needs improvement?

I'd like to see built in support to detect more security incidents.

For how long have I used the solution?

I've been using it for 10 months.

Buyer's Guide
USM Anywhere
May 2025
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
853,831 professionals have used our research since 2012.

What do I think about the stability of the solution?

We had no issues with the stability.

What do I think about the scalability of the solution?

It's been able to scale for our needs.

How are customer service and support?

They're very good.

Which solution did I use previously and why did I switch?

This is the first time we've used a solution of this type.

How was the initial setup?

The basic setup was straightforward, but it would have been nice if I could have had more information on a full setup and the advanced features.

What's my experience with pricing, setup cost, and licensing?

You should license it for all your devices including endpoints, as this will make it more valuable to you.

Which other solutions did I evaluate?

We did compare it to some others solutions, but I don't remember which.

What other advice do I have?

Try it first as you get a free evaluation.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for taking time to provide your feedback on your use of AlienVault USM.

it_user466518 - PeerSpot reviewer
IT Security Architect at a healthcare company with 1,001-5,000 employees
Vendor
I can see all HIDS and IDS events in one place. Setup is complex when playing with custom plugins.

What is most valuable?

The SIEM part where I can see all HIDS and IDS events in one place alongwith the correlation directives.

How has it helped my organization?

We have a better detection rate for malware and other cyber-attacks. Really helps when USM integrated in the incident response plan.

What needs improvement?

  • Database query speed when dealing with millions of events per day
  • Reports customization and types
  • Dashboards TV modes (SOC surveillance monitors)

For how long have I used the solution?

I've been using it for three years.

What do I think about the stability of the solution?

I've experienced frequent slowness, and we had to downgrade to filter out many logs.

What do I think about the scalability of the solution?

The AIO is not fast enough for a network over 100 EPS, so you have to go with a dedicated server option for better speed.

How are customer service and technical support?

7/10

Which solution did I use previously and why did I switch?

We had nothing in place prior to this.

How was the initial setup?

It's complex when playing with custom plugins.

What's my experience with pricing, setup cost, and licensing?

The price is low, and it's good quality but require effort.

Which other solutions did I evaluate?

There were no other options looked at.

What other advice do I have?

To take full advantage of the product you have to work under the hood.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for your time to provide your comments on using USM.

Buyer's Guide
USM Anywhere
May 2025
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
853,831 professionals have used our research since 2012.
it_user466902 - PeerSpot reviewer
IT Engineer at a energy/utilities company with 501-1,000 employees
Vendor
Due to the logger feature, everything is centralized on the AlientVault Server.

Valuable Features:

Event Correlation is the most valuable feature for every SIEM. AlienVault has ISO 27001 compliance which is very helpful for the companies looking to have the ISO 27001 certification.

Improvements to My Organization:

As it includes a logger feature for gathering all logs from all devices (network devices, servers, hosts etc.) it has basically become the only software that we look at when we have a problem. We don’t need to search from one device to another as it’s all centralized on the same AlienVault Server which enables us to save time and become more efficient at work.

Room for Improvement:

As it includes multiple security softwares, the installation and configuration takes a lot of time. It would be good if they could work on that but the time is understandable given all the features AlienVault offers.

Other Advice:

It’s a very good SIEM with plenty of functionalities which helped improve our KPI.

Disclosure: I am a real user, and this review is based on my own experience and opinions.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Wajdi Ayari - I thank you so much for taking time to provide feedback on your experience with USM.

it_user466506 - PeerSpot reviewer
Group Information Security Officer at a consumer goods company with 1,001-5,000 employees
Vendor
Before AlientVault we had no visibility of our vulnerabilities without looking up WSUS and matching this against the Windows bulletins.

What is most valuable?

The correlation from the Host Based Intrusion to Network Intrusion against the vulnerabilities in my network.

How has it helped my organization?

We had no visibility of our vulnerabilities without looking up WSUS and matching this against the Windows bulletins. This completely missed the mark when it came to third party patches and poor configuration and waster hours upon hours for half a story. Not to mention we have a much better understanding of how and when we are being attacked.

What needs improvement?

The reporting could do with some improvements for example the vulnerability report only tells you what vulnerabilities are open and lists them but there is no indication of how old they are at a glance and what vulnerabilities have been closed since the previous scans. I would also like to see the ability to scan my devices for compliance against the CIS Benchmarks.

For how long have I used the solution?

I have had this solution in place for just over a year now.

What do I think about the stability of the solution?

I've not experienced any issues with this yet.

What do I think about the scalability of the solution?

I've not experienced any issues with this yet.

How are customer service and technical support?

The tech support guys have been very friendly and helped as soon as there has been any issue. I cannot fault their technical support.

Which solution did I use previously and why did I switch?

I used multiple products to try and get someway towards the level of visibility afforded by AlienVault. ManageEngine SIEM, Qualys, vulnerability management, and Norton for HIDS. Having this all in one interface made more sense which swayed the decision to go with Alienvault.

How was the initial setup?

Very easy for initial set-up. My system was up and running within two hours. When you start to get into it more, then you need a better technical understanding.

What's my experience with pricing, setup cost, and licensing?

This is much cheaper than some of the big names it is very affordable and scalable.

Which other solutions did I evaluate?

We looked at managed services from Dell SecureWorks as well as Qualys & Nessus.

What other advice do I have?

Being the only Security professional in an organisation of well over 1000 people AlienVault lets me keep a watchful eye whilst getting on with my day job. This is a very good product with excellent support. Personally I would have preferred to go on the AlienVault System Engineers course as I believe this would help in fine tuning the system.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thanks so much for the feedback on your experience with AlienVault & USM.

it_user466923 - PeerSpot reviewer
Information Security Administrator at a government with 1,001-5,000 employees
Vendor
It provides greater visibility of host based and network activity through its HIDS and NIDS functionality. They should simplify the HIDS agent reporting/custom rule creation.

What is most valuable?

  • Central log aggregation
  • Security correlation

How has it helped my organization?

It provides greater visibility of host-based and network activity through its HIDS and NIDS functionality.

What needs improvement?

They should simplify the HIDS agent reporting/custom rule creation.

For how long have I used the solution?

I've used it for one year.

What do I think about the stability of the solution?

We had issues but this was due to us receiving improper training from a third party and not necessarily due to the product.

What do I think about the scalability of the solution?

Servers/sensors cap at 2048 host based agent deployments, but servers and sensors are easily scalable for a medium sized business.

How are customer service and technical support?

10/10

Which solution did I use previously and why did I switch?

I haven't used anything similar.

What's my experience with pricing, setup cost, and licensing?

AlienVault is willing to offer flexible and competitive pricing.

Which other solutions did I evaluate?

We also looked at AccelOps, LogRhythm, and IBM QRadar.

What other advice do I have?

If you have any questions, AlienVault's support team is more than willing to help with your installation, implementation, and integration.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you for your feedback & comments.

PeerSpot user
Network Engineer II at a healthcare company
Vendor
We now can find the source of where Windows account lockouts are occurring.

What is most valuable?

We now have the ability to see what is happening in the environment.

How has it helped my organization?

We now can find the source of where Windows account lockouts are occurring.

What needs improvement?

It needs to be easier to deploy switch monitoring.

For how long have I used the solution?

We've been using it for four months.

What do I think about the stability of the solution?

We've had no issues so far.

What do I think about the scalability of the solution?

We've been able to scale it for our needs without issues.

How are customer service and technical support?

I've not had to contact them yet.

Which solution did I use previously and why did I switch?

We switched because our previous solution wasn't scalable.

How was the initial setup?

It was pretty straightforward.

What's my experience with pricing, setup cost, and licensing?

It was a reasonably priced solution.

Which other solutions did I evaluate?

We didn't look at any other solutions.

What other advice do I have?

It’s pretty easy to setup but to really take advantage you should have a dedicated person who will devote their time, to customizing and utilizing the power this solution has.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Lenny - thank you so much for your feedback & comments.

it_user467313 - PeerSpot reviewer
IT Field Support Manager at a consumer goods company with 1,001-5,000 employees
Vendor
We already used a lot of the open source products in this suite. This brought them all under one roof and allowed one person do all the work.

What is most valuable?

The SIEM and intrusion detection.

How has it helped my organization?

We already used a lot of the open source products in this suite but they were too cumbersome for our IT team to handle. This brought them all under one roof and allowed one person to do what 10 could not in a few hours a day.

What needs improvement?

They need to be faster in developing custom plugins.

For how long have I used the solution?

We've been using it for six months.

What do I think about the stability of the solution?

We've had no issues so far and the product works great.

What do I think about the scalability of the solution?

We have not scaled it yet but it handles our entire environment without a problem.

How are customer service and technical support?

4/10 - they need to provide faster responses to emails.

Which solution did I use previously and why did I switch?

We previously used Splunk for SIEM.

How was the initial setup?

It is a complex product, but a lot less complex than the products it's built on like Snort and Splunk.

What's my experience with pricing, setup cost, and licensing?

Get the Virtual Appliance and build the unit yourself. The software is the valuable piece as AlienVault is not a hardware builder and the machine they sell is fine but you could build better yourself for much less.

Which other solutions did I evaluate?

We also looked at Solarwinds SIEM and network monitoring.

What other advice do I have?

Go slow and get everything into your SIEM so you can do some really neat correlations and alerts.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Thank you so much Mike for taking the time to provide your feedback of AlienVault USM.

it_user466524 - PeerSpot reviewer
Senior Infrastructure Analyst at a pharma/biotech company with 1,001-5,000 employees
Vendor
Provides a single way to analyze traffic and threats on our network.

What is most valuable?

Enabling visibility of traffic on our network, merging of multiple systems reporting and analysis and clear method to highlight potential issues.

How has it helped my organization?

Previously we had no single way to analyze traffic and threats on our network, relying instead on multiple, independent systems. We can now correlate reported threats and anomalies to better determine what threats we face.

What needs improvement?

The configuration is somewhat complex and the interface a bit non-intuitive. Whilst very useful for reporting, interpretation of the results can be difficult: improved features to help with this would be welcome.

For how long have I used the solution?

I've been using it for six months.

What do I think about the stability of the solution?

We’ve had 100% uptime since installation.

What do I think about the scalability of the solution?

We have not had any requirements to change the scope of the installation since first deployment.

How are customer service and technical support?

Good. Initial help with deployment was excellent, and the facility to create a tunnel for tech support personnel to troubleshoot system is very useful.

Which solution did I use previously and why did I switch?

We didn't have anything like AlienVault previously.

How was the initial setup?

It's fairly complex. There is quite a bit of additional config required in order to get the most from the system. A base config allows for monitoring, but to get the most, you need to add plugins for various systems on your network: this config is somewhat complex and requires a good knowledge of how AV works.

What's my experience with pricing, setup cost, and licensing?

Unless you have a small network, you really need the unlimited endpoint license, which is the most expensive option. Best to negotiate to get this version, otherwise scalability will be an issue (unless your total number of endpoints in under approx. 100).

Which other solutions did I evaluate?

We also looked at Tripwire.

What other advice do I have?

The initial onboarding during the trial period, including assisted setup, was most useful. Ensure you get the most from this, as if you require further setup assistance, it comes under (paid-for) professional services. AV is a very useful tool, but must be configured correctly in order to get the most out of it.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at AlienVault
Real User

Alan - thank you for your thoughtful feedback & comments.

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.