The primary use case is threat detection. We have configured various rules to monitor the environment for any suspicious activity.
ICT Support Analyst at a tech services company with 1-10 employees
Has a robust threat intelligence feature along with efficient asset grouping functionality
Pros and Cons
- "It has helped us remediate threats in the past by providing significant events that assisted in identifying suspicious activities, such as logins from multiple countries."
- "I suggest more in-built rules based on modern threats and environments to make it a more competitive solution."
What is our primary use case?
What needs improvement?
Collecting logs can sometimes be tedious, especially compared to my experience with Microsoft Sentinel.
I suggest more in-built rules based on modern threats and environments to make it a more competitive solution.
For how long have I used the solution?
I have been using AlienVault OSSIM for six months.
What other advice do I have?
I find the overall threat intelligence feature robust and the asset grouping feature, allows us to correlate events with entire asset groups.
It has helped us remediate threats in the past by providing significant events that assisted in identifying suspicious activities, such as logins from multiple countries.
The asset discovery functionality, once set up, automatically identifies all devices on the network. It aids compliance efforts and helps us understand the network's device landscape.
While integration is possible with other tools like EDR and Cisco Office 365 Defender ATP, it is not as fast or easy as integrating with Microsoft products.
I recommend it, particularly for medium to large companies with complex IT infrastructures.
Overall, I rate the product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AlienVault OSSIM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Anomali
Fortinet FortiSIEM
Exabeam
USM Anywhere
Sentinel
Stellar Cyber Open XDR
Securonix Next-Gen SIEM
Buyer's Guide
Download our free AlienVault OSSIM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
- What Questions Should I Ask Before Buying SIEM?
- What are the pros and cons of internal SOC vs SOC-as-a-Service?















