No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs LevelBlue USM Anywhere comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 24, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
LevelBlue USM Anywhere
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Log Management (28th), Endpoint Detection and Response (EDR) (37th), Compliance Management (14th)
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.2%, down from 3.1% compared to the previous year. The mindshare of LevelBlue USM Anywhere is 1.5%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
AlienVault OSSIM1.2%
USM Anywhere1.5%
Other97.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the logging capability."
"You can customize the dashboards as well as the reporting."
"Inbuilt IDS, inbuilt integration with threat intelligence platform and with vulnerability assessment modules."
"Technical support is excellent; they are very helpful and responsive."
"The most valuable features of this solution are the data correlation and vulnerability assessment."
"Asset discovery is good."
"The product is majorly used for threat detection of the agents on servers and endpoints."
"It is a perfectly nice and free tool for compliance testing, assessment, and some basic vulnerability."
"In terms of monitoring, my best feature would be the monitoring of components across the network; it monitors the respective nodes and any new node that comes onto the network and provides reports, and the reporting dashboards are really helpful for management in terms of making decisions around patch management."
"The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
"We used, tested, and tried several solutions prior to this solution; this solution answered too many questions under one reasonable cost, as opposed to piecemealing everything together for more money."
"The ROI is very good if you evaluate all the services which AlienVault can help you with: detection of Malware, bad activities, suspicious behavior, etc."
"AlienVault is an amazing product that I would highly recommend."
"The pricing is amazing and really cheap."
"The pricing for this solution with the 3 major components: SIEM, FIM, and vulnerability scanning, can’t be beat."
"With AlienVault we are able to respond to incidents and take necessary action faster than we could before without the solution in place."
 

Cons

"The initial setup was a bit complex. You've got to do a lot of reading. It's not an intuitive implementation."
"The correlation engine needs to be improved."
"The user interface needs to be friendlier across the board."
"I would like the solution to be able to integrate with my firewall, my IDS and my Honeypot solutions so that it can provide real-time reporting as things occur and then have alert sent to me on my phone when suspicious activity is happening."
"The solution needs more integration with cyber intelligence systems. Our customers want to use a single tool for managing cybersecurity."
"AlienVault OSSIM’s configuration and integration could be a little easier."
"I would advise others to not implement it for any enterprise-level organization."
"AlienVault OSSIM could improve by having better integration with some of the newer tools."
"One area that has room for improvement is storage. AllienVault is a good place to put logs, but sometimes it's a tough place to go get logs... The logger can only hold so much data. If they improved that, that would help."
"It is a lot of work to get the software configured and set up properly."
"As it includes multiple security softwares, the installation and configuration takes a lot of time."
"I've been using it just for my own personal upskilling in terms of how the product works. At the moment, it is pretty straightforward and simple, and it is working how it is supposed to. The feedback would come once it is deployed to customer sites. They'll be using it on a more frequent basis, and that's when the feedback would come in terms of the areas in which they're facing issues or are looking for simplicity."
"I had a renegade plugin that was installed by the company who helped me with the initial setup. The plugin was missing a command to rotate logs and would fill my hard drives capacity to full quickly."
"Plugins could be better utilized, as some of them do not recognize all logs."
"The reporting tools are a bit lacking for building reports to give directly to customers, but support has been helpful in giving our requests for new features to the development team and following up with us."
"The system slows down considerably when a large number of events are fed in."
 

Pricing and Cost Advice

"AlienVault pricing is the best. Whatever cost you are paying, you are getting a return on every penny... It's not like your IBM, your QRadar, or Splunk, where the cost is too high."
"The solution is open source, so it's free to use."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"When comparing AlienVault OSSIM to Microsoft Sentinel, AlienVault OSSIM incurs additional costs due to its licensing price structure. If you are using AlienVault for security purposes at a certain level it can have a higher price point than the current pricing of Microsoft Sentinel."
"I used the paid version of the tool and found it to be expensive. It has been a while since I changed to Securonix. I will have to check whether AlienVault charges per device, user, or log."
"We are using the community version, which can be used for free."
"The tool's licensing costs are yearly."
"AlienVault OSSIM is free."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"Its price is in the medium to upper range."
"​The price point is good.​"
"It is a product that is priced in a medium range, making it neither a cheap nor a costly product."
"The licensing fees are dependent on usage."
"Use the AlienVault team. They are helpful and the documentation that they provide is second to none."
"​The vulnerability management solution is worse than buying a Nessus Professional license.​"
"Pricing is very competitive with other products and you get much more functionality from AlienVault."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
15%
Financial Services Firm
8%
University
7%
Manufacturing Company
7%
Construction Company
20%
Outsourcing Company
18%
Comms Service Provider
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
What is your primary use case for AlienVault OSSIM?
This solution is very similar to most of the other MSSPs that you would find out there. When I look at use cases, AlienVault was initially aimed at small to medium businesses. It grew, and that was...
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
 

Also Known As

OSSIM
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Council Rock School District
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about AlienVault OSSIM vs. LevelBlue USM Anywhere and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.