No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs OpenText Enterprise Security Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
16th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
OpenText Enterprise Securit...
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
98
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.3%, down from 3.6% compared to the previous year. The mindshare of OpenText Enterprise Security Manager is 1.5%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
AlienVault OSSIM1.3%
OpenText Enterprise Security Manager1.5%
Other97.2%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
DayaramGoyal - PeerSpot reviewer
Vice President, Technology at Cache Digitech Pvt Ltd.
Integration shines but threat detection and technical support need attention
Regarding threat detection capabilities, I think OpenText Enterprise Security Manager covers the MITRE ATT&CK framework at an average level, and on a scale of one to ten, I would rate it only five. They have to improve in those areas in terms of threat detection capabilities. For ArcSight, they need to give the complete package, with UBA being part of that. They have added it, but I question what capabilities are there, especially on the SOAR side where they have to improve because the SIEM was very strong. For the SOAR side, because SIEM was very strong when they were earlier launched, but for SOAR, they were integrating with third-party solutions initially, and then they built the capability. They have acquired some company, but it is not up to that potential. They slowly and gradually lost that ground to Splunk, QRadar, and other companies, so when anybody talks about the full capabilities, they are not thinking about Micro Focus as of now. I would desire additional features in OpenText Enterprise Security Manager, especially on the SOAR side, and maybe on the UBA side, as threats intel and all, which are part of bundled solutions. Those are the areas they have to improve so that customers can trust and enhance those things, and maybe the customers will feel they should go for this product. As of now, if we are evaluating our own scenario, we are not even thinking about it. Earlier, that was not the scenario when they were selling this SIEM solution in the market; everybody was thinking OpenText was the default option, but now, if you're looking for a complete solution stack, nobody is even considering it.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The open vault component and the checking of vulnerabilities are the most valuable features. The page management helps with this. If you know how your device is vulnerable at least you can do something about it."
"The most valuable feature is the logging capability."
"The threat alerts it gives me from time to time on harmful code within the network, or if they are generating any network traffic, are very useful."
"The paid version of the solution has reporting and better scalability options."
"The most valuable features of this solution are the data correlation and vulnerability assessment."
"OSSIM is the only solution that includes the large number of modules that we need: a vulnerability scanner, a network IDS system, a host IDS system."
"OSSIM is the only solution that includes the large number of modules that we need: a vulnerability scanner, a network IDS system, a host IDS system."
"What I like about this product, is that it is a fully-fledged solution."
"ArcSight gives us better visibility into threats that were unknown earlier."
"It has increased our detective capabilities in the cybersecurity landscape."
"The most valuable feature is the real-time alerts."
"We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens."
"The simple fact that HPE ArcSight helped us several times to survive malware attacks (Conficker was one such attack) and it also helped a lot with different compliance audits, which was enough for us."
"ArcSight helps to track all configuration changes and correlates with corresponding service tickets, helping a lot in auditing system and network admins with minimal time and cost."
"I really like the correlation part and the way the logs are correlated; I have never faced issues with parsing in this product, and I like the way it parses, and everything is so clear to me."
"If you're looking for a single product that will let you aggregate, correlate and analyze many different sources in a single place, then there are few competitors that can come close to ArcSight's features."
 

Cons

"The initial setup was not so easy, partly because the documentation was not up to date."
"I would advise others to not implement it for any enterprise-level organization."
"The correlation engine needs to be improved."
"AlienVault OSSIM could improve by having better integration with some of the newer tools."
"It does not give me a prompt response for any such malicious traffic; it takes time to get that alert from the AlienVault system."
"Lacking in depth of reporting."
"The documentation could be improved."
"The log collection is okay, but tracing the logs or tracing the events is a bit difficult."
"There are SO MANY things you can do in AS, and there is a lack of really in-depth documentation on a lot of it."
"It is quite complex and could use a better UI. It is pretty complicated to use."
"The user interface of ArcSight Enterprise Security Manager could improve. It is not very good."
"Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it."
"The dashboard looks a bit cumbersome with the current version."
"The onboarding process for this solution could be better."
"I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions. We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved."
"I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions."
 

Pricing and Cost Advice

"The price of AlienVault OSSIM is too high sometimes for us to present to our customers. The price should be lower. We are on a three-year license to use the solution. We had to pay extra for the support."
"AlienVault OSSIM is an open-source solution."
"We are using a free version of the solution. If you purchase a license there are more features available but the price is a little high. The solution should be cheaper to allow more customers to be able to afford it."
"AlienVault OSSIM is free."
"I used the paid version of the tool and found it to be expensive. It has been a while since I changed to Securonix. I will have to check whether AlienVault charges per device, user, or log."
"OSSIM is free."
"The solution is open source, so it's free to use."
"AlienVault OSSIM is expensive compared to its competitors."
"The pricing is great compared to others."
"ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value."
"The pricing model is expensive compared to open-source alternatives."
"ArcSight can be a little bit expensive because of the area that we work in and the cost. Licensing is mostly on a yearly basis, not monthly."
"Customers without a ton of resources to dedicate to deployment may be better served by a managed ArcSight service."
"HPE ArcSight pricing might be more expensive than other SIEM solutions, but in my opinion it has powerful features and great flexibility in developing complex use cases."
"We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees."
"The solution is super expensive. At our organization size and license model, I think the price is average to what anyone else would charge us."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Comms Service Provider
15%
Manufacturing Company
8%
Educational Organization
8%
Computer Software Company
8%
Financial Services Firm
15%
Marketing Services Firm
10%
Manufacturing Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise14
Large Enterprise57
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools. It is worth the investment if you are considering the cost.
What needs improvement with ArcSight Enterprise Security Manager (ESM)?
Regarding threat detection capabilities, I think OpenText Enterprise Security Manager covers the MITRE ATT&CK framework at an average level, and on a scale of one to ten, I would rate it only f...
 

Also Known As

OSSIM
Micro Focus ArcSight, HPE ArcSight, ArcSight
 

Overview

 

Sample Customers

Council Rock School District
Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Find out what your peers are saying about AlienVault OSSIM vs. OpenText Enterprise Security Manager and other solutions. Updated: April 2026.
893,244 professionals have used our research since 2012.