No more typing reviews! Try our Samantha, our new voice AI agent.

LevelBlue USM Anywhere vs NetWitness Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 24, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

LevelBlue USM Anywhere
Ranking in Log Management
28th
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (37th), Compliance Management (14th)
NetWitness Platform
Ranking in Log Management
36th
Ranking in Security Information and Event Management (SIEM)
34th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Log Management category, the mindshare of LevelBlue USM Anywhere is 1.4%, up from 0.4% compared to the previous year. The mindshare of NetWitness Platform is 1.1%, up from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
USM Anywhere1.4%
NetWitness Platform1.1%
Other97.5%
Log Management
 

Featured Reviews

Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AlienVault is my security person looking at irregularities and letting me know when something has occurred."
"The asset management of nodes has been a large help in terms of being able to track applications with more detail and have changes made being monitored into one source."
"AlienVault support is what really makes this product a great investment."
"The vulnerability manager and the file integration are very good."
"We have a better detection rate for malware and other cyber-attacks, and it really helps when USM is integrated in the incident response plan."
"Being able to identify security issues as they occur at near real time and then respond to them as soon as they occur is priceless."
"You will wonder how you lived without it."
"AlienVault provides a checklist answer when using SIEM."
"What we are mainly using are the RSA concentrator, RSA Decoder, Archiver, Broker, and Log Decoder."
"The most valuable feature is the correlation, as it can report in real-time and monitor the management."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"Packet Solution: Allows analyst proactive hunting and alerting on daily sophisticated APTs."
"Once it is deployed and you are used to it, you can do whatever you want."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"The product's initial setup phase was not at all difficult."
 

Cons

"The only complex area of the setup was writing the custom scripts."
"Its reporting tools need improvements."
"It was easy on PoC, but when we got to the product it was different story. We had to learn the product again and got feeling that the PoC was a different product."
"I have found difficulties in searches within security events and configuring some areas looks complicated."
"Plugins could be better utilized, as some of them do not recognize all logs."
"Customer service is 4/10 - they need to provide faster responses to emails."
"We develop additional rules and scripts to make it more usable."
"We would love to be able to create custom rules based on a series of events, to create rule-sets where, for example, failed logins to the VPN Server are logged and then when a successful attempt follows soon after, it triggers an alarm for a Brute Force."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"RSA NetWitness Logs and Packets can improve the threat level aspect, it is lacking compared to other solutions. Whenever any hacking activity or any other threat factor occurred they used to provide the coverages very fast when comparing RSA NetWitness Logs and Packets. I heard the other three solutions, from a discussion with my team members who had experience in other solutions, they used to say that. Whenever any issues happened across the globe RSA NetWitness Logs and Packets are a little bit slow improving those detection mechanisms."
"We encountered stability issues in the earlier versions, and much fewer in the newer versions."
"Advance monitoring and alerting feature is not stable (Event Stream Analysis)."
"Health monitoring of the event sources and devices."
"We have encountered issues with unresolved crashes."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"I believe they could improve their support, there are often delays."
 

Pricing and Cost Advice

"Use an MSSP instead. It is much cheaper."
"Its price is in the medium to upper range."
"It is affordable, and it also has many features that the premium products such as ArcSight and QRadar have. It is a very good platform for a SIEM solution. Everything is included in the price."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"It's affordable for most customers."
"Pricing is very competitive with other products and you get much more functionality from AlienVault."
"Use the AlienVault team. They are helpful and the documentation that they provide is second to none."
"The ROI is quite good."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"It is cheap."
"It’s cheaper to run virtual machines in a VMware environment."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"We are on an annual license for the use of the solution."
"Our license is for one year."
"Compared to the competition, the is price is not that high."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
20%
Outsourcing Company
18%
Comms Service Provider
8%
Financial Services Firm
7%
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
11%
Outsourcing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
RSA Security Analytics
 

Overview

 

Sample Customers

Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Los Angeles World Airports, Reply
Find out what your peers are saying about LevelBlue USM Anywhere vs. NetWitness Platform and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.