No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Log Management
37th
Ranking in Security Information and Event Management (SIEM)
36th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
USM Anywhere
Ranking in Log Management
31st
Ranking in Security Information and Event Management (SIEM)
29th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Endpoint Detection and Response (EDR) (39th), Compliance Management (14th)
 

Mindshare comparison

As of August 2026, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 1.0%, up from 0.6% compared to the previous year. The mindshare of USM Anywhere is 1.4%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
USM Anywhere1.4%
NetWitness Platform1.0%
Other97.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Alerting Module: It provides real-time event processing language on all the logs/packets stream for advanced alerting, i.e., using SQL LIKE statements."
"The most valuable features are the packet decoder, log decoder, and concentrator."
"The most valuable feature is the security that it provides."
"Their customer service is excellent, one of the best."
"The most valuable feature is the hunting ability to work in a CERT."
"Offers a good wireless feature."
"Technical support is very good; they try to resolve issues with the proper SLAs which are defined by them and they understand the client's requirements as well as the client's infrastructure in a better manner."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The pricing for this solution with the 3 major components: SIEM, FIM, and vulnerability scanning, can’t be beat."
"AlienVault provided the best bang for buck."
"The other big selling feature for us was its integration capabilities with all the other security-based products."
"In terms of monitoring, my best feature would be the monitoring of components across the network; it monitors the respective nodes and any new node that comes onto the network and provides reports, and the reporting dashboards are really helpful for management in terms of making decisions around patch management."
"The USM is a work horse, no matter what devices or the number of logs we throw at it, the system processes them in real time, correlates the events, and alerts on only events that need human review."
"I'm glad we purchased it, wished we would have gone with outside monitoring instead of inhouse and there is a lot to learn; great product though."
"We had used previous products and found AlienVault centralized the logging for our security."
"AlienVault gave our organization a centralized tool to manage our security with its intrusion detection, asset management, vulnerability assessments, along with all of its other features, it has become an invaluable asset for our small organization."
 

Cons

"Security needs improvement. We would still like to know how the traffic is entering the organization."
"The initial setup is complex. It requires some knowledge in order to set it up."
"The product continues to crash. Even with tech support help, it does not resolve itself."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"The tool's integration capability isn't so great."
"The user interface is a little bit difficult for new users and it needs to be improved."
"The price of AT&T AlienVault USM could be reduced."
"IPv6 not supported Correlate with external logs from other sources makes little bit difficult to work"
"More information about what the alerts mean and how they are derived would be useful when determining their significance."
"The reporting and dashboards have room for improvement."
"AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive."
"Scaling, and it has no APIs! It would be hard for any legitimate MSSP to use it."
"Taking into account that server access credentials are controlled by the tool, some more management-focused actions could be performed from AlienVault."
"It would be nice to see some machine learning and monitoring of the configuration in network devices."
 

Pricing and Cost Advice

"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"We are on an annual license for the use of the solution."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"This is a pricey solution; it's not cheap."
"It’s cheaper to run virtual machines in a VMware environment."
"The licenses are good but the cost is very expensive."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"It's very reasonably priced. It was one of the lowest among the ones I looked at. Licensing is pretty flexible. They can do a two-year or a three-year, even a one-year, perhaps."
"Its price is much lower than McAfee ESM."
"Pricing is very competitive with other products and you get much more functionality from AlienVault."
"The price for this solution is very good, but since the features do not work the price is expensive."
"So far, it has been a good solution for a tight budget."
"I don't think the product's pricing is a good value because they try to raise the price 50 percent every year... AlienVault needs to understand that not all customers are huge enterprises... Their sales team is way too aggressive. The price they advertise is not always the price you get."
"It is a product that is priced in a medium range, making it neither a cheap nor a costly product."
"We checked out several competitors. For what it can do and the cost, it was the best option!"
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
908,877 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
13%
Financial Services Firm
11%
Comms Service Provider
9%
Outsourcing Company
9%
Construction Company
23%
Financial Services Firm
9%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also limited when used with bigger products and has complex password requirements.
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools.
 

Also Known As

RSA Security Analytics
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about NetWitness Platform vs. USM Anywhere and other solutions. Updated: August 2026.
908,877 professionals have used our research since 2012.