We use this solution for lag management and to protect our network. We are customers of Alert Logic.
System Administrator at INSIGHT CREDIT UNION
Excellent intrusion detection and everything is in one dashboard
Pros and Cons
- "The value of Alert Logic is that everything is in one dashboard; I'm notified when there's an incident, kept up to date and advised on what steps to take."
- "It would be great to see more of an endpoint protector."
What is our primary use case?
What is most valuable?
The value of Alert Logic is that everything is in one dashboard; I'm notified when there's an incident, kept up to date and advised on what steps to take. The solution has good intrusion detection.
What needs improvement?
It would be great to see more of an endpoint protector. I'd also like to be able to send commands to firewalls which is something the old UI had but the new one does not. For example, if I wanted to block an attack I used to be able to send a command to the firewall but that is no longer possible.
What do I think about the stability of the solution?
This solution is very reliable.
Buyer's Guide
LevelBlue Managed Detection and Response
September 2026
Learn what your peers think about LevelBlue Managed Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I've scaled this product and haven't had any issues.
How are customer service and support?
Technical support is great. They are very responsive and they know their product.
How was the initial setup?
The initial setup was straightforward. We sent them what needed to be done, and the environment was already up. To get the implementation sorted took about a month. Documentation is readily available and helpful.
What's my experience with pricing, setup cost, and licensing?
Licensing is on an annual basis. The price could be better and I know that Alert Logic is more expensive than other solutions on the market.
What other advice do I have?
It's important to know the product and make sure the right rules are in place. The configurations and alerts are really important.
I rate this product an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Site Reliability Engineer at a retailer with 10,001+ employees
Great reporting and session logic with an easy initial setup
Pros and Cons
- "The initial setup is pretty straightforward."
- "It's been a positive experience for us overall."
- "We'd like to have triggered alerts sent to us so we see errors quicker."
- "One pain point we have, for example, is if the search keyword is related inside an XML, we will get an XML; if it is a normal log, however, you will get a null pointer exception or something, and we don't get the complete trace."
What is our primary use case?
We are primarily using the solution for an e-commerce company.
The application is deployed in multiple countries, and therefore the servers are very huge servers. Sometimes, at the same time, there will be 40 to 50 or 100 nodes also. For our application log, for example, if any request goes to any particular node, and we don't know which we can look at the node's logs in Alert Logic. We will just simply mention our order ID or whatever text we are searching for, and it will tell you which node it is. If it is an XML format, you will get a complete XML in a short time, instead of going to the PuTTY, connecting to the node and getting the XML, fetching everything, and wasting your time.
How has it helped my organization?
We have used other solutions, such as Splunk, and in comparison, this solution is very user-friendly and there is less confusion when you are using the app. It's faster. You can configure more than 100 nodes and you'll get all the speed and accuracy you need.
What is most valuable?
The searching aspects of the solution are very valuable for our organization.
The reporting on the solution is quite useful for us.
The log messages and session logic are excellent. As an engineer, it's very useful to get the logs immediately if any production issues arise. We have everything we need to troubleshoot at our fingertips.
The initial setup is pretty straightforward.
What needs improvement?
One pain point we have, for example, is if the search keyword is related inside an XML, we will get an XML. If it is a normal log, however, you will get a null pointer exception or something, and we don't get the complete trace. We will just get a few lines only. It would be ideal if we could get a complete trace. There just needs to be more transparency around error tracing.
We'd like to have triggered alerts sent to us so we see errors quicker.
For how long have I used the solution?
I've been using the solution for three years at this point.
What do I think about the stability of the solution?
The stability is great. There are no bugs or glitches. It doesn't crash or freeze. It's excellent overall.
What do I think about the scalability of the solution?
The solution is extremely scalable. If a company needs to expand it, it can do so easily.
We have about nine or ten people using the solution currently. They are mostly engineers, including support engineers and senior support, system reliability engineers, production support engineers, and technical engineers.
Although I'm unsure of the company's long-term plans, we could easily increase usage in the future.
How are customer service and technical support?
Technical support has been amazing. They are very supportive and helpful. We are quite satisfied with the level of support on offer. If we have issues we just reach out. We have dedicated support, however, we rarely have any issues with Alert Logic. Whenever we migrate to Microsoft Azure Cloud or something, we may have to get assistance, however, apart from that, we really rarely need them. Of course, if we do, we know their response is immediate and quick.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
The initial setup isn't too difficult. It's pretty straightforward. An organization shouldn't have too much trouble with the setup.
The deployment is very fast. It doesn't take too much time at all. It's likely less than five minutes. Honestly, it's almost instantaneous.
There is no mapping. Once you're done with the customization you can use it. It's not time-consuming. The customization part is based on whatever keywords and attributes you are adding, and that's less than a minute of time to handle. There is no time consumed. You just need to add to a filter.
You don't really need to worry about having too much maintenance. It's not required really. Maybe once the log is full, you may require a maintenance checkup of six months on. We have a server team that manages that aspect.
What's my experience with pricing, setup cost, and licensing?
We pay for licensing on a yearly basis. However, I don't handle the payments. I'm not in charge of billing. I can't speak to the exact costs of the solution.
What other advice do I have?
We are using the latest version of the solution at the moment. I do not have the version number on-hand, however.
I would recommend the solution to other organizations. It's been a positive experience for us overall.
I would caution that, in the beginning, people who are first-time users, will find it a bit complicated. They will easily learn quickly once they started using that. It's a very easy process to get habituated to.
I've been a production support engineer for the past 10 years. In only the last three years I've been using Alert Logic. Previously, I have faced a lot of problems finding the logs. This solution helps me a lot. There are so many times it's helped to identify the root cause - and quickly.
Overall, I would rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
LevelBlue Managed Detection and Response
September 2026
Learn what your peers think about LevelBlue Managed Detection and Response. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
914,109 professionals have used our research since 2012.
Information Technology Manager at Alaina M Callahan Consultant LLC
An extremely reliable, easy-to scale, and user-friendly solution that provides detailed notifications and has good pricing and licensing
Pros and Cons
- "Notifications and the detail of notifications are most valuable. It is a user-friendly solution."
- "My advice would be to go ahead with the product because it really is a very good tool that adds a lot of value."
- "Its menu is not very intuitive. I would like to see the user menu expanded a bit. The user menu is very layered, and because of the layers, you have to go down a path that is not very intuitive."
What is our primary use case?
In the most recent instance, I have used Alert Logic to monitor the architecture for an IT software company. I am an IT consultant by trade, and I was contracted to design and support the infrastructure for a SaaS company.
How has it helped my organization?
The lead database administrator felt that there was a need to have a particular port open for the application to communicate and gather data effectively. That particular DBA and I were not in agreement over the potential risk of this open port. With the use of Alert Logic, I was able to prove factually that having that port open was a great risk. Because of it, we eventually closed the port and changed the design of the app.
What is most valuable?
Notifications and the detail of notifications are most valuable. It is a user-friendly solution.
What needs improvement?
Its menu is not very intuitive. I would like to see the user menu expanded a bit. The user menu is very layered, and because of the layers, you have to go down a path that is not very intuitive.
What do I think about the stability of the solution?
It is extremely reliable. I have also used it in other environments and situations.
What do I think about the scalability of the solution?
It is extremely easy to scale. I've expanded it in the latest use case and previous use cases.
Only two people are using it. One is the owner of the company to confirm the security of the environment. I monitor the environment and make certain that we're secure. This product is being used in 100% of the environment, so there are no plans to increase its usage because we can't.
How are customer service and technical support?
I have called them up, and their team is very responsive and very thorough.
Which solution did I use previously and why did I switch?
I have used other solutions. Alert Logic is very linear. It is very easy to follow the way it works. The other product was more complex and more confusing.
How was the initial setup?
It was very straightforward. The installation took us maybe two hours.
We deployed it to all of our servers. We needed to build a virtual appliance, and that was actually the only pain point. The communication around that virtual appliance was not very clear, so I went down the wrong path only to discover that I had wasted some time, and it wasn't required.
What about the implementation team?
I did it myself with the assistance of an Alert Logic representative.
It does require maintenance but not in the traditional sense. The actual upkeep of the product and the upkeep of the agents fall to Alert Logic, but from time to time, the agent will send out an alert of failure. These failures need to be investigated. Ten times out of ten, they were false failures. They raised an alert of a failure of the product, and the investigation proved that it hadn't failed at all.
What was our ROI?
The return on the investment was not exactly tangible. It was in the redesign of the application and the ultimate security of that application. It was an intangible return on investment in that it took away the debate between people's opinions and gave a fact. Based on this fact, we could then redesign the application.
What's my experience with pricing, setup cost, and licensing?
Its pricing is very reasonable considering what you get for what you pay. There is quite a good value there.
Its licensing is also very logical. They've got the licensing price points at a reasonable level. It is on a monthly license but a yearly contract. There are no additional costs to the standard licensing fees.
What other advice do I have?
My advice would be to go ahead with the product because it really is a very good tool that adds a lot of value. I would also recommend that the person implementing the product should have a very good working knowledge of IT infrastructure. I would say that IT infrastructure is more of a requirement than a background in IT security, and it certainly makes the process a lot more straightforward.
The biggest lesson that I have learned from using Alert Logic is that for the amount of money invested in the product, the sense of security and the tightness that it gives to the environment is a real selling point for clients.
I would rate Alert Logic a nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
AWS Admin at a marketing services firm with 501-1,000 employees
The installation and configuration were slick. However, this product needs to mature more.
Pros and Cons
- "The installation and configuration were slick."
- "We receive infrastructure security warnings from it. So, we know what is going on and what needs to be addressed."
- "It implemented pretty quickly; we have everything you need, and while it would typically take a lot of other solutions weeks to set up, this set up within fifteen minutes, which is pretty slick, and it has a lot of different interfaces."
- "This product needs to mature more. While it is a good product, there are some areas where it needs work."
What is our primary use case?
We use it to be able to review logs and the overall system help and learn on anything that we need to handle.
How has it helped my organization?
Our organization's issue is that we implemented it and kicked the tires, but we never put an administrator behind it to own it and do a whole lot for it. There were a couple of select cases that we found and acted on those alerts. However, for the most part, it's just a climbing number of alerts with nobody touching them.
We needed a better plan for implantation. If we put something out there, we have to have people lined up to look at it and admin it, then reap the benefits of everything it's telling us to act on it. If you're not doing this, you have good intentions, but you fell short.
What is most valuable?
We receive infrastructure security warnings from it. So, we know what is going on and what needs to be addressed, e.g., things that we didn't have somebody looking for. It shows us these automatically, using things like automated scanning.
What needs improvement?
This product needs to mature more. While it is a good product, there are some areas where it needs work. If this is a cloud service, I shouldn't have to tell them how to develop analytics to tell me this is what is going on. They should be able to do it. Over time, their own system should be able to identify, "This is something that is a continuous thing with a particular user or company." Or, I should be able to click on it being able to "ignore" it, dropping it completely. It should be smarter than what it is, and it is not.
For how long have I used the solution?
One to three years.
How was the initial setup?
It implemented pretty quickly.
We have everything you need. It would typically take a lot other solutions weeks to set up. This set up within fifteen minutes, which is pretty slick, and it has a lot of different interfaces.
The installation and configuration were slick. After installing in 20 to 30 minutes, you can start provisioning access, so people can take a look.
What's my experience with pricing, setup cost, and licensing?
I was not involved in the pricing and licensing.
Which other solutions did I evaluate?
Other solutions that we evaluated were Datadog and LogRhythm, but it is not an apples to apples comparison.
Alert Logic was not my choice. I implemented it, and said, "Here you go guys. Kick the tires."
What other advice do I have?
We only use the AWS version.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at Provo IT
You can automate the process pretty easily, but they don't have a dedicated security team who will work on an attack
Pros and Cons
- "It has the ability to install agents, it is pretty straightforward, and you can automate the process pretty easily."
- "They have ideas and email you whatever they find, but they don't have a dedicated security team who will work on an attack or a specific security instance."
What is our primary use case?
It is used to track production and for IDS.
What is most valuable?
It has the ability to install agents. It is pretty straightforward. You can automate the process pretty easily.
What needs improvement?
They have ideas and email you whatever they find, but they don't have a dedicated security team who will work on an attack or a specific security instance.
As an MSP, it is better if we can hand off the security stuff over to a third-party or some other dedicated security people, and we can just focus on AWS-related products and improving our infrastructure.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It is just an EC2 instance, so it depends on what the EC2 instance is provisioned with.
What do I think about the scalability of the solution?
It's agent-based, and you can also integrate it with your whole account. Scalability isn't much of an issue for Alert Logic.
The biggest client that we have who is using Alert Logic right now is about 800 to 900 employees.
How is customer service and technical support?
Response rates are so-so. I would put them at about 70 percent good, and while 70 percent good is very good for a lot of companies. However, in such a scaling market, like cloud and AWS in general, this is hard to work with. We want to able to off-hand responsibilities to a third-party.
How was the initial setup?
There are problems with the Threat Manager and networking stuff that have to be handled prior to setting things up, so it does take a little while to integrate. You need to have all your networking stuff come into this one specific AWS instance called Threat Manager that they have detailed instructions on how to set up. However, there is a lot of manual work that needs to be done ahead of time before you scale out and use it for other purposes.
The integration and configuration with Alert Logic in our AWS environment was straightforward.
What's my experience with pricing, setup cost, and licensing?
Alert Logic has better competitive pricing than some of its competitors.
Almost any product that is on the AWS Marketplace is super easy to subscribe to.
Which other solutions did I evaluate?
We do use Trend Micro as well. We are an MSP, so there are different clients using different products, and Alert Logic is one of them.
What other advice do I have?
Know what the product does and how to integrate it with your stuff before actually jumping into it. Compare other products which are doing the same exact thing, see what your company can do and what your company needs, and what your requirements are, then make the decision after that.
We have been moving away from Alert Logic for awhile now.
We only use the AWS version.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Engineer at Modec Inc
We don't want to be bombarded with unnecessary issues and have the real ones slip through. The product is very stable.
Pros and Cons
- "It is a very stable product."
- "Technical support is pretty decent with Alert Logic."
- "I would like to see it do initial scans and start capturing data, which it will truly analyze, not just be a reporting system saying, "Here is an email. Here is an email. Here is an email.""
- "The product needs to mature. We don't want to be bombarded with unnecessary issues and have the real ones slip through."
- "Our ROI would probably be zero. We don't even use it."
What is our primary use case?
We use this as an intrusion detection system (IDS). It observes and reports what is coming in our network, then sends us a report.
How has it helped my organization?
It has not improved our organization.
What is most valuable?
I like that it is physical hardware. With virtual, the processing can go bad and can get hung up. However, if it is physical, it's its own box. E.g., there is no noisy neighbor issue.
What needs improvement?
This product needs to mature more. While it is a good product, there are some areas where it needs work. If this is a cloud service, I shouldn't have to tell them how to develop analytics to tell me this is what is going on. They should be able to do it. Over time, their own system should be able to identify, "This is something that is a continuous thing with a particular user or company." Or, I should be able to click on it being able to "ignore" it, dropping it completely. It should be smarter than what it is, and it is not.
I would like to see it do initial scans and start capturing data, which it will truly analyze, not just be a reporting system saying, "Here is an email. Here is an email. Here is an email." Thus, I can get 5000 emails, and if you get 5000 emails in ten minutes, you have no emails because they are no good. All they are doing is filling up your inbox. If one good email comes out of those 5000, you miss it. This might be on us as far the configuration, but then this goes back to the compute side in the cloud where they should be able to identify, "We have a lot of user lockouts."
They should be able to go into their code, making this an automated process, not manual. They should use smart technology, not just put a box together, and say, "Go get the information."
The product is not ready to be put into our AWS environment because we have SAP. We're already having some issues, not related to AWS or Alert Logic. We have our own issues it that we are trying to iron out. Since the Alert Logic hardware is not helping us anyway, moving it to the cloud as software, would not really make a difference for us.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It is a very stable product. We have it directly connected to our Nexus 9000s in Houston and Singapore. We have it connected to 9000s in Brazil and Tokyo, as well. So, we have four of them placed around the world in our data centers. We have it set up as a SPAN port on the Nexus.
The stress is going to be average because it's connected to two different Nexus 9000s in our data centers. It has two interfaces that it talks to with one management interface, one for each Nexus.
We put about ten or twenty percent stress on it. I don't know the specs of the box itself, but I don't expect it to be working hard because all it is doing is observing. It grabs all the data, then it sends it up to the cloud. We can do better than that. You want to send it up to the cloud to to do more compute, then send it back down. However, that is not what is happening.
How is customer service and technical support?
Technical support is pretty decent with Alert Logic. The engineers behind the scenes, when I have called them, have been pretty good. It is all Linux, and Linux is a great system.
How was the initial setup?
This version was not easy to install. It was very complicated and took a lot of time.
What was our ROI?
Our ROI would probably be zero. We don't even use it. It sits in there. We get emails and just delete them. Around the world, we don't even use it.
Which other solutions did I evaluate?
I don't have purchasing power. Management said, "We are getting this product. Here it is. Put it in." There was no discussion with the engineers.
What other advice do I have?
If someone one was looking at this product or similar solutions, I will tell them, "Find something else."
They have a great concept, but the product needs to mature. We don't want to be bombarded with unnecessary issues and have the real ones slip through.
We use the product on-premise.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Engineer at Upland Software
It fully integrates with our AWS environment and is quick to set up
Pros and Cons
- "The quicker implementation of changes to our infrastructure from Alert Logic tell us if there are any problems."
- "It fully integrates with our AWS environment, which is brilliant."
- "The documentation, especially with the initial setup, needs improvement."
What is our primary use case?
The primary use case is security.
How has it helped my organization?
The quicker implementation of changes to our infrastructure from Alert Logic tell us if there are any problems.
What is most valuable?
- Easy to use, nice interface.
- It is quick set up.
What needs improvement?
The documentation, especially with the initial setup, needs improvement.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
The stability is good. We trust it fully.
What do I think about the scalability of the solution?
Scalability seems good. This was one of the other features that we were interested in.
We have eight different accounts and are able to implement the solution across them easily.
How is customer service and technical support?
I go internally into the business for technical support rather than using the supplier for technical support.
How was the initial setup?
It fully integrates with our AWS environment, which is brilliant.
Alert Logic integrates with all of our products, which was one of the reasons that we went for it.
Which other solutions did I evaluate?
We also evaluated on-premise and open source products. We went with Alert Logic because it was quicker to implement.
What other advice do I have?
Try and get a demo. It is the best one products. As soon as you see it working, you will see it is very good.
We are using the cloud version.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Systems Engineer at Turner Broadcasting System
It improves our security by scanning containers correctly and quickly
Pros and Cons
- "It improves our security. Before, we didn't have anything scanning our containers. We had software scanning all the physical servers, but we had nothing to scan our containers. With Alert Logic, we can do that."
- "I would like more data on the alert payload. It would be good to have the ability to customize the alert payload to add whatever data that we want on there. Right now, it is a bit limited."
What is our primary use case?
We use it for security scanning containers on Kubernetes. We have containers running on Kubernetes, so we use it to scan for vulnerabilities.
How has it helped my organization?
It improves our security. Before, we didn't have anything scanning our containers. We had software scanning all the physical servers, but we had nothing to scan our containers. With Alert Logic, we can do that.
What is most valuable?
It scans correctly and quickly. For example, we had an issue where we had Bitcoin mined and sold in some of our containers, and Alert Logic was able to find it and alert us about it. Then, we were able to find out why the containers were being hacked and killed it.
What needs improvement?
I would like more data on the alert payload. It would be good to have the ability to customize the alert payload to add whatever data that we want on there. Right now, it is a bit limited.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
It's stable. We've not had any issues with stability.
What do I think about the scalability of the solution?
It is scalable. We have been adding more AWS accounts every day. We have been adding more containers, but we are not seeing any issues.
We have 240 AWS accounts. We have about 1000 containers, but we have 300 to 400 services which are running with containers on the cloud, and we are still able to continue to scale.
How is customer service and technical support?
I have not contacted the technical support.
Which other solutions did I evaluate?
The security team chose the product. I wasn't involved in the process.
What other advice do I have?
Give it a try. It is very useful.
The product is integrated with a product called BigPanda. It's an alerting platform, and it post alerts through SAP to BigPanda. The integration was good, but standard.
We have only used the AWS version.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free LevelBlue Managed Detection and Response Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Popular Comparisons
Qualys TotalCloud
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
IBM Security QRadar
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Qualys Exposure Management
Huntress Managed EDR
TrendAI Vision One – Cloud Security
Zafran Security
Buyer's Guide
Download our free LevelBlue Managed Detection and Response Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How inadvisable is it to use a single vulnerability analysis tool?
- What are the benefits of continuous scanning for vulnerability management?
- When evaluating Vulnerability Management, what aspect do you think is the most important to look for?
- What is a more effective approach to cyber defense: risk-based vulnerability management or vulnerability assessment?
- What are the main KPIs that need to be implemented to have better posture in vulnerability projects?
- Which is the best vulnerability scanner tool?
- What are your recommended automated penetration testing tools?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- Can you recommend API for Tenable Connector into ServiceNow
- What penetration testing tool (or tools) do you recommend for SMB/SME?

















