What is our primary use case?
We use the solution for identity management, we are using Windows Active directory. We used to see if there is any malicious item, or if somebody is trying to elevate to administrative privileges, then we also use it to monitor confidential data. We have confidential data stored in our file servers, so we see which are all the users who tried to access, or tried to delete or modify those confidential files. We keep track of those things.
What is most valuable?
It is easy to adopt. I don't have hands-on experience in implementing it, however, when talking to the security team, it was clear they were able to install the product and start using it quickly. It was also quick to learn the basics.
It is stable.
What needs improvement?
The product does not have certain advantages, especially the correlation tools. It was not working as per our expectations. We are not able to implement certain aspects.
The scalability is limited.
For how long have I used the solution?
I've used the solution for close to four years.
What do I think about the stability of the solution?
We don't have any issues with stability. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability depends. We have to add memory. It is scalable to that extent. However, it is not dynamically scalable in the way it would be in the cloud. Since this is an on-premises implementation, the scalability is limited.
We have about 2,000 users.
We have two SOC analysts who use it to generate reports and send them to the appropriate managers. They handle maintenance as well, and if there is a new rule that is needed, they can create it.
How are customer service and support?
Technical support is responsive. They have support services in Chennai. Whenever we request them, we get a prompt response. Since we are in South East Asia, the time difference is minimal.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
This is the first time we have used SIEM, and it's the only product that we have used.
We already used some other products of ManageEngine, and we came to know that they also have a SIEM product, so we wanted to try it. Now, we want to increase our SOC capability, so we're looking for some other products, like IBM QRadar.
How was the initial setup?
The initial setup was very simple and straightforward, according to our security team. It was very fast to get it up and running. The management team supported the process, and everything went very smoothly.
We don't just have to set up the software. We have to configure the rules for the use cases as well. We defined our requirements as per the company requirements.
What about the implementation team?
The security team handled the setup. We had a third party assist us.
What's my experience with pricing, setup cost, and licensing?
We have a yearly subscription that we must renew annually.
I cannot recall the exact cost. If a company is an SMB, a small and medium business, this is more of an economical solution. We initially spent around 1.5 million Indian Rupees when we purchased it. It's good for beginners.
What other advice do I have?
We are a customer.
For new users, I would advise that the company has to sort out the requirements clearly and they have to discuss with their team to see what requirements can be addressed using this product, and then they have to decide if the product would work for them.
ManageEngine also has other products Cloud 360+. We haven't used it, so I'm not able to give more information on that. I don't know what features they have in their current lineup. They have some add-on modules, however, we didn't get a chance to review or implement those products yet.
I'd rate the product six out of ten. While it meets our requirements.
Which deployment model are you using for this solution?
On-premises