What is our primary use case?
Security Onion is primarily used for network security monitoring, threat detection, log management, and centralized visibility across our infrastructure, serving as the primary means for our organization.
Security Onion is used in our organization by continuously leveraging the Linux platform, Linux system, and network-based architecture to monitor threat detections and log management systems, which has proven very helpful for our organization in terms of network security monitoring.
What is most valuable?
The most valuable features of Security Onion are its threat detection capabilities, centralized log management system, and network security monitoring.
Security Onion has positively impacted our organization by providing features such as log management and threat detection, alongside network security monitoring, which creates a significant impact in our environment, particularly in incident investigation support.
What needs improvement?
Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use.
I assigned a rating of eight out of ten because the initial setup requires documentation reading and planning, which could be improved to make it easier for first-time users.
I do not think of any other improvements for Security Onion.
For how long have I used the solution?
I have been using Security Onion for approximately nine months.
What do I think about the stability of the solution?
Since using Security Onion, we have not faced any issues or downtime, which indicates it is very stable.
Under heavy workloads, Security Onion works very smoothly, although there are occasions when it slows down, but overall it performs exceptionally.
What do I think about the scalability of the solution?
Security Onion is a highly scalable platform, making it suitable for medium to large-scale enterprises.
How are customer service and support?
Customer support for Security Onion is very good; whenever issues arise, help is quick and documentation is well maintained.
Which solution did I use previously and why did I switch?
I have not previously used any other solution and switched directly to using Security Onion from the start.
How was the initial setup?
Security Onion can be made easier to set up initially, as it is somewhat difficult at the start, but once configured, it becomes a great tool to use.
I assigned a rating of eight out of ten because the initial setup requires documentation reading and planning, which could be improved to make it easier for first-time users.
What about the implementation team?
Security Onion is handled by our team very effectively, as we manage issues and maintain updates whenever necessary.
For new team members, we provide reading materials and training on Security Onion platform usage after familiarizing them with basic tasks.
We handle incident response and investigation with Security Onion, where alerts indicate issues directly, leading our team to respond quickly and solve problems efficiently.
What was our ROI?
We achieve a return on investment through improved threat detection and faster incident response in log management and centralized visibility across the infrastructure.
What's my experience with pricing, setup cost, and licensing?
Security Onion does not require any cost, as it is open-source and free.
Which other solutions did I evaluate?
Before choosing Security Onion, we evaluated alternatives such as Splunk Enterprise Security.
What other advice do I have?
Security Onion is a completely open-source and free platform, making it a cost-effective solution that works smoothly and effectively for our organization.
Security Onion integrates well with our existing tools, primarily using Linux systems in our organization, allowing us to monitor logs and manage threat detection and operations in the public cloud effectively.
Security Onion is very helpful in meeting compliance requirements and supports regular standards for our environment.
I advise organizations that use Linux or have network security knowledge to consider Security Onion, as it satisfies requirements such as threat detection and log management systems.
I would rate this review eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?