Alerts derived from logs.
Director of Information Technology at a healthcare company with 51-200 employees
Simplified log analysis and log management.
Pros and Cons
- "You will wonder how you lived without it."
- "More information about what the alerts mean and how they are derived would be useful when determining their significance."
What is most valuable?
How has it helped my organization?
Simplified log analysis and log management.
What needs improvement?
More information about what the alerts mean and how they are derived would be useful when determining their significance. Support is good to provide this information though.
For how long have I used the solution?
>12 months
Buyer's Guide
USM Anywhere
May 2026
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
What do I think about the stability of the solution?
No.
How are customer service and support?
Excellent.
How was the initial setup?
Fairly straightforward. It does take some time to tune the system to your environment – to prevent getting alerts on activity your find acceptable in your environment.
What's my experience with pricing, setup cost, and licensing?
They do give discounts towards the end of quarters if your renewal is due.
What other advice do I have?
You will wonder how you lived without it.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Chief Security Officer at a financial services firm with 501-1,000 employees
The integration of IDS and OSSEC is valuable as it enables correlation between Network IDS events and host system event logs
Pros and Cons
- "With AlienVault we are able to respond to incidents and take necessary action faster than we could before without the solution in place."
- "Some customizations with the integration between AlienVault components have room for improvement and enabling users with WebUI interfaces instead of having to edit configuration files on the system to achieve certain actions would be a good improvement."
What is most valuable?
The integration of IDS and OSSEC is valuable as it enables correlation between Network IDS events and host system event logs.
How has it helped my organization?
AlienVault USM has improved how we manage events and incidents in our infrastructure. With AlienVault we are able to respond to incidents and take necessary action faster than we could before without the solution in place.
What needs improvement?
Some customizations with the integration between AlienVault components have room for improvement and enabling users with WebUI interfaces instead of having to edit configuration files on the system to achieve certain actions would be a good improvement.
For how long have I used the solution?
Three years.
What do I think about the stability of the solution?
No issues with instability has been encountered in our environment.
What do I think about the scalability of the solution?
No issues with scalability has been encountered in our environment.
How are customer service and technical support?
The AlienVault Technical support is good and has helped out several time with some really specific configurations in our environment.
Which solution did I use previously and why did I switch?
We used an outsourced MSSP solution but we needed to get the solution in-house in order to better integrate with our datacenters and systems and comply with financial regulatory and PCI-DSS requirements.
How was the initial setup?
The initial setup was straightforward and quite easy to setup. Requires Linux knowledge to manage but given that we use Linux for our critical infrastructure services it was no problem for us.
What's my experience with pricing, setup cost, and licensing?
We chose AlienVault partly do the the many features and functionalities that was bundled with the product to the pricing and licensing models that was offered. Many other solutions did not have the full spectrum of features but was significantly more expensive so we would have been forced to get additional solutions to cover all our requirements. With AlienVault we got a all-in-one solution that covered our needs.
Which other solutions did I evaluate?
We had a look at the current offerings at that time, including Tripwire, McAfee, SourceFire, etc., but concluded that we would get the best-bang-for-the-bucks with AlienVault solution
What other advice do I have?
As with any Security solution, you still need to have knowledgeable people to manage the solution and the solution is not a silver-bullet that takes care of all your issues without being properly managed. Make sure you have the necessary knowledge and headcount to use the solution before implementing this or any other solution. With Security, the most of the cost is in OPEX, not CAPEX, so make sure you have the necessary expertise to operate the solution as efficiently as possible.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
thanks for your feedback.
Buyer's Guide
USM Anywhere
May 2026
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
Information Security Officer at a healthcare company with 1,001-5,000 employees
Valuable features include integrated vulnerability assessment, intrusion/anomaly detection and monitoring, with a simple management interface.
Pros and Cons
- "Pricing was a very important consideration and lower than the other SIEM solutions evaluated."
- "Upgrading the network cards (from 1GB to 10GB) was not “supported” on the appliance, so we had to purchase a second one as a sensor."
What is most valuable?
Integrated vulnerability assessment, intrusion/anomaly detection and monitoring, with a simple management interface.
How has it helped my organization?
AlienVault provided improved visibility into the environment as well as the ability to report on the organization’s security posture.
What needs improvement?
Asset scanning and inventory (stale assets, scheduling scans) and correlation (false positives).
For how long have I used the solution?
2 years
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
Yes. Upgrading the network cards (from 1GB to 10GB) was not “supported” on the appliance, so we had to purchase a second one as a sensor. The secondary appliance with the 10GBs NICs is the same as the primary appliance, so this was disappointing.
How are customer service and technical support?
High (seldom used).
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
Simple and straightforward. The bulk of the work is understanding your own environment and tuning events (syslog, scans, alarm).
What's my experience with pricing, setup cost, and licensing?
Pricing was a very important consideration and lower than the other SIEM solutions evaluated. The price point makes it accessible for SMB organizations that may be constrained of resources (budget and people/skills) so deployment can be gradual while still deriving value out of the solution.
Which other solutions did I evaluate?
SolarWinds, Splunk, LogRhythm.
What other advice do I have?
As with any SIEM, it is not a “turn-key” or “set it and forget it” solution. It requires resources and skills to deploy, although this can be done in stages. Appropriate resources for maintenance is also key so the information is accurate, relevant and timely. Otherwise it becomes a repository of stale ignored events and alarms.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thanks Pedro for taking time to provide your feedback & comments.
Manager, Information Security at a retailer with 5,001-10,000 employees
I'm able to scan for vulnerabilities quickly on existing devices and also for new devices being deployed.
Pros and Cons
- "The pricing for this solution with the 3 major components: SIEM, FIM, and vulnerability scanning, can’t be beat."
- "I had some initial issues with some of the upgrades in version, but with the help of their support team, we were able to resolve all of them."
What is most valuable?
The fact that I am a very small security team and AlienVault allows me to have a SIEM, FIM and Vulnerability scanner all in one.
How has it helped my organization?
I am able to scan for vulnerabilities quickly on existing devices and also for new devices being deployed. Since I don’t have a lot of time to learn new and complicated tools, being an e-commerce company, this allows me to increase the security posture of the overall organization and also to help pass PCI compliance.
What needs improvement?
With all these products there is always room for improvement. Whether it’s making the filtering of anomalies better, making setup and deployment faster, streamlining more of the functional aspects of the product, etc. There is really not one thing that stands out in particular.
For how long have I used the solution?
About one year
What do I think about the stability of the solution?
I had some initial issues with some of the upgrades in version, but with the help of their support team, we were able to resolve all of them.
What do I think about the scalability of the solution?
No, not yet. We are growing at a rapid pace and eventually will need more sensors, but I believe that will be a painless upgrade.
How are customer service and technical support?
Tech support is great. Very knowledgeable, reliable, and have resolved all problems, escalated when necessary, and handled all my cases very professionally.
Which solution did I use previously and why did I switch?
I have used different solutions at previous jobs. AlienVault was a new purchase and install. When asked for my opinion, I did recommend AlienVault as the solution since my comparison of all products came down to AlienVault being the best for our particular environment.
How was the initial setup?
It was very straightforward. I had made a couple of little mistakes that most likely would have been avoided if I had not rushed a few aspects of the install, but tech support was able to get me back on the right track.
What's my experience with pricing, setup cost, and licensing?
The pricing for this solution with the 3 major components: SIEM, FIM, and vulnerability scanning, can’t be beat. There are other systems that are way more robust, but way more complicates and way more expensive. This solution was perfect for us.
Which other solutions did I evaluate?
I had eliminated others prior to evaluating AlienVault based on prior experience. Tripwire for FIM, QRadar for SIM, eEye Digital for vulnerability scans. All of which are great tools, but much more pricey. We briefly looked at LogRhythm, Tenable, and Splunk as well.
What other advice do I have?
I would say to implement it. It has all the components needed to help secure your environment as long as you have someone who can dedicate some time to it. But even if you don’t, like in my case, it is a much better solution that the others.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thank you Don for your thoughtful feedback.
IT Security Administrator at a local government with 501-1,000 employees
The basic setup was straightforward. I'd like to see built in support to detect more security incidents.
Pros and Cons
- "We now get a better view into what is happening on our network and to the servers than previously."
- "I'd like to see built in support to detect more security incidents."
What is most valuable?
- Security alarms
- Log collection
How has it helped my organization?
We now get a better view into what is happening on our network and to the servers than previously.
What needs improvement?
I'd like to see built in support to detect more security incidents.
For how long have I used the solution?
I've been using it for 10 months.
What do I think about the stability of the solution?
We had no issues with the stability.
What do I think about the scalability of the solution?
It's been able to scale for our needs.
How are customer service and technical support?
They're very good.
Which solution did I use previously and why did I switch?
This is the first time we've used a solution of this type.
How was the initial setup?
The basic setup was straightforward, but it would have been nice if I could have had more information on a full setup and the advanced features.
What's my experience with pricing, setup cost, and licensing?
You should license it for all your devices including endpoints, as this will make it more valuable to you.
Which other solutions did I evaluate?
We did compare it to some others solutions, but I don't remember which.
What other advice do I have?
Try it first as you get a free evaluation.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thank you for taking time to provide your feedback on your use of AlienVault USM.
IT Security Architect at a healthcare company with 1,001-5,000 employees
I can see all HIDS and IDS events in one place. Setup is complex when playing with custom plugins.
Pros and Cons
- "We have a better detection rate for malware and other cyber-attacks, and it really helps when USM is integrated in the incident response plan."
- "I've experienced frequent slowness, and we had to downgrade to filter out many logs."
What is most valuable?
The SIEM part where I can see all HIDS and IDS events in one place alongwith the correlation directives.
How has it helped my organization?
We have a better detection rate for malware and other cyber-attacks. Really helps when USM integrated in the incident response plan.
What needs improvement?
- Database query speed when dealing with millions of events per day
- Reports customization and types
- Dashboards TV modes (SOC surveillance monitors)
For how long have I used the solution?
I've been using it for three years.
What do I think about the stability of the solution?
I've experienced frequent slowness, and we had to downgrade to filter out many logs.
What do I think about the scalability of the solution?
The AIO is not fast enough for a network over 100 EPS, so you have to go with a dedicated server option for better speed.
How are customer service and technical support?
7/10
Which solution did I use previously and why did I switch?
We had nothing in place prior to this.
How was the initial setup?
It's complex when playing with custom plugins.
What's my experience with pricing, setup cost, and licensing?
The price is low, and it's good quality but require effort.
Which other solutions did I evaluate?
There were no other options looked at.
What other advice do I have?
To take full advantage of the product you have to work under the hood.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thank you for your time to provide your comments on using USM.
IT Engineer at a energy/utilities company with 501-1,000 employees
Due to the logger feature, everything is centralized on the AlientVault Server.
Pros and Cons
- "As it includes a logger feature for gathering all logs from all devices (network devices, servers, hosts etc.) it has basically become the only software that we look at when we have a problem."
- "As it includes multiple security softwares, the installation and configuration takes a lot of time."
Valuable Features:
Event Correlation is the most valuable feature for every SIEM. AlienVault has ISO 27001 compliance which is very helpful for the companies looking to have the ISO 27001 certification.
Improvements to My Organization:
As it includes a logger feature for gathering all logs from all devices (network devices, servers, hosts etc.) it has basically become the only software that we look at when we have a problem. We don’t need to search from one device to another as it’s all centralized on the same AlienVault Server which enables us to save time and become more efficient at work.
Room for Improvement:
As it includes multiple security softwares, the installation and configuration takes a lot of time. It would be good if they could work on that but the time is understandable given all the features AlienVault offers.
Other Advice:
It’s a very good SIEM with plenty of functionalities which helped improve our KPI.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Wajdi Ayari - I thank you so much for taking time to provide feedback on your experience with USM.
Group Information Security Officer at a consumer goods company with 1,001-5,000 employees
Before AlientVault we had no visibility of our vulnerabilities without looking up WSUS and matching this against the Windows bulletins.
Pros and Cons
- "Being the only Security professional in an organisation of well over 1000 people AlienVault lets me keep a watchful eye whilst getting on with my day job."
- "The reporting could do with some improvements for example the vulnerability report only tells you what vulnerabilities are open and lists them but there is no indication of how old they are at a glance and what vulnerabilities have been closed since the previous scans."
What is most valuable?
The correlation from the Host Based Intrusion to Network Intrusion against the vulnerabilities in my network.
How has it helped my organization?
We had no visibility of our vulnerabilities without looking up WSUS and matching this against the Windows bulletins. This completely missed the mark when it came to third party patches and poor configuration and waster hours upon hours for half a story. Not to mention we have a much better understanding of how and when we are being attacked.
What needs improvement?
The reporting could do with some improvements for example the vulnerability report only tells you what vulnerabilities are open and lists them but there is no indication of how old they are at a glance and what vulnerabilities have been closed since the previous scans. I would also like to see the ability to scan my devices for compliance against the CIS Benchmarks.
For how long have I used the solution?
I have had this solution in place for just over a year now.
What do I think about the stability of the solution?
I've not experienced any issues with this yet.
What do I think about the scalability of the solution?
I've not experienced any issues with this yet.
How are customer service and technical support?
The tech support guys have been very friendly and helped as soon as there has been any issue. I cannot fault their technical support.
Which solution did I use previously and why did I switch?
I used multiple products to try and get someway towards the level of visibility afforded by AlienVault. ManageEngine SIEM, Qualys, vulnerability management, and Norton for HIDS. Having this all in one interface made more sense which swayed the decision to go with Alienvault.
How was the initial setup?
Very easy for initial set-up. My system was up and running within two hours. When you start to get into it more, then you need a better technical understanding.
What's my experience with pricing, setup cost, and licensing?
This is much cheaper than some of the big names it is very affordable and scalable.
Which other solutions did I evaluate?
We looked at managed services from Dell SecureWorks as well as Qualys & Nessus.
What other advice do I have?
Being the only Security professional in an organisation of well over 1000 people AlienVault lets me keep a watchful eye whilst getting on with my day job. This is a very good product with excellent support. Personally I would have preferred to go on the AlienVault System Engineers course as I believe this would help in fine tuning the system.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thanks so much for the feedback on your experience with AlienVault & USM.
Information Security Administrator at a government with 1,001-5,000 employees
It provides greater visibility of host based and network activity through its HIDS and NIDS functionality. They should simplify the HIDS agent reporting/custom rule creation.
Pros and Cons
- "AlienVault is willing to offer flexible and competitive pricing."
- "They should simplify the HIDS agent reporting/custom rule creation."
What is most valuable?
- Central log aggregation
- Security correlation
How has it helped my organization?
It provides greater visibility of host-based and network activity through its HIDS and NIDS functionality.
What needs improvement?
They should simplify the HIDS agent reporting/custom rule creation.
For how long have I used the solution?
I've used it for one year.
What do I think about the stability of the solution?
We had issues but this was due to us receiving improper training from a third party and not necessarily due to the product.
What do I think about the scalability of the solution?
Servers/sensors cap at 2048 host based agent deployments, but servers and sensors are easily scalable for a medium sized business.
How are customer service and technical support?
10/10
Which solution did I use previously and why did I switch?
I haven't used anything similar.
What's my experience with pricing, setup cost, and licensing?
AlienVault is willing to offer flexible and competitive pricing.
Which other solutions did I evaluate?
We also looked at AccelOps, LogRhythm, and IBM QRadar.
What other advice do I have?
If you have any questions, AlienVault's support team is more than willing to help with your installation, implementation, and integration.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Thank you for your feedback & comments.
Network Engineer II at a healthcare company
We now can find the source of where Windows account lockouts are occurring.
Pros and Cons
- "It’s pretty easy to setup but to really take advantage you should have a dedicated person who will devote their time to customizing and utilizing the power this solution has."
- "It needs to be easier to deploy switch monitoring."
What is most valuable?
We now have the ability to see what is happening in the environment.
How has it helped my organization?
We now can find the source of where Windows account lockouts are occurring.
What needs improvement?
It needs to be easier to deploy switch monitoring.
For how long have I used the solution?
We've been using it for four months.
What do I think about the stability of the solution?
We've had no issues so far.
What do I think about the scalability of the solution?
We've been able to scale it for our needs without issues.
How are customer service and technical support?
I've not had to contact them yet.
Which solution did I use previously and why did I switch?
We switched because our previous solution wasn't scalable.
How was the initial setup?
It was pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
It was a reasonably priced solution.
Which other solutions did I evaluate?
We didn't look at any other solutions.
What other advice do I have?
It’s pretty easy to setup but to really take advantage you should have a dedicated person who will devote their time, to customizing and utilizing the power this solution has.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Lenny - thank you so much for your feedback & comments.
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
Datadog
SentinelOne Singularity Cloud Security
Splunk Enterprise Security
Dynatrace
Microsoft Defender for Cloud
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Tanium
Huntress Managed EDR
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?














thank you for your comments!