We have customers from the retail, industrial, strategic resource, and OT infrastructure sectors who are using AT&T AlienVault USM. The solution has several use cases.
Coordinator de Servicios  at MAINT
Easy to use and intuitive platform against security threats, with a feature for adding apps
Pros and Cons
- "Easy to use, scalable, stable, and very intuitive platform that provides protection against security threats."
- "Adding a parsing interface for the customers would make AT&T AlienVault USM better."
What is our primary use case?
What is most valuable?
I like that AT&T AlienVault USM is deployed on cloud, because the previous solution, the all-in-one solution wasn't, so we had a lot of problems with the all-in-one solution. Either the database was corrupted, or there was a large delay in the appliance. With AT&T AlienVault USM being on cloud, all of those problems disappeared.
Another feature I like about the solution is the ability to add apps. It's a really good feature.
AT&T AlienVault USM is a very intuitive tool, especially for analysts. It's easy to use.
What needs improvement?
An improvement for AT&T AlienVault USM is the option for us to build the connectors ourselves, for us to do the parsing ourselves, because those options disappeared with the version of the solution that we're currently using. I know I can talk to the vendor to ask for a new parsing option for the application, for any new platform, but I understand that it can take several months. Adding a parsing interface for the customers would be good.
What do I think about the stability of the solution?
AT&T AlienVault USM is a stable solution.
Buyer's Guide
USM Anywhere
September 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the scalability of the solution?
AT&T AlienVault USM is a scalable solution, especially because we have the option to use more sensors, and we have an average scale of log space for log rotation.
How are customer service and support?
We don't deal with the support team for AT&T AlienVault USM, in terms of big issues, but in terms of them answering a question, or giving information about design specs, their response is good. Their response is correct, so we have no problem with the support for this solution.
From one to five, where one is bad and five is good, I'm rating their support a four.
How was the initial setup?
The initial setup for AT&T AlienVault USM was easy.
Which other solutions did I evaluate?
We evaluated another product: AlienVault OSSIM, but only for testing, we did not suggest it to our customers.
What other advice do I have?
We are using AT&T AlienVault USM. It's our main SIEM solution. We've been a partner of AT&T for four to five years. We still have a customer using the all-in-one solution, but now we are mainly promoting AlienVault USM Anywhere.
I know that the solution is undergoing changes to become even more useful, so we have no problems with it. There's no problem, even in terms of integration.
We use three people for the deployment and maintenance of the solution. One person is in charge of designing and implementing. Another person supports the implementation and the requirements of the customer. The third person does the monitoring exclusively. We provide our customers with the services of a security operations center.
I'm recommending AT&T AlienVault USM to others and I'm rating AT&T AlienVault USM eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

DevOps Engineer at a tech services company with 201-500 employees
Impressive visuals, high performance, and good user experience
Pros and Cons
- "AT&T AlienVault USM is good for ELK Stack, the user experience is great because of its architecture. The ELK has a great performance and it has very good speed in the search and Kibana. Additionally, the visuals and dashboards and very nice and customizable."
- "The AT&T AlienVault USM is okay, but the relational database is not very good for large amounts of data. For example, many logs cannot be processed. It has been very slow for the queries and some data which are large, it is not very good in this case."
What is our primary use case?
We are using AT&T AlienVault USM for SIEM, collecting logs from clients, traffic, analyzing, forensics, and security.
What is most valuable?
AT&T AlienVault USM is good for ELK Stack, the user experience is great because of its architecture. The ELK has a great performance and it has very good speed in the search and Kibana. Additionally, the visuals and dashboards and very nice and customizable.
What needs improvement?
The AT&T AlienVault USM is okay, but the relational database is not very good for large amounts of data. For example, many logs cannot be processed. It has been very slow for the queries and some data which are large, it is not very good in this case.
For how long have I used the solution?
I have been using AT&T AlienVault USM for approximately five years.
What do I think about the scalability of the solution?
We are using AT&T AlienVault USM as a client, if we want to increase the data we can collect more data because the solution can expand well horizontally.
Between the cellphones and laptops usage, we have more than 250 users using his solution in my organization.
How are customer service and support?
We have not used the technical support but we have clear documentation that we use.
How was the initial setup?
The initial setup was straightforward. We have a server room which we deploy from.
What about the implementation team?
The maintenance of the solution is not very difficult.
What other advice do I have?
I would recommend this solution because it is simple to deploy, has high performance, and has a great user experience.
I rate AT&T AlienVault USM a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
USM Anywhere
September 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Solutions Engineer at a computer software company with 51-200 employees
Useful for compliance, very scalable, and pretty stable
Pros and Cons
- "We're using it more for reporting, that's all. We're using it to help our customers to pass any kind of audits that they receive."
- "There could be some type of integration with our existing portal. We have our own customer portals, and it would be good if there was an integration so that our portal can provide reports. There could be some type of API into the AlienVault system with the USM system so that it is easy to show the customers high-level reports of the system through our portal."
What is our primary use case?
We use it for compliance. We're not using it as a security operation center type of thing. Its usage is more from an auditing standpoint at this point.
We partner with them for customers who need something like a SIEM, so we're a cloud provider and integrator.
It is deployed on the cloud. It is a combination of AT&T's own cloud and our cloud. We run our own infrastructure. So, it is a hybrid and private cloud.
What is most valuable?
We're using it more for reporting, that's all. We're using it to help our customers to pass any kind of audits that they receive.
What needs improvement?
I don't have any suggestions for improvement. On our side, as a provider, we should develop a real security operation center type of practice, which we don't have right now.
There could be some type of integration with our existing portal. We have our own customer portals, and it would be good if there was an integration so that our portal can provide reports. There could be some type of API into the AlienVault system with the USM system so that it is easy to show the customers high-level reports of the system through our portal.
What do I think about the stability of the solution?
It is pretty stable from what I hear.
What do I think about the scalability of the solution?
It is cloud-based, so it is very scalable. It really depends on how many devices they have in their environment. Our customers are more mid-sized companies, so it fits what we need.
We don't have a lot of clients using this SIEM. Usually, a client is interested in something like this to help them with their auditing. So, we don't have a lot of customers using it right now. Probably in the near future, its usage will be increased in terms of the customers requesting it from a security standpoint.
How are customer service and technical support?
It is pretty good. I usually don't contact their support. I usually contact their sales team. I work with their pre-sales and sales engineer and account rep.
How was the initial setup?
It is pretty straightforward from what I've seen, but it has to be verified to make sure any changes in the environment are added to the configuration. Like anything, it is not set it and forget it. You really have to make sure that it is capturing everything if things change or new systems are brought online. It is more of a procedural thing where you have to make sure somebody is keeping it up to date.
For its maintenance, we have someone who manages the product itself. In our company, for IT people, we have around 100 or so staff. We have customers nationwide, but we probably have two to three people managing this product. They are in more of a security analyst type of role dedicated to security.
What's my experience with pricing, setup cost, and licensing?
I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs.
There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer.
What other advice do I have?
I would advise knowing your requirements and your data. What are you trying to protect or monitor? Before implementing something like this, you really should have basic security in place. You should have systems that are generating logs, for example, antivirus software and firewall. You have to have that all in place first to make this kind of product useful because this type of product is really meant to aggregate things after the fact. After you've put all the systems in place, then this system aggregates and collects everything together. You really need all the endpoint security, firewall security, and server security first, so you have meaningful data to look at. The SIEM is not going to be useful if you don't have any meaningful data for it to collect.
I still need to dig into it deeper to see exactly what it does. Our practice is kind of evolving, so this is probably something that we need to offer more to customers. We need to get more product knowledge on it and develop a practice around it. A lot of customers are asking for security operations center (SOC) services for remediation of problems. We don't do that right now, but that's something that I know is probably on the roadmap. With everything going on, that would be a helpful service to our customers, and I think they're asking for that. We've encountered customers asking for that type of service. We don't do it yet. I know there are other partners out there that do that, so really it's on our side to develop the product more. Whether it involves staying with this AT&T product or going for maybe another one, customers are looking for a little bit more. They are not just to have it set up, but also to have someone to act on any kind of alerts or any kind of potential breaches. They're looking for a service for somebody to actually remediate.
From what I know of the product, I would rate it an eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Unstable features, poor technology integration, and support needs improvement
Pros and Cons
- "The solution has all the features that we need, however they do not work correctly."
- "In the future, I would like to see all these features of the solution working properly."
What is our primary use case?
I am using the solution for security information and event management.
What is most valuable?
The solution has all the features that we need, however they do not work correctly.
What needs improvement?
This solution has too many issues with integration with other technologies. For example, you can configure the solution to integrate with your technology today but tomorrow it will stop working. You have to continually update the login, save the issue, and create a ticket with support. It is a long process that takes too long for the support to resolve quickly.
In the future, I would like to see all these features of the solution working properly.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
The solution is not stable. Sometimes the virtual machines are not working and it is not a network issue. There are many compatibility issues. There have been times when upgrading the firmware the device is not operational, you then have to restore to the older version.
How are customer service and technical support?
The customer support has not been very helpful when issues arise.
What's my experience with pricing, setup cost, and licensing?
The price for this solution is very good, but since the features do not work the price is expensive.
What other advice do I have?
I would not recommend anyone to use it.
I rate ATT AlienVault USM a one out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Operation Manager at Checksum Consultancy
Easy to deploy, good integration with OTX, and good at asset discovery and vulnerability scanning
Pros and Cons
- "Asset discovery and vulnerability scanner are good features. The integration between this solution and OTX, which is an AlienVault platform for Open Threat Exchange, is also a valuable feature. It is also quick and easy to deploy, so you can quickly engage with a customer's environment."
- "Its reporting tools need improvements. It would be good if they can provide integration with other ticketing systems. Currently, we only have integration with Slack and Jira. It is also a bit slow, and its replication engine can be improved."
What is our primary use case?
We provide information security services to clients. We are seeking some clients to provide monitoring services by using AlienVault. We are also providing AlienVault USM Anywhere, which is cloud-based and has integration with cloud platforms such as AWS, Azure, and Google Cloud.
What is most valuable?
Asset discovery and vulnerability scanner are good features. The integration between this solution and OTX, which is an AlienVault platform for Open Threat Exchange, is also a valuable feature. It is also quick and easy to deploy, so you can quickly engage with a customer's environment.
What needs improvement?
Its reporting tools need improvements. It would be good if they can provide integration with other ticketing systems. Currently, we only have integration with Slack and Jira.
It is also a bit slow, and its replication engine can be improved.
For how long have I used the solution?
I have been using this solution for six months.
How are customer service and technical support?
We provide technical support for our clients.
Which solution did I use previously and why did I switch?
I have used McAfee ESM. McAfee ESM has many good features, but it is not very integrated with cloud-based assets. AlienVault is already a cloud-based solution, and it is native to cloud assets, which gives AlienVault an advantage over McAfee ESM. On the other hand, McAfee ESM is much better than AlienVault in terms of search engine, data collection, and events.
How was the initial setup?
It is very easy to deploy. It just takes one or two days and allows you to engage with your customer's environment quickly.
What's my experience with pricing, setup cost, and licensing?
Its price is much lower than McAfee ESM.
What other advice do I have?
I would encourage others to go with this solution because it is easy to deploy, and it provides good tools to know more about your network and the traffic on it. Its reporting needs some improvements, but it fulfills the needs.
I would rate AlienVault USM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Manager at WASHI
A stable, user-friendly security solution with a reasonable price tag and easy deployment
Pros and Cons
- "The solution is stable."
- "The dashboard could be improved as well as the level of customization."
What is our primary use case?
The primary use case of this solution is for security.
What needs improvement?
The solution is very user-friendly, but the dashboard could be improved as well as the level of customization.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The deployment of this solution is easy, but you need some level of understanding.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is reasonable, which is one of the reasons why we selected it over other solutions.
What other advice do I have?
I would recommend this solution to other users.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Operating Officer / SR. Project Manager at SCS
Helpful threat intelligence capability, but the reporting is mediocre
Pros and Cons
- "The most valuable feature is threat intelligence."
- "The reporting is mediocre and is something that needs to be improved."
What is our primary use case?
We are a managed security service provider and we offer AlienVault USM to our clients. We use it to monitoring their environments and to maintain their logs.
What is most valuable?
The most valuable feature is threat intelligence. Their community is a very helpful tool and I think it's one of the values of AlienVault.
What needs improvement?
They set aside a lot of the functionality from the on-premises version that we found very helpful in managing tickets. As it is now, the cloud-based deployment is lacking these useful features.
The reporting is mediocre and is something that needs to be improved.
For how long have I used the solution?
I have been using the cloud-based deployment of this solution for about two years.
What do I think about the stability of the solution?
The stability is fine.
What do I think about the scalability of the solution?
Scalability in a cloud solution is tied to costs. With any cloud solution, the more data you have and the larger your company, the higher the price point. I wouldn't say that scaling is easy, but it is standard.
How are customer service and technical support?
Technical support is slow to respond when we put in a ticket. We're a number.
Which solution did I use previously and why did I switch?
We use both the on-premises version and USM Anywhere. The latter is a SaaS solution.
How was the initial setup?
The initial setup is okay. At an additional cost, they offer services to assist with deployment.
What's my experience with pricing, setup cost, and licensing?
Our take on it is that we are paying more for this product because of the AT&T name. We don't necessarily find that we are getting more functionality or quality, given the price point.
The licensing fees are dependent on usage.
Which other solutions did I evaluate?
We are currently evaluating different SIEM solutions. I have found that all of them have issues, whether it is related to functionality or price point. Even the ones that have a high price don't provide everything that you need.
What other advice do I have?
My advice for anybody who is considering this product is to evaluate all of the options that are out there. There is no one, great answer, so you have to figure out what best fits your needs.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Good security management capabilities but the interface needs to be more user-friendly
Pros and Cons
- "The most valuable feature of this solution is security management for PCI DSS."
- "This solution could be easier to use."
What is our primary use case?
This is a SIEM solution that our customers use in an on-premises deployment.
What is most valuable?
The most valuable feature of this solution is security management for PCI DSS.
What needs improvement?
This solution could be easier to use. It is hard for some people to understand, and they need to get training and certification just to understand what it's showing them.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
In terms of stability, I would give it fifty percent.
What do I think about the scalability of the solution?
The scalability of this solution is good.
We have a large number of customers who use this product on a daily basis.
How are customer service and technical support?
Technical support is very good from their side.
How was the initial setup?
The initial setup of this solution is a bit complex. Specifically, it is the way that it integrates with other products.
What about the implementation team?
We deployed this solution in-house.
What other advice do I have?
This is a good product but it can be made more user-friendly.
I would rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Datadog
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Rapid7 InsightIDR
LogRhythm SIEM
Fortinet FortiSIEM
AlienVault OSSIM
Sentinel
Fortinet FortiAnalyzer
Securonix Next-Gen SIEM
Exabeam
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?