My company wanted to get software which would be able to monitor resources in AWS, mainly IDS in one cumulative GUI, then add extra requirements with AlienVault match.
admin at KIL A&T
I can easily check all logs and data in relation to attacks in one place
Pros and Cons
- "I can easily check (in one place) all the logs and data in relation to attacks. It also gives me an overview if a server is not configured properly."
- "Plugins could be better utilized, as some of them do not recognize all logs."
- "It was easy on PoC, but when we got to the product it was different story. We had to learn the product again and got feeling that the PoC was a different product."
What is our primary use case?
How has it helped my organization?
From my perspective, it saves me about two to seven hours weekly. Now, I can easily check (in one place) all the logs and data in relation to attacks. It also gives me an overview if a server is not configured properly.
What is most valuable?
- Centralized logs: All the details are in one place. This is helpful if you have over 100 servers.
- Centralized IDS: We need this as we are able to see what is happening in (almost) real time.
What needs improvement?
- Plugins could be better utilized, as some of them do not recognize all logs.
- We could add little more customization to dashboards.
Buyer's Guide
USM Anywhere
June 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
Everything has worked fine since we have had this tool.
What do I think about the scalability of the solution?
We have been adding more servers, and it has been working. We have run out of storage space once or twice, so we had to check and choose which logs that we needed to minimize this problem.
How are customer service and support?
It has very good customer service. I have opened about five cases. They were ones which I did not have time to search or could not find information on the support website.
Which solution did I use previously and why did I switch?
I previously worked with Nagios, SolarWinds, and Big Brother. Though, this was at a different company.
These products did not match the requirements in AWS at the time that we were getting AlienVault.
How was the initial setup?
Setup required time. It will take time to set it up and utilize it at a percentage with which you will be satisfied.
It was easy on PoC, but when we got to the product it was different story. We had to learn the product again and got feeling that the PoC was a different product.
Which other solutions did I evaluate?
We were also looking at LogRhythm, Splunk, and few others. We decided on AlienVault, as they had a nice presentation (which told us what we wanted to hear) and the PoC proved it could do what we needed.
What other advice do I have?
Check other products, do POC as change from one to other get be very pricey and time consuming. Also training of people and changes cost lots of resources and not all employees like such changes every year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a tech services company with 1-10 employees
Its powerful correlation engine helps reduce time in manually correlating events
Pros and Cons
- "Its powerful correlation engine helps reduce time in manually correlating events."
- "The only complex area of the setup was writing the custom scripts."
- "It should be able to communicate with other security solutions to stop threats."
How has it helped my organization?
Its powerful correlation engine helps reduce time in manually correlating events.
What is most valuable?
- Alarms
- Correlation
What needs improvement?
It should be able to communicate with other security solutions to stop threats.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
How are customer service and technical support?
Customer Service:
I would rate customer service as a nine out of 10.
Technical Support:
I would rate technical support as a nine out of 10.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
How was the initial setup?
The only complex area of the setup was writing the custom scripts.
What about the implementation team?
We use both a vendor team and an in-house team for implementation.
What was our ROI?
The ROI is quite good.
What's my experience with pricing, setup cost, and licensing?
Use an MSSP instead. It is much cheaper.
Which other solutions did I evaluate?
We did not evaluate other options.
What other advice do I have?
It is quite awesome.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
USM Anywhere
June 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
Client Development Manager at a tech services company with 51-200 employees
Allowed us to help our customers satisfy compliance needs around logging and monitoring
Pros and Cons
- "The asset management functionality (active and passive scans) is also really important. You can't protect what you do not know about, so having an inventory of all your devices and software is critical to a security management program."
- "Allowed us to help our customers satisfy compliance needs around logging and monitoring."
- "AlienVault needs to continue to integrate with other third-party technologies that clients want to have monitored."
Primary Use Case
I work for a Managed Service Provider, who uses AlienVault USM Anywhere as the backbone of our vulnerability management and logging solution, which we deliver to our clients.
Improvements to My Organization
AlienVault has allowed us to help our customers satisfy compliance needs around logging and monitoring (HIPAA, PCI, etc.) and has also provided a comprehensive platform that goes beyond just being a SIEM. It allows us to serve our customers in many different ways.
Valuable Features
The Vulnerability Scanning Engine using OpenVAS is a quality tool. The asset management functionality (active and passive scans) is also really important. You can't protect what you do not know about, so having an inventory of all your devices and software is critical to a security management program.
Room for Improvement
AlienVault needs to continue to integrate with other third-party technologies that clients want to have monitored. The plugin builder in the most recent version update is helpful, but it is still a little "clunky" at times.
Use of Solution
One to three years.
Disclosure: My company has a business relationship with this vendor other than being a customer. Sword & Shield is one of AlienVault's premier training partners and offers 24/7/365 SOC services around the AlienVault platform.
Network and Securirty Engineer at a tech vendor with 501-1,000 employees
It has allowed us to see what is happening on our servers
Pros and Cons
- "The main menu: You can see everything there, what is happening on the servers, and in the logs, you can view more details of each event."
- "It has allowed us to see what is happening on our servers."
- "As this software is in the cloud, you do not have control on updates and general changes which are happening."
What is our primary use case?
We have devices in AWS and in the data center. The main reason is to do an IDS inspection in the cloud, as it was really hard to get proper software to do this and we did not want to install a virtual firewall in each timezone. We have over 200 servers being protected with this software.
How has it helped my organization?
It has allowed us to see what is happening on our servers. You can do a similar setup with AWS, but monitoring it can give you a headache if you ave over 10 servers.
What is most valuable?
The main menu: You can see everything there, what is happening on the servers, and in the logs, you can view more details of each event. Everything you need is in 'one place'.
What needs improvement?
As this software is in the cloud, you do not have control on updates and general changes which are happening. It can be a somewhat annoying that DC sensors are updated and you will not have control when this happens.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
So far, stability has been okay.
What do I think about the scalability of the solution?
So far, no issues with scalability. We see that too many logs are being sent out, but you have to work out logging what you need.
How are customer service and technical support?
They quickly respond on what you need, not on what they know.
Which solution did I use previously and why did I switch?
We did not use a previous solution.
How was the initial setup?
It was easy to set up. AlienVault was helpful here.
What about the implementation team?
We used our team, but with the help of the AlienVault team.
What was our ROI?
We have been using it less then a year, but it does saves time when searching logs.
What's my experience with pricing, setup cost, and licensing?
Negotiate the best package for your environment.
Which other solutions did I evaluate?
We ran a few PoCs. The price and feature set were the best with AlienVault.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SOC Analyst II at Shatter I.T.
Incoming alarms provide an overview of suspicious traffic going through the network
Pros and Cons
- "The Event Correlation and vulnerability scans have been the most useful. As a 24/7 SOC, we use the incoming alarms to give an overview of suspicious traffic going through the network. It's easy to look at the correlated events and see the broad picture of traffic for that customer. Vulnerability scans are good for providing patch and remediation guidelines to keep customer systems secure."
- "The UI and overall processes need a little bit more love. This shows in the error banners that come up when you select certain things. There isn't a day that goes by that the UI doesn't error out and I can't view events for an alarm."
- "The reporting tools are a bit lacking for building reports to give directly to customers, but support has been helpful in giving our requests for new features to the development team and following up with us."
What is our primary use case?
We are an MSSP. We have a distributed environment that spans multiple networks and customers in various locations. We have one federated that receives information from all of our children servers deployed at customer locations.
How has it helped my organization?
AlienVault has provided a nice, unified system for monitoring and reporting. Since we use this for customer security services, the vulnerability scans have come in handy for overall system health checks, for making sure customers aren't vulnerable to known attacks.
What is most valuable?
The Event Correlation and vulnerability scans have been the most useful. As a 24/7 SOC, we use the incoming alarms to give an overview of suspicious traffic going through the network. It's easy to look at the correlated events and see the broad picture of traffic for that customer. Vulnerability scans are good for providing patch and remediation guidelines to keep customer systems secure.
What needs improvement?
The UI and overall processes need a little bit more love. The development job postings have the requirement, for prospective candidates, of "values progress over perfection". This shows in the error banners that come up when you select certain things. There isn't a day that goes by that the UI doesn't error out and I can't view events for an alarm. It's nice that they have new features rolling, keeping up with demand, but fixing the events/alarm database errors would be nice too.
The reporting tools are a bit lacking for building reports to give directly to customers, but support has been helpful in giving our requests for new features to the development team and following up with us.
Network Breach
We have not, but being a 24/7 SOC we have someone checking at all hours.
Efficiency of Security Team
Yes.
Events per Day
500,000.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability.
How are customer service and technical support?
AV support has never been anything less than amazing.
Which solution did I use previously and why did I switch?
We did not use anything else prior. We tried the free version of AV then decided to go with the paid option and become an MSSP, since it fit our company needs for the right price.
How was the initial setup?
Straightforward, once going through a course.
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
Our company normally handles everything from setup to configuration, refinement, and monitoring. We are an MSSP so we all handle this for the customer when they inquire about services.
Which other solutions did I evaluate?
No, AlienVault fit what we needed for the phase we were in with the SOC.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Architect at Envision IT LLC
Cloud-based panel is excellent, enabling our SOC to review and respond to threats
Pros and Cons
- "The new cloud-based panel is excellent both for client review as well as for our SOC to review and respond to threats. It is much easier to configure and use than the previous solution from AlienVault."
What is our primary use case?
We are an MSP and we utilize an AlienVault USM Anywhere solution for threat detection in client networks.
How has it helped my organization?
Alienvault USM Anywhere is a great evolution of a proven product. While the feedback and customization requirements remain largely the same, the user interface has been significantly improved. This significantly improves the interaction our clients have with their data, and we have received significant positive feedback.
What is most valuable?
The cloud console is by far the best improvement of the product. In the past, our less technical clients had trouble sorting through the dashboards within the USM console, and we had received complaints on viewing the real-time data versus our prepared reports.
The new cloud-based panel is excellent both for client review as well as for our SOC to review and respond to threats. It is much easier to configure and use than the previous solution from AlienVault.
What needs improvement?
It can still be difficult to feed products that are not supported out-of-the-box. It would be good if they had a better plugin exchange/store with AlienVault QA to ensure data is being processed properly.
For how long have I used the solution?
One to three years.
Disclosure: My company has a business relationship with this vendor other than being a customer. MSSP/Reseller
Engineer - Network Security at a tech company with 11-50 employees
Review about AlienVault
What is our primary use case?
I'm a System Engineer working for a IT Security Solution Provider. My organization received a request for SIEM and FIM solution to be deployed for a Financial Organization. We have found AlienVault provide SIEM and FIM features in USM All In One
This was my first ever SIEM deployment and started from the scratch after doing a good POC with the customer.
How has it helped my organization?
It has helped me to give some InfoSec guidance to my customer after deployed the AlienVault in their premises.
Now they were able to get to know what kind of traffic passing through the firewalls and what kind of traffic hits the traffic.
What is most valuable?
SIEM and the FIM are the first preferences when I started the deployment. Because the customer wanted to monitor network security incidents of the Servers and any file modification done to their critical files residing in the production servers.
Vulnerability scanning and OTX helped us to manage all in one single point.
The alerting and security intelligence is the heart of the product. Monitoring customer's critical network is now almost a one man job.
What needs improvement?
Still I was working on the implementation I have found difficulties in searches within security events. Configuring some areas looks complicated.
I had issues while installing OSSEC agent in Solaris and CentOS Servers. A workaround for this issue will give some value for users.
For how long have I used the solution?
Still implementing.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Analyst at a tech company with 51-200 employees
Review about AlienVault
What is our primary use case?
SIEM, Log ingestion and evaluation. We use this not only for internal but also for clients that we manage. It has proven its worth and more. We are currently very pleased with this product and has performed as advertised. We obviously use this for being able to ascertain visibility on each network in which it is deployed not only from the NIDS/HIDS side but also evaluation of each interaction every device has.
How has it helped my organization?
We have benefited greatly due to gaining the visibility we need for different instances. It has improved our security posture and has helps us respond to alarms/events as they have come down through the pipeline to our ticketing system we use. All in all, it has improved our SOC.
What is most valuable?
AlienApps that we use to integrate with our current setup is awesome! Not only that, they have roadmapped being able to open up their API so we can integrate and flex the USM Anywhere as much as we want and when we want to. The staff has been incredibly helpful on getting us further down the line with our constructive feedback and have worked on implementing changes to their system to help improve their product.
What needs improvement?
A tailored OTX map for each customer's central would be awesome to have for displays. A lot of companies like to have visuals for their central instance in order to be able to see when an IOC comes through and it would help have something in front of analysts/engineers to respond to promptly if they were away from central working downstream.
For how long have I used the solution?
Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Thank you for taking time to provide your feedback & comments. If you'd like to speak with someone here at AlienVault from the product team, please do not hesitate to reach out to me directly. My email: tandrews@alienvault.com

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Datadog
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Graylog
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Fortinet FortiAnalyzer
Securonix Next-Gen SIEM
Exabeam
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
Thank you Patrick for your time to review AlienVault USM and for your candid feedback!