No more typing reviews! Try our Samantha, our new voice AI agent.
it_user829533 - PeerSpot reviewer
IT Manager at a manufacturing company with 51-200 employees
User
Mar 4, 2018
It is my "security person" looking at irregularities and letting me know when something has occurred
Pros and Cons
  • "SIEM log collection is great, and all of the rules that support updates with maintenance."
  • "AlienVault is my security person looking at irregularities and letting me know when something has occurred."
  • "More complimentary training needs to be done for use with this tool. If you get into a bind, then it will cost you."

What is our primary use case?

We were looking to add another layer of security to our network, which included intrusion detection, intrusion prevention, SIEM collection, and more. After looking at a few solutions, we ended up purchasing AlienVault. We are located in a physical location with a 100 users.

How has it helped my organization?

AlienVault has provided me with a management console which gives me alerts and other information about the traffic on my network. AlienVault is my "security person" looking at irregularities and letting me know when something has occurred. I also see vulnerabilities in my systems and can assign tickets to other staff members.

What is most valuable?

SIEM log collection is great, and all of the rules that support updates with maintenance. 

What needs improvement?

More complimentary training needs to be done for use with this tool. If you get into a bind, then it will cost you.

Buyer's Guide
USM Anywhere
May 2026
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
Real User

Thank you for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
Network and Security Engineer at a tech services company with 51-200 employees
Real User
Feb 25, 2018
It has powerful threat detection, incident response, and compliance management
Pros and Cons
  • "It has powerful threat detection, incident response, and compliance management."
  • "AlienVault has an advanced component within one package. With this, we can cover more area with one solution."
  • "It is the most valuable tool that I have seen of the SIEM solutions."
  • "AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive."

What is our primary use case?

AlienVault Unified Security Management (USM) has powerful threat detection, incident response, and compliance management. We can use this across cloud, on-premise and hybrid environments. 

The reason to use USM is that it has the following components in its package: 

  • Asset Discovery
  • Vulnerability Assessment
  • Intrusion Detection
  • Behavioral Monitoring
  • SIEM & Log Management.

How has it helped my organization?

AlienVault has an advanced component within one package. With this, we can cover more area with one solution. 

As a example, it has vulnerability assessment component built-in. From this, we can do the vulnerability assessment easily and we do not have to buy another solution for the vulnerability assessment. It is easy to use and we can take better advantage from an all-in-one solution like USM. 

What is most valuable?

AlienVault USM has a vulnerability assessment feature and only one SIEM feature compared to other SIEM solutions. 

What needs improvement?

AlienVault must improve their correlation feature. Some of the events do not match with the correlation rules and some of the correlation events are false-positive.

For how long have I used the solution?

Less than one year.

What other advice do I have?

It is the most valuable tool that I have seen of the SIEM solutions.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner in Sri Lanka.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
Real User

Thank you Tharaka for your time to review AlienVault USM and for your candid feedback!

Buyer's Guide
USM Anywhere
May 2026
Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
900,838 professionals have used our research since 2012.
PeerSpot user
Network and Security Engineer at a tech services company with 11-50 employees
Real User
Feb 25, 2018
We are able to get alerts perfectly with FIM and VA features
Pros and Cons
  • "This is a USM, so being able to get all the features under one roof makes it a good product with good new features."
  • "We are able to get alerts perfectly with FIM and VA features."
  • "Here we can get file integrity monitoring and a vulnerability assessment tool together with SIEM."
  • "Pay attention to false-positive event automatic correlations."
  • "The Log Management and configuration of email notifications should be user-friendly."

What is our primary use case?

This has an OTX feed. With it, we are able to get notifications about every incident that happens.

By forwarding device logs, we are able to get alerts perfectly with FIM and VA features.

How has it helped my organization?

We are the Partners in Sri Lanka. We are doing deployments in Sri Lanka, Maldives, and Bangladesh. 

This is a USM, so being able to get all the features under one roof makes it a good product with good new features.

What is most valuable?

Unified Security Manager (USM). In every SIEM, having only SIEM features (log management, alerting, notifications, etc.) is typical. Here we can get file integrity monitoring and a vulnerability assessment tool together with SIEM

I have never seen a tool like this.

What needs improvement?

The Log Management and configuration of email notifications should be user-friendly. Pay attention to false-positive event automatic correlations. 

Efficiency of Security Team

Yes.

Events per Day

60.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No, we did not have issues with stability.

What do I think about the scalability of the solution?

No, we did not have issues with scalability.

How are customer service and technical support?

Good. They have technically fluent engineers there.

Which solution did I use previously and why did I switch?

Yes. We switched because this is a USM (SIEM, FIM, and VA tool in one product) and the price.

How was the initial setup?

The initial setup is straightforward, but some features are little bit difficult.

What about the implementation team?

We are the partners in Sri Lanka. Therefore, we are directly involved with implementations.

What's my experience with pricing, setup cost, and licensing?

It has good pricing.

Which other solutions did I evaluate?

We evaluated EventTracker.

What other advice do I have?

Our customers have good references about AlienVault.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are partners in Sri Lanka
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
Real User

Thank you Kalana for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
Head of MSS Platform and Product Management at a tech services company with 51-200 employees
Consultant
Feb 25, 2018
Allows for a lot of out-of-the-box features but it does not have APIs
Pros and Cons
  • "It allows for a lot of out-of-the-box features: vuln scanning, HIDS/HIPS, and IDS."
  • "Asset discovery seems to be good."
  • "Scaling, and it has no APIs! It would be hard for any legitimate MSSP to use it."

What is our primary use case?

  • Supporting an MSSP.
  • Supporting clients with minimum on-premise install.
  • We are rolling out a USM appliance.

How has it helped my organization?

It allows for a lot of out-of-the-box features: vuln scanning, HIDS/HIPS, and IDS. The Suricata rule set is pretty lame

What is most valuable?

Asset discovery seems to be good. Nice that everything is bundled.  

What needs improvement?

Scaling, and it has no APIs! 

It would be hard for any legitimate MSSP to use it.  

For how long have I used the solution?

Still implementing.

What's my experience with pricing, setup cost, and licensing?

The price point is good.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
Real User

Thank you Brian for your time to review AlienVault USM and for your candid feedback! If you'd like to set up some time to speak with the team about the issues you've raised, I'd be happy to facilitate that on your behalf. Please reach out to me at: tandrews@alienvault.com. Thank you in advance for your time and consideration!

PeerSpot user
Engineer - Information Security at a tech services company with 51-200 employees
Reseller
Top 20
Feb 22, 2018
Categorization of Security Events Helps Our Soc Analyst for Further Analysis.
Pros and Cons
  • "Implementation took few days and it's easy to complete the task within the given project time line."
  • "User friendly interface could be an advantage. Sometimes we may face trouble when we were going through the settings of AlienVault SIEM."

What is our primary use case?

I'm a re-seller of AlienVault SIEM in Sri Lanka. We have deployed AlienVault SIEM in one of the bank in Sri Lanka three months back. Currently we are working on the fine tuning. It took me two weeks to complete the basic deployment and integration of devices up-to 50 with the clients technical team.

How has it helped my organization?

Since we are re-seller, AlienVault helped us because of their cheaper price compared to other SIEM solutions and the addition of FIM in the solution. Implementation took few days and it's easy to complete the task within the given project time line.

What is most valuable?

Raw logs: Clients require to store their raw logs in a data-store rather than keep it in the actual device.

Alarm section: It's very easy to see the Alarms for any incidents rather than going through all the logs.

Security events: Categorization of Security events helps our SOC analyst for further analysis.

What needs improvement?

User friendly interface could be an advantage. Sometimes we may face trouble when we were going through the settings of AlienVault SIEM.

For how long have I used the solution?

Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Tami Andrews - PeerSpot reviewer
Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
Real User

Thank you Shayanthan for your time to review AlienVault USM and for your candid feedback!

PeerSpot user
IT/IS Officer - Marketing Director at a tech services company with 51-200 employees
Real User
Feb 22, 2018
It Has Become an Invaluable Asset for Our Small Organization
Pros and Cons
  • "AlienVault gave our organization a centralized tool to manage our security with its intrusion detection, asset management, vulnerability assessments, along with all of its other features, it has become an invaluable asset for our small organization."

    What is our primary use case?

    Working as the CIO for a small community bank, resources for staffing and manpower can be limited. AlienVault helps to simplify the management of Information Security and helps me to detect threats and manage alerts with ease!

    How has it helped my organization?

    AlienVault gave our organization a centralized tool to manage our security with its intrusion detection, asset management, vulnerability assessments, along with all of its other features, it has become an invaluable asset for our small organization.

    What is most valuable?

    We have found the AIO USM the most valuable because of its centralized grouping of all of the tools necessary to manage our security in an "All In One" solution.  Of its parts, the scheduled vulnerability assessment tool has been helpful as a preventative measure to help keep ahead of security threats!

    What needs improvement?

    As with many of its users, I have submitted suggestions in the past and AlienVault has seemed to listen to suggestions from its users and have implemented them every time.  I am happy with the product as it is today.

    For how long have I used the solution?

    Three to five years.
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
    Real User

    Thank you Kirk for your time to review AlienVault USM and for your candid feedback!

    PeerSpot user
    System Administrator at a tech services company with 10,001+ employees
    MSP
    Feb 6, 2018
    We have been able to ensure the health of our servers
    Pros and Cons
    • "As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business."
    • "Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour."
    • "For what it can do and the cost, it was the best SIEM tool!"
    • "For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier."

    What is our primary use case?

    We use the appliance in a few of ways: monitoring network behaviour, asset discovery, and running vulnerability scans. We can monitor the availability of servers and any particular software. As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business.

    How has it helped my organization?

    We have been able to ensure the health of our servers. We can also use vulnerability scans to ensure our system is as good as it could be.

    Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour. The ranking can be modified to allow us to apply a standard rule and also be customized, which suits our business needs.

    What is most valuable?

    I have used the asset discovery and the vulnerability scans the most. As a system administrator, it is important that we are prepared for any eventualities. I also like how you can use the hardware “out-of-the-box”, or using logs you can actually customise the performance to fit your environment and needs.

    What needs improvement?

    For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    No stability issues.

    What do I think about the scalability of the solution?

    No scalability issues.

    Which solution did I use previously and why did I switch?

    We did not have any sustainable solution, previously.

    What's my experience with pricing, setup cost, and licensing?

    Use the AlienVault team. They are helpful and the documentation that they provide is second to none.

    Which other solutions did I evaluate?

    We checked out several competitors. For what it can do and the cost, it was the best SIEM tool!

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
    Real User

    Thank you Adrian for your time to review AlienVault USM and for your candid feedback!

    PeerSpot user
    Network Operations Manager / Systems Engineer at a tech services company
    Real User
    Top 20
    Jan 14, 2018
    Asset management of nodes has been a large help in terms of being able to track applications with more detail
    Pros and Cons
    • "Vulnerability scanning helped out shortcomings of what was not patched in the past and what needed to be patched. This assisted with fine tuning the environment for compliance."
    • "It brought our logs into one place for review and set up alarms based on changes we were missing due to lack of having one place for everything to go."
    • "The asset management of nodes has been a large help in terms of being able to track applications with more detail and have changes made being monitored into one source."
    • "The all-in-one source for the needs of compliance has put everything into one location without the need of other applications and tools to accomplish the tasks."
    • "Source material on the forums to be more up-to-date with the changes happening within the product. Forums being out-of-date with information due to the changes makes troubleshooting a little more difficult - specific to the HIDS agents."

    What is our primary use case?

    AlienVault is used in our infrastructure for compliance purposes. It was brought in as a replacement for use in multiple products at the time, such as Kiwi and Nexpose scanner. With the environment being new, it was the best place to start with being everything into one location for Syslog and Asset management. The vulnerability scanner also made the difference where the scans created tickets for remediation.

    How has it helped my organization?

    The all-in-one source for the needs of compliance has put everything into one location without the need of other applications and tools to accomplish the tasks. It brought our logs into one place for review and set up alarms based on changes we were missing due to lack of having one place for everything to go. Vulnerability scanning helped out shortcomings of what was not patched in the past and what needed to be patched. This assisted with fine tuning the environment for compliance. The reports also helped upper management with the ease the product was doing in its job and holes that were being filled.

    What is most valuable?

    The asset management of nodes has been a large help in terms of being able to track applications with more detail and have changes made being monitored into one source. The vulnerability scanning has also been an aide of reviewing the systems and having feedback of what is missing patches and holes in our environment that need review and remediation. The all-in-one aspect has been helpful to see items and correlate within one source rather then multiple.

    What needs improvement?

    Source material on the forums to be more up-to-date with the changes happening within the product. Forums being out-of-date with information due to the changes makes troubleshooting a little more difficult - specific to the HIDS agents. Troubleshooting connectivity is limited to very view articles with very little information. Perhaps adding templates into the HIDS agents for collection based on systems or a clickable addition of files to collect with check boxes rather than configuring the HIDS agents through text. 

    Also, more information on how specific sections relate to PCI and how to use/setup the SIEM to follow the guidelines of the areas. Some information is vague on how to accomplish specific items within PCI on help forums through AlienVault.

    For how long have I used the solution?

    Less than one year.
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
    Real User

    Thank you Phillip for your time to review AlienVault USM and for your candid feedback!

    PeerSpot user
    IT Systems Administrator at a financial services firm with 201-500 employees
    Real User
    Dec 14, 2017
    It has streamlined log aggregation and analysis to meet organizational and regulatory needs
    Pros and Cons
    • "It has streamlined log aggregation and analysis to meet organizational and regulatory needs."
    • "The most useful feature is the customization for alarms, alerts, and reports."
    • "Reporting is convoluted and difficult at times, although they claim to have hundreds of pre-built reports, very few of them are actually useful for anything but what the USM is doing."
    • "Windows log collection works with HIDS, but documentation is sparse and confusing."
    • "Reporting and Windows log collection is the biggest drawback."

    What is our primary use case?

    The primary use case for AlienVault is Log Management and SIEM functionality with the added benefit of IDS.

    How has it helped my organization?

    It has streamlined log aggregation and analysis to meet organizational and regulatory needs.

    What is most valuable?

    The most useful feature is the customization for alarms, alerts, and reports. AlienVault is situated to be adapted and changed to meet many different needs and use cases, but still being effective at most of them. 

    What needs improvement?

    Reporting and Windows log collection is the biggest drawback. Reporting is convoluted and difficult at times, although they claim to have hundreds of pre-built reports, very few of them are actually useful for anything but what the USM is doing. Windows log collection works with HIDS, but documentation is sparse and confusing. You have to trace back to how Windows Event ID ultimately correlates with AlienVault events through HID's IDs. 

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    Some minor issues here and there with updating/services not working, but AlienVault support is quick and easy to work with and will handle it. 

    What do I think about the scalability of the solution?

    No issues. Make sure you do size appropriately though for the level of logs you want to collect and retain. 

    How was the initial setup?

    Complex in some ways, but AlienVault is pretty easy and will help along the way. Also, taking the training class is very valuable. 

    What's my experience with pricing, setup cost, and licensing?

    Do the one month trial and try to work out the kinks during it, as it has free support and service hours. The staff is great at knowing what to do and what they can do to help. 

    Which other solutions did I evaluate?

    Yes. Our SIEM tool list, from which we were evaluating, included Splunk and LogRhythm.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
    Real User

    Thank you Jon for your time to review AlienVault USM and for your candid feedback!

    PeerSpot user
    Security Administrator at a financial services firm with 501-1,000 employees
    Vendor
    Nov 2, 2017
    It has allowed us to gain a better understanding of how data flows within our network
    Pros and Cons
    • "It allows you to define what alerts you want to see, or not to see, as well as if you want them grouped, or ungrouped."
    • "AlienVault provides you with a unified view for all aspects of what is going on in your environment."
    • "The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing."

    How has it helped my organization?

    It has allowed us to gain a better understanding of how data flows within our network, and has helped us think about what type of things we want to be alerted on, or not alerted on.

    What is most valuable?

    AlienVault provides you with a unified view for all aspects of what is going on in your environment. It allows you to define what alerts you want to see, or not to see, as well as if you want them grouped, or ungrouped.

    What needs improvement?

    The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing. The views are also very static and do not give you a lot of options on how the data is presented.

    What do I think about the stability of the solution?

    No, the product is stable.

    What do I think about the scalability of the solution?

    No, our network has stayed for the most part the same. In the future, it should be scalable with additional sensors.

    How are customer service and technical support?

    Customer Service:

    This is an area that could be improved.

    Technical Support:

    This is an area that could be improved. However, once you get a knowledgeable tech support person, they are good to work with.

    Which solution did I use previously and why did I switch?

    No, this is our first SIEM device.

    How was the initial setup?

    Both. It was simple to just get up and running. However, when you start tweaking it for your organization it gets more complex.

    What about the implementation team?

    A little bit of both. The vendor team's expertise was amazing. I highly recommend using them.

    What was our ROI?

    The time that it would take to manually investigate events versus looking at one dashboard.

    What's my experience with pricing, setup cost, and licensing?

    Definitely get professional services.

    Which other solutions did I evaluate?

    Darktrace and QRadar.

    What other advice do I have?

    Once set up, for the most part, it is a "set it and forget it" solution. There is some upkeep with making sure all the things are monitored, but other than that AlienVault provides what you need out-of-the-box.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Tami Andrews - PeerSpot reviewer
    Tami AndrewsSr. Customer Programs Manager at a tech vendor with 201-500 employees
    Real User

    Thank you David for your time to review AlienVault USM and for your candid feedback!

    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2026
    Buyer's Guide
    Download our free USM Anywhere Report and get advice and tips from experienced pros sharing their opinions.