We use the appliance in a few of ways: monitoring network behaviour, asset discovery, and running vulnerability scans. We can monitor the availability of servers and any particular software. As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business.
System Administrator at a tech services company with 10,001+ employees
We have been able to ensure the health of our servers
Pros and Cons
- "As we have to service several servers, we can manage them in a economical way, which is beneficial to our team and business."
- "Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour."
- "For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier."
What is our primary use case?
How has it helped my organization?
We have been able to ensure the health of our servers. We can also use vulnerability scans to ensure our system is as good as it could be.
Any unusual behaviour, we can monitor. We have alerts set up to be sent when we receive signs of any unusual behaviour. The ranking can be modified to allow us to apply a standard rule and also be customized, which suits our business needs.
What is most valuable?
I have used the asset discovery and the vulnerability scans the most. As a system administrator, it is important that we are prepared for any eventualities. I also like how you can use the hardware “out-of-the-box”, or using logs you can actually customise the performance to fit your environment and needs.
What needs improvement?
For creating new rules, you have to be familiar with regular expressions. I feel there could be something built-in to make sure that process is easier.
Buyer's Guide
USM Anywhere
June 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No stability issues.
What do I think about the scalability of the solution?
No scalability issues.
Which solution did I use previously and why did I switch?
We did not have any sustainable solution, previously.
What's my experience with pricing, setup cost, and licensing?
Use the AlienVault team. They are helpful and the documentation that they provide is second to none.
Which other solutions did I evaluate?
We checked out several competitors. For what it can do and the cost, it was the best SIEM tool!
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Operations Manager / Systems Engineer at a tech services company
Asset management of nodes has been a large help in terms of being able to track applications with more detail
Pros and Cons
- "Vulnerability scanning helped out shortcomings of what was not patched in the past and what needed to be patched. This assisted with fine tuning the environment for compliance."
- "It brought our logs into one place for review and set up alarms based on changes we were missing due to lack of having one place for everything to go."
- "The asset management of nodes has been a large help in terms of being able to track applications with more detail and have changes made being monitored into one source."
- "Source material on the forums to be more up-to-date with the changes happening within the product. Forums being out-of-date with information due to the changes makes troubleshooting a little more difficult - specific to the HIDS agents."
What is our primary use case?
AlienVault is used in our infrastructure for compliance purposes. It was brought in as a replacement for use in multiple products at the time, such as Kiwi and Nexpose scanner. With the environment being new, it was the best place to start with being everything into one location for Syslog and Asset management. The vulnerability scanner also made the difference where the scans created tickets for remediation.
How has it helped my organization?
The all-in-one source for the needs of compliance has put everything into one location without the need of other applications and tools to accomplish the tasks. It brought our logs into one place for review and set up alarms based on changes we were missing due to lack of having one place for everything to go. Vulnerability scanning helped out shortcomings of what was not patched in the past and what needed to be patched. This assisted with fine tuning the environment for compliance. The reports also helped upper management with the ease the product was doing in its job and holes that were being filled.
What is most valuable?
The asset management of nodes has been a large help in terms of being able to track applications with more detail and have changes made being monitored into one source. The vulnerability scanning has also been an aide of reviewing the systems and having feedback of what is missing patches and holes in our environment that need review and remediation. The all-in-one aspect has been helpful to see items and correlate within one source rather then multiple.
What needs improvement?
Source material on the forums to be more up-to-date with the changes happening within the product. Forums being out-of-date with information due to the changes makes troubleshooting a little more difficult - specific to the HIDS agents. Troubleshooting connectivity is limited to very view articles with very little information. Perhaps adding templates into the HIDS agents for collection based on systems or a clickable addition of files to collect with check boxes rather than configuring the HIDS agents through text.
Also, more information on how specific sections relate to PCI and how to use/setup the SIEM to follow the guidelines of the areas. Some information is vague on how to accomplish specific items within PCI on help forums through AlienVault.
For how long have I used the solution?
Less than one year.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
USM Anywhere
June 2025

Learn what your peers think about USM Anywhere. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,632 professionals have used our research since 2012.
IT Systems Administrator at a financial services firm with 201-500 employees
It has streamlined log aggregation and analysis to meet organizational and regulatory needs
Pros and Cons
- "It has streamlined log aggregation and analysis to meet organizational and regulatory needs."
- "Reporting is convoluted and difficult at times, although they claim to have hundreds of pre-built reports, very few of them are actually useful for anything but what the USM is doing."
- "Windows log collection works with HIDS, but documentation is sparse and confusing."
What is our primary use case?
The primary use case for AlienVault is Log Management and SIEM functionality with the added benefit of IDS.
How has it helped my organization?
It has streamlined log aggregation and analysis to meet organizational and regulatory needs.
What is most valuable?
The most useful feature is the customization for alarms, alerts, and reports. AlienVault is situated to be adapted and changed to meet many different needs and use cases, but still being effective at most of them.
What needs improvement?
Reporting and Windows log collection is the biggest drawback. Reporting is convoluted and difficult at times, although they claim to have hundreds of pre-built reports, very few of them are actually useful for anything but what the USM is doing. Windows log collection works with HIDS, but documentation is sparse and confusing. You have to trace back to how Windows Event ID ultimately correlates with AlienVault events through HID's IDs.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
Some minor issues here and there with updating/services not working, but AlienVault support is quick and easy to work with and will handle it.
What do I think about the scalability of the solution?
No issues. Make sure you do size appropriately though for the level of logs you want to collect and retain.
How was the initial setup?
Complex in some ways, but AlienVault is pretty easy and will help along the way. Also, taking the training class is very valuable.
What's my experience with pricing, setup cost, and licensing?
Do the one month trial and try to work out the kinks during it, as it has free support and service hours. The staff is great at knowing what to do and what they can do to help.
Which other solutions did I evaluate?
Yes. Our SIEM tool list, from which we were evaluating, included Splunk and LogRhythm.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Administrator at a financial services firm with 501-1,000 employees
It has allowed us to gain a better understanding of how data flows within our network
Pros and Cons
- "It allows you to define what alerts you want to see, or not to see, as well as if you want them grouped, or ungrouped."
- "The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing."
How has it helped my organization?
It has allowed us to gain a better understanding of how data flows within our network, and has helped us think about what type of things we want to be alerted on, or not alerted on.
What is most valuable?
AlienVault provides you with a unified view for all aspects of what is going on in your environment. It allows you to define what alerts you want to see, or not to see, as well as if you want them grouped, or ungrouped.
What needs improvement?
The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing. The views are also very static and do not give you a lot of options on how the data is presented.
What do I think about the stability of the solution?
No, the product is stable.
What do I think about the scalability of the solution?
No, our network has stayed for the most part the same. In the future, it should be scalable with additional sensors.
How are customer service and technical support?
Customer Service:
This is an area that could be improved.
Technical Support:
This is an area that could be improved. However, once you get a knowledgeable tech support person, they are good to work with.
Which solution did I use previously and why did I switch?
No, this is our first SIEM device.
How was the initial setup?
Both. It was simple to just get up and running. However, when you start tweaking it for your organization it gets more complex.
What about the implementation team?
A little bit of both. The vendor team's expertise was amazing. I highly recommend using them.
What was our ROI?
The time that it would take to manually investigate events versus looking at one dashboard.
What's my experience with pricing, setup cost, and licensing?
Definitely get professional services.
Which other solutions did I evaluate?
Darktrace and QRadar.
What other advice do I have?
Once set up, for the most part, it is a "set it and forget it" solution. There is some upkeep with making sure all the things are monitored, but other than that AlienVault provides what you need out-of-the-box.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a tech services company with 201-500 employees
The low cost of entry SIEM functionality has increased due to network views and network traffic
Pros and Cons
- "Ease of deployment across various environments."
- "Support can be slow at times, but the quality is high. Posted knowledge base articles could use improvement."
How has it helped my organization?
The low cost of entry SIEM functionality has increased due to network views and network traffic.
What is most valuable?
- General SIEM tool functionality.
- Ease of deployment across various environments.
What needs improvement?
Support can be slow at times, but the quality is high. Posted knowledge base articles could use improvement.
What do I think about the stability of the solution?
None, which are related to this solution.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
Seven out of ten.
Technical Support:
Seven out of ten.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
It was a a blend. The implementation was primarily internal with support provided as needed. The vendor team had a good quality of expertise.
What was our ROI?
Medium-high.
What's my experience with pricing, setup cost, and licensing?
Research the solution heavily prior to investing.
Setting up a bench OSSIM install should help identify possible pain points with the setup.
Which other solutions did I evaluate?
No.
What other advice do I have?
The solution is improving steadily, particularly in relation to the quality and breadth of documentation. Though some areas are still weak.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of IT at a consultancy with 201-500 employees
We use the HIDS to monitor our servers, which track user account locks and logon failures
What is most valuable?
- Network monitoring
- SIEM
How has it helped my organization?
We have much greater visibility in what is happening on our network.
What needs improvement?
Backup, restore, and upgrade - some menu options are a bit convoluted.
For how long have I used the solution?
Six months.
What was my experience with deployment of the solution?
No.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service:
Excellent, every contact with customer services, support, and training has been superb.
Technical Support:Excellent - very good, comprehensive, and knowledgeable staff.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
Yes - simple deployment in VM, worked the first time.
What about the implementation team?
In-house.
What was our ROI?
Difficult to answer - specifically, this was a new product for us to increase and improve upon security.
What's my experience with pricing, setup cost, and licensing?
We did market research, web reviews, etc. We spoke to a number of vendors (LogRhythm, etc.), but we felt that AlienVault was the best value and most comprehensive for our organisation's size.
Which other solutions did I evaluate?
Yes, LogRhythm, and Splunk.
What other advice do I have?
We are very happy. The training was excellent, and the interaction with AlienVault is first rate - real leader in customer service, the OTX pulse feature is very useful.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Officer with 51-200 employees
Visibility For Your Network and To Find Bottlenecks
How has it helped my organization?
Recently, we used the NetFlow capability to find a bottleneck in the network and the offending computer.
What is most valuable?
The most valuable aspect of AlienVault is the visibility into the network. You have the capability to gather logs from multiple sources and easily see what is going on in the network.
What needs improvement?
It is a lot of work to get the software configured and set up properly.
What do I think about the stability of the solution?
There were some issues with the reporting functions. AlienVault corrected that problem in a new update.
How are customer service and technical support?
Customer Service:
The customer service department is very responsive to questions.
Technical Support:
The technical support team is very knowledgeable. It is helpful that they are able to have remote support sessions to review the problem.
Which solution did I use previously and why did I switch?
No.
What about the implementation team?
We deployed this system in-house. We are not a fan of moving things to cloud-based solutions.
What's my experience with pricing, setup cost, and licensing?
The engineering support that is provided by AlienVault upon first installation was excellent! They went way above and beyond what I was expecting.
Which other solutions did I evaluate?
We evaluated the popular SIEM tools Splunk, LogRhythm, and SolarWinds. AlienVault provided the most features for the price point.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a tech services company
Quickly got insight into my environment
How has it helped my organization?
Quickly got insight into my environment.
What is most valuable?
Deployment was very easy. I got my servers and devices reporting very quickly.
What needs improvement?
It would be great if there was a feature to add in watch lists, like McAfee or QRadar have -- to keep track of IPs, domain, etc. that I have identified as being malicious.
Also, being able to connect into other TAXII/STIX feeds other than OTX.
How are customer service and technical support?
Customer Service:
Excellent. Customer service was very responsive.
Technical Support:
Excellent. Support was very responsive.
Which solution did I use previously and why did I switch?
Yes, McAfee ESM. Even after upgrading to Version 10, the interface was still hard to navigate through and did not work on every browser. Writing effective rules was difficult.
How was the initial setup?
Very straightforward.
What about the implementation team?
In-house.
What's my experience with pricing, setup cost, and licensing?
Very reasonable and for the value of the product, we couldn't ask for better pricing.
Which other solutions did I evaluate?
We did a SIEM solution comparison with McAfee ESM, IBM QRadar, and Fortinet.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management Endpoint Detection and Response (EDR) Compliance ManagementPopular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Datadog
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Graylog
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Fortinet FortiAnalyzer
Securonix Next-Gen SIEM
Exabeam
Buyer's Guide
Download our free USM Anywhere Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- AlienVault saying I can't use it in a DHCP environment. Help!
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?
Thank you Adrian for your time to review AlienVault USM and for your candid feedback!