I like the automated asset discovery feature, once we created the network tap, we could easily discover assets on the dashboard.
Another feature that I absolutely love is the integration with Alienvault OTX, having to group/categorise IP addresses and hostnames based on pulses from OTX gives you an idea of what you're about to investigate before you even get started.
What do you dislike about the product?
The least helpful thing would be the need to spend more for EPS.
If you have a large on-prem environment and you decide to use Alienvault, you could be regularly over-shooting the EPS count for your license, this increases cost.
The more your environment grows, the more you have to pay for licenses.
What problems is the product solving and how is that benefiting you?
We can use the Vulnerability Scanner without having to pay for another Vulnerability Scanning software, and not incur the risks associated with open source scanners.
Running a hybrid environment means we need full visibility on both cloud and on-prem assets, and Alienvault gives us that coverage.
Super easy to use and works well for all of our clients
What do you like best about the product?
This is a great SIEM with all the features we need. It has central management which is huge for us since we are an MSSP and have many clients in many different environments. It also has some built in connections with tools that are super helpful.
What do you dislike about the product?
I don't really dislike anything about Alienvault. The cost isn't very high and the services offered are pretty wide. If I had to change anything I think I would add rules based on time.
What problems is the product solving and how is that benefiting you?
We use this for every client as a SIEM And a way to generate alerts for anything that seems unusual. This has been working great and it integrates with many of their tools.
It is good for the small org. to start with security monitoring.
What do you like best about the product?
They have an easy-to-understand UI, the case management is really good. Also, suppression of the false-positive area is very easily available. Onboarding of the data sources are easy.
What do you dislike about the product?
Availability of the SIEM tool is the major issue here. They have a lot of downtimes and even sometimes without prior notice, it is not accessible. Also the performance is very poor. It takes minutes after clicking once.
What problems is the product solving and how is that benefiting you?
We have multiple security data sources, so it was a bit difficult to monitor all at the same time. But AlienVault allows us to monitor all things at one place and allowed us to configure rules over there.
A SIEM in all-in-one format, with which you can easily have the functionalities of a SIEM, network behavior analysis and vulnerability analysis.
Plus, it's easy to deploy and has plenty of integrations available to use.
What do you dislike about the product?
In very large environments, it is very heavy to manage and servers can consume a lot of RAM.
High availability is not well designed, so you have to look for workarounds to secure the solution.
What problems is the product solving and how is that benefiting you?
It allows to deploy a complete and simple solution in small clients, who cannot afford other much more expensive solutions. Being able to have a complete security solution.
Alien Vault is essential to the day to day operations of our entire intel team. Being able to pivot on related files and prove maliciousness of a domain makes AV one of the best OSINT tools on the market.
What do you dislike about the product?
I dislike how much Alien Vault charges for their enterprise accounts.
What problems is the product solving and how is that benefiting you?
I am solving internet security issues by being able to perform my daily duties.
ATT transformed AlienVault for enterprises but not for MSPs
What do you like best about the product?
the rich interface and the ThreatIntell overall was pretty good.
What do you dislike about the product?
the management and maintenance are too cumbersome.
Recommendations to others considering the product:
Make sure you have 3 engineers to manage, maintain, and Operate the SIEM platform alone. You also need 6 security analyst. The training is expensive so make sure you have one SME to teach others.
What problems is the product solving and how is that benefiting you?
Good SIEM tool for monitoring and tracking events.
What do you like best about the product?
Great to monitor events and provide feedback. Good product coverage. It has integration with SQL, AWS and other cloud infrastructure with ease. Better than cloudwatch. This tool is cheaper than splunk.
What do you dislike about the product?
Sometimes becomes overly complicated to analyze DDoS attacks. Not very user friendly.
Recommendations to others considering the product:
The UI is complicated to use. Basic tasks are easy.
What problems is the product solving and how is that benefiting you?
To timely monitor suspicious events within AWS. Utilization within load balancer.
The ease of use and customization. The USM is a work horse, no matter what devices or the number of logs we throw at it, the system processes them in real-time, correlates the events, and alerts on only events that need human review. USM Anywhere was a great progression of the product, whether you are a small business with no security team or a large enterprise with a large team, AlienVault will meet your needs.
What do you dislike about the product?
The one thing I continue to dislike about the USM Anywhere the lack of an on-prem deployment option.
Recommendations to others considering the product:
Compare how AlienVault does Events Per Second (EPS) compared to others. Most other products charge based on EPS, the more events the more you have to pay. This causes most companies to limit the amount of logs sent and processed. AlienVault charges by the number of devices managed, you can send anything and everything to the USM. The more logs you can process the better correlation you will have. I have found that companies that limit their logs then have a security incident would have been able to identify the attack if they would have been monitoring all events in their logs.
What problems is the product solving and how is that benefiting you?
We are able to get a real-time view on of our security that is accurate. We have seen a dramatic increase in the productivity and efficiency of our security team. We are now able to identify and stop security issues before they get out of control, usually before anyone else even notices.