Alert Logic Managed Detection and Response vs. AlienVault OSSIM

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Alert Logic
Score 9.1 out of 10
N/A
Alert Logic delivers managed detection and response (MDR) with comprehensive coverage for public clouds, SaaS, on-premises, and hybrid environments. Alert Logic is a HelpSystems brand since the 2022 acquisition announced in March.N/A
AlienVault OSSIM
Score 8.6 out of 10
N/A
OSSIM leverages the power of the AlienVault Open Threat Exchange by allowing users to both contribute and receive real-time information about malicious hosts. AlienVault OSSIM is an open source Security Information and Event Management (SIEM) product. It is a unified platform providing: Asset discovery Vulnerability assessment Intrusion detection Behavioral monitoring SIEM OSSIM provides the basis for AlienVault's proprietary Unified Security…N/A
Pricing
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Alert LogicAlienVault OSSIM
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Top Pros
Top Cons
Features
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Alert Logic Managed Detection and Response
-
Ratings
AlienVault OSSIM
7.5
11 Ratings
4% below category average
Centralized event and log data collection00 Ratings9.410 Ratings
Correlation00 Ratings7.011 Ratings
Event and log normalization/management00 Ratings8.111 Ratings
Deployment flexibility00 Ratings8.211 Ratings
Integration with Identity and Access Management Tools00 Ratings9.36 Ratings
Custom dashboards and workspaces00 Ratings9.410 Ratings
Host and network-based intrusion detection00 Ratings9.29 Ratings
Data integration/API management00 Ratings5.32 Ratings
Behavioral analytics and baselining00 Ratings5.42 Ratings
Rules-based and algorithmic detection thresholds00 Ratings5.33 Ratings
Response orchestration and automation00 Ratings6.32 Ratings
Reporting and compliance management00 Ratings8.44 Ratings
Incident indexing/searching00 Ratings6.43 Ratings
Best Alternatives
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Small Businesses
ESET PROTECT
ESET PROTECT
Score 9.0 out of 10
AlienVault USM
AlienVault USM
Score 8.0 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Splunk Enterprise
Splunk Enterprise
Score 8.4 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Microsoft Sentinel
Microsoft Sentinel
Score 8.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Likelihood to Recommend
8.7
(7 ratings)
9.3
(11 ratings)
Usability
-
(0 ratings)
8.0
(1 ratings)
Support Rating
-
(0 ratings)
7.9
(3 ratings)
User Testimonials
Alert Logic Managed Detection and ResponseAlienVault OSSIM
Likelihood to Recommend
Fortra
This is pretty good AV product - lightweight, easy to install, and easy on system resources. It will take some getting used to on the end user side, it doesn't scan in a traditional way, and it does not have a taskbar icon so it hard to know if it's working or installed. My only complaint would be the false positives which I know every AV system has, but the problem with Barkly is that it alerts the users with a message (which they freak out about) and it alerts IT with an email. Again, not a major issue, but it can be annoying until it is overridden. The override process is super easy though, so its again, not a big deal.
Read full review
AT&T Cybersecurity
If this is your first experience with a SIEM, this one can get you started. Take the time to learn the ins and outs of the product and you'll most likely be satisfied with it if your company is an SMB. If you need compliance reports, OSSIM is too small for you, you'll need to go with USM or USM Anywhere.
Read full review
Pros
Fortra
  • Customer Service. Usually, I'd put the technical details up front, and they're good with that too. But the service from pre-sales all the way through onboarding and continued account management is top tier. Our onboarding schedule got messed up, partly because of us, but that was rather minor. I always get prompt replies to any tickets, and they've even reached out to discuss my feature requests. When it comes to security, it's critical to have a responsive team, and they've got it.
  • Detection seems good. It's hard to quantify exactly, but it seems that they always detect the bad actors. And when we get an alert, they include a bunch of details so we know what kind of scan they're trying to do, how far they got, etc. You can't prevent everyone from doing a scan on your IP, but it gives you a really good idea of where your soft spots might be. And if you're getting those low-level alerts, it's a reminder that it's there and working if you have a major event too.
  • Very easy setup. This goes back to their customer support to some extent, as they walk you through all the steps required. But it's also about their technical solution, it's not so overly complex that it's fragile, nor does it take a great deal of time to deploy. And it's been zero effort to maintain since then.
Read full review
AT&T Cybersecurity
  • Asset discovery. Once installed in a centric, network-accessible server, OSSIM can poll all your endpoints with common protocols (SSH, SNMP, WMI) to detect and discover site-wide assets to monitor. You only need to group them by your own criteria once added to the product.
  • SIEM Event Correlation. You can define quite complex correlation rules to detect possible suspicious or malicious actions or attempts in your network, in order to categorize them as real threats or as false positives, thus streamlining your risk assessment and management.
  • Ease of installation. The entire AlienVault OSSIM is self-contained in an ISO file, which can be burned into a DVD or just mounted in your server of choice (physical or virtual) for deployment. The installation process is automated and quote verbosed, with options for static IP, email messaging and others.
  • Ease of access. Being AlienVault OSSIM a self-contained appliance, it can be accessed via web by any device that supports a web browser, being that desktops, workstation, mobile devices, etc. The OSSIM dashboard and other features are automatically rearranged to adapt to the particular device being in use.
Read full review
Cons
Fortra
  • The interface is a little lacking from a search perspective but its not really meant for us to have to do the work
Read full review
AT&T Cybersecurity
  • Creating custom rules is a bit complicated
  • Reporting could be improved
  • Agent has caused conflicts with a couple of our other applications
Read full review
Usability
Fortra
No answers on this topic
AT&T Cybersecurity
AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
Read full review
Support Rating
Fortra
No answers on this topic
AT&T Cybersecurity
Everything is done through MSSP and installation pro services. Once those hours are burned up, then you're on your own without a lot of help. Typically the pro services hours aren't enough to get past 60 days and MSSP are hit and miss. We had a miss for installation helpers.
Read full review
Alternatives Considered
Fortra
I was using Alert Logic Insight for myself to improve my skills and ability to it. My organization was not happy using our previous website security program so I recommended for them to use this software. It has been more than 1 year and still, they are using this program without having any problem so far.
Read full review
AT&T Cybersecurity
Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created by hand. As other tools have come out with the ability to do automated responses such as Stellar Data processor, we have begun to evaluate alternatives.
Read full review
Return on Investment
Fortra
  • Return on Investment is measured in how protected our reputation is and Alert Logic contributes to this is a large way.
  • Alert Logic provides excellent information security assurance to the business and allows us to feel more proactive.
Read full review
AT&T Cybersecurity
  • It satisfied a requirement of our audit team (internal and external).
  • Custom written alerts allow us to be proactive for some events.
  • Stable product means we don't spend a lot of time keeping it up and running.
Read full review
ScreenShots