What users are saying about
184 Ratings
25 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener'>trScore algorithm: Learn more.</a>
Score 8.9 out of 100
184 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener'>trScore algorithm: Learn more.</a>
Score 8.5 out of 100

Feature Set Ratings

    Security Information and Event Management (SIEM)

    7.8

    AlienVault OSSIM

    78%

    Elasticsearch

    Feature Set Not Supported
    N/A
    AlienVault OSSIM ranks higher in 13/13 features

    Centralized event and log data collection

    9.3
    93%
    10 Ratings
    N/A
    0 Ratings

    Correlation

    7.9
    79%
    11 Ratings
    N/A
    0 Ratings

    Event and log normalization/management

    8.3
    83%
    18 Ratings
    N/A
    0 Ratings

    Deployment flexibility

    8.6
    86%
    11 Ratings
    N/A
    0 Ratings

    Integration with Identity and Access Management Tools

    9.0
    90%
    6 Ratings
    N/A
    0 Ratings

    Custom dashboards and workspaces

    9.3
    93%
    16 Ratings
    N/A
    0 Ratings

    Host and network-based intrusion detection

    9.4
    94%
    9 Ratings
    N/A
    0 Ratings

    Data integration/API management

    5.4
    54%
    2 Ratings
    N/A
    0 Ratings

    Behavioral analytics and baselining

    5.7
    57%
    2 Ratings
    N/A
    0 Ratings

    Rules-based and algorithmic detection thresholds

    6.1
    61%
    3 Ratings
    N/A
    0 Ratings

    Response orchestration and automation

    7.4
    74%
    2 Ratings
    N/A
    0 Ratings

    Reporting and compliance management

    8.0
    80%
    4 Ratings
    N/A
    0 Ratings

    Incident indexing/searching

    7.3
    73%
    3 Ratings
    N/A
    0 Ratings

    Attribute Ratings

    • AlienVault OSSIM is rated higher in 1 area: Support Rating
    • Elasticsearch is rated higher in 1 area: Usability
    • AlienVault OSSIM and Elasticsearch are tied in 1 area: Likelihood to Recommend

    Likelihood to Recommend

    9.0

    AlienVault OSSIM

    90%
    11 Ratings
    9.0

    Elasticsearch

    90%
    46 Ratings

    Likelihood to Renew

    AlienVault OSSIM

    N/A
    0 Ratings
    10.0

    Elasticsearch

    100%
    1 Rating

    Usability

    8.0

    AlienVault OSSIM

    80%
    1 Rating
    10.0

    Elasticsearch

    100%
    1 Rating

    Support Rating

    7.9

    AlienVault OSSIM

    79%
    6 Ratings
    7.8

    Elasticsearch

    78%
    18 Ratings

    Implementation Rating

    AlienVault OSSIM

    N/A
    0 Ratings
    9.0

    Elasticsearch

    90%
    2 Ratings

    Likelihood to Recommend

    AlienVault OSSIM

    If this is your first experience with a SIEM, this one can get you started. Take the time to learn the ins and outs of the product and you'll most likely be satisfied with it if your company is an SMB. If you need compliance reports, OSSIM is too small for you, you'll need to go with USM or USM Anywhere.
    Ivan Montilla Miralles | TrustRadius Reviewer

    Elasticsearch

    Elasticsearch is a really scalable solution that can fit a lot of needs, but the bigger and/or those needs become, the more understanding & infrastructure you will need for your instance to be running correctly.Elasticsearch is not problem-free - you can get yourself in a lot of trouble if you are not following good practices and/or if are not managing the cluster correctly.Licensing is a big decision point here as Elasticsearch is a middleware component - be sure to read the licensing agreement of the version you want to try before you commit to it.Same goes for long-term support - be sure to keep yourself in the know for this aspect you may end up stuck with an unpatched version for years.
    Borislav Traykov | TrustRadius Reviewer

    Pros

    AlienVault OSSIM

    • Asset discovery. Once installed in a centric, network-accessible server, OSSIM can poll all your endpoints with common protocols (SSH, SNMP, WMI) to detect and discover site-wide assets to monitor. You only need to group them by your own criteria once added to the product.
    • SIEM Event Correlation. You can define quite complex correlation rules to detect possible suspicious or malicious actions or attempts in your network, in order to categorize them as real threats or as false positives, thus streamlining your risk assessment and management.
    • Ease of installation. The entire AlienVault OSSIM is self-contained in an ISO file, which can be burned into a DVD or just mounted in your server of choice (physical or virtual) for deployment. The installation process is automated and quote verbosed, with options for static IP, email messaging and others.
    • Ease of access. Being AlienVault OSSIM a self-contained appliance, it can be accessed via web by any device that supports a web browser, being that desktops, workstation, mobile devices, etc. The OSSIM dashboard and other features are automatically rearranged to adapt to the particular device being in use.
    Jose Quintero | TrustRadius Reviewer

    Elasticsearch

    • As I mentioned before, Elasticsearch's flexible data model is unparalleled. You can nest fields as deeply as you want, have as many fields as you want, but whatever you want in those fields (as long as it stays the same type), and all of it will be searchable and you don't need to even declare a schema beforehand!
    • Elastic, the company behind Elasticsearch, is super strong financially and they have a great team of devs and product managers working on Elasticsearch. When I first started using ES 3 years ago, I was 90% impressed and knew it would be a good fit. 3 years later, I am 200% impressed and blown away by how far it has come and gotten even better. If there are features that are missing or you don't think it's fast enough right now, I bet it'll be suitable next year because the team behind it is so dang fast!
    • Elasticsearch is really, really stable. It takes a lot to bring down a cluster. It's self-balancing algorithms, leader-election system, self-healing properties are state of the art. We've never seen network failures or hard-drive corruption or CPU bugs bring down an ES cluster.
    Anonymous | TrustRadius Reviewer

    Cons

    AlienVault OSSIM

    • The reports are clunky and a bit tedious to parse through.
    • Sometimes there's so much noise it's hard to tell what a true positive is. There are lots of false ones that trigger alerts but are normal behavior in many environments.
    John Keenan | TrustRadius Reviewer

    Elasticsearch

    • Joining data requires duplicate de-normalized documents that make parent child relationships. It is hard and requires a lot of synchronizations
    • Tracking errors in the data in the logs can be hard, and sometimes recurring errors blow up the error logs
    • Schema changes require complete reindexing of an index
    Keith Lubell | TrustRadius Reviewer

    Pricing Details

    AlienVault OSSIM

    General

    Free Trial
    Free/Freemium Version
    Premium Consulting/Integration Services
    Entry-level set up fee?
    No

    Starting Price

    AlienVault OSSIM Editions & Modules

    Additional Pricing Details

    Elasticsearch

    General

    Free Trial
    Free/Freemium Version
    Premium Consulting/Integration Services
    Entry-level set up fee?
    No

    Starting Price

    $0

    Elasticsearch Editions & Modules

    Edition
    Standard$16.001
    Gold$19.001
    Platinum$22.001
    EnterpriseContact Sales
    1. per month
    2. none
    Additional Pricing Details

    Likelihood to Renew

    AlienVault OSSIM

    No score
    No answers yet
    No answers on this topic

    Elasticsearch

    Elasticsearch 10.0
    Based on 1 answer
    We're pretty heavily invested in ElasticSearch at this point, and there aren't any obvious negatives that would make us reconsider this decision.
    Aaron Gussman | TrustRadius Reviewer

    Usability

    AlienVault OSSIM

    AlienVault OSSIM 8.0
    Based on 1 answer
    AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
    Jose Quintero | TrustRadius Reviewer

    Elasticsearch

    Elasticsearch 10.0
    Based on 1 answer
    To get started with Elasticsearch, you don't have to get very involved in configuring what really is an incredibly complex system under the hood. You simply install the package, run the service, and you're immediately able to begin using it. You don't need to learn any sort of query language to add data to Elasticsearch or perform some basic searching.If you're used to any sort of RESTful API, getting started with Elasticsearch is a breeze. If you've never interacted with a RESTful API directly, the journey may be a little more bumpy. Overall, though, it's incredibly simple to use for what it's doing under the covers.
    Anonymous | TrustRadius Reviewer

    Support Rating

    AlienVault OSSIM

    AlienVault OSSIM 7.9
    Based on 6 answers
    AlienVault OSSIM support has been very good. I have not had an issue that they were not able to quickly identify and provide a fix for. They are very quick to respond to open cases and are very knowledgeable in the product, which makes troubleshooting issues fast and solutions are provided quickly.
    Laurie Keith | TrustRadius Reviewer

    Elasticsearch

    Elasticsearch 7.8
    Based on 18 answers
    We've only used it as an opensource tooling. We did not purchase any additional support to roll out the elasticsearch software. When rolling out the application on our platform we've used the documentation which was available online. During our test phases we did not experience any bugs or issues so we did not rely on support at all.
    Anonymous | TrustRadius Reviewer

    Implementation Rating

    AlienVault OSSIM

    No score
    No answers yet
    No answers on this topic

    Elasticsearch

    Elasticsearch 9.0
    Based on 2 answers
    Do not mix data and master roles. Dedicate at least 3 nodes just for Master
    Anonymous | TrustRadius Reviewer

    Alternatives Considered

    AlienVault OSSIM

    Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created by hand. As other tools have come out with the ability to do automated responses such as Stellar Data processor, we have begun to evaluate alternatives.
    Anonymous | TrustRadius Reviewer

    Elasticsearch

    As far as we are concerned, Elasticsearch is the gold standard and we have barely evaluated any alternatives. You could consider it an alternative to a relational or NoSQL database, so in cases where those suffice, you don't need Elasticsearch. But if you want powerful text-based search capabilities across large data sets, Elasticsearch is the way to go.
    Anonymous | TrustRadius Reviewer

    Return on Investment

    AlienVault OSSIM

    • It's difficult to put a monetary value on security, but with proper monitoring and alerting, incidents will be easier to avoid.
    • Helps with your compliancy, as it automatically alerts you for critical events.
    • Collects logs in the cloud, so protected from local issues, like SAN failures.
    Anonymous | TrustRadius Reviewer

    Elasticsearch

    • We have had great luck with implementing Elasticsearch for our search and analytics use cases.
    • While the operational burden is not minimal, operating a cluster of servers, using a custom query language, writing Elasticsearch-specific bulk insert code, the performance and the relative operational ease of Elasticsearch are unparalleled.
    • We've easily saved hundreds of thousands of dollars implementing Elasticsearch vs. RDBMS vs. other no-SQL solutions for our specific set of problems.
    Anatoly Geyfman | TrustRadius Reviewer

    Add comparison