What users are saying about
<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
598 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
255 Ratings

AlienVault USM

<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
598 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 7.9 out of 101

Splunk Enterprise

<a href='https://www.trustradius.com/static/about-trustradius-scoring#question3' target='_blank' rel='nofollow noopener noreferrer'>Customer Verified: Read more.</a>
Top Rated
255 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 8.7 out of 101

Likelihood to Recommend

AlienVault USM

AlienVault Unified Security Management (USM) Anywhere is a cloud-based security information and event management solution that provides effective and affordable threat detection, incident response, and compliance management capabilities. USM Anywhere is well suited to mid-size enterprise environments operating in the cloud. USM Anywhere is also well suited to enterprises whose operations teams require easy deployment and management. Last, USM Anywhere is considered a highly affordable option compared to competitors. USM Anywhere lags competitors in several areas, such as application monitoring, database monitoring, and integrations with third-party solutions such as cloud access security brokers (CASB), DAM, DAP, and DLP.
Matthew Stacks profile photo

Splunk Enterprise

Pros: Splunk is very well suited if you have multiple log sources of related data. All of them can be correlated and tasks can be automated based on the requirement. Other than alerts, Splunk can also run a specific script of your choice, based on some defined conditions. Cons: If you have a few logs but a large number of log sources, Splunk can be very expensive.
Kuntal Das profile photo

Feature Rating Comparison

Security Information and Event Management (SIEM)

AlienVault USM
7.3
Splunk Enterprise
8.7
Centralized event and log data collection
AlienVault USM
8.0
Splunk Enterprise
9.2
Correlation
AlienVault USM
8.0
Splunk Enterprise
8.7
Event and log normalization
AlienVault USM
8.0
Splunk Enterprise
9.0
Deployment flexibility
AlienVault USM
7.0
Splunk Enterprise
8.3
Custom dashboards and views
AlienVault USM
6.0
Splunk Enterprise
9.0
Host and network-based intrusion detection
AlienVault USM
7.0
Splunk Enterprise
8.7
Integration with Identity and Access Management Tools
AlienVault USM
Splunk Enterprise
8.0

Pros

AlienVault USM

  • Alienvault USM is THOROUGH. We have a highly integrated workspace that's most SAAS, and I monitor those integrations and their security with AV. If I am trying to track the uptime of a laptop, I don't go to VPN or our Directory Services... I go to AV.
  • As I mentioned before, we use Sophos to protect our laptops. If a questionable file shows up on someones laptop, I hear about it from AlienVault before I hear about it from our Sophos service.
  • The OTX Pulse feature is a built-in feature that lets you subscribe to industries and you are notified about new threats that affect that industry on a daily basis. The pulse alerts are added to your AV watchlist.
Christian Holton profile photo

Splunk Enterprise

  • Allow for separation of control where we don't let some employees have access to production but still can diagnose issues.
  • Common location to go for all logs even if the logs themselves aren't in the same place.
  • Ability to ingest logs from different locations without having to change the code to put logs in a certain place (pro and con).
No photo available

Cons

AlienVault USM

  • While there are many features, many of them are not very advanced. Vulnerability scanning as an example is extremely simplistic and almost unusable for an enterprise organization. It's just enough to get a program off the ground.
  • Cloud-only deployment model (SaaS) may not fit all organizations. Not all organizations are "cloud friendly".
  • Reporting capabilities out of the box are lack luster. Vulnerability management reporting as an example does not include a single canned report.
Frank DePaola profile photo

Splunk Enterprise

  • Even though there is a search tool as a help function, you still have to read through many documentation to find the answers you're looking for and sometimes you don't find it. The help function in Splunk could be improved to be more intuitive or have a built-in help per report, panel or dashboard.
  • Creating a Splunk dashboard is rather straightforward however, customization is not. Splunk could be improved to provide more tools or features for customization such as adding colors and font options for text and graphs or graphics.
  • My dashboard has a lot of useful information and I want the important panels and reports at the top but there is no easy way to do this. Perhaps Splunk could be improved to allow features such as adding URL links to other dashboards or some other clever way to emphasize the important data in my dashboard without compromising space.
Trung Pham profile photo

Likelihood to Renew

AlienVault USM

AlienVault USM 4.4
Based on 16 answers
The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
Aaron Rothstein profile photo

Splunk Enterprise

Splunk Enterprise 10.0
Based on 17 answers
We are using Splunk extensively in our projects and we have recently upgraded to Splunk version 6.0 which is quite efficient and giving expected results. We keep track of updates and new features Splunk introduces periodically and try to introduce those features in our day to day activities for improvement in our reporting system and other tasks.
No photo available

Usability

AlienVault USM

AlienVault USM 7.3
Based on 35 answers
The product once properly configured seems to offer a wealth of information but has it's issues. I feel that the initial setup/ installation should include technical support to get up and running. My personal experience from the configuration as installed indicates that the network adaptors are not properly configured to read information. The network ports where configured to only ready 1/2 the network?? So having help to get the system up and running should be part of the initial purchase.
James Ellsworth profile photo

Splunk Enterprise

Splunk Enterprise 9.0
Based on 3 answers
You can literally throw in a single word into Splunk and it will pull back all instances of that word across all of your logs for the time span you select (provided you have permission to see that data). We have several users who have taken a few of the free courses from Splunk that are able to pull data out of it everyday with little help at all.
Kenneth Taitingfong profile photo

Reliability and Availability

AlienVault USM

AlienVault USM 6.4
Based on 3 answers
No answer on this topic is available.

Splunk Enterprise

Splunk Enterprise 10.0
Based on 1 answer
When properly setup and configured, Splunk is extremely reliable.
No photo available

Support

AlienVault USM

AlienVault USM 7.5
Based on 25 answers
I have not had a single issue with the alienvault support staff. Any issue or question that we had, especially in the beginning during the installation phase the support staff was readily available via phone and email to help us. I am very happy with the decision we made to go with alienvault.
Mikhail Suleymanov profile photo

Splunk Enterprise

Splunk Enterprise 9.2
Based on 8 answers
It helped us and is still helping to deploy new modules, installing and configuring new databases without worrying about a huge bottleneck or lack of understanding, and monitoring the post-deploy impacts. This has been our main tool across the University IT sectors to utilize all of its monitoring options, and sharing those alerts with end-users as needed.
No photo available

Online Training

AlienVault USM

AlienVault USM 8.6
Based on 6 answers
The instructor was very knowledgeable and was able to answer everyone's questions. He also was able to teach to many different levels. Some folks in the class had already been using USM or a similar product whereas I and a few others were brand new. He also provided a way of reaching out with questions after the training was over. Everyone in the training seemed to enjoy the class.
Christian Holton profile photo

Splunk Enterprise

No score
No answers yet
No answers on this topic

Implementation

AlienVault USM

AlienVault USM 6.6
Based on 38 answers
Initial implementation was okay, but we should have gone on the one week course first as an understanding of the features and what to look for would have been of great use. This is especially relevant when fine tuning and correlating events and creating parsers.Once set up the system is pretty resilient and adding in configuration is quite an easy process. We only had on the odd few occasions had to progress any set up problems to tech support.There are also some great whitepapers and set up articles on AlienVault's website support.
Philip Clarke profile photo

Splunk Enterprise

Splunk Enterprise 9.0
Based on 2 answers
Smooth without too many major issues.
No photo available

Alternatives Considered

AlienVault USM

USM Appliance provides you with the ability to identify your critical assets and to set policies to alert you when those assets have vulnerabilities or are subjected to attacks. USM Appliance will generate alarms based upon the risk associated with any given security event captured in USM Appliance.USM Appliance provides you with the ability to identify your critical assets and to set policies to alert you when those assets have vulnerabilities or are subjected to attacks. USM Appliance will generate alarms based upon the risk associated with any given security event captured in USM Appliance. Identifying patterns of events that indicate a possible threat or vulnerability.
Mpho Lekota profile photo

Splunk Enterprise

Splunk is proving to be a formidable replacement for Qradar, which we had as our previous SIEM. Qradar was powerful, but not easy to customize and quite limited. Splunk is not per se a "SIEM" but it can be in the way you used it. Also there is an Enterprise Security App that is available to buy and sit on top of Splunk, and that will take care of any concerns with needing a full-fledged SIEM. Splunk wins.
No photo available

Scalability

AlienVault USM

AlienVault USM 6.3
Based on 3 answers
No answer on this topic is available.

Splunk Enterprise

Splunk Enterprise 9.1
Based on 1 answer
Splunk can scale in to the petabyte per day range which of course is awesome
Rick Yetter profile photo

Return on Investment

AlienVault USM

No answers on this topic

Splunk Enterprise

  • I'm not a data analyst so I can not provide concrete examples on how the business has benefited from implementing Splunk. However, the analysts I have worked with have provided a wealth of support in reducing workstation issues across the enterprise. This alone reduces the time it takes to determine where the exact problem lies between a workstation and the servers it tries to communicate with.
No photo available

Screenshots

Splunk Enterprise

Pricing Details

AlienVault USM

General

Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
Yes
Entry-level set up fee?
Optional

Splunk Enterprise

General

Free Trial
Yes
Free/Freemium Version
Yes
Premium Consulting/Integration Services
Entry-level set up fee?
No

Rating Summary

Likelihood to Recommend

AlienVault USM
7.9
Splunk Enterprise
8.9

Likelihood to Renew

AlienVault USM
4.4
Splunk Enterprise
10.0

Usability

AlienVault USM
7.3
Splunk Enterprise
9.0

Reliability and Availability

AlienVault USM
6.4
Splunk Enterprise
10.0

Performance

AlienVault USM
7.3
Splunk Enterprise

Support

AlienVault USM
7.5
Splunk Enterprise
9.2

In-Person Training

AlienVault USM
4.5
Splunk Enterprise

Online Training

AlienVault USM
8.6
Splunk Enterprise

Implementation

AlienVault USM
6.6
Splunk Enterprise
9.0

Scalability

AlienVault USM
6.3
Splunk Enterprise
9.1

Add comparison