AlienVault USM vs. IBM Security QRadar SIEM

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
AlienVault USM
Score 8.0 out of 10
N/A
AlienVault® Unified Security Management® (USM) delivers threat detection, incident response, and compliance management in one unified platform. It is designed to combine all the essential security capabilities needed for effective security monitoring across cloud and on-premises environments, including SIEM, intrusion detection, vulnerability management, as well as continuous threat intelligence updates. The vendor states that even for resource-limited IT security teams, AlienVault…
$1,075
per month
IBM Security QRadar SIEM
Score 8.7 out of 10
N/A
IBM Security QRadar is security information and event management (SIEM) Software.N/A
Pricing
AlienVault USMIBM Security QRadar SIEM
Editions & Modules
Essentials
$1,075
per month
Standard
$1,695
per month
Premium
$2,595
per month
No answers on this topic
Offerings
Pricing Offerings
AlienVault USMIBM Security QRadar SIEM
Free Trial
YesNo
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeOptionalNo setup fee
Additional Details
More Pricing Information
Community Pulse
AlienVault USMIBM Security QRadar SIEM
Considered Both Products
AlienVault USM
Chose AlienVault USM
AlienVault USM offers a user-friendly interface and comprehensive features at a lower cost compared to QRadar, making it our preferred choice for effective threat detection and response.
Chose AlienVault USM
Easy to deploy and ease of use, good training by ATT
Chose AlienVault USM
QRadar is one of the top SIEMs on the market. AlienVault USM is more suitable for companies or clients having a smaller budget, as AlienVault USM is cheaper than QRadar. Regarding features, QRadar trumps AlienVault USM, as it is a product with a vast array of features.
Chose AlienVault USM
AlienVault USM is considerably more user-friendly, but it does fall short with the search functionality that a query language offers when looking for specific logs/statistics/data.
Chose AlienVault USM
The price and the ease-of-use, and the support from AlienVault are better. I had a lot of trouble starting out, but they guided me very well. The training provided by AlienVault was fantastic, because I could play without the fear of breaking anything.
Chose AlienVault USM
I didn't select either product but I have used both. I suspect IBM QRadar is more expensive, however, it is also more responsive, includes support for e-streamer, does parse the "blocked" field in source fire logs, and includes UEBA.
Chose AlienVault USM
Compared to the main competitor's products, the AlienVault USM is particularly good in terms of cost effectiveness. Your company does not need to spend a huge amount of money in the first place just to test out the result. By using AlienVault USM, you can also get great support …
Chose AlienVault USM
AlienVault USM is particularly outperforming the competitors in terms of security threats detection. However, like all the other tools, it does not automatically do the thing that you want to do. But with correctly setting up the rules and properly tuning the tool, it can …
Chose AlienVault USM
The tool works well compared with the two others. As I said previously, AlienVault USM gives you a lot of visibility right out of the box and with very little configuration.

However, I like the ability to customize pieces, such as log parsers and dashboards, as I see fit without …
Chose AlienVault USM
Alienvault was the most aggressive in their pricing and marketing of ease of deployment. The ease of deployment was what really aided in their ability to win our business. The ROI was worth the investment for our security at the time. Also being a market leader aided in our …
Chose AlienVault USM
AlienVault USM is more affordable than the other solutions and much easier to deploy and maintain.
Chose AlienVault USM
We selected AlienVault USM because it was a lot less expensive than many other SIEM tools in the marketplace.
Chose AlienVault USM
Honestly, pricing is the main reason. AlienVault was already purchased when I was hired as Director, and the company did not have enough budget for anything else. Implementation was subpar, very disappointing, and renewal was a nightmare.
Chose AlienVault USM
With the exception of Solar Winds, AlienVault USM is far easier to administer and support, but far less extensible. LogRhythm and Splunk are going to offer far more advanced capabilities in the way of deployment models, features, and automation capabilities. Also, other …
Chose AlienVault USM
AlienVault was the cheapest solution compared with the competition and had similar or better features. Also, the SaaS based solution made it easy to deploy the solution without the need to maintain additional servers on premise. It was very easy to use and had a great UI which …
Chose AlienVault USM
SIEM vendors are having to adapt and thus it is difficult to perform a true apples-to-apples comparison between all the vendors. They offer different features and can even take different approaches to solving the logging and SIEM issue. Still, with that consideration in mind, …
Chose AlienVault USM
Though IBM QRadar is a good product, it is not easy to manage and maintain. It's too bulky to understand and manage. The correlation rules are also not easy to work with. AlienVault has great support and knowledge. The community strength derived from being open source gives …
Chose AlienVault USM
Both of the products I have used in the past were much more medium-large sized businesses. They both had functionalities which are helpful from a trending perspective, have better reporting, and a much more involved user base. The cost of these are prohibitive compared to …
Chose AlienVault USM
While they have a comparable range of features and functionality as SIEM's, QRadar was built to be a SIEM first and foremost where AlienVault USM has amore rounded all-inclusive set of features. Despite having more elements, AlienVault USM Anywhere is the more intuitive and …
Chose AlienVault USM
IBM QRadar - long and clunky installation process, after which we weren't blown away by the tired and over-complicated user interface - wasn't a good fit for us.
InsightIDR - disappointing engagement with their sales team, who weren't able to answer surface-level questions about …
Chose AlienVault USM
For us it came down to cost. AlienVault's competitors just could not compare on cost for a small organization like us. They are out of touch. Everyone needs a solid tool like AlienVault, but too often the industry only caters to big budgets. More often than not, that results in …
Chose AlienVault USM
Being able to integrate multiple uses into a single appliance is a great win for small and medium enterprises. The cost for the single solution also ends up being in reach for the SME vs. some of the other available solutions.
Chose AlienVault USM
Comparisons with other products can be tricky, since AlienVault packs a lot into its product, and that essentially is its main strength vs. the competition. For people just looking for SIEM like functionality it is definitely compatible to other products, but some of the …
Chose AlienVault USM
AlienVault Unified Security Management is a budget-friendly solution to a typical SIEM implementation. Although it is not as robust and well known as others, my organization decided to purchase AlienVault due to the cost savings and user-friendly interface that is available out …
IBM Security QRadar SIEM
Chose IBM Security QRadar SIEM
With IBM supplying this solution, you're inherently getting the globally recognized IBM support environment as well. As an enterprise solution, Qradar is among stiff competition but the reliability and availability make it a cut above the rest. While I also recommend …
Top Pros
Top Cons
Features
AlienVault USMIBM Security QRadar SIEM
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
AlienVault USM
8.0
8 Ratings
3% above category average
IBM Security QRadar SIEM
8.6
54 Ratings
10% above category average
Centralized event and log data collection8.58 Ratings9.927 Ratings
Correlation8.58 Ratings8.854 Ratings
Event and log normalization/management8.08 Ratings9.527 Ratings
Deployment flexibility8.67 Ratings7.927 Ratings
Integration with Identity and Access Management Tools7.35 Ratings8.250 Ratings
Custom dashboards and workspaces7.08 Ratings7.454 Ratings
Host and network-based intrusion detection8.05 Ratings9.625 Ratings
Data integration/API management00 Ratings9.07 Ratings
Behavioral analytics and baselining00 Ratings8.133 Ratings
Rules-based and algorithmic detection thresholds00 Ratings9.134 Ratings
Response orchestration and automation00 Ratings7.75 Ratings
Reporting and compliance management00 Ratings7.632 Ratings
Incident indexing/searching00 Ratings8.97 Ratings
Best Alternatives
AlienVault USMIBM Security QRadar SIEM
Small Businesses

No answers on this topic

AlienVault USM
AlienVault USM
Score 8.0 out of 10
Medium-sized Companies
Splunk Enterprise
Splunk Enterprise
Score 8.3 out of 10
Splunk Enterprise
Splunk Enterprise
Score 8.3 out of 10
Enterprises
Splunk Enterprise
Splunk Enterprise
Score 8.3 out of 10
Splunk Enterprise
Splunk Enterprise
Score 8.3 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
AlienVault USMIBM Security QRadar SIEM
Likelihood to Recommend
8.8
(391 ratings)
8.6
(75 ratings)
Likelihood to Renew
7.2
(18 ratings)
9.1
(3 ratings)
Usability
6.7
(34 ratings)
9.1
(1 ratings)
Availability
6.4
(3 ratings)
-
(0 ratings)
Performance
7.3
(3 ratings)
-
(0 ratings)
Support Rating
7.3
(25 ratings)
8.4
(49 ratings)
In-Person Training
4.5
(1 ratings)
-
(0 ratings)
Online Training
8.3
(6 ratings)
-
(0 ratings)
Implementation Rating
6.4
(38 ratings)
-
(0 ratings)
Configurability
8.0
(3 ratings)
-
(0 ratings)
Ease of integration
7.3
(3 ratings)
8.1
(45 ratings)
Product Scalability
6.3
(3 ratings)
-
(0 ratings)
Vendor post-sale
7.6
(3 ratings)
-
(0 ratings)
Vendor pre-sale
8.2
(3 ratings)
-
(0 ratings)
User Testimonials
AlienVault USMIBM Security QRadar SIEM
Likelihood to Recommend
AT&T Cybersecurity
At this point I'm saying a 4. While the marketing material make it appear to be easy to use and it was relatively easy to set up, as previously mentioned, each event description is based upon the individual asset making it nearly impossible for the administrator to be a SME for each asset. For example, if one of the assets reporting is a router, the administrator monitoring alerts would need to know what the various events are that can be triggered as an event for the particular router; however, if the asset is a workstation, the administrator would need to know the various events that are triggered for workstations.
Read full review
IBM
monitoring network traffic is much easier while having siem in your organization and the scenario where siem is less apricated is installing adding logs source making rules according to your desire or the last thing ibm support team not proving the good feedback on instant basis in case of any critical scenarios
Read full review
Pros
AT&T Cybersecurity
  • AlienVault USM is simple and easy to deploy. Sensors can be deployed in as little as 15 minutes through the setup wizard.
  • The USM UI is easy to understand. I've trained multiple analysts who are able to perform their duties on their first day, in part because of USM Anywhere's ease of use.
  • Top-notch built-in compliance templates and reporting features.
Read full review
IBM
  • Enables identification and prioritization of vulnerabilities in IT infrastructure for corrective action.
  • Facilitates security incident investigation and forensic analysis.
  • Provides a real-time view of security events, enabling immediate incident response.
  • Can integrate with external threat intelligence sources to enrich data and improve threat detection.
  • Enables the generation of detailed and customized reports.
Read full review
Cons
AT&T Cybersecurity
  • Personally, I've wished I could purchase a service that would configure AV for my environment. I get a lot of traffic on a daily basis and I almost need to hire an analyst that just works on AV.
  • Some of the filters when looking for a specific alert aren't that easy to use.
Read full review
IBM
  • Need to spend more time configuring the system to properly interpret and normalize different type of data collected from multiple resources.
  • While Rule creation QRadar uses that rules to detect security threats and generate alerts, but to creating and managing rules is bit complex & tedious work to complete.
  • IBM Security QRadar SIEM is excellent in handling large & complex systems that requires in-depth knowledge and extensive training to configure and maintain the system which includes upgrading, optimization of performance & issue troubleshooting.
Read full review
Likelihood to Renew
AT&T Cybersecurity
The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
Read full review
IBM
With the arrival of IBM Security QRadar SIEM at our company, we have a better vision of all the security needs that may arise, it is a very safe software to use that prevents threats from damaging our IT environment, it is impossible to change it for another software.
Read full review
Usability
AT&T Cybersecurity
Once you are able to navigate the different panels, finding what you need is quite easily. Before getting used it it can be a bit of challenge . Each panel is quite well laid out and the filtering search capabilities are quite strong.
Read full review
IBM
A very special system to use without problems, the process is very genuine and does not require complicated procedures.
Read full review
Reliability and Availability
AT&T Cybersecurity
We do have issues with maintenance on the AlienVault USM as the disk fills up from time to time with other data sources. Sources for scanning logs and net flow data isn't calculated in regular disk maintenance and can easily fill up our disk if we do not keep an eye on it with some custom Nagios plugins. The system does properly trim logging data from logging sources properly.
Read full review
IBM
No answers on this topic
Performance
AT&T Cybersecurity
With the latest release of AlienVault USM overall performance has not been an issue. We have noticed single source events per second does not scale well with the overall system. 2,000eps on a vmware system with a single source produces delays of up to an hour for us. Pages, reporting and even raw log searches are rather quick though.
Read full review
IBM
No answers on this topic
Support Rating
AT&T Cybersecurity
The support we received from alienvault was excellent. They went above and beyond in making sure everything was working as it needed to be. They REALLY want their product implementation to be a success and our security goals be achieved. They are like a member of our security team.
Read full review
IBM
Customer support is Good of IBM, While Using IBM QRadar its deployment is to slow and suddenly stop working and crashed we have contacted IBM Support and Rised a Ticket within a few minute we get call back from customer support and Query Resolved by them Fast And Rapid Support of Ibm
Read full review
In-Person Training
AT&T Cybersecurity
I did not have any experience with "in person" training directly. The free online classes offered for a half a day are based on the actual training offered. These little teasers are very good and well worth your time to learn a few quick and dirty ways of getting more information from your SIEM
Read full review
IBM
No answers on this topic
Online Training
AT&T Cybersecurity
It was very well organized and helpful in using the product to the fullest extent. The instructor allowed time for folks who were involved with managed services to receive tuning tips in order to better support their customers. In addition, the course materials were automatically updated when the new version came out.
Read full review
IBM
No answers on this topic
Implementation Rating
AT&T Cybersecurity
AlienVault USM was a very simple to implement and get up and running. We started with a trial version and had that up and going within an hour of receiving email instructions from the sales engineer. We never had to contact support to get the system up and going. It was extremely easy to convert over to a full license once we started with a paid version.
Read full review
IBM
No answers on this topic
Alternatives Considered
AT&T Cybersecurity
Splunk's ES is a paid add-on on top of an already pricey product. Finding a MSSP that supports Splunk and isn't a 6 figure annual commitment seems unlikely. LogRhythm did not have a cloud-based solution when we were considering SIEMs. Fantastic product though and have a good MSSP base. Devo did not have a MSSP partner base when we looked. Their product is fantastic too. AlienVault USM has good partners to choose from as well as an affordable cloud model, that's why we chose it.
Read full review
IBM
IBM Qradar takes the best from its competitors. Reliable and stable but sometimes very expensive, the SIEM from IBM offers a wide range of scenarios in which the customers can suite and size their own infrastructures. IBM Qradar doesn't really needs to stack up againt its competitors because it already sets an example in the SIEM world.
Read full review
Scalability
AT&T Cybersecurity
The AlienVault USM is not very scalable. Some scalability can be achieved by installing additional sensors, but this only offers 500eps per sensor and is still overall limited by the installation type of VM or physical. We have also noticed the EPS (events per second) is rated overall and not towards a single source. A single source on a very healthy VMware partition tops out at 2,000eps for us, no matter how we configure it. Maybe this is a problem of the 5.2 release?
Read full review
IBM
No answers on this topic
Return on Investment
AT&T Cybersecurity
  • Once you hit the 150 asset mark, you have to jump to their unlimited license. There is no middle ground. We were only 10 or so assets above the 150 so we had to chose to either not monitor those assets or pay the price of the upgrade.
  • AlienVault brings all the information to one place which makes it much quicker to track down problems.
Read full review
IBM
  • Offense investigation was really helped in tackling the incidents. It was accurate and brief
  • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
  • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
Read full review
ScreenShots

AlienVault USM Screenshots

Screenshot of USM Anywhere NIDS Dashboard