The LevelBlue USM Anywhere XDR platform (replacing the former AlienVault USM) delivers threat detection, incident response, and compliance management.
$1,075
per month
Splunk AppDynamics
Score 8.2 out of 10
N/A
AppDynamics is an APM and Mobile APM program, with application mapping and predictive capabilities. These capacities enable automated remediation and code-level diagnostics in real time. It can be deployed on-premise or as a SaaS.
N/A
Sumo Logic
Score 8.8 out of 10
N/A
Sumo Logic is a log management offering from the San Francisco based company of the same name.
All of the other products have their strengths and weaknesses. In trying to keep the platform focused on security while keeping the spend contained, we chose AlienVault. Both LogRhythm and Splunk had great solutions, but AlienVault just checked off more of our organizational …
At this point I'm saying a 4. While the marketing material make it appear to be easy to use and it was relatively easy to set up, as previously mentioned, each event description is based upon the individual asset making it nearly impossible for the administrator to be a SME for each asset. For example, if one of the assets reporting is a router, the administrator monitoring alerts would need to know what the various events are that can be triggered as an event for the particular router; however, if the asset is a workstation, the administrator would need to know the various events that are triggered for workstations.
Platforms for software as a service (SaaS) frequently cater to a large number of users with a variety of needs and usage patterns. Because AppDynamics offers multi-tenant monitoring capabilities to track performance across various customer environments, it is a good choice for SaaS platform monitoring. SaaS providers can maximize resource utilization, proactively detect and resolve performance issues, and provide a dependable and consistent user experience for their clients with AppDynamics.
SumoLogic is a fantastic log aggregator and analysis tool, a fine alternative to Splunk. Searching is powerful and mostly intuitive and results come fast. If you have application logs in clusters or Kubernetes pods that lose their logs every time they're restarted, Sumo is the solution for you
AlienVault USM is simple and easy to deploy. Sensors can be deployed in as little as 15 minutes through the setup wizard.
The USM UI is easy to understand. I've trained multiple analysts who are able to perform their duties on their first day, in part because of USM Anywhere's ease of use.
Top-notch built-in compliance templates and reporting features.
Business Transaction Monitoring is one of its signature strengths. This represents a major differentiator from generic infrastructure monitoring tools.
AI‑driven anomaly detection and intelligent alerting provide a significant advantage over traditional monitoring.
When combined with Splunk AppDynamics, full‑stack observability becomes a key part of Cisco/Splunk’s unified observability strategy.
Sumo Logic allowed for our InfoSec team to ingest logs from our CDN directly, in real-time, instead of massive compressed archives that were sent every two-hours (the only alternative at the time). Sumo Logic had an app for these logs, that allowed us to easily get an immediate payoff from the data, with canned dashboard and saved searches.
Sumo Logic has a fairly extensive REST API when it comes to log sources, source configurations, dashboard data, searches, etc. Their wiki for the API is usually kept up to date.
Sumo Logic, during the period of time I had used their product, had added the ability to configure agents via configuration files. This allowed customers to configure their endpoints, and modify the endpoints, with configuration management tools like Chef / Puppet / Salt. Beforehand, the only option was to always make changes either via the web portal or REST API.
The solutions engineers were extremely helpful, and easily reachable when issues would occur.
Users at our company found it easy to get started, working on new dashboards, scheduled searches, and alerting. The alerting worked well with our third-party paging tool.
Personally, I've wished I could purchase a service that would configure AV for my environment. I get a lot of traffic on a daily basis and I almost need to hire an analyst that just works on AV.
Some of the filters when looking for a specific alert aren't that easy to use.
AppDynamics may enhance its capacity to track transactions through complex distributed systems and microservices, offering a more comprehensive understanding of application behavior.
Better search and filtering capabilities would enable engineers to quickly obtain deeper context by drilling down into individual data points.
AppDynamics might be more widely available to engineers and organizations if it offered subscription plans or tiered pricing options.
The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
On a scale of 1 to 10, I would rate our likelihood to renew Splunk AppDynamics as a 10. Our leadership is fully committed to the State of Indiana’s Application Performance Monitoring (APM) Program, which has become a national leader within the SLED (State, Local, and Education) vertical. AppDynamics plays a critical role in our ability to deliver reliable, high-performing digital services to citizens and stakeholders. Its capabilities align closely with our strategic goals around operational excellence, proactive incident management, and data-driven decision-making, making it an indispensable part of our technology ecosystem.
Once you are able to navigate the different panels, finding what you need is quite easily. Before getting used it it can be a bit of challenge . Each panel is quite well laid out and the filtering search capabilities are quite strong.
Since I'm a regular user of appD and have been using it for the last 3 years, I believe it does pretty well for what it's designed to do. It works well for monitoring and tracking issues, working on load testing - checking traffic, request failure, and improving, so overall I'm satisfied, and it really helped a lot to improve our application overall, so happy to review and rate it.
Sumo Logic is very powerful but definitely requires some configuration work to get the most out of it. You can get a certification related to this, but it is definitely not something you can just throw together.
We do have issues with maintenance on the AlienVault USM as the disk fills up from time to time with other data sources. Sources for scanning logs and net flow data isn't calculated in regular disk maintenance and can easily fill up our disk if we do not keep an eye on it with some custom Nagios plugins. The system does properly trim logging data from logging sources properly.
On a scale of 1 to 10, I would rate the availability of Splunk AppDynamics as a 9. Overall, the platform has proven to be highly reliable and is available when we need it. It consistently supports our monitoring and performance management needs across critical applications and infrastructure. There have been occasional issues with platform availability, such as intermittent application errors or brief unplanned outages. However, these instances have been infrequent and typically resolved quickly, minimizing any significant impact on operations. The stability and uptime of the platform have met our expectations, and we continue to rely on it as a core component of our APM strategy.
With the latest release of AlienVault USM overall performance has not been an issue. We have noticed single source events per second does not scale well with the overall system. 2,000eps on a vmware system with a single source produces delays of up to an hour for us. Pages, reporting and even raw log searches are rather quick though.
On a scale of 1 to 10, I would rate the performance of Splunk AppDynamics as a 6. While the platform generally delivers the expected functionality, we’ve experienced periodic slowness—particularly with page loads and report generation. These performance issues can be frustrating, especially when trying to quickly access critical data during incident response or analysis. One contributing factor may be our use of a shared controller environment with other enterprises, which can introduce resource contention and impact overall responsiveness. In some cases, this has led to delays in accessing dashboards or completing complex queries. Despite these challenges, the platform remains a valuable tool, and we’re exploring options to improve performance, including potential changes to our deployment model and support agreements.
The support we received from alienvault was excellent. They went above and beyond in making sure everything was working as it needed to be. They REALLY want their product implementation to be a success and our security goals be achieved. They are like a member of our security team.
AppDynamics has its own community site that includes forums and a knowledge base. On the forums, you can converse with other members of the community and ask technical questions as you have them. Though this forum isn’t filled with people there are active members for you to gain some valuable insights.
I would give this rating because I attended a free Sumo Logic training at a WeWork in Chicago. I found the training very useful, and I learned a lot of features that I was not aware of before I went to the training. I like the idea that SumoLogic provides free training seminars. I am certified in level1, and I plan on certifying to level2.
I did not have any experience with "in person" training directly. The free online classes offered for a half a day are based on the actual training offered. These little teasers are very good and well worth your time to learn a few quick and dirty ways of getting more information from your SIEM
It was very well organized and helpful in using the product to the fullest extent. The instructor allowed time for folks who were involved with managed services to receive tuning tips in order to better support their customers. In addition, the course materials were automatically updated when the new version came out.
On a scale of 1 to 10, I would rate the online training for Splunk AppDynamics as a 7. The training was generally acceptable and covered the core concepts and functionality of the platform. However, there were some challenges with communication during sessions—particularly around clarity and instructor engagement—which occasionally made it difficult to fully grasp certain topics. Additionally, the training could benefit from being more focused and tailored to specific roles or use cases. A more structured approach with clearer learning paths and practical, hands-on examples would enhance the overall effectiveness and help users apply the knowledge more confidently in real-world scenarios.
AlienVault USM was a very simple to implement and get up and running. We started with a trial version and had that up and going within an hour of receiving email instructions from the sales engineer. We never had to contact support to get the system up and going. It was extremely easy to convert over to a full license once we started with a paid version.
On a scale of 1 to 10, I would rate our satisfaction with the implementation of Splunk AppDynamics as a 9. The deployment process was smooth and well-coordinated, thanks to the collaborative efforts between Cisco Professional Services, our internal business stakeholders, and agency technical teams. Key Insights from the Implementation: Cross-functional Collaboration Was Critical: Engaging both technical and business teams early in the process ensured that the platform was configured to meet a wide range of operational and strategic needs. Value of Expert Guidance: Cisco’s Professional Services provided invaluable expertise, helping us navigate complex configurations and tailor the solution to our environment. Their involvement accelerated deployment and ensured best practices were followed. Importance of Planning and Communication: A well-defined implementation roadmap and regular communication across teams helped us stay aligned, manage expectations, and address challenges proactively. Scalable Architecture: We designed the implementation with scalability in mind, allowing us to expand usage across agencies and applications without major rework. Overall, the implementation laid a strong foundation for our APM program and positioned us for long-term success.
I was satisfied with the implementation, as at the time, it was the best way to implement the product with the available feature sets in Sumo Logic. User creation and management became more of an issue during continued use, instead of it being an issue related to deploying the product in our environment.
Splunk's ES is a paid add-on on top of an already pricey product. Finding a MSSP that supports Splunk and isn't a 6 figure annual commitment seems unlikely. LogRhythm did not have a cloud-based solution when we were considering SIEMs. Fantastic product though and have a good MSSP base. Devo did not have a MSSP partner base when we looked. Their product is fantastic too. AlienVault USM has good partners to choose from as well as an affordable cloud model, that's why we chose it.
It is distinguished from these programs because the platform provides visualizations of application processes, showing the interplay between various parts and services. Understanding the architecture of complicated apps and finding their weak spots is greatly aided by this.
Sumo Logic works very well out of the gate. For a small business it has given us what we need. I worked at a larger company previously, and we produced so many logs we had to create a custom logging service to handle them all. Cost and availability are big issues when deciding between the different services, whether self maintained and hosted, or provided by another company.
While the overall value of the Splunk AppDynamics platforms is strong, the pricing structure and contract terms can be complex and difficult to navigate. Unit pricing, licensing tiers, and billing frequency are not always intuitive, which can make it challenging to align purchases with the State’s evolving needs. I rely heavily on our Account Manager to help interpret and tailor the licensing model to our specific requirements. Their support has been invaluable in ensuring we make informed decisions. The most impactful change would be to simplify the licensing and pricing model. Clearer documentation, more transparent pricing tiers, and streamlined purchasing processes would significantly improve the experience and reduce administrative overhead.
The AlienVault USM is not very scalable. Some scalability can be achieved by installing additional sensors, but this only offers 500eps per sensor and is still overall limited by the installation type of VM or physical. We have also noticed the EPS (events per second) is rated overall and not towards a single source. A single source on a very healthy VMware partition tops out at 2,000eps for us, no matter how we configure it. Maybe this is a problem of the 5.2 release?
On a scale of 1 to 10, I would rate the overall scalability of Splunk AppDynamics as a 7. The platform is designed to support enterprise-wide deployments across multiple departments and sites, and it performs well in large-scale environments. Its architecture allows for horizontal scaling and supports a wide range of application types and infrastructures. However, the agent management and deployment process can be complex and time-consuming, especially when onboarding a large number of applications or systems. Coordinating agent installation, configuration, and updates across diverse environments requires careful planning and often significant manual effort. Streamlining these processes—perhaps through more centralized management tools or automation—would enhance scalability and reduce operational overhead. Despite these challenges, once deployed, AppDynamics scales effectively and provides consistent performance and visibility across the enterprise.
Our experience with the professional services team supporting Splunk AppDynamics has been exceptional. They demonstrated deep technical expertise, strong collaboration skills, and a clear understanding of our business objectives. Their guidance was instrumental in the successful implementation of our APM program and platform integration. The rating of 9 reflects our high level of satisfaction, with a small margin left to acknowledge that continuous improvement is always possible. Overall, their support has been a key factor in the success of our deployment.
Once you hit the 150 asset mark, you have to jump to their unlimited license. There is no middle ground. We were only 10 or so assets above the 150 so we had to chose to either not monitor those assets or pay the price of the upgrade.
AlienVault brings all the information to one place which makes it much quicker to track down problems.
Through the identification of performance bottlenecks and efficient resource allocation, AppDynamics has contributed to cost savings and resource optimization. This has a direct positive impact on our overall return on investment.
While AppDynamics' numerous capabilities help maximize efficiency, they may place a strain on your system. Organizations with limited infrastructure capacity may have difficulties and therefore give this serious thought before implementing it.