AlienVault OSSIM
AlienVault OSSIM
Overview
Recent Reviews
Popular Features
View all 13 featuresCustom dashboards and workspaces (16)
9.3
93%
Deployment flexibility (11)
8.6
86%
Event and log normalization/management (18)
8.3
83%
Correlation (11)
7.9
79%
Reviewer Pros & Cons
View all pros & consVideo Reviews
Leaving a video review helps other professionals like you evaluate products. Be the first one in your network to record a review of AlienVault OSSIM, and make your voice heard!
Pricing
View all pricingEntry-level set up fee?
- No setup fee
Offerings
- Free Trial
- Free/Freemium Version
- Premium Consulting / Integration Services
Would you like us to let the vendor know that you want pricing?
5 people want pricing too
Alternatives Pricing
Features Scorecard
Security Information and Event Management (SIEM)
7.8
78%
Product Details
What is AlienVault OSSIM?
OSSIM leverages the power of the AlienVault Open Threat Exchange by allowing users to both contribute and receive real-time information about malicious hosts. AlienVault OSSIM is an open source Security Information and Event Management (SIEM) product. It is a unified platform providing:
It also leverages the power of the AlienVault Open Threat Exchange by allowing users to both contribute and receive real-time information about malicious hosts.
- Asset discovery
- Vulnerability assessment
- Intrusion detection
- Behavioral monitoring
- SIEM
It also leverages the power of the AlienVault Open Threat Exchange by allowing users to both contribute and receive real-time information about malicious hosts.
AlienVault OSSIM Video
AlienVault® USM vs. OSSIM™
AlienVault OSSIM Technical Details
Operating Systems | Unspecified |
---|---|
Mobile Application | No |
Comparisons
View all alternativesCompare with
Reviews and Ratings
 (25)
Reviews
(1-9 of 9)- Popular Filters
Companies can't remove reviews or game the system. Here's why
November 24, 2021
Lego block SIEM
- Datadog, Splunk Enterprise Security (SIEM), Azure Sentinel, IntSights Cyber Intelligence, from Rapid7 and Stellar Data Recovery & Erasure
Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created by hand. As other tools have come out with the ability to do automated responses such as Stellar Data processor, we have begun to evaluate alternatives.
November 04, 2021
Alienvault - the friend from another world
We did not evaluate or use any other product previous to AlienVault [OSSIM]. We had a specific need to meet our audit requirements and AlienVault [OSSIM] provided all the features needed as well as being simple enough to deploy without any dedicated staff. Real-time alerts from custom rules gives us a heads-up immediately to investigate any threat.
July 21, 2021
High Quality SIEM (plus more)
GravityZone is more or less an EPP/EDR solution for individual workstations, however, it includes centralized management, which can help mitigate/prevent cybersecurity incidents. AlienVault monitors the entire network monitors clients/accounts for suspicious behavior and it's more flexible as does not require any form of a client to be installed on any devices in the business. In the end, I have decided our business can benefit from both and have purchased both GravityZone for all of my workstations/remote workers and AlienVault to cover our entire network.
February 11, 2020
A dinosaur aging gracefully!
I liked it but it seemed a bit pricey for our organization at the time in comparison to AlienVault.
October 15, 2019
AlienVault OSSIM is the bomb!
We have not used any other products similar to AlienVault so I do not have anything to compare it to. We did look at a few others when first purchasing, but at this point, I do not recall what they were.
October 09, 2019
AlienVault OSSIM: Best Bang for Your Buck Hands Down!
Best bang for the buck. Darktrace did not perform even close to AlienVault. I ran them concurrently. AlienVault consistently found issues that Darktrace didn't pick up, and the Darktrace incidents were false positives. At one point, Darktrace stated I had 2,000 servers and I have 112.
FortiSIEM is an awesome package but it's more then I need (or can afford). I would need to add staff, for at least the first year or so, just to get it setup and configured correctly.
FortiSIEM is an awesome package but it's more then I need (or can afford). I would need to add staff, for at least the first year or so, just to get it setup and configured correctly.
December 01, 2018
AlienVault OSSIM
OSSIM is the free version of the Alien Vault USM and comes packed with most of the features you will need to get going. Like most free to use products, it is missing aspects that make the use of the product much more productive.
As an example, you will need a separate system for log storage, as the OSSIM does not have storage like the USM does, making the setup a little longer and more systems needed to make it work.
As an example, you will need a separate system for log storage, as the OSSIM does not have storage like the USM does, making the setup a little longer and more systems needed to make it work.
March 30, 2018
A robust yet lightweight SIEM in a single package
AlienVault OSSIM has the upper ante in initial deployment price, being that it's open source. Also, with perhaps the exception of SolarWinds, it has a lower optimal requirements for onsite deployment, hence your OPEX won't be hit very hard by investing in new hardware to suit the appliance. The correlation engine is somewhat more robust that their counterparts in LogRhythm and SolarWinds, and the IDS (both NIDS and HIDS) are more reliable as well in terms of results. Finally, although Tenable SecurityCenter is more robust in dashboards, alerts and reports, it comes short in front of OSSIM in terms of real-time IDS and SIEM correlation.
March 14, 2018
A hands-on proper security solution!
AlienVault OSSIM as the first experience with a SIEM is very fine, especially if your company is an SMB. Every SIEM shares some features in common with other products, features such as log retrieval and normalization. So if you stick with principles, you can learn other SIEM products as well. If your environment is not of a minimum size, LogRhythm might be overkill for your network, same with McAfee Enterprise Security Manager.