Best SIEM
Updated May 15, 2017

Best SIEM

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with AlienVault USM

It’s somewhat complex so it’s hard for management but security teams enforce management to do desired changes as per logs. So it’s necessary to use it in the whole organization. It’s required to understand how AlienVault is working, what AlienVault shows you from the management point of view (or any other department like software teams) while deploying the applications or using vulnerable software.
  • Easy to use.
  • Correlate the external logs.
  • Best feature is that it shows an attack when detected.
  • When external logs are placed it never shows up sometimes and for that, it requires [forceful] operation on the backend.
  • Complex to learn.
  • USM GUI not responsive when you do not have the compatible setup of the hardware.
It’s a great product and you can remain secure with this tool. It’s an easy way to know which software are harmful for organization or which websites are necessary to block. The real-time feed is also the best thing about AlienVault to get touch with what is happening in the external world and what actions need to be taken to overcome those problems.
Alarms are important to get the desired action. but IPV6 feature is not available in this and nowadays attackers more sophisticated so its hard to detect when attack based on IPV6.
Rather than IPV6 alienvault has all type of feature that every SIEM tool need.
OTX threat intelligence is very best to know IOC that are know to the whole world,by using this we can mitigate the threats.