Alien Vault USM goods and not so goods
April 12, 2019

Alien Vault USM goods and not so goods

David Green | TrustRadius Reviewer
Score 7 out of 10
Vetted Review

Software Version

USM Anywhere (SaaS)

Overall Satisfaction with AlienVault USM

We are 200 employees strong and have presence in 5 states. We utilize AlienVault (AV) across our entire MPLS network. It addresses the issue of visibility of our servers and workstations to analyze potential threats and less common issues with auditing we wouldn’t otherwise catch but can cause major issues if not resolved.
  • AlienVault is very customizable. We can set up many built-in rules and alerts which saves time but can also be extremely granular to properly scan our unique network.
  • Great technical support. When I need assistance setting up a new sensor or target scan, AlienVault engineers are there to assist and get me on track.
  • Although the interface shows a lot of development and thought put into it, there are some buggy issues at times with simple form submission and web navigation.
  • Initially setting up Alien Vault in our environment was challenging and there was a lack of support around the “hardware level” meaning our VMWare environment.
SolarWinds provides a great way to analyze logs and search through many different servers to look for patterns and common issues. AlienVault does that and much more. Its real-time capable scanning and threat detection are much more developed than others.
AT&T sold us AlienVault as a replacement for penetration testing but before investing do your research. AV is a great tool but ultimately is just. SEIM. It’s the best SIEM on the market but it does have limitations. AT&T needs to be aware of this and how they sell this.