AT&T AlienVault USM Review

Valuable features include integrated vulnerability assessment, intrusion/anomaly detection and monitoring, with a simple management interface.


Valuable Features

Integrated vulnerability assessment, intrusion/anomaly detection and monitoring, with a simple management interface.

Improvements to My Organization

AlienVault provided improved visibility into the environment as well as the ability to report on the organization’s security posture.

Room for Improvement

Asset scanning and inventory (stale assets, scheduling scans) and correlation (false positives).

Use of Solution

2 years

Stability Issues

No.

Scalability Issues

Yes. Upgrading the network cards (from 1GB to 10GB) was not “supported” on the appliance, so we had to purchase a second one as a sensor. The secondary appliance with the 10GBs NICs is the same as the primary appliance, so this was disappointing.

Customer Service and Technical Support

High (seldom used).

Previous Solutions

No.

Initial Setup

Simple and straightforward. The bulk of the work is understanding your own environment and tuning events (syslog, scans, alarm).

Pricing, Setup Cost and Licensing

Pricing was a very important consideration and lower than the other SIEM solutions evaluated. The price point makes it accessible for SMB organizations that may be constrained of resources (budget and people/skills) so deployment can be gradual while still deriving value out of the solution.

Other Solutions Considered

SolarWinds, Splunk, LogRhythm.

Other Advice

As with any SIEM, it is not a “turn-key” or “set it and forget it” solution. It requires resources and skills to deploy, although this can be done in stages. Appropriate resources for maintenance is also key so the information is accurate, relevant and timely. Otherwise it becomes a repository of stale ignored events and alarms.

Disclosure: IT Central Station contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
1 visitor found this review helpful
1 Comment
Tami AndrewsVendor

Thanks Pedro for taking time to provide your feedback & comments.

26 June 17
Guest
Sign Up with Email