AT&T AlienVault USM Review

Some of the valuable features are real-time email alerts, event correlations, and log management.

What is most valuable?

  • Real-time email alerts
  • Event correlations
  • Log management
  • System monitoring
  • Network monitoring
  • Up-time monitoring
  • OTX threat intelligence
  • Vulnerability scanning reporting

There are too many to list.

How has it helped my organization?

It has given us insight into our network:

  • What is on it
  • What traffic is on it
  • What is happening on our servers

It is one location to view many things.

What needs improvement?

The menu system can be a little confusing, until you use it for a while. Such as at the top right there is a “settings” menu. Which is more of a user profile menu. I would like that to say what it is “My Profile.” Under the “Settings” menu I had rather see true system settings. Such as User Accounts, Configuration Backups/Restore, SMTP server Setting, AD (LDAP) settings, Password Policies, and other true System Settings. There is also a large button at the right called “Configuration.” I would change that to something like “Deployment Settings”. Under this menu I would have settings specifically related to “this deployment of AlienVault”. Such as Plugins, Sensors, Remote Locations, and Services Running on this deployment (with the ability to Enable/Disable these and Start/Stop these). Also here I would have a sub-menu called “System Performance” with metrics (CPU usage, Swap, Ram, database health (with cleanup and compress options), Network Traffic In/Out performance for each NIC, and etc. Currently Threat Intelligence items are also under Configuration. I would make a separate “Threat Intelligence” menu and expand upon it to cover more items. Just my thoughts.

I guess it comes down to my being old school and would like traditional menus. Such as text-style drop-down menus from the top and not the huge big button menus. Like File, Analysis, Environment, Reports, Settings, Deployment Settings, Preferences, help, and etc. The text-type tend to be much more explanatory as to what is in them below. I know a lot of software has gone to the big button/ribbon style menus (MS Office). I assume that is to make things mobile friendly. To me it makes navigation less easy and more confusing and the big buttons take up too much screen real estate that I have rather see for other things such as alarms and real-time system activities.

For how long have I used the solution?

We have been using this solution for just over one year.

What was my experience with deployment of the solution?

There have been no major deployment issues.

What do I think about the stability of the solution?

There have been no major stability issues.

What do I think about the scalability of the solution?

There have been no scalability issues. We recently moved from 150 asset licenses to unlimited and the process was very easy.

How is customer service and technical support?

Customer Service:

Customer support is excellent. Support has been good for simple config issues and for alert questions. They have a great forum base as well as live support.

Technical Support:

I would rate technical support as very good.

Which solutions did we use previously?

We used hardware based as well as open source solutions before. We still use some of them, but AlienVault allowed us to consolidate a lot of services into one.

How was the initial setup?

The installation was straightforward. We use the VMware base All-In-One USM. It was quite straightforward. It required a little customization, but it was not too difficult to sort through.

What about the implementation team?

It was a joint collaboration.

What was our ROI?

We saw a positive ROI within six months, especially in terms of manpower.

What's my experience with pricing, setup cost, and licensing?

Just give them a call. They can work with you in many ways to help you get what you need.

Which other solutions did I evaluate?

We looked at several options. And we were already using several of them, both paid and open source. AlienVault allowed us to combine several solutions into one.

What other advice do I have?

If you are interested, sign up for some of their webinars, download the free trial or open source versions, and play with it.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
1 visitor found this review helpful
1 Comment
author avatarTami Andrews

Thanks for your time to review USM and for the feedback!

Sign Up with Email