What do you like most about AlienVault OSSIM?
Thanks for sharing your thoughts with the community!
The most valuable feature is the logging capability.
Its user-friendliness is the most valuable. It is very easy to use and explore. The dashboard is very well packaged and integrated. You don't have to spend a lot of time in configuring it and checking out the RPM etc.
It is also free and very powerful.
You can customize the dashboards as well as the reporting.
The threat policies of the solution are always very advanced and the best in the market. They are very persistent in terms of keeping up with security protocols.
Inbuilt IDS, inbuilt integration with threat intelligence platform and with vulnerability assessment modules.
Better than other SIEM solutions because almost everything can be integrated.
The dashboard is the solution's most valuable aspect. It brings everything into one central point where I can actually look at it and go, "Okay, I understand what's going on."
OSSIM is the only solution that includes the large number of modules that we need: a vulnerability scanner, a network IDS system, a host IDS system.
The most valuable features of this solution are the data correlation and vulnerability assessment.
The open vault component and the checking of vulnerabilities are the most valuable features. The page management helps with this. If you know how your device is vulnerable at least you can do something about it.
You pay monthly for the solution. I think it's one of the best products. If you compare with other companies, like LogRhythm, etc., the top 8 or 10 CMs, I think Alien Vault has the best price-performance ratio.
The initial setup was straightforward. I didn't have any problems.
With AlienVault you get everything in one box.
The solution has a very good open source community, and whenever we have problems, we are always able to resolve it online.
The solution is very stable. Compared to Qradar and Splunk, it's very stable.
The threat alerts it gives me from time to time on harmful code within the network, or if they are generating any network traffic, are very useful.