AlienVault OSSIM (discontinued) vs. Cisco Secure Network Analytics

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
AlienVault OSSIM (discontinued)
Score 8.9 out of 10
N/A
AlienVault OSSIM was an open source Security Information and Event Management (SIEM). AlienVault was acquired by AT&T Cybersecurity, now LevelBlue, and OSSIM is no longer available for sale.N/A
Cisco Secure Network Analytics
Score 8.9 out of 10
N/A
Cisco Stealthwatch is a network behavior analysis product based on technology acquired by Cisco with its Lancope acquisition in 2015.N/A
Pricing
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Features
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
AlienVault OSSIM (discontinued)
7.5
Ratings
3% below category average
Cisco Secure Network Analytics
-
Ratings
Centralized event and log data collection9.40 Ratings00 Ratings
Correlation6.90 Ratings00 Ratings
Event and log normalization/management8.10 Ratings00 Ratings
Deployment flexibility8.20 Ratings00 Ratings
Integration with Identity and Access Management Tools9.30 Ratings00 Ratings
Custom dashboards and workspaces9.40 Ratings00 Ratings
Host and network-based intrusion detection9.20 Ratings00 Ratings
Data integration/API management5.30 Ratings00 Ratings
Behavioral analytics and baselining5.40 Ratings00 Ratings
Rules-based and algorithmic detection thresholds5.30 Ratings00 Ratings
Response orchestration and automation6.30 Ratings00 Ratings
Reporting and compliance management8.40 Ratings00 Ratings
Incident indexing/searching6.40 Ratings00 Ratings
Best Alternatives
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.7 out of 10

No answers on this topic

Medium-sized Companies
Sumo Logic
Sumo Logic
Score 9.4 out of 10
InsightIDR
InsightIDR
Score 9.5 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 9.4 out of 10
InsightIDR
InsightIDR
Score 9.5 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Likelihood to Recommend
9.3
(0 ratings)
7.6
(0 ratings)
Likelihood to Renew
-
(0 ratings)
8.0
(0 ratings)
Usability
8.0
(0 ratings)
7.3
(0 ratings)
Availability
-
(0 ratings)
7.0
(0 ratings)
Support Rating
7.9
(0 ratings)
7.9
(0 ratings)
Implementation Rating
-
(0 ratings)
8.0
(0 ratings)
Ease of integration
-
(0 ratings)
8.0
(0 ratings)
User Testimonials
AlienVault OSSIM (discontinued)Cisco Secure Network Analytics
Likelihood to Recommend
The most obvious scenario in which OSSIM is well suited is in a single office/home office (SOHO) or small business, in which budget is reduced but asset discovery and vulnerability management are greatly needed and appreciated. OSSIM is lightweight and free, so the real challenge to face is to hire or assign an administrator to manage and operate it, instead of any investment on an expensive appliance. Also, as resellers, promoting usage of OSSIM to customers charging for professional services for installation, administration, and maintenance (remember that OSSIM doesn't have official support from AlienVault) is a great asset for the organization.
Read full review
Cisco
Secure Network Analytics is a compulsion to any organization looking to secure their network in silence with a complete record and analysis of the threats. All the critical information of the client is also preserved for instance and assistance for future needs. Cyber-attacks can’t even think to roam about your
network in any case.
Read full review
Pros
  • Threat analysis. It can correlate different events happening to detect a pattern or an attack.
  • Dashboard provides a clean, single location to see what is going on in our environment.
  • Up to date open threat exchange means everything new popping up out there is included and watched for in our environment.
Read full review
  • It's really good at mapping out like what applications are, like who's talking to what. To see if someone thinks that a particular application is only being used a certain way and we can validate what's talking to that system with the tool.
Read full review
Cons
  • Creating custom rules is a bit complicated
  • Reporting could be improved
  • Agent has caused conflicts with a couple of our other applications
Read full review
  • Tool is little hard to configure so need to be light to save resource consumption.
  • Features are so in-depth that integrated guidance should be available to help the users on how to use.
  • Graphical view can be improved to make it more convenient to understand the data representation.
Read full review
Likelihood to Renew
No answers on this topic
Cisco Secure Network Analytics is a fantastic tool, but does require some setup and upkeep which may turn off smaller IT Security teams. However, once all the flows are set up and the product is functioning with the proper rules, the insight into your network is fantastic. For us, the product has a significant ROI and will be a product we keep up on.
Read full review
Usability
AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
Read full review
Strong and complete tool which gives comprehensive methods to discover cyber security incidents and prevent data leakage. In case of common use of Cisco StealthWatch and Cisco ISE, you will receive [the] ability [to] not just discover cyber security incidents but also dynamically respond to them. This makes StealthWatch one of most valuable products through[out] [the] whole Cisco Security product portfolio.
Read full review
Reliability and Availability
No answers on this topic
We haven't had too many issues with the uptime and availability of CSNA, but the application does have a lot of dependancies and we have seen issues after an upgrade that caused an outage for several hours.
Read full review
Support Rating
Everything is done through MSSP and installation pro services. Once those hours are burned up, then you're on your own without a lot of help. Typically the pro services hours aren't enough to get past 60 days and MSSP are hit and miss. We had a miss for installation helpers.
Read full review
Overall winner because it exceeds our expectations by answering all our requirements and at the same time empowers our operations thru other built-in capabilities it has. Visibility is a key to security operations and Cisco StealthWatch really gives us a magnifying glass to check all logs in the network for threat intelligence and threat hunting.
Read full review
Implementation Rating
No answers on this topic
Implementation of the product can be tedious, especially fine tuning its rules to customize it to your environment. However, after that is done, CSNA is a very useful and flexible product that would enhance the security posture of any corporate network.
Read full review
Alternatives Considered
AlienVault OSSIM as the first experience with a SIEM is very fine, especially if your company is an SMB. Every SIEM shares some features in common with other products, features such as log retrieval and normalization. So if you stick with principles, you can learn other SIEM products as well. If your environment is not of a minimum size, LogRhythm might be overkill for your network, same with McAfee Enterprise Security Manager.
Read full review
While other platforms such as Nagios and Solarwinds NTA provide visibility of the traffic, it either (*) does not provide API/programmatic way to pull the data to other platforms or (*) does not interface with secondary security systems to report on malicious traffic activity. Ultimately, these platforms accomplish the visibility, but do little else in the overall IT/security ecosystem of product, making them "dead end" data flow products where data goes in but does not share elsewhere.
Read full review
Return on Investment
  • OSSIM and the installers didn't really help us optimize at installation. OSSIM went without optimization for almost two years before that fact was noticed. I think this decreased ROI.
  • Finding and researching incidents is much faster with all data available. Sometimes too much data, though.
Read full review
  • Once tuned and baselines established, it is far easier to identify issues on a network
  • Management is able to look at the dashboard and fairly quickly get an update on the status of how the network is performing and what threats may be out there
  • Reports can be scheduled to send on a regular basis to all involved with management of the infrastructure and the security team
Read full review
ScreenShots