TrustRadius: an HG Insights company

AlienVault OSSIM (discontinued) vs. Splunk Enterprise Security

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    AlienVault OSSIM (discontinued)

    Score8.9 out of 10
    N/AAlienVault OSSIM was an open source Security Information and Event Management (SIEM). AlienVault was acquired by AT&T Cybersecurity, now LevelBlue, and OSSIM is no longer available for sale.N/A

    Splunk Enterprise Security

    Score9.8 out of 10
    N/ASplunk Enterprise Security is an analytics-driven SIEM that helps to combat threats with actionable intelligence and advanced analytics at scale.N/A
    Pricing
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Community Pulse
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Considered Both Products
    Discontinued Products
    Chose AlienVault OSSIM (discontinued)
    Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created …
    Incentivized
    Cisco
    No answer on this topic
    Key User Insights
    Would buy again
    No answers on this topic
    99%
    Would buy again
    100 Answers
    Delivers good value for the price
    No answers on this topic
    94%
    Delivers good value for the price
    84 Answers
    Happy with the feature set
    No answers on this topic
    94%
    Happy with the feature set
    95 Answers
    Lived up to sales and marketing promises
    No answers on this topic
    93%
    Lived up to sales and marketing promises
    74 Answers
    Implementation went as expected
    No answers on this topic
    91%
    Implementation went as expected
    84 Answers
    Features
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of AlienVault OSSIM (discontinued) and Splunk Enterprise Security
    Feature
    AlienVault OSSIM (discontinued)
    7.5
    10 Ratings
    3% below category average
    Splunk Enterprise Security
    8.4
    102 Ratings
    8% above category average
    Centralized event and log data collection9.49 Ratings9.3100 Ratings
    Correlation6.910 Ratings8.699 Ratings
    Event and log normalization/management8.110 Ratings8.5100 Ratings
    Deployment flexibility8.210 Ratings8.3101 Ratings
    Integration with Identity and Access Management Tools9.36 Ratings7.896 Ratings
    Custom dashboards and workspaces9.49 Ratings9.2102 Ratings
    Host and network-based intrusion detection9.29 Ratings7.996 Ratings
    Data integration/API management5.32 Ratings8.498 Ratings
    Behavioral analytics and baselining5.42 Ratings7.795 Ratings
    Rules-based and algorithmic detection thresholds5.33 Ratings8.596 Ratings
    Response orchestration and automation6.32 Ratings7.087 Ratings
    Reporting and compliance management8.44 Ratings8.695 Ratings
    Incident indexing/searching6.43 Ratings9.2101 Ratings
    Best Alternatives
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    IBM Security QRadar SIEM
    Score9 out of 10
    IBM Security QRadar SIEM
    Score9 out of 10
    Enterprises
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Likelihood to Recommend
    9.3
    (10 ratings)
    8.9
    (103 ratings)
    Likelihood to Renew
    -
    (0 ratings)
    9.0
    (3 ratings)
    Usability
    8.0
    (1 ratings)
    7.5
    (2 ratings)
    Availability
    -
    (0 ratings)
    9.1
    (1 ratings)
    Performance
    -
    (0 ratings)
    8.2
    (1 ratings)
    Support Rating
    7.9
    (3 ratings)
    6.6
    (6 ratings)
    In-Person Training
    -
    (0 ratings)
    9.1
    (1 ratings)
    Online Training
    -
    (0 ratings)
    8.2
    (1 ratings)
    Implementation Rating
    -
    (0 ratings)
    9.1
    (1 ratings)
    Configurability
    -
    (0 ratings)
    7.3
    (1 ratings)
    Contract Terms and Pricing Model
    -
    (0 ratings)
    7.3
    (1 ratings)
    Ease of integration
    -
    (0 ratings)
    6.4
    (1 ratings)
    Product Scalability
    -
    (0 ratings)
    9.3
    (100 ratings)
    Professional Services
    -
    (0 ratings)
    9.1
    (1 ratings)
    Vendor post-sale
    -
    (0 ratings)
    8.2
    (1 ratings)
    Vendor pre-sale
    -
    (0 ratings)
    8.2
    (1 ratings)
    User Testimonials
    AlienVault OSSIM (discontinued)Splunk Enterprise Security
    Likelihood to Recommend
    Discontinued Products
    If this is your first experience with a SIEM, this one can get you started. Take the time to learn the ins and outs of the product and you'll most likely be satisfied with it if your company is an SMB. If you need compliance reports, OSSIM is too small for you, you'll need to go with USM or USM Anywhere.
    Incentivized
    Read full review
    Cisco
    Well suited: Splunk ES is highly recommended in an environment with many data sources and experienced computer engineers. It has a steep learning curve, but once that hurdle is crossed, it is absolutely a beast. It is also very expensive, so a company putting a high amount of budget in Security is needed. Not well suited: Splunk ES is not recommended if a company has only a few sources and some non-technical IT users. The price won't justify the fewer data sources and scratching just the surface level. Moreover, non-technical IT users would be better off with something that has a query builder, unlike Splunk.
    Incentivized
    Read full review
    Pros
    Discontinued Products
    • Asset discovery. Once installed in a centric, network-accessible server, OSSIM can poll all your endpoints with common protocols (SSH, SNMP, WMI) to detect and discover site-wide assets to monitor. You only need to group them by your own criteria once added to the product.
    • SIEM Event Correlation. You can define quite complex correlation rules to detect possible suspicious or malicious actions or attempts in your network, in order to categorize them as real threats or as false positives, thus streamlining your risk assessment and management.
    • Ease of installation. The entire AlienVault OSSIM is self-contained in an ISO file, which can be burned into a DVD or just mounted in your server of choice (physical or virtual) for deployment. The installation process is automated and quote verbosed, with options for static IP, email messaging and others.
    • Ease of access. Being AlienVault OSSIM a self-contained appliance, it can be accessed via web by any device that supports a web browser, being that desktops, workstation, mobile devices, etc. The OSSIM dashboard and other features are automatically rearranged to adapt to the particular device being in use.
    Incentivized
    Read full review
    Cisco
    • Advanced Threat Detection and Correlation: ES stands out in its ability to detect sophisticated threats by correlating data from multiple sources. For instance, it can identify unusual patterns in user behavior, cross-referencing with network logs to flag potential insider threats.
    • Real-time Monitoring and Alerting: ES offers robust real-time monitoring capabilities. It excels in promptly alerting us to critical security events, such as suspicious network traffic spikes or unauthorized access attempts, allowing for immediate response.
    • Comprehensive Log Analysis: ES ingests and analyzes an extensive range of log data. It's particularly adept at parsing and making sense of complex log formats, making it a versatile tool for understanding system activities and security events.
    Incentivized
    Read full review
    Cons
    Discontinued Products
    • Creating custom rules is a bit complicated
    • Reporting could be improved
    • Agent has caused conflicts with a couple of our other applications
    Incentivized
    Read full review
    Cisco
    • ES on the cloud (SaaS) has too many limitations with platform administration.
    • Supported integrations are not always on par with enterprise support especially when dependent on 3rd-party proprietary APIs.
    • In later versions, unforeseen glitches seem to show up that have no resolution except version upgrade. This used to not be the case in prior versions which were very stable.
    Read full review
    Likelihood to Renew
    Discontinued Products
    No answers on this topic
    Cisco
    We are very happy with Splunk and would advise anyone to take a serious look at it. It might look pricey but the rewards Splunk offers seem endless.
    Incentivized
    Read full review
    Usability
    Discontinued Products
    AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
    Incentivized
    Read full review
    Cisco
    You definitely need to learn how to use Splunk to get the most of the tool. There are many courses available for free to get up to speed on the usability of the tool but it's not that simple. It will take time to digest all the data and to understand how to query for what you are looking for.
    Incentivized
    Read full review
    Reliability and Availability
    Discontinued Products
    No answers on this topic
    Cisco
    I'm not an ES user, but, in my implementation I usually try to prevent all service stops to guarantee High availability to the final customers.
    Incentivized
    Read full review
    Performance
    Discontinued Products
    No answers on this topic
    Cisco
    ES requires a very performant infrastructure: if it has it's performant, otherwise not. I had situation with a very performant infrastructure and I didn't notized that it was a distributed architecture, it seemed that there ware few data on my PC, othewise I experienced less performant infrastructures with less performaces.
    Incentivized
    Read full review
    Support Rating
    Discontinued Products
    Everything is done through MSSP and installation pro services. Once those hours are burned up, then you're on your own without a lot of help. Typically the pro services hours aren't enough to get past 60 days and MSSP are hit and miss. We had a miss for installation helpers.
    Incentivized
    Read full review
    Cisco
    It's good when it's responsive, but I've had times where I had to wait quite a while for a response. But these are typically the exceptions rather than the rule. When you do get a response it is always well-informed and appropriate. I would say they've been trending better over time with this.
    Incentivized
    Read full review
    In-Person Training
    Discontinued Products
    No answers on this topic
    Cisco
    I experienced only on-line training, but the trainers were very professional and competent. Maybe it could be more useful if they also have an experience in projects because sometimes they didn't have a real project experience to communicate to the students. Anyway, it was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself, aven if I have more than 10 years of Splunk activity experience.
    Incentivized
    Read full review
    Online Training
    Discontinued Products
    No answers on this topic
    Cisco
    It was very interesting and I learned many thing that's very difficoult (or maybe impossible!) to have by myself. The only problem was that, when I worked with the Splunk Professional Services, I found some difference between the training contents and the information from PS. In addition is required a long experience on Splunk Enterprise for the data ingestion part, in other words I'm able to work with ES because I'm worling on Splunk since 11 years, otherwise I'd some problem.
    Incentivized
    Read full review
    Implementation Rating
    Discontinued Products
    No answers on this topic
    Cisco
    It's a fantatic product and it was very useful the presence of Splunk Professional Services for the Design Phase and the final Health Check.
    Incentivized
    Read full review
    Alternatives Considered
    Discontinued Products
    Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created by hand. As other tools have come out with the ability to do automated responses such as Stellar Data processor, we have begun to evaluate alternatives.
    Incentivized
    Read full review
    Cisco
    Splunk enterprise is the only solution that we’ve been able to identify that provides risk based alerting, which allows our SOC to reduce analyst fatigue which would be a huge problem without it. Before RBA, there were thousands of alerts a day and it was impossible to review all of them
    Incentivized
    Read full review
    Contract Terms and Pricing Model
    Discontinued Products
    No answers on this topic
    Cisco
    for my exterience, unit pricing and billing frequency are correct. As I already said, I hint to have more discount flexibility, expecially with new customers, because there are competitors less expensive and very aggressive that are dangerous. In addition the possibility to don't pay the license for the development period could be a very interesting feature for the final customers.
    Incentivized
    Read full review
    Scalability
    Discontinued Products
    No answers on this topic
    Cisco
    - 8 out of 10 and took 2 for the data pipeline and administration part. Even if you'd like to improve yourself or your team, you have to pay a lot of money and it could be more than GIAC education + cert. - Normalization for Data models and CPU-based searches can be a problem sometimes.
    Incentivized
    Read full review
    Professional Services
    Discontinued Products
    No answers on this topic
    Cisco
    I had a fantastic experience with Splunk Professional Services: they worked with us in our last SON project (a SOC migration for a very large customer) and helped to build a multi tenent environment even if ES isn't a multi tenant platform. Th Splunk PS was a very professional and competent people, he is italian and was able to speak with our italian customers.
    Incentivized
    Read full review
    Return on Investment
    Discontinued Products
    • It's difficult to put a monetary value on security, but with proper monitoring and alerting, incidents will be easier to avoid.
    • Helps with your compliancy, as it automatically alerts you for critical events.
    • Collects logs in the cloud, so protected from local issues, like SAN failures.
    Incentivized
    Read full review
    Cisco
    • ES has highly impacted ROI because as the customer of the ES the work we do for creating use cases for clients in terms of security-related aspects by their logs has given more return than investment.
    • The correlation searches we run to get detailed results from the Data models are very less time-consuming than Splunk Enterprise itself we can get quick responses to the use cases and dashboards populated because of ES.
    • The CIM compliance feature is ES has made more jobs easy in the terms of finding more Authentication related data we can get data onboarded in the Email data model from O365 and search is email data model instead of searching for particular indexes.
    Incentivized
    Read full review
    ScreenShots