AlienVault OSSIM was an open source Security Information and Event Management (SIEM). AlienVault was acquired by AT&T Cybersecurity, now LevelBlue, and OSSIM is no longer available for sale.
N/A
RackFoundry Total Security Management (discontinued)
Score 1.4 out of 10
N/A
RackFoundry was a firewall solution with VPN, SIEM, automated vulnerability scanning and log management features scaled for SME’s. It has been discontinued and is no longer available.
N/A
Pricing
AlienVault OSSIM (discontinued)
RackFoundry Total Security Management (discontinued)
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
AlienVault OSSIM (discontinued)
RackFoundry Total Security Management (discontinued)
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
AlienVault OSSIM (discontinued)
RackFoundry Total Security Management (discontinued)
Considered Both Products
AlienVault OSSIM (discontinued)
Verified User
Anonymous
Chose AlienVault OSSIM (discontinued)
Originally my organization leveraged alien value due to the lower cost of entry and ability to manage it as a service provider. Unfortunately, after several years of working with this tool, it became unwieldy to use as it felt that almost every useful report had to be created …
We did not evaluate or use any other product previous to AlienVault [OSSIM]. We had a specific need to meet our audit requirements and AlienVault [OSSIM] provided all the features needed as well as being simple enough to deploy without any dedicated staff. Real-time alerts …
We have not used any other products similar to AlienVault so I do not have anything to compare it to. We did look at a few others when first purchasing, but at this point, I do not recall what they were.
Best bang for the buck. Darktrace did not perform even close to AlienVault. I ran them concurrently. AlienVault consistently found issues that DarkTrace didn't pick up, and the DarkTrace incidents were false positives. At one point, DarkTrace stated I had 2,000 servers and I …
OSSIM is the free version of the Alien Vault USM and comes packed with most of the features you will need to get going. Like most free to use products, it is missing aspects that make the use of the product much more productive.
As an example, you will need a separate system for …
AlienVault OSSIM as the first experience with a SIEM is very fine, especially if your company is an SMB. Every SIEM shares some features in common with other products, features such as log retrieval and normalization. So if you stick with principles, you can learn other SIEM …
AlienVault OSSIM has the upper ante in initial deployment price, being that it's open source. Also, with perhaps the exception of SolarWinds, it has a lower optimal requirements for onsite deployment, hence your OPEX won't be hit very hard by investing in new hardware to suit …
RackFoundry Total Security Management (discontinued)
Verified User
Anonymous
Chose RackFoundry Total Security Management (discontinued)
We choose Rackfoundry because it was supposed to be a budget friendly solution that punched above its weight class. Instead what we got was a virtual appliance that powers a web app that does not work.
Chose RackFoundry Total Security Management (discontinued)
There are a few reasons we chose Rack Foundry:
1. At the end of the day cost is a huge concern for a small company. With that being said we had a great sales person who walked us through all the offerings and basically worked with us to get us to be in a position where we can …
Chose RackFoundry Total Security Management (discontinued)
Well I have experience with the big names: SecureWorks, IBM and Splunk. Individually their logging tools are much better than RackFoundry's Total Security Management. This is great for large corporations and urban cities, however not so great for municipalities, mid size …
RackFoundry Total Security Management (discontinued)
Likelihood to Recommend
The most obvious scenario in which OSSIM is well suited is in a single office/home office (SOHO) or small business, in which budget is reduced but asset discovery and vulnerability management are greatly needed and appreciated. OSSIM is lightweight and free, so the real challenge to face is to hire or assign an administrator to manage and operate it, instead of any investment on an expensive appliance. Also, as resellers, promoting usage of OSSIM to customers charging for professional services for installation, administration, and maintenance (remember that OSSIM doesn't have official support from AlienVault) is a great asset for the organization.
I would not recommend RackFoundry to any company whatsoever. At first it seems like a viable solution for the cost. Offering SOC monitoring, implementation and deployment all-in-one seems like a great deal. However it all falls apart when push comes to shoves. As it currently stands we are just over a year into our deployment. All we have to show for it is a fancy web app that does not display any information. In the year that this deployment has been ongoing it has taken us a few months just to get the virtual appliance installed. Then it was another few months of back and forth until we finally got credentials. Then when I finally logged in we began the process of deploying agents and began collecting data. Shortly afterward things began to stall to where they are now. We faced major issues with the web app, scans were not running, assets were not reporting in and data and reports were not being generated. After doing some more research and googling I realized that we were not alone with these issues. Countless other reports from companies who have had similar issues to ours. Each time I ask when the issues were going to be resolved, I got the same answer every time: "The next release should fix the issues you have been experiencing", only for the next release to come, and the issues remain.
AlienVault OSSIM is far easy to use and manage - provided you know what you're doing. As any SIEM application, there is some background knowledge required in order to take advantage of the product's functionalities, such as the log correlation and analysis. Other than that, the application is quite usable and robust.
Everything is done through MSSP and installation pro services. Once those hours are burned up, then you're on your own without a lot of help. Typically the pro services hours aren't enough to get past 60 days and MSSP are hit and miss. We had a miss for installation helpers.
AlienVault OSSIM as the first experience with a SIEM is very fine, especially if your company is an SMB. Every SIEM shares some features in common with other products, features such as log retrieval and normalization. So if you stick with principles, you can learn other SIEM products as well. If your environment is not of a minimum size, LogRhythm might be overkill for your network, same with McAfee Enterprise Security Manager.
Well I have experience with the big names: SecureWorks, IBM and Splunk. Individually their logging tools are much better than RackFoundry's Total Security Management. This is great for large corporations and urban cities, however not so great for municipalities, mid size businesses and companies who fluctuate between 1-7 members on their IT staff. Why? Because it takes too much of their resources and integration with other products gets a little rough as you will need to configure your preferences to theirs. When a company has stability it is great to have a name brand product, however renewals and upgrade costs can be taxing to an organization.
OSSIM and the installers didn't really help us optimize at installation. OSSIM went without optimization for almost two years before that fact was noticed. I think this decreased ROI.
Finding and researching incidents is much faster with all data available. Sometimes too much data, though.