TrustRadius: an HG Insights company

LevelBlue USM Anywhere

Score4.3 out of 10

733 Reviews and Ratings

What is LevelBlue USM Anywhere?

The LevelBlue USM Anywhere XDR platform (replacing the former AlienVault USM) delivers threat detection, incident response, and compliance management.

AlienVault USM: Simplifying Security with Cost-Effective Threat Detection.

Use Cases and Deployment Scope

Our organization uses AlienVault USM to enhance the security posture and streamline our clients' threat detection and response. The product helps us address critical business problems, such as identifying and mitigating security threats, monitoring network activity, and ensuring compliance with regulations. Our use case involves deploying USM across our network to monitor logs, detect anomalies, and respond to incidents effectively.

Pros

  • Asset discovery.
  • Real-time threat detection.
  • Centralized log management.
  • Provides actionable insights into emerging threats.
  • Intrusion detection.

Cons

  • Enhancing user interface intuitiveness.
  • Granular customization options for alerts and reporting.
  • Integration with third-party tools and expanding support for emerging threat intelligence sources would be beneficial since the alien app only supports a few.

Return on Investment

  • AlienVault USM has significantly improved our and our client's overall security posture.
  • Reducing the risk of cyber threats and data breaches.
  • Improved regulatory compliance.

Alternatives Considered

IBM Security QRadar SIEM

Other Software Used

IBM Security QRadar SIEM, Fortinet FortiGate, Proofpoint Insider Threat Management

Best product I've seen for a smaller enterprise network.

Pros

  • Security event correlation.
  • Security event alarms
  • Security event investigations
  • Potential vulnerability identification

Honest Opinions Only

Pros

  • Vulnerability visibility and remediation
  • Log management and compilation

Cons

  • The vulnerability scanner could use some tweaking as I feel it isn't always working
  • The integrations could use some more testing

Solid unified security solution

Pros

  • Endpoint detection notification with detailed logs
  • Vulnerability detection
  • Investigation tracking

Cons

  • Endpoint protection agent rollout
  • Vulnerability management historical tracking
  • Endpoint tracking across DHCP infrastructure

Alternatives Considered

Rapid7 Nexpose, Splunk Enterprise and Logger (formerly HPE Arcsight Logger)

Great introduction to SIEMs

Pros

  • Great documentation.
  • Overall good support.
  • Nice UI.

Cons

  • UI can be wonky at times.
  • Log search from the SIEM UI is quite troublesome as every filter applied performs the search again.
  • Some features can stop working seemingly out of nowhere, requiring contacting support.

Alternatives Considered

IBM QRadar