Splunk uses forwarders to ship logs to its platform and then it does the parsing and normalization. Vijilan uses its virtual appliance, ThreatSensor, to do the parsing and normalization on the prem first. This decentralized and distributed architecture felt more stable and secure than AlientVault by design. Splunk is great but costly. Vijilan partnered with Humio and crowdstrike. For large MSSPs, I’d go with vijilan.
Already have AlienVault USM (from AT&T Cybersecurity)?
About AlienVault USM (from AT&T Cybersecurity)
AlienVault USM Anywhere is a cloud-based security management solution that accelerates and centralizes threat detection, incident response, and compliance management for your cloud, hybrid cloud, and
With over 2.5 million reviews, we can provide the specific details that help you make an informed software buying decision for your business. Finding the right product is important, let us help.