---
title: LevelBlue USM Anywhere Reviews
meta_title: 'LevelBlue USM Anywhere Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 114 reviews by the users' company size, role or industry
  to find out how LevelBlue USM Anywhere works for a business like yours.
aggregate_rating:
  rating_value: 4.4
  review_count: 114
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: System Security
  url: https://www.g2.com/categories/system-security
---


# LevelBlue USM Anywhere Reviews
**Vendor:** LevelBlue  
**Category:** [Security Information and Event Management (SIEM) Software](https://www.g2.com/categories/security-information-and-event-management-siem)  
**Average Rating:** 4.4/5.0  
**Total Reviews:** 114
## About LevelBlue USM Anywhere
LevelBlue USM Anywhere is a cloud-based security management solution that accelerates and centralizes threat detection, incident response, and compliance management for your cloud, hybrid cloud, and on-premises environments. USM Anywhere includes purpose-built cloud sensors that natively monitor your Amazon Web Services (AWS) and Microsoft Azure cloud environments. On premises, lightweight virtual sensors run on Microsoft Hyper-V and VMware ESXi to monitor your virtual private cloud and physical IT infrastructure. With USM Anywhere, you can rapidly deploy sensors into your cloud and on-premises environments while centrally managing data collection, security analysis, and threat detection from the AlienVault Secure Cloud. Five Essential Security Capabilities in a Single SaaS Platform AlienVault USM Anywhere provides five essential security capabilities in a single SaaS solution, giving you everything you need for threat detection, incident response, and compliance management—all in a single pane of glass. With USM Anywhere, you can focus on finding and responding to threats, not managing software. An elastic, cloud-based security solution, USM Anywhere can readily scale to meet your threat detection needs as your hybrid cloud environment changes and grows. 1. Asset Discovery 2. Vulnerability Assessment 3. Intrusion Detection 4. Behavioral Monitoring 5. SIEM




## LevelBlue USM Anywhere Reviews
  ### 1. It is good for the small org. to start with security monitoring.

**Rating:** 2.5/5.0 stars

**Reviewed by:** Nisarg S. | Cyber Security Expert, Enterprise (> 1000 emp.)

**Reviewed Date:** June 23, 2022

**What do you like best about LevelBlue USM Anywhere?**

They have an easy-to-understand UI, the case management is really good. Also, suppression of the false-positive area is very easily available. Onboarding of the data sources are easy.

**What do you dislike about LevelBlue USM Anywhere?**

Availability of the SIEM tool is the major issue here. They have a lot of downtimes and even sometimes without prior notice, it is not accessible. Also the performance is very poor. It takes minutes after clicking once.

**What problems is LevelBlue USM Anywhere solving and how is that benefiting you?**

We have multiple security data sources, so it was a bit difficult to monitor all at the same time. But AlienVault allows us to monitor all things at one place and allowed us to configure rules over there.

  ### 2. It does the job

**Rating:** 3.0/5.0 stars

**Reviewed by:** Clark B. | Small-Business (50 or fewer emp.)

**Reviewed Date:** July 21, 2018

**What do you like best about LevelBlue USM Anywhere?**

The software is user-friendly, and anyone can be trained to use it. New employees don't take a LOT of time trying to get used to it. In my organization's scenario, the on-premise appliance provides great value as we are a small company with site inter-connectivity. Where I am not too sure of is how exactly the product scales with very large networks with separate Windows and network domains.


**What do you dislike about LevelBlue USM Anywhere?**

Could be a little less expensive for other companies to try out. Walking through all the devices after a Nmap or device discovery scan can be tedious to get the data correct

**What problems is LevelBlue USM Anywhere solving and how is that benefiting you?**

The vault helps protect all kinds of data and helps with encryption as well


**Official Response from Tami Andrews:**

> Clark - Thank you for taking time to provide your feedback!

  ### 3. Okay Solution that does not play well with others

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** April 24, 2018

**What do you like best about LevelBlue USM Anywhere?**

The log analysis component works well and adding additional alerting rules is pretty simple.
They have a large number of modules for ingesting logs from a variety of systems.
Support is pretty good.
Open threat exchange is an excellent idea and well implemented.
 The UI is ok
Annual cost is better than most
Using the USM client is a quick and easy way to forward system logs into USM.
They have a easy to read task list of what is in their pipeline for new features.

**What do you dislike about LevelBlue USM Anywhere?**

The lack integration with other tools.  They have a ticket system that is ok, it would be better if they had integration with third party tools like Jira.
They have assets that are used to conduct scans and assign modules for understanding logs taken from it.  Again there is no integration with any third party asset management system.
They have a vulnerability scanner however its not as through as some of the alternatives and you can not initiate scans via an api.
They claim to have a compliance scanner what they really have is a set of canned reports that you can provide to an auditor.  A compliance scanner is something like openscap.
They only allow in the ingesting and processing of Office 365 logs in their cloud solution.  There is no reason why this couldn't also be done with their on premise solution as well.
It would seem that development of their USM product has slowed to a crawl.  If you monitor their change lists on their website the upcoming changes to their USM product is woefully lacking.  It would be better if they used the same code base for both platforms and when one feature was added to one platform it would also be available to the other.

**Recommendations to others considering LevelBlue USM Anywhere:**

Do a feature comparison and go with the system that has the best cost for the features you need.
Qualys appears to be the most featured product but the most expensive.
Rapid 7 is a little more expensive but has a few more features that Alienvault needs to add.
I would take another look at tenable's solution as its changed a good bit since my last eval.
Alienvault may be missing some of the features I was looking for but they have provided great support and their features cover most of what I was looking for.

The Alienvault USM Appliance seems to be lagging behind their USM Anywhere product as far as development goes.  If you are not required to have Fedramp certified cloud services I would recommend going with USM anywhere over the USM appliance.  However USM Anywhere does cost a bit more.

**What problems is LevelBlue USM Anywhere solving and how is that benefiting you?**

AlienVault USM analyses our logs and reports vulnerabilities.


**Official Response from Tami Andrews:**

> Thank you for your feedback and comments. I would like to connect you with someone on the product and/or support team so that the issues you've raised can be addressed and hopefully resolved. If you'd like to reach out to me directly, please do so on my corporate email: tandrews@alienvault.com. I would be more than happy to get your review escalated to the proper team(s). Thank you again!

  ### 4. It’s decent 

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Sporting Goods | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 15, 2018

**What do you like best about LevelBlue USM Anywhere?**

I like the display, It is aesthetically pleasing 

**What do you dislike about LevelBlue USM Anywhere?**

Too complicated. While the display is great, it is not as user friendly as it could be

**What problems is LevelBlue USM Anywhere solving and how is that benefiting you?**

Solving possible hacker problems. 

**Official Response from Tami Andrews:**

> Thank you for taking time to provide your feedback!

  ### 5. AlienVault USM 

**Rating:** 3.0/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Enterprise (> 1000 emp.)

**Reviewed Date:** February 23, 2018

**What do you like best about LevelBlue USM Anywhere?**

Alarms for bad actors.  Notifications to email on specific events.  Reporting on custom events is nice for tracking usage.  

**What do you dislike about LevelBlue USM Anywhere?**

Couple of dislikes...  HIDS is very slow so if you're trying to audit Active directory logons for a specific user forget it.  Plugins are just too hard to write if you aren't a programmer.  Need a professional to do any real "tweaking" as support only does break fix.

**Recommendations to others considering LevelBlue USM Anywhere:**

Learn Regex/Python

**What problems is LevelBlue USM Anywhere solving and how is that benefiting you?**

SIEM window pane for threats and HIPAA compliance through audits and notifications.

**Official Response from Tami Andrews:**

> Thank you for taking time to provide your feedback!


## LevelBlue USM Anywhere Discussions
  - [How is AlienVault, Splunk and Vijilan compared in terms of pricing?](https://www.g2.com/discussions/33327-how-is-alienvault-splunk-and-vijilan-compared-in-terms-of-pricing) - 1 comment, 1 upvote

- [View LevelBlue USM Anywhere pricing details and edition comparison](https://www.g2.com/products/levelblue-usm-anywhere/reviews?filters%5Bnps_score%5D%5B%5D=3&section=pricing&secure%5Bexpires_at%5D=2026-08-14+04%3A17%3A31+-0500&secure%5Bsession_id%5D=226daa97-b189-40fb-b1ee-5df2a3e17106&secure%5Btoken%5D=9fc9a0ab693bd20bf54cd0b95dabd1997940a5e36ebbcbbea5a1bec3ea8a088c&format=llm_user)

## LevelBlue USM Anywhere Features
**Additional Functionality**
- Penetration Testing
- Alerts/Notifications
- Audit Trail
- Anti Virus
- Vulnerability Scanning
- Remote Monitoring & Management
- VPN
- Behavior Analytics
- Reporting/Analytics
- Real-Time Notifications
- Access Controls/Permissions
- SSL Security
- Patch Management
- Event Logs
- Anomaly/Malware Detection
- DNS Leak Protection
- Third-Party Integrations
- Server Monitoring
- Real-Time Monitoring
- Compliance Management
- Network Provisioning
- API
- Email Alerts
- Security Auditing
- Intrusion Detection System
- Data Visualization
- Two-Factor Authentication
- Generative AI
- Firewalls
- AI Copilot
- Anti Spam
- Threat Response
- Activity Monitoring
- Risk Alerts
- Data Loss Prevention
- Single Sign On
- Intrusion Prevention System
- Secure Login
- Policy Management
- Activity Dashboard

**Prevention**
- Intrusion Prevention
- Firewall
- Encryption
- Security hardening
- Cloud Data Protection

**Security**
- Compliance Monitoring
- Anomoly Detection
- Data Loss Prevention
- Cloud Gap Analytics

**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans
- Anomaly/Malware Detection

**Response**
- Resolution Automation
- Resolution Guidance
- System Isolation
- Threat Intelligence
- Incident Investigation

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Network Management**
- Activity Monitoring
- Asset Management
- Log Management
- Network Monitoring
- Server Monitoring
- File Integrity Monitoring
- Real-Time Monitoring
- User Management
- Endpoint Management
- Compliance Management
- Incident Management
- Vulnerability Management
- Policy Management
- Event Logs

**Detection**
- Intrusion Detection
- Security Monitoring
- Anti-Malware / Malware Detection

**Compliance**
- Governance
- Data Governance
- Sensitive Data Compliance

**Network**
- Compliance Testing
- Perimeter Scanning
- Configuration Monitoring
- Vulnerability Scanning
- Source-Code Scanning
- Web Scanning

**Records**
- Incident Logs
- Incident Reports

**Security**
- Data Security
- Data loss Prevention
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Incident Management**
- Event Management
- Automated Response
- Incident Reporting
- Real-Time Reporting

**Administration**
- Compliance
- Administration Console -
- API / integrations

**Administration**
- Policy Enforcement
- Auditing
- Workflow Management

**Application**
- Manual Application Testing
- Risk Analysis

**Management**
- Incident Alerts
- Incident Case Management
- Workflow Management

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Security Intelligence**
- Threat Intelligence
- Vulnerability Assessment
- Behavioral Analytics
- Data Examination
- Real-Time Data

**Generative AI**
- AI Text Summarization

**Agentic AI - Security Information and Event Management (SIEM)**
- Autonomous Task Execution
- Multi-step Planning
- Proactive Assistance
- Decision Making

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Runtime Container Security
- Asset Discovery
- Threat Intelligence
- Vulnerability Protection
- Alerts/Notifications
- Vulnerability/Threat Prioritization
- Generative AI
- SQL Injections
- Real-Time Analytics
- Threat Protection
- Web-Application Security
- Password Protection
- Website Crawling
- Vulnerability Assessment

**Additional Functionality**
- Real-Time Notifications
- Audit Trail
- Application Security
- Risk Analysis
- AI Copilot
- Data Import/Export
- Alerts/Notifications
- Prioritization
- Security Auditing
- Search/Filter
- Compliance Tracking
- Generative AI
- API
- Third-Party Integrations
- Activity Dashboard
- Data Visualization

**Generative AI**
- AI Text Generation
- AI Text Summarization
- Generative AI

**Agentic AI - Intrusion Detection and Prevention Systems (IDPS)**
- Autonomous Task Execution
- Proactive Assistance

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security

## Top LevelBlue USM Anywhere Alternatives
  - [IBM QRadar SIEM](https://www.g2.com/products/ibm-ibm-qradar-siem/reviews) - 4.4/5.0 (283 reviews)
  - [Microsoft Sentinel](https://www.g2.com/products/microsoft-sentinel/reviews) - 4.4/5.0 (275 reviews)
  - [Splunk Enterprise Security](https://www.g2.com/products/splunk-enterprise-security/reviews) - 4.3/5.0 (224 reviews)

