A must have for securing AWS Deployments.
One of the most difficult tasks with securing a deployment in AWS is full visibility of the environment. Most SIEM products I have tried to use previous to the AlienVault AWS USM were not AWS aware, e.g. handle CloudTrail logging etc. Having a centralized SIEM that can handle AWS console security while providing standard AlienVault USM SIEM functionality is a huge plus.
Installation:
Contrary to the other reviewer's comments, the installation of the AlienVault AWS USM went smooth, especially when you reach out to AlienVault support if you run into any issues. Since the AWS USM uses CloudFormation for deployment, when asked AlienVault quickly made changes to the template we used to deploy our instance so it would work with our existing VPC environment. Once this was done, launching and getting the AWS USM up and running was a piece of cake and took little effort on our part.
Post Installation:
Because we had turned on CloudTrail prior to deploying the AWS USM we had a lot of existing log data. It took some time for the AWS USM to ingest all of the logs however considering it was a large amount of data, it was expected.
Once the logs were parsed by the AWS I was presented with a slew of useful and very actionable information about our AWS environment. So much so I wished that the AWS USM had been available sooner.
AlientVault's USM SIEM was great, this new AWS USM is even better.