ArcSight Enterprise Security Manager (ESM) vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2023
 

Categories and Ranking

ArcSight Enterprise Securit...
Ranking in Security Information and Event Management (SIEM)
12th
Average Rating
7.8
Number of Reviews
93
Ranking in other categories
No ranking in other categories
LogRhythm SIEM
Ranking in Security Information and Event Management (SIEM)
6th
Average Rating
8.4
Number of Reviews
166
Ranking in other categories
Log Management (8th)
 

Market share comparison

As of June 2024, in the Security Information and Event Management (SIEM) category, the market share of ArcSight Enterprise Security Manager (ESM) is 1.0% and it decreased by 62.5% compared to the previous year. The market share of LogRhythm SIEM is 5.0% and it decreased by 22.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
Log Management
6.0%
 

Featured Reviews

it_user285777 - PeerSpot reviewer
Jan 12, 2017
Most devices are covered out-of-the-box. I would like to see high-end, predictive analytics.
The most valuable features are flexible setup of the architecture and large coverage of devices. Most devices deployed in enterprise environments are covered out-of-the-box by ArcSight. Unlike a few other solutions, the last-mile connectivity with ArcSight agent servers is free and flexible across…
DH
Oct 11, 2022
Robust with helpful workflow management and good log filtering
So far, it's pretty robust, and yet, we look for more improvements. On a day-to-day basis, maybe we could look for more improvements with automation, however, so far, it's good. In terms of blind spots, we are looking for more improvements since we don't have visibility over everything. Right now, we just use LogRhythm for our on-prem solution, not our cloud solution. We could definitely use more improvements with that in the next product. Ingesting logs into the web console user interface and probably updating the threat intelligence database are the two places where we'd like to see improvement. We get a lot of noise. Oftentimes, we see a lot of false positives, so possibly using AI or machine learning would be ideal. Implementing that more into the next product would help us actually determine whether it's a false positive or legitimate threat.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The stability of ArcSight Enterprise Security Manager is good."
"The filters and the ability to do what you want are the most valuable features. There is nothing that you cannot do in this solution. It has all the features, which makes it very dynamic."
"ArcSight gives us better visibility into threats that were unknown earlier."
"ESM has valuable features for event prediction and security analysis."
"Stable solution with good customer service support."
"This process has helped to improve our organization because we have centralized the intra-group security equipment logs."
"The webpage algorithm is the most valuable feature because it was the fastest feature for searching the logs, events, and correlation."
"We do consulting and I get feedback from our clients that the product really helped them with compliance, especially with GDPR."
"It supports most standard log sources."
"I would say the most valuable feature of LogRhythm is that it has built-in UEBA functionality, among other basic Windows packages."
"LogRhythm's GUI is easy to explore. We also like other features, such as its integration with other security solutions, log correlation, and the deployment of use cases."
"As a SIEM, probably the best feature is that it can be tuned effectively. There are very few SIEMs out there that can be effectively tuned to provide you with meaningful information and not be overwhelmed."
"The log analysis feature is valuable."
"Its ability to work with all different sorts of log sources has been extremely valuable."
"The ability to drill down and pivot from an event is one of the biggest advantage the product has compared to other things that I have seen in the market."
"The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation."
 

Cons

"Deployment typology could be improved. Difficult to scale across all the different lines of businesses."
"We have pricing issues. ArcSight ESM may not be the most user-friendly option, and its interface is quite traditional. However, despite these aspects, we find it a good cybersecurity solution. It needs to improve the dashboards, documentation, and support as well."
"The API integration could be better, and I'd like to see more machine-learning capabilities in the future."
"It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are."
"The dashboard looks a bit cumbersome."
"The stability isn't quite perfect. We occasionally run into problems."
"The solution could be more stable."
"ArcSight ESM could improve the alerts for the storage capacities or actions."
"It should have some more message monitoring features. It can also have some free message monitoring tools."
"We need to get better training for things like creating code and playlists. The way it's done now takes a long time."
"There used to be the ability to create alarms based on message text that was included in LR Version 6.x that has been removed in LogRhythm 7.x, and on that, I would like to see it added back."
"Appliance-based setups can sometimes pose scalability issues"
"We've tried to work with a couple of engineering department guys there. We've called them and called them but we never hear anything back."
"The reporting on the dashboard should be improved from a management perspective. It would be helpful if they adjusted the colors and the presentation to make things clearer and easier to read."
"The console installation is an area with a shortcoming in the solution that needs improvement. If LogRhythm SIEM can offer a web console, it would be great."
"Sometimes, the tool fails to get the correlated events that triggered the alerts."
 

Pricing and Cost Advice

"We have a license to use this solution. The price of ArcSight Enterprise Security Manager is expensive."
"We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees."
"​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders.​"
"The licensing cost is affordable if you get an enterprise license. The licensing is based on EPS, so you can probably provide a package of license for multiple ESMs with their correlational end fees. It is cost-effective."
"The product licenses are inexpensive."
"ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value."
"There is a license required for this solution."
"Aggregation can help a lot in pushing down licensing costs."
"LogRhythm's licensing is based on MPS. There are some add-on features like advanced UEBA, the cloud component for advanced UEBA, and SIEM."
"It costs a great amount, but its pricing is competitive with some of the other vendors. For licensing and support, we pay about 20,000. There are no additional costs or anything like that."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"LogRhythm's pricing and licensing is extremely competitive and it's one of the top three reasons we continue to invest in the platform."
"The pricing is very reasonable and accessible compared to other products in the market but I am not very sure about the exact licensing cost per year for our company."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"Look for whatever will give you the most value. That's the main point. It is not one size fits all."
"In comparison to the competition, they are more affordable. This allows us to do more with less."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
13%
Manufacturing Company
9%
Government
9%
Educational Organization
38%
Computer Software Company
9%
Government
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What do you like most about ArcSight Enterprise Security Manager (ESM)?
We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities.
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
The pricing model is expensive compared to open-source alternatives, especially as your needs grow.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What do you like most about LogRhythm NextGen SIEM?
LogRhythm does a very good job of helping SOCs manage their workflows.
What is your experience regarding pricing and costs for LogRhythm NextGen SIEM?
LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform.
 

Also Known As

Micro Focus ArcSight, HPE ArcSight, ArcSight
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about ArcSight Enterprise Security Manager (ESM) vs. LogRhythm SIEM and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.