ArcSight Logger is an impressive tool for collecting and analyzing large amounts of log data. The UEBA feature has reduced event response time, while the provisioning engine is highly valued. The solution is specifically designed to manage large environments of network devices and servers. The log digestion features from threat intelligence platforms are valuable, and it is capable of handling massive database platforms. Users appreciate the speed of search operations and ease of exporting and forwarding logs to other products.
Areas for improvement in ArcSight Logger include better functioning connectors and updated user manuals. Some find the product slow, making it difficult to work with, and the dashboard is not intuitive or efficient, requiring training to use effectively. There have also been issues with storage capacity, and the search mechanism is complicated for new users. There are also performance issues noted by some when ingesting and forwarding data.
ArcSight Logger is seen to be an expensive and difficult enterprise product to set up. Licensing costs are charged yearly and are standard.
Users report positive experiences with ArcSight Logger's customer service and technical support. The support is considered good, with some users praising their cooperation and accommodation during the problem-solving process.
There have been complaints about the availability of level-3 engineers in certain time zones, leading to delays in receiving support.
Some found the initial setup straightforward and easy, while others found it to be time-consuming and complex. There are multiple components to address, and setting up the use cases can also take a significant amount of time.
The scalability of ArcSight Logger is highly praised by its users, with many rating it a 10 out of 10. The solution is easy to expand and add more sources to, with some users having up to 6,000 machines sending logs.
Proper identification of areas that require more resources is important for successful scaling, as the architecture of ArcSight Logger can become complex for larger organizations.
ArcSight Logger is found to be a stable solution.
ArcSight Logger was previously known as Micro Focus Arcsight Logger, HPE Arcsight Logger.