- Powerful Correlation
- Customization
- Integration capabilities
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Network investigation is poor but it's highly customizable
What is most valuable?
What needs improvement?
- Very complex install and management
- Steep learning curve
- Poor Network Investigation
- Poor analytics.
For how long have I used the solution?
Six years.
What do I think about the stability of the solution?
Yes, Logger, ESM and Connector ecosystem if not set up properly, lead to stability issues both in point operations as well as integrations.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.
What do I think about the scalability of the solution?
No. ArcSight is very scalable.
How are customer service and support?
3 out of 5.
What about the implementation team?
We implemented it in-house.
What was our ROI?
Poor as the product takes more effort to generate value. Its CAPEX cost is high too.
What other advice do I have?
If you really want the power and flexibility of customizing your Security monitoring and correlation, go with ArcSight, but beware of the effort involved in set up and maintenance.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Consultant at a tech services company with 51-200 employees
The ESM and logger are powerful tools but log support needs improvement
What is most valuable?
Too many to name, but here are a few:
- Its versatility when it comes to vendor support.
- The ESM and logger are powerful tools. If used properly, we can achieve much more than we previously could. The Alert and Case Tracking mechanism contribute to the work of ESM and Logger.
- Express, all-in-one component is best for small businesses.
- NTP is efficient in blocking identified threats.
- ArcSight Flex Connector Development module is an excellent feature if you want to get the logs from unsupported vendor products.
How has it helped my organization?
I am a service provider for this product, so I provide value to the customer based on their requirements. The requirements are generally based on the lines of compliance and better security vision of what is going on in the organization, and who is doing what etc. and to mitigate external threats like port scans, DOS, malware ingestion, phishing etc.
What needs improvement?
Better reporting with the nice look and feel available in the wider market; also more vendor log support. HP should improve their Tech Support status.
For how long have I used the solution?
3+ years
What was my experience with deployment of the solution?
A few, depending on the specific organization's structure and policies.
What do I think about the stability of the solution?
No
What do I think about the scalability of the solution?
The solution itself is very scalable, but it is also a lot more expensive than other players.
How are customer service and technical support?
Customer Service: PoorTechnical Support: Poor
Which solution did I use previously and why did I switch?
No
Which other solutions did I evaluate?
Splunk, RSA Envision, McAfee Nitro and IBM QRadar
What other advice do I have?
Consider the complexity of this solution and choose the right people to deploy it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.
System Engineer at a tech services company with 51-200 employees
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation. They need to fix some bugs and increase the search speed.
Valuable Features
The dashboard is the most valuable feature for us as it can show a lot of information about real-time incidents.
Improvements to My Organization
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation.
Room for Improvement
They need to fix some bugs and increase the search performance speed. Sometimes there are issues when I perform log correlations.
Deployment Issues
We have had no issues with the deployment.
Stability Issues
There have been no stability issues.
Scalability Issues
We have had no issues scaling it for our needs.
Customer Service and Technical Support
Customer Service:
5/10
Technical Support:5/10
Initial Setup
The initial setup was quite easy and straightforward.
Implementation Team
I work for a reseller, and we set up ArcSight for our customers, and I am learning a lot about its architecture.
Other Solutions Considered
For SIEM, I think HP ArcSight is a leading competitor alongside Splunk.
Other Advice
You need to learn about architecture and practice more before implementation since this product is not easy to learn and takes time to master.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technological Officer at a tech consulting company with 51-200 employees
Very useful tool for intelligence building as it has many use cases and many rule sets
Pros and Cons
- "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
- "It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are."
What is our primary use case?
We use ArcSight Enterprise Security Manager for any type of cyber security attack.
It is in the cloud and on the customer's infrastructure. I am only deploying one agent and the agent is deploying all the information from the customers and then sending it to the cloud.
I am an integrator, but we sell our services. I'm not selling the software directly to customers. I'm selling my service with this product.
What is most valuable?
It is a very useful tool for intelligence building because it has many use cases and many rule sets.
What needs improvement?
It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are.
In the next release, it would be nice if the Logger model and the ESM model would be merged. Right now there are two big models, Logger and ESM, but from a Windows perspective, it is not good because they're sending Logger and ESM separately. So if you need ESM, you have to buy both Logger and ESM but if you only need Logger, you are buying just Logger. You can deploy them on one system, but you have two different systems and different databases. My suggestion would be to merge Logger and ESM together.
For how long have I used the solution?
I have been using ArcSight Enterprise Security Manager for about a year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Arc Sight Enterprise Security Manager is scalable.
The number of people running it should be based on the organization's size. If you have a company with 500 assets, you should have at least one field engineer for the ESM product and two security analysts to operate this software. This is minimum. One engineer and two security analysts is minimum to start if the organization is midsize.
How are customer service and support?
Their technical support is generally good. On a scale of five, I'd give them four out of five.
How was the initial setup?
The initial setup is complex.
Installation is not complex, but Micro Focus also has different intelligence products. One runs on containers and it is quite complex to install and use, but it is a different product. So maybe if we can remove this wall then we should be all right.
I have two products from Micro Focus. I have this ESM and one for Web. It is for user IT behavior analytics. The second product is quite complex and it's linked to it. Then you have to connect these things together. So the complexity is in the Web product, not in ESM.
Our own site deployment took about one month to deploy and we can deploy services for our customers in about two weeks minimum. But that is a minimum. If the infrastructure is big, it may take up to two or three months. If the infrastructure is not logging or if there are many customer applications, it makes it complex to deploy. Every ESM product will be complex to implement if the organization is big and the logging is not enabled correctly.
What other advice do I have?
My advice to anyone considering Arc Sight Enterprise Security Manager is to just read the manual. Just read the manual and documentation.
On a scale of one to ten, I would rate it a nine.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CISO and DPO at ValueLabs LLP
Good visibility into end-to-end communications helps discover security threats
Pros and Cons
- "ArcSight gives us better visibility into threats that were unknown earlier."
- "We would like the ability to easily identify either unused resources or those that are being used sub-optimally."
What is our primary use case?
Flexibility, high ingestion rate, and complexity of use cases.
How has it helped my organization?
ArcSight gives us better visibility into threats that were unknown earlier. We now have an ability to assess end-to-end communications, as well as alerts from various security solutions along the path.
What is most valuable?
The most valuable features are lists, correlation, escalation matrix, and customers.
What needs improvement?
The following needs to be improved:
- We would like the ability to easily identify either unused resources or those that are being used sub-optimally.
- ESM should make usage of variables and other such deep customizations, highly intuitive.
- User behavior analytics is too pricey but an essential tool.
For how long have I used the solution?
We have been using ArcSight for eight years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior ICT Security Officer at a financial services firm with 1,001-5,000 employees
It provides us with event correlations that are automated and prioritized according to level of security risk and compliance violation.
Valuable Features:
- Real-time rules for threat detection
- Event correlations that are automated and prioritized according to level of security risk and compliance violation
Improvements to My Organization:
It allows us to be in better compliance with security protocols. It also gives us a better global vision of what is happening in the organization in terms of security threats and how best to analyze and mitigate them.
Room for Improvement:
I would like to have native cluster for connectors as a software version and not as an appliance. It also needs a better disaster recovery procedure.
Use of Solution:
We've been using ArcSight since 2007.
Deployment Issues:
We've deployed it without any issues.
Stability Issues:
We haven't had any issues with instability.
Scalability Issues:
It's scaled fine for our needs.
Other Solutions Considered:
We chose ArcSight when they had no real competitor and we stayed with them.
Other Advice:
I'm pleased with the current capabilities.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber threat Intelligence Manager at CyberLab Africa
Scalable, good technical support, but stability could improve
Pros and Cons
- "We have been satisfied with the support."
- "The solution could be more stable."
What is our primary use case?
We are using ArcSight Enterprise Security Manager (ESM) for data analytics. We monitor the reports on security event information.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
The solution could be more stable.
What do I think about the scalability of the solution?
We have not had any issue with the scalability.
We have approximately 20 users using this solution in my organization.
How are customer service and technical support?
We have been satisfied with the support.
How was the initial setup?
The installation was easy.
What about the implementation team?
We had assistance with the implementation of the solution. We have approximately five individuals that do the maintenance.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution.
What other advice do I have?
I would recommend this solution to others.
I rate ArcSight Enterprise Security Manager (ESM) a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Information Security Engineer at a tech services company with 501-1,000 employees
The user has multiple levels of options to generate reports and get alerted based on conditions.
Valuable Features
- Collection - Collects logs from a wide range of products, even those not supported by default and the users can develop a connector for log collection.
- Detection - Caliber to detect subtle attacks with a powerful correlation engine.
- Report/Alert - The user has multiple levels of options to generate reports and get alerted based on conditions.
Improvements to My Organization
By using ArcSight ESM and its correlation technology, it thwarts multiple attacks from external sources before exploitations such as SQL injection, UNIX password file attempt, brute force to published servers, and more.
In addition, internal frauds have been prevented through preventing unauthorized login attempts to the firewall, database, critical servers, etc.
Room for Improvement
ArcSight Connector appliance needs some improvement, as it has some bugs which triggers issues most of the time. I believe that the Connector is going to hit end-of-service.
Deployment Issues
We experienced no issues with the deployment.
Stability Issues
We had the bugs in Connector as detailed in the Areas for Improvement section.
Scalability Issues
We've had no issues with scalability.
Customer Service and Technical Support
Customer Service:
3.5*
Technical Support:Technical support should be improved. Many times, I've raised a case but none of them solved it and it took the guys from the Protect724 forum so solve my issue. The support team simply collects the logs from end users and makes you wait, and you carry on passing the same information which is available in the Admin guide.
Initial Setup
All you need is proper planning and pre-requisites information, and it's straightforward. Some newbies say that this product is hard to handle, but basically practice makes perfect.
Other Advice
HP are doing their job perfectly by bringing new features in every version, such as RepSM, HA capability, etc. It has never failed me.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine EventLog Analyzer
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?