It's the security analyst for incident response, forensic investigations, and security monitoring.
Information Security and Business Data Protection Specialist at a comms service provider with 1,001-5,000 employees
The webpage algorithm is the most valuable feature because it is the fastest feature for searching logs, events, and correlation
Pros and Cons
- "The webpage algorithm is the most valuable feature because it was the fastest feature for searching the logs, events, and correlation."
- "The security area has room for improvement."
What is our primary use case?
How has it helped my organization?
It has improved our organization because we had many investigations that it helped us with.
What is most valuable?
The webpage algorithm is the most valuable feature because it was the fastest feature for searching the logs, events, and correlation.
What needs improvement?
The security area has room for improvement.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
November 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,816 professionals have used our research since 2012.
For how long have I used the solution?
More than five years.
What other advice do I have?
I would rate this solution a seven out of ten. To make it a ten they should develop a design for the security operations. It's a SIEM solution and I can see that it has some segregation of the consoles and duties for the different parties when we want to monitor different components like the security operations center.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sales Engineer at a tech services company with 1,001-5,000 employees
Enables you to create a dashboard for analytics and set alerts.
What is most valuable?
It is easy to use when we created some dashboards for analytics. ArcSight allows you to create a dashboard and provides an on-the-fly filter.
How has it helped my organization?
It makes things easy when I create a new alert.
What needs improvement?
They need to improve the Web UI, similar to how it is done with Splunk.
ArcSight is still using a Java app to do analytics.
ArcSight Express is using HTML5, which is good. However, the capabilities of ArcSight Express are not good when the data grows.
What do I think about the stability of the solution?
I did not have any issues with stability.
What do I think about the scalability of the solution?
I did not have any issues with scalability.
How are customer service and technical support?
Technical support responds quickly.
Which solution did I use previously and why did I switch?
We previously used RSA enVision. We had issues with the report generation.
How was the initial setup?
The installation is very easy.
What's my experience with pricing, setup cost, and licensing?
The licensing should come with EPS format, and not with EPD format.
What other advice do I have?
You need to first know the SIEM concept. SIEM can grow significantly, so you need to understand how to use a collector properly.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
November 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,816 professionals have used our research since 2012.
Information Security Consultant with 1,001-5,000 employees
ArcSight helps a lot in auditing system and network admins; Needs to improve in High Availability
What is most valuable?
The ArcSight log collection mechanism is simple and it supports a large number of devices. Rules, Report and Dashboard can be customized based on the user requirements and hence it helped a lot to impress our customers. Additionally, ArcSight has tight integration with incident response tools such as HP Threat Response Manager, CIRT and Encase. ArcSight provides platform to integrate third party dashboard tools such as idashboard and Tableau. Also HP ArcSight inbuild case management is very simple and can be exported to external HP service Manager.
How has it helped my organization?
ArcSight helps to track all configuration changes and correlates with corresponding service tickets. Hence, helps a lot in auditing system and network admins with minimal time and cost. ArcSight use cases which helps us to detect insider threats as well as external attacks. Before implementing SIEM, these were not detected by manual monitoring process. Lastly, ArcSight helps the human resource team and Fraud management team in incident analysis and provides forensic data as needed. This was always a challenge to the team previously.
What needs improvement?
As of now, HP doesn’t have healthy integration of flows, this could use significant improvement. High Availability is a major concern for all of our customers, HP needs to significantly improve in HA.
For how long have I used the solution?
I have been using this solution for the last 6 years.
What was my experience with deployment of the solution?
No. ArcSight implementation is simple and robust.
What do I think about the stability of the solution?
Yes. ArcSight Logger and Connector appliance RAID failed sometimes.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Customer Service: Good.Technical Support: HP support needs to improve a lot. For solving one ticket HP support takes a lot of time and there is no proper problem management process.
Which solution did I use previously and why did I switch?
I have been working with ArcSight since I started my career.
How was the initial setup?
Straightforward. All the components are clubbed into single installable so installation is very simple and straight forward.
What about the implementation team?
Vendor. They had a good amount of ArcSight implementation experience.
Which other solutions did I evaluate?
We evaluated Alien Vault.
What other advice do I have?
I would recommend buying ArcSight.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber threat Intelligence Manager at CyberLab Africa
Scalable, good technical support, but stability could improve
Pros and Cons
- "We have been satisfied with the support."
- "The solution could be more stable."
What is our primary use case?
We are using ArcSight Enterprise Security Manager (ESM) for data analytics. We monitor the reports on security event information.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
The solution could be more stable.
What do I think about the scalability of the solution?
We have not had any issue with the scalability.
We have approximately 20 users using this solution in my organization.
How are customer service and technical support?
We have been satisfied with the support.
How was the initial setup?
The installation was easy.
What about the implementation team?
We had assistance with the implementation of the solution. We have approximately five individuals that do the maintenance.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution.
What other advice do I have?
I would recommend this solution to others.
I rate ArcSight Enterprise Security Manager (ESM) a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Techniqal Lead Enterprise Solution at a tech services company with 51-200 employees
Arcsight ESM is one of the best SIEM platform having market leading corelation engine, which is the plus point of Arcsight ESM it is very stable by its distributed architecture and scalability.
Pros and Cons
- "I am satisfied with the solution's stability."
- "Micro Focus does not have a physical presence here in Pakistan, although IBM does."
What is our primary use case?
We help our customers to implement the solution to detect known threats by state of the art variety of use cased offerings.
How has it helped my organization?
Arcsight ESM help customer in Automation for their complex security use case in order to detect the bad guys.
What is most valuable?
Corelation Engine by corelating the cross domain logs.
What needs improvement?
OOB content is limited Microfocus should release the smart connector update on quaterly basis.
For how long have I used the solution?
I've been working with the Micro Focus ArcSight portfolio for nearly six years.
What do I think about the stability of the solution?
I am satisfied with the solution's stability.
What do I think about the scalability of the solution?
I am satisfied with the solution's scalability.
How are customer service and technical support?
We are satisfied with technical support and most of our problems have been resolved.
How was the initial setup?
Simple and pretty straight forward.
What about the implementation team?
We provide the implementation and maintenance services of the solution for our customers.
Which other solutions did I evaluate?
According to the Gartner Reports and Gartner Reviews, the main competitors of the solution are IBM and Splunk. They provide their services world-wide and do much implementation in the region.
the plus point for Arcsight ESM is having cross domain corelation feature.
What other advice do I have?
I rate ArcSight Enterprise Security Manager (ESM) as a 8 out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Information Security Analyst at a comms service provider with 1,001-5,000 employees
The roadmap is not clear but it has a very good correlation feature
Pros and Cons
- "The correlation feature is good."
- "The roadmap is not clear."
What is our primary use case?
Our primary use case is for security purposes. We are customers of ArcSight and I'm an information security analyst.
What is most valuable?
I think the correlation feature is one of the best features of ArcSight.
What needs improvement?
A lot of improvements could be made in the product. I think the roadmap is not clear, and there is no AI or machine learning solution.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
We haven't had any issues with stability.
How are customer service and technical support?
I think there is good technical skill with the technical support but their attitude and response time is not good.
How was the initial setup?
I recall that the initial setup was quite complex. We took subscription services for two weeks which covered the period of deployment.
Which other solutions did I evaluate?
We are actually moving to another solution because the roadmap is not clear. We are just a small team and we don't need to monitor 24/7. We're looking to replace it with another more intelligent solution like Splunk or Securonix.
What other advice do I have?
Honestly, I won't recommend the ArcSight to another person.
I would rate this solution a four out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Delivery Consultant - Security Solutions with 1,001-5,000 employees
By tweaking use case conditions one could identify potential security breaches, but admin is complex
Pros and Cons
- "Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events."
- "Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it."
How has it helped my organization?
Recent attacks like Shamoon and WannaCry were under continuous monitoring by using this solution. It is understood that every SIEM is a detective technology and not a preventive, but by tweaking the use case conditions one could identify potential security breaches.
What is most valuable?
Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events. Competitors offer the something similar but ArcSight does gives you more detail.
What needs improvement?
Complexity, administration. Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it.
What do I think about the stability of the solution?
Yes, quite a few times. But that depends on the admin, on how well the tool is maintained. Proper health checks are required on regular basis.
What do I think about the scalability of the solution?
Yes. Storage is an issue. Before deploying the product in the organization, proper scaling has to be done or else you end up losing the oldest data, hence failing to meet the audit.
How are customer service and technical support?
Eight out of 10.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
It was complex a few years. Lately it is all GUI and things are quite straightforward.
What's my experience with pricing, setup cost, and licensing?
ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value.
Which other solutions did I evaluate?
No.
What other advice do I have?
On-boarding is easy but administration is challenging and more fun.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solutions Architect- SIEM and Solutions with 1,001-5,000 employees
Most devices are covered out-of-the-box. I would like to see high-end, predictive analytics.
What is most valuable?
The most valuable features are flexible setup of the architecture and large coverage of devices. Most devices deployed in enterprise environments are covered out-of-the-box by ArcSight. Unlike a few other solutions, the last-mile connectivity with ArcSight agent servers is free and flexible across all location deployments.
How has it helped my organization?
I have implemented it for a few organizations and they have benefited by early attack detection and usage of the right incident response mechanisms.
What needs improvement?
I would like to see high-end, predictive analytics. ArcSight ESM has some features that help in advanced correlation rules creation. However, intelligence around predictive analytics, understanding the current security posture and ability to map it with possible threats in the future is not something that is present in ArcSight at the moment.
For how long have I used the solution?
We’ve been using ArcSight for 3 years.
What do I think about the stability of the solution?
I have not had any issues with stability.
What do I think about the scalability of the solution?
I have not had any issues with scalability.
How is customer service and technical support?
I have never used technical support much, but will give it 3/5.
How was the initial setup?
The connectors are straightforward. The baselining is where the issues start.
What's my experience with pricing, setup cost, and licensing?
Licensing is straightforward, but the solution is fairly pricey.
Which other solutions did I evaluate?
We looked at QRadar and LogRhythm.
What other advice do I have?
Ensure your scope is very clear and so are the components.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Google Chronicle Suite
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- What Questions Should I Ask Before Buying SIEM?
- RSA-EMC vs. other SIEM products?