From a customer perspective, the most important thing is network visibility. Companies have more visibility on what is happening in the network, so they will be able to make decisions, whether automatic or human decisions, based on the analysis given by ArcSight Enterprise Security Manager (ESM). This helps improve the security within the organization.
Business Development Manager at Escom Bulgaria EOOD
Enables better network visibility; with artificial intelligence, correlation, and machine learning features
Pros and Cons
- "Feature-rich solution which provides better network visibility for improved security"
- "The onboarding process for this solution could be better. It also needs a better GUI."
How has it helped my organization?
What is most valuable?
The features I found most important in this solution are artificial intelligence and correlation tools. Machine learning which was recently added to the platform is also an important feature.
What needs improvement?
The onboarding process for this solution could be better.
Additional features I'd like to see in the next release is a better GUI (graphic user interface), and for them to include intelligence tools, e.g. dark web threat intelligence, etc.
For how long have I used the solution?
We've distributed ArcSight Enterprise Security Manager (ESM) in the last 12 months.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.
What do I think about the stability of the solution?
This solution is stable.
What other advice do I have?
We are a distributor here in Bulgaria for Micro Focus. We distribute ArcSight Enterprise Security Manager (ESM) here in Bulgaria and we are in touch with Micro Focus for the ArcSight portfolio.
I'm not a very technical guy. Especially for our market here in Bulgaria, it's very important to have local technical support from Micro Focus, e.g. presales engineers, to be able to close more sales, because the main competitor here: IBM Security QRadar has representation with local technical engineers. This is important when we are trying to do a new business.
Deploying this solution requires three to five engineers: network and EMC engineers.
ArcSight Enterprise Security Manager (ESM) is a very popular product with our customers, though we are trying to promote it daily and weekly to make it even more popular. We have a dedicated marketing channel for this.
My advice to future clients looking into implementing this solution is that every company needs it, especially in this day and age when it is mandatory to have cyber security investigation and protection. Another advice is that if you want this project to be successful, you must rely on a local technical team who will be able to implement and configure the product.
I'm rating ArcSight Enterprise Security Manager (ESM) an eight out of ten because there is still room for improvement.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Principal Enterprise Architect (Technology, Cloud & Security) at a retailer with 10,001+ employees
It supports cloud deployment and is very stable
Pros and Cons
- "The feature that I have found the most useful is that it can be deployed to the cloud."
- "The centralized dashboard for the hybrid cloud environment needs to be more focused. It needs to be redefined because it's missing most of the information. It should be a little bit easy to use. Currently, integration with various applications and connectors is not that easy. Deployment is easy, but integration is not that easy. ArcSight also has a very high bandwidth consumption to pull the local servers. It should have some kind of better process or ability to transfer files from on-premises to the cloud, from the cloud to on-premises, and from a cloud to another cloud."
What is most valuable?
The feature that I have found the most useful is that it can be deployed to the cloud.
What needs improvement?
The centralized dashboard for the hybrid cloud environment needs to be more focused. It needs to be redefined because it's missing most of the information.
ArcSight should also be a little bit easy to use. Currently, integration with various applications and connectors is not that easy. Deployment is easy, but integration is not that easy.
ArcSight also has a very high bandwidth consumption to pull the local servers. It should have some kind of better process or ability to transfer files from on-premises to the cloud, from the cloud to on-premises, and from a cloud to another cloud.
For how long have I used the solution?
I have been using ArcSight for six years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is not always scalable.
How are customer service and technical support?
I didn't take any kind of support.
Which solution did I use previously and why did I switch?
I have worked with IBM QRadar. IBM QRadar is very expensive, and it is not easy to deploy like ArcSight. It can't be deployed without an SME. ArcSight is better than IBM QRadar.
How was the initial setup?
The initial setup was very straightforward. It hardly took four weeks.
What other advice do I have?
If you have data centers, an SME or in-house resource to train people, and no budget constraint, then go with IBM. If you have a limited budget, hybrid environment, and untrained manpower, then go for Darktrace, AlienVault, or some other solution.
I would rate ArcSight an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.
Head - Professional Services at a computer software company with 51-200 employees
A mature and simple to use product, but needs a cloud deployment option
Pros and Cons
- "The product is quite mature. It's been around for a long time."
- "The biggest requirement is that there is no cloud solution for this product yet. They need to create a cloud version. It's the biggest thing they can do to make the solution better."
What is our primary use case?
We primarily provide this solution to clients.
What is most valuable?
The simplicity of the solution is the most valuable aspect of the product.
The product is quite mature. It's been around for a long time.
The integration is easy for the most part.
What needs improvement?
Over the past two years, a lot of improvements have been happening.
The biggest requirement is that there is no cloud solution for this product yet. They need to create a cloud version. It's the biggest thing they can do to make the solution better.
The dashboard and user interface need some work. It's my understanding that they are developing better versions of those now.
For how long have I used the solution?
I've been using the solution for eight years or so. I started working on Version Five and have continued to update it from there.
What do I think about the stability of the solution?
The stability of the solution is very good. It's pretty perfect, actually. We don't have crashes. It doesn't freeze. There aren't bugs or glitches. It's completely reliable.
What do I think about the scalability of the solution?
The solution is easily scalable. If an organization needs to expand it, they most certainly can.
What we used to do traditionally, to scale, that each device throws up certain EPS and we size the solution accordingly. Once they have a cloud solution, it will be even easier to scale.
The solution works for any size of organization, from small companies to large enterprises.
How are customer service and technical support?
The solution's technical support is excellent. I'm in India, however, their support is on a global scale.
HP as an organization had one toll-free number. You plug in your requirements. However, by the time it reached the team, it became difficult as everyone was routed centrally. However, once the site was taken over by Micro Focus, we are seeing some great improvements in the support.
How was the initial setup?
The initial setup is not complex. It's very straightforward.
If you have a well-skilled technician, you probably only need a few people to handle the deployment and maintenance.
In terms of how long a deployment takes, a SIEM implementation depends on the number of devices, and which we are integrating with. The kind of dashboards and reports the customer is looking for also come into play in calculating the amount of time that will be needed. Therefore, the duration of the implementation would be purely dependent on the client's specific needs.
A standard deployment is typically four weeks. However, I've seen some deployments take as long as 12 weeks.
What about the implementation team?
We deploy the solution for our clients. We also tend to handle the maintenance for our clients as well.
Which other solutions did I evaluate?
I have some experience with Splunk and Curator.
There are a few differences. Splunk, for example, is a native cloud product. That makes it excellent for scalability. Any on-premise challenges a company might face are answered by Splunk.
In both solutions, you are able to integrate and manage other devices as well, which isn't necessarily true on Arcsight.
What other advice do I have?
We're an authorized partner. We provide this solution to our clients.
In terms of implementation, new users should make a list of the requirements they need in order to have a broad idea of what they want the solution to achieve. Once they understand their requirements, it will be easier to find a solution that will match them.
For Arcsight, users need to go in with the compliance packs. Arcsight has some additional modules called compliance packs, which can get you automatic reports. That needs to be configured pretty well.
The biggest piece everyone needs to consider is the sizing part. It's an on-premise solution. If you are not buffering the sizing with at least about 25% additional computation and the storage space, then you're in for trouble down the line. Always go bigger than you need.
Overall, I'd rate the solution seven out of ten.
ArcSight, in the last one and a half years, have been delivering on time, in terms of a better dashboard, a better user interface, and now, with an add-on EDA. MailStore is also getting into it. We are seeing that they are catching up with what the market needs. We will have to wait and see what the new release brings. Version Eight is coming in now. They seem to be doing everything now and are committing for some great features in a future release.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Manager at Royal Cemerlang
Enables us to minimize the damages of WannaCry attacks
Pros and Cons
- "When WannaCry attacks I can minimize the damage. My company had no protection at the time. We get alerts in ArcSight and then whenever a user got a copy of WannaCry and the WannaCry malware wants to connect to the mother ship, it alerts me in the ArcSight dashboard, and that helps us a lot. We then just go to the user and erase the malware."
- "In other products, I have found that they use some kind of GUI that is drag and drop. While in ArcSight they use still scripting. They should keep scripting because some people prefer scripting but they should have the option for those who prefer using drag and drop."
What is our primary use case?
Our primary use case if for analyzing cybersecurity.
How has it helped my organization?
When WannaCry attacks I can minimize the damage. My company had no protection at the time. We get alerts in ArcSight and then whenever a user got a copy of WannaCry and the WannaCry malware wants to connect to the mother ship, it alerts me in the ArcSight dashboard, and that helps us a lot. We then just go to the user and erase the malware.
What needs improvement?
In other products, I have found that they use some kind of GUI that is drag and drop. While in ArcSight they still use scripting. They should keep scripting because some people prefer scripting but they should have the option for those who prefer using drag and drop.
They should do something similar to what Splunk is doing. They have Enterprise Security and ArcSight should include some use cases that concentrate on Enterprise Security.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
It's quite stable.
What do I think about the scalability of the solution?
Our initial sizing is enough for our needs.
How was the initial setup?
The initial setup was straightforward. The correlation engine took us a lot of time. It took us three months to do the implementation. We required two staff for deployment.
What about the implementation team?
We used a partner for the implementation.
What's my experience with pricing, setup cost, and licensing?
The pricing is great compared to others.
Which other solutions did I evaluate?
At the time that we were looking into options, we did a PoC for Splunk. We found that ArcSight is more user-friendly than Splunk because Splunk uses more scripting in the configuration and initial setup.
What other advice do I have?
I would rate it an eight out of ten. Not a ten because of the drag and drop feature I'd like for them to include and because I think they should include more enterprise security use cases.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Manager at a tech services company with 10,001+ employees
Allows me to view events in real time. The FlexConnector configuration is complex.
What is most valuable?
The web logger allows me to view and inquire about various events in real time. It is the most useful feature for me for the following reasons:
- Allows me to look at the traffic in real time
- Allows me to add filters that remove the traffic that is not interesting
- Allows me to narrow down my research to only important traffic.
- Helps me in my troubleshooting work. I need to know a bit of SQL query syntax, but that is straightforward.
- Allows me to create reports, evaluate my findings, and send information to my customers.
How has it helped my organization?
I was able to provide intelligence reports to my customers. The organization relies on this information in order to sell services.
What needs improvement?
I would like to see the following:
- An improvement in the connector/agent configuration.
The connector configuration is CLI based. If the connectors are pre-defined and built by HPE, then the configuration/installation seems to be OK.
- Making the FlexConnector configuration less complex.
You need development skills in order to do your job in creating/configuring agents and connectors. I tried to learn the syntax in order to customize the software (connectors and agents) for a particular device, and it was a nightmare. The cost for this work, via HPE consultancy, is huge.
For how long have I used the solution?
I've been using this product for three and a half years. I am one of the supporters of the product.
What was my experience with deployment of the solution?
Some of the connectors need to be developed in-house. There were also issues with forwarding events. We noticed that some logs were lost between connectors and the central reporting unit.
How are customer service and technical support?
I would give technical support a rating of 4 or 5 out of 10.
Which solution did I use previously and why did I switch?
We also use Splunk to compare features. ArcSight is the favorite solution for my organization.
How was the initial setup?
The initial setup is straightforward, but the customization can become a nightmare very easily.
What about the implementation team?
We had an in-house implementation. I would recommend a dedicated team for implementation, support, and operation.
What other advice do I have?
This product requires a dedicate team to operate it from a to z. HPE support needs to be clearly defined and considered.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Forensic Consultant at A Cyber 1 Company
Good out-of-the-box rules, but the integration and reporting features can be improved
Pros and Cons
- "The out-of-the-box rules that help us configure functioning rules within the environment are valuable."
- "Customer service and support is our biggest challenge."
What is our primary use case?
We use this solution in our customers company and we deploy the solution on cloud and on-premises.
What is most valuable?
The out-of-the-box rules that help us configure functioning rules within the environment are valuable. For example, they have good resources to help detect and populate the dashboard if something malicious happens. Additionally, we value a good visual representation of a company and network infrastructure.
What needs improvement?
The solution can be improved regarding integration with other security products, ease of implementing some features, and feeling like we're not utilizing the solution as best as we could. In the next release, the solution should incorporate some threat intel features and integrate well with other network solutions, EDRs, palm solutions and the sorts. Additionally, the reporting can be improved to bring out very insightful reports showing senior management value for the solution.
For how long have I used the solution?
We have been using the solution for approximately six months.
What do I think about the stability of the solution?
The solution is stable. I rate it an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable and has approximately 500 users utilizing it for enterprise businesses.
How are customer service and support?
Customer service and support are one of the biggest challenges we are having. Although it is provided, and once you log tickets, they follow up quickly, sometimes some of the challenges we face drag on for a while because of ironing out specific details about technical support and payments.
How was the initial setup?
The initial setup was a bit complex. Getting things running and configured took a while. Furthermore, some integrations were unavailable, and some had to be custom scripted, so getting the solution up and running was a bit tedious.
What about the implementation team?
We implement in-house, and it takes approximately two months to complete implementation.
What's my experience with pricing, setup cost, and licensing?
The licensing costs are high and the solution is priced through events that come in so the cost tends to be heavy on the client. The price of the license could be lower.
What other advice do I have?
I rate the solution a six out of ten. The solution is good, but its integration and reporting features can be improved. I advise users to have a mature security infrastructure and scale up their technical resources. However, for smaller organizations considering the solution, I advise them to think of other solutions before using ArcSight Enterprise Security Manager.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
CEO at Kapstone Technological Services LLP
A stable and scalable enterprise data security manager, but the initial setup could be more straightforward
Pros and Cons
- "ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product."
- "The initial setup could be more straightforward."
What is our primary use case?
I'm an administrator, and I implement ArcSight Enterprise Security Manager (ESM). I use ArcSight SIEM and have all the security information, events, logins, and security logs. We compile all the information so we can file and stop it from happening or provide an alert.
What is most valuable?
ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product.
What needs improvement?
The initial setup could be more straightforward.
What do I think about the stability of the solution?
ArcSight Enterprise Security Manager (ESM) is a stable solution. However, it depends on how well it's deployed in the customer's location.
Because SIEM doesn't have much to do with blocking the traffic, even if it doesn't get deployed well, it doesn't matter to the customer because the work is going on, and the traffic is flowing in.
It's just that the correlation will never happen. The security post of the company goes for all; that's the only problem. Apart from that, there would be no problem with the operations website.
What do I think about the scalability of the solution?
ArcSight Enterprise Security Manager (ESM) is scalable, but you must size it well.
How are customer service and support?
ArcSight technical support is a bit better than the QRadar.
How was the initial setup?
The initial setup is complex. In general, it takes about three months to implement this solution.
What other advice do I have?
I will only make recommendations based on the customer's requirements and environment.
On a scale from one to ten, I would give ArcSight Enterprise Security Manager (ESM) a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Works at NOOSC Global
Helpful for detecting malware and intrusions, but needs support for devices that are absent of log files
Pros and Cons
- "For the typical malware or intrusion, this solution assists us by identifying the symptoms based on network traffic from the application servers."
- "The weakness in this system comes about because, with so many different logs, it is possible that the security analyst will lose information."
What is our primary use case?
We have a customer who is using this solution for information security monitoring.
How has it helped my organization?
For the typical malware or intrusion, this solution assists us by identifying the symptoms based on network traffic from the application servers. We are then able to prevent others from accessing critical information.
What is most valuable?
I really like the dashboard.
What needs improvement?
One of the problems for the security center is that there are many logs that need to be retrieved from a variety of network devices. The weakness in this system comes about because, with so many different logs, it is possible that the security analyst will lose information. I would like to have better support for wide-area data analytics.
Ideally, I would like to see ArcSight have the ability to consume raw information, or raw data, without being dependent on a log file.
For how long have I used the solution?
Between five and six years.
What do I think about the scalability of the solution?
There are more than six thousand users. However, because it is a log-based system, the scalability is limited. As such, our customer is looking for a solution that can scale better as the number of users and the number of devices in the infrastructure increases.
How are customer service and technical support?
There is not much in terms of support that is available for this solution. There are not many people with the competency for visualization and creating use cases.
How was the initial setup?
The initial setup of this solution is pretty complex. Once this installation is complete, we need to set up the use cases.
Deployment for this solution took between three and six months and was performed with four to five people.
What about the implementation team?
A reseller assisted our customer with the deployment.
What's my experience with pricing, setup cost, and licensing?
The cost of the solution is not very high, although hiring a qualified analyst to work with the product is expensive.
What other advice do I have?
In summary, this solution requires a dedicated person that has specific competency in this product. It is not a plug and play product that allows you to simply focus on the analytics. It is not easy for an amateur.
The suitability of this solution depends on the complexity of the system. If the organization is very large, for example nationwide, then a log-based approach such as this one will be very difficult to implement.
Obviously, if the device does not generate a log then it is not supported by this solution. Our client has successfully deployed it for use with several devices, including firewalls and IPS, but they have no support for some in-house applications.
I would rate this solution a five out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Securonix Next-Gen SIEM
Google Chronicle Suite
ManageEngine EventLog Analyzer
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?