- It has flexible and rich correlation capabilities. This is the most mature product in this area.
- It has the capability to manipulate every parameter - sub-strings, indexes, and custom functions.
- Active Lists - This is the most powerful feature which supports correlation. It also has multi-column active lists, parameters manipulation, and correlation capabilities that provide great flexibility.
- Full control of correlation flow - There are no black-box closed rules, unlike with McAfee Nitro, and no default aggregation which is hard to analyze, unlike Offenses in QRadar.
Senior IT Security Consultant, Cybersecurity Technology Services at a consultancy with 1,001-5,000 employees
It has flexible and rich correlation capabilities. It has the capability to manipulate every parameter - sub-strings, indexes, and custom functions.
What is most valuable?
How has it helped my organization?
This is the best product to build and supports SOC operations and SOC use cases.
What needs improvement?
The layout of the analyst's console need improvement. It has had no significant changes in at least nine years. Also, the advanced statistics in visualizations simply don't work, and I've performed an analysis of these functions.
For how long have I used the solution?
We've been using it for nine years.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
February 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What was my experience with deployment of the solution?
We have had no issues with the deployment.
What do I think about the stability of the solution?
We have had no issues with the stability.
What do I think about the scalability of the solution?
We have had no issues scaling it for our needs.
How are customer service and support?
I have not had to use tech support for at least two years now. From what I recall, they were good.
How was the initial setup?
The initial setup was simple and the implementation was straightforward as the supporting documentation is pretty good. Help for setup, which is available from the analyst console, is really great and complex with diagrams and screens.
What about the implementation team?
ArcSight makes it easy to achieve ROI because of its great flexibility.
Which other solutions did I evaluate?
This is the best SIEM solution on the market comparing to its competitors. I'm also familiar with IBM QRadar, RSA Security Analytics, McAfee Nitro, and Splunk.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Information Security Professional at a financial services firm with 1,001-5,000 employees
The response is good for Read/Write functions but I've encountered other minor issues. Better than it's competitors.
Valuable Features
Correlation Rules, Dashboards, Active Channels, Active Lists and many more. All these features make this product better than it's competitors.
Improvements to My Organization
ArcSight functions to integrate all network & security logs. It's very easy to use and thus real time monitoring has become easy by implementing active channel with all correlated alerts. SOC can monitor these correlated alerts and take action on them.
Room for Improvement
ArcSight uses Oracle DB, which is a bit slow for read/write functions and the main downside to this product. Recently, HP came up with a custom DB for ArcSight 6.0 which they are calling CORR engine. With these Read/Write functions, response is good but unfortunately I've encountered many other minor issues which have room for improvement.
Use of Solution
I've been using it for the last 6 years.
Deployment Issues
Yes, minor issues were encountered and resolved in a timely manner by HP support.
Stability Issues
Yes, Read/Write functions to DB is the main concern and this slows down the events processing.
Scalability Issues
I don't think there are any issues with Scalability.
Customer Service and Technical Support
Customer Service: GoodTechnical Support: Pretty good and timely.
Initial Setup
Slightly complex, but manageable.
Implementation Team
With the help of a vendor team. They are really helpful and cooperative.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
February 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Security Consultant at a tech services company with 5,001-10,000 employees
It makes user behavior and problems on the network visible, which we can then solve
Pros and Cons
- "The real-time analysis adds value."
- "HPE ArcSight has a quite steep learning curve."
How has it helped my organization?
- User behavior and problems on the network are visible, which we can then solve.
- We can align policies with how people actually behave.
- MSSP options are very good.
What is most valuable?
- Large scale installations work well.
- The new user interface is nice.
- The real-time analysis adds value.
- The default packages on the new HPE Marketplace are useful and give nice default dashboards and reports for most of the well-known products.
What needs improvement?
HPE ArcSight has a quite steep learning curve. If you get to know the product well, it is the most powerful product that I have worked with. It would be nice if new users could start using the product more easily.
What do I think about the stability of the solution?
I would prefer to roll out HPE ArcSight ESM on physical hardware. Without proper tuning, running ESM on VMware does not work well. Loggers and connectors work fine on virtual components.
10,000 events per second, including correlation, on pretty normal hardware work well.
What do I think about the scalability of the solution?
We encountered no issues with scalability. If needed, ESM can be setup in tiered form. Loggers can be scaled horizontally very efficiently. One box can handle a lot of events.
How are customer service and technical support?
Customer Service:
Seven out of 10. Basic questions get answered quickly. More in depth questions require more time, which can be a problem. It has improved over the last two years.
Technical Support:
Initially, the level of technical support was not so good. Once you get put through to the people in the US, you will get the better answers.
Which solution did I use previously and why did I switch?
I have also used LogRhythm, which in my opinion has less features than ArcSight. 80% of use cases work well on both, for the most interesting 20%, I would use ArcSight.
How was the initial setup?
Initial setup was straightforward. From the manuals, it is clear what components need to be installed where. Not having to install agents on servers is a big advantage of ArcSight over other solutions that I have worked with.
What about the implementation team?
We did not use a vendor team to do the implementation. Our in-house teams could roll out ArcSight very well. Cooperation of a lot of teams is often needed to implement SIEM solutions: networking, OS, and compliancy. Depending on your company structure, cooperation between teams can cost the most time.
What was our ROI?
I have not been involved in the ROI calculations and considerations, thus I cannot give my thoughts on this point.
What's my experience with pricing, setup cost, and licensing?
Do not scale out (horizontally) too quickly. A good box can handle a lot of EPS. You will not need to buy more licenses if you use one box in a good way. Also, aggregation can help a lot in pushing down licensing costs.
Which other solutions did I evaluate?
We also looked at Splunk and LogRhythm for every installation. All three have their own benefits. For large scale installations with multiple users and (sub) companies, ArcSight is the best option.
What other advice do I have?
Get a training course and start working with it quickly after getting your course. It is easy to forget all the options ArcSight has.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Director, Corporate Information Security at a comms service provider with 1,001-5,000 employees
It correlates security events and then allows us to take action to address those events.
What is most valuable?
The most valuable feature for us is its ability to correlate security events and then allowing us to take action to address those events.
How has it helped my organization?
We're able to customize it so that it suits our business needs.
What needs improvement?
Although we're able to customize it, it requires some level of subject-matter expertise for all the special adapters for collection.
We also had initial stability issues that were probably caused by our architecture and not the solution itself.
For how long have I used the solution?
We've been on the on-site platform for four years.
What was my experience with deployment of the solution?
We've had no issues with deployment.
What do I think about the stability of the solution?
We had some initial issues withs stability, but we worked through it. I think our architecture and design were initially flawed, so that was more of our problem and not HP's.
What do I think about the scalability of the solution?
We've had no issues scaling it in the last three years.
How are customer service and technical support?
We've used technical support several time and found them to be good.
Which solution did I use previously and why did I switch?
We moved from a managed outsource service, provided by a competitor. He wanted to in-source it, or in-house it, so we had the ability to be a little bit more effective and nimble.
How was the initial setup?
The initial setup was complex, but HP's professional services helped us out.
What other advice do I have?
Make sure you staff up internally, and have the right subject-matter expertise to take advantage of the platform. Otherwise, it's not going to help.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Practice Director at Rolta AdvizeX
Capable product that integrates with many different platforms.
Valuable Features
They're the leader of the SIEM market for fifteen years or so. ArcSight is a very capable product that integrates with many different platforms. It's huge with a lot of moving parts, but nothing can compete with it in terms of capability.
Room for Improvement
I'm a little concerned that the market is moving around ArcSight. It's a fantastic SIEM, but the recent metrics show that relying too heavily on a SIEM solution isn't protecting us. ArcSight addresses that by integrating with other solutions, but I'd like to see that to be a more central element of it.
Deployment Issues
We've had no issues with deployment.
Stability Issues
It is incredibly stable and road-tested, reasons why it's a market leader.
Scalability Issues
It's highly scalable. It works in small scenarios as well as the biggest that I can imagine.
Customer Service and Technical Support
Technical support from the vendor has been good. There's a particular challenge with ArcSight not in the technical support, but in the fact that it supports the platform and the integration.
Initial Setup
The initial setup is relatively complex because it's not a small solution. It's not only complex to set up, but the interface with business operations is even more complex around scoping, implementing, and running an implementation.
Other Advice
Make sure you tune it to your business and infrastructure, which isn't necessarily part of technical support. It requires some consulting, which is a market challenge of the product.
It's not a one-size-fits-all solution and it isn't sold with the appropriate professional services. So the number one thing with ArcSight is that you have to make sure that you get professional services to help size it for your particular use case, including integrations with your tools, operational model, and security operations.
Disclosure: My company has a business relationship with this vendor other than being a customer: We're partners.
Sr Security Engineer at a tech services company with 51-200 employees
There are SO MANY things you can do in AS, and there is a lack of really in-depth documentation on a lot of it.
What is most valuable?
Not really a feature, per se, but the ability to do multi-tenant SIEM.
How has it helped my organization?
We help our customers do more than 'check a box' for security and compliance and we are very proud of that. We tend to be more like partners to a lot of our customers, and they rely on us to deliver high-fidelity, relevant security alerts.
What needs improvement?
There are SO MANY things you can do in AS, and there is a lack of really in-depth documentation on a lot of it. I am not sure why this is, but it is a little hard to be self-sufficient when this is the case. I am sure this is why real ArcSight experts are in demand! Being too feature-rich can be as bad as being oversimplified!
For how long have I used the solution?
I have been working as an analyst using AS for 9 months now. This work involves monitoring the multi-tenant implementation of AS, sending reports to customers, doing investigations on alerts that come in, and implementing new Connectors and content. Connectors are how AS gets events from the devices.
What was my experience with deployment of the solution?
Again, system complexity can be an issue, but not really.
What do I think about the stability of the solution?
None. ArcSight is very stable. Period.
What do I think about the scalability of the solution?
Again, none. It is a system that is more than capable of multi-tenant implementations.
How are customer service and technical support?
They try really, really hard.
Which solution did I use previously and why did I switch?
No, the folks I work for were at ArcSight before HP acquired it and have always been users and proponents of it. It's a powerful product for sure.
How was the initial setup?
Setup is fairly complex, and with so many features, it is difficult to just 'set it and forget it' with ArcSight. It requires a lot of care and feeding, as well as a pretty good amount of ongoing maintenance and configuration to really get good quality alerts out of it.
What about the implementation team?
In-house experts.
Which other solutions did I evaluate?
I've been looking at Open Source SIEM recently, and paying a lot of attention to the others in the commercial market, like IBM and MacAfee, but I don't have any practical experience. I have heard mixed reviews about all of them (including AS from some folks I know).
What other advice do I have?
Implementation advice: this is a big job, and unless you are able to hire and train a dedicated SIEM engineer, I would look at getting staff augmentation from HP or other consulting types. Be prepared to Read The Friendly Manual (RTFM), and do a lot of searches online. Take the entry-level certs that HP offers, and get classes if there is budget.
Disclosure: My company has a business relationship with this vendor other than being a customer: ArcSight partner
Senior Security Consultant, CISSP, HPE ArcSight Specialist at a retailer with 5,001-10,000 employees
Parses raw logs, converts them to common event format so you don't need expertise in all products
Pros and Cons
- "SmartConnector: Normalization parses raw logs and converts them into CEF (common event format). This is the core of the product."
- "They need to develop NetFlow appliances that can be installed in the customer network on span ports, collect NetFlow, and send it to ArcSight without relying on the devices' NetFlow capability and their position in the network."
How has it helped my organization?
This product is one of the best SIEM solutions, which helps SOC analysts to consolidate all security-relevant logs of many products into one place in a common format. It doesn’t require that you have expertise in each and every product. It facilitates pinpointing indicators of compromise and investigating security incidents more quickly than the legacy way of checking every product log separately. The old way required a huge effort (and the pain) of human correlation.
What is most valuable?
- SmartConnector: Normalization parses raw logs and converts them into CEF (common event format). This is the core of the product.
- Filtration, Aggregation: Both features provide a good way to save EPS (events per second).
- Logger: Long log retention, fast search, and reporting.
- ESM/Express: Correlation via standard rules and data monitors, active list, session list, active channels, reports, trends, queries, dashboards (query viewers and data monitors), and lightweight rules.
What needs improvement?
Developing more products/modules that make it more independent from relying on other vendors’ products to get all the necessary logs. For example, develop NetFlow appliances that can be installed in the customer network on span ports, collect NetFlow, and send it to ArcSight without relying on the devices' NetFlow capability and their position in the network.
What do I think about the stability of the solution?
Overall, the product stability is very good. But without continuous tuning of the developed content and improper usage of the product, you can encounter performance issues with ESM/Express, and sometimes hangs, which requires a services restart.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Sometimes very good and sometimes moderate.
Which solution did I use previously and why did I switch?
No.
How was the initial setup?
Straightforward for Logger and Express appliance; more considerations for ESM software version.
What's my experience with pricing, setup cost, and licensing?
HPE ArcSight pricing might be more expensive than other SIEM solutions, but in my opinion it has powerful features and great flexibility in developing complex use cases. So, in my opinion, it's worth trying first (via PoC, for example) before making any decision based on cost.
Which other solutions did I evaluate?
No.
What other advice do I have?
If you are implementing Express/ESM, I advise disabling all out-of-the-box content and building your own. Also, keep monitoring partial matches and your session/active list sizes as you develop your correlation rules, as it has a big performance hit on the system.
Disclosure: My company has a business relationship with this vendor other than being a customer: HPE implementation partner.
System Support Engineer at a tech services company with 501-1,000 employees
Parsers are easy to create and test.
What is most valuable?
It’s a highly customizable solution. Rules can be customized to a great extent. Session lists, active lists, and global and local variables are pretty unique to the solution.
How has it helped my organization?
It can collect logs from many unsupported log sources. Parsers are easy to create and test.
What needs improvement?
The solution needs quite a bit of initial customization.
It needs more product integration, like NBAD and VM solutions, etc. Although the solution currently supports log collection from NBAD and VM solutions, it would be good to add features for HPE to have their own NBAD and VM solution.
There is room to improve the storage requirement.
Most SIEM solutions now have their own Vulnerability Management, NBAD, File Integrity Monitoring etc solutions that can be bought as an add on module. HP does not seem to have any of those capabilities. The most important advantage of having such capabilities is that it allows users to view and analyse all the data on a single pane of glass. Regarding the initial customization, the solution needs some effort in terms of fine tuning to get the dashboards and reports to work. Once it is setup I think the way the data can be used with in the solution is the best as it allows high customization.
For how long have I used the solution?
I have been using ArcSight for over five years.
What do I think about the stability of the solution?
The hardware requirements are very high and the solution has poor stability when they are not met.
What do I think about the scalability of the solution?
HPE ArcSight scales very well at the connector level, Logger level and the ESM level.
How is customer service and technical support?
Technical support is poor. This is one area that needs improvement
How was the initial setup?
The initial setup is not complex, but is a little time consuming. Since the solution is highly customizable, the number of configurable options are high. HPE ArcSight allows distributed architecture.
What's my experience with pricing, setup cost, and licensing?
Pricing is high. There are multiple licensing options available. Hardware/software or hybrid licensing options are available. Some of the license upgrades are paper license upgrades.
Which other solutions did I evaluate?
We evaluated IBM QRadar, McAfee ESM, and AlienVault.
What other advice do I have?
Planning is very important. You need to know the security threats to your organisation to create the relevant rules. Look at other less-discussed modules of HPE ArcSight, like ArcSight Interactive Discovery and ArcSight ThreatDetector, for better results.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Rapid7 InsightIDR
Sumo Logic Security
Fortinet FortiSIEM
Securonix Next-Gen SIEM
Google Chronicle Suite
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?