Try our new research platform with insights from 80,000+ expert users
it_user418164 - PeerSpot reviewer
Senior Security Consultant & Solution Architect at a financial services firm with 10,001+ employees
Real User
It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.

What is most valuable?

  • Alert correlation
  • Reporting
  • Retention

These are the features we find most valuable for us and which we use the most.

How has it helped my organization?

It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.

Due simply to the user features available out-of-the-box, the convenience it can bring to any organization (when deployed and configured correctly) can greatly assist any enterprise in many facets, from an increased and enhanced security posture, to auditory regulations and even data retention.

What needs improvement?

It needs additional and better user customization for SmartConnectors. It has additional device support for more obscure log sources.  

Also needed is a configuration wizard for organizations lacking the in-depth knowledge required to integrate the solution successfully.

What was my experience with deployment of the solution?

We've had no issues with deployment.

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.

What do I think about the stability of the solution?

We've had no issues with instability. It's been stable for us.

What do I think about the scalability of the solution?

We've been able to scale it for our needs. We've had no issues with scalability.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user409203 - PeerSpot reviewer
Security Business Analyst at a tech services company with 10,001+ employees
Consultant
It has good options for shaping data and using them in very complex rules. Performance is the product's Achilles' heel.

What is most valuable?

I think the ability to create rules more flexible than in other products (i.e. IBM QRadar) is its most valuable feature. It has good options for shaping data and using them in very complex rules.

How has it helped my organization?

It has increased our detective capabilities in the cybersecurity landscape. We're able to build SOC around it, and make it a central tool for detecting network compromises.

What needs improvement?

Performance is the product's Achilles' heel. The aggregation can't be done for a long period of time, i.e. one week. On top of that, in comparison to the competition, ArcSight works very slowly and the WebUI is not very user-friendly.

For how long have I used the solution?

We've been using it for 10 months and the program is still in the development phase.

What was my experience with deployment of the solution?

There were no issues with the deployment.

What do I think about the stability of the solution?

There have been no stability issues.

What do I think about the scalability of the solution?

We have had no issues scaling it to our needs.

How are customer service and technical support?

The level of technical support is low. I think HP should invest money to train support people. Furthermore, sometimes I feel they are overworked because they used to sending notifications about cases without closing them.

Which solution did I use previously and why did I switch?

Previously, I worked with IBM QRadar.

How was the initial setup?

SIEM in general is not straightforward. I think the initial setup was simple, but to get value from this product, you have to do something more than the initial setup.

What about the implementation team?

We did it in-house with help from the vendor's professional services. My advice is to think first where you would like to put your collectors. Assess if your network will be able to lift extra loads, assess what logging level will be required, and if log sources are capable of delivering it.

Which other solutions did I evaluate?

ArcSight was chosen by my new company management without asking me for my opinion.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
January 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,369 professionals have used our research since 2012.
reviewer987771 - PeerSpot reviewer
Senior Manager at a tech services company with 51-200 employees
Real User
Lacking scalable cloud technology, poor stability, but easy to use
Pros and Cons
  • "The most valuable features of ArcSight ESM are ease of use and readily usable components."
  • "ArcSight ESM is lacking cloud scalable technology."

What is our primary use case?

We have a large footprint of 25 plus subsidiaries reporting into a consolidated security reporting and action team using ArcSight ESM.

How has it helped my organization?

ArcSight ESM has improved our organization because we have better incident reporting. It was originally deployed in order to fulfill compliance requirements. We were required to have security monitoring, ArcSight ESM was a quick and effective way to be able to meet that minimum requirement.

What is most valuable?

The most valuable features of ArcSight ESM are ease of use and readily usable components.

What needs improvement?

ArcSight ESM is lacking cloud scalable technology.

For how long have I used the solution?

I have been using ArcSight Enterprise Security Manager (ESM) for approximately three years.

What do I think about the stability of the solution?

ArcSight ESM has average capabilities. It's not seen as being particularly robust or usable for advanced threats.

What do I think about the scalability of the solution?

The scalability of ArcSight ESM is average to poor.

We have approximately 60,000 users using the solution.

How are customer service and support?

The support from ArcSight ESM is very poor. We had a negative experience.

I rate the support from ArcSight ESM one out of five.

Which solution did I use previously and why did I switch?

We did not use a solution prior to ArcSight ESM.

How was the initial setup?

The initial setup of ArcSight ESM was relatively straightforward. The full deployment took us approximately six months. The implementation strategy was to get basic monitoring templates as fast as possible.

What about the implementation team?

We used an integrator for the implementation of ArcSight ESM.

What was our ROI?

The ROI was not important at first because we were trying to cover our basic compliance requirement for monitoring.

What's my experience with pricing, setup cost, and licensing?

We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees.

Which other solutions did I evaluate?

We evaluated other solutions prior to choosing ArcSight ESM, such as Splunk and RSA NetWitness. We decided on ArcSight ESM because it was cost-effective.

What other advice do I have?

We are replacing ArcSight ESM with Microsoft Sentinel. We wanted to shift to cloud-based, cloud-scalable technology.

My advice to others is for them to take a hard look at the total cost of ownership, specifically the maintenance and upkeep that's required to maintain the appropriate service levels.

I rate ArcSight ESM a four out of five.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 5Leaderboard
Scalable, with good support and live reporting
Pros and Cons
  • "The most useful features are directories, price, and live reporting."
  • "The customer experience could be improved."

What is our primary use case?

We are resellers. We deal with many vendors to provide and implement solutions for our clients. We primarily use this product for logging data.

What is most valuable?

The most useful features are directories, price, and live reporting.

What needs improvement?

The customer experience could be improved.

I think they can improve the AI and monitoring. Also, they need an updated database.

For how long have I used the solution?

I have been dealing with this solution for approximately three years.

We are working with the last updated version.

What do I think about the stability of the solution?

The stability can be improved. The competitors are more stable.

What do I think about the scalability of the solution?

It's a scalable product and the scalability is good.

Our clients are usually enterprise companies.

How are customer service and technical support?

The technical support is good. They have been able to resolve our issues.

Which solution did I use previously and why did I switch?

We are using SIEM. It has a better dashboard and is more complete.

How was the initial setup?

The initial setup can be simple and also complex. It depends on the client's infrastructure.

What about the implementation team?

We implement the solution and maintain it for the clients.

What's my experience with pricing, setup cost, and licensing?

It's a good price, it's one of the cheaper solutions.

There are no additional costs.

What other advice do I have?

Depending on the size of the companies, I would recommend this solution. It's more suited for small to medium-sized companies.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies
Real User
Easy setup but should offer an entire report listing of integrated devices
Pros and Cons
  • "There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive."
  • "I would like to have a feature that gives us an entire report listing what devices are integrated."

What is most valuable?

There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive. 

What needs improvement?

The security is difficult. 

I would like to have a feature that gives us an entire report listing what devices are integrated.

For how long have I used the solution?

I have been using ArcSight for the last five years. 

How are customer service and technical support?

In the beginning, we got good support but it hasn't been what it used to be. On weekends we get the list of devices that are integrated but if we need to generate the lists of rights, it doesn't send the logs.

How was the initial setup?

The initial setup was simple. The initial setup took five to six days.

What other advice do I have?

I would rate it a seven out of ten. In the next release, I would like for them to include a list of integrated devices. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Manager at Royal Cemerlang
Real User
Can pinpoint the story behind every virus or network attack to the environment
Pros and Cons
  • "It prevented my users from getting infected by ransomware. It can also pinpoint the story behind every virus or network attack to our environment."
  • "The product should include a lot more predefined scenarios so the adopted company will have knowledge and a broader skill set in security and network."

What is our primary use case?

Our primary use case is SIEM. It is a data lake for logs from all of our servers and devices (routers, switches, firewalls, wireless controllers, etc.).

How has it helped my organization?

It prevented my users from getting infected by ransomware. It can also pinpoint the story behind every virus or network attack to our environment.

What is most valuable?

ArcSight ESM: The module has user-defined rules capabilities. This feature lets us define almost any threat.

What needs improvement?

The product should include a lot more predefined scenarios so the adopted company will have knowledge and a broader skill set in security and network.

For how long have I used the solution?

Three to five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
CommMan719 - PeerSpot reviewer
CommMan719Commercial Manager at a tech services company with 11-50 employees
Real User

Weinstein have projects in goverment sector

PeerSpot user
Security Expert at a tech services company
Consultant
The correlation capabilities are valuable. It is too restrictive to suit the flexibility needs of the infrastructure.

What is most valuable?

Correlation capabilities: This product provides an advanced level of correlations, which is highly valued.

How has it helped my organization?

HPE ArcSight has helped us gain visibility of the solutions across the organization. We have been constantly identifying anomalous activities both internally as well as externally. These include malware proliferation, data loss, proxy bypass attempts, phishing and spear-phishing, port scans, etc

What needs improvement?

It can be more user-friendly. The product is too restrictive to suit the flexibility needs of the infrastructure. It is sometimes hard to implement the solution as recommended by HPE.

For how long have I used the solution?

I have used this solution for around four and a half years. Currently, we are using HPE ArcSight Express 5, ESM 6.8, Connector Appliances and SmartConnectors 7.4.

What do I think about the stability of the solution?

In version 5, I used to experience some issues as it was using Oracle DB. Although, I do not have any problems in version 6+.

What do I think about the scalability of the solution?

This product is not easily scalable. We particularly required skilled personnel to do this activity and it also took a significant amount of time.

How are customer service and technical support?

The technical support is poor.

Which solution did I use previously and why did I switch?

We were not using any other solution before. We started using HPE ArcSight straightaway.

How was the initial setup?

Setting up of the ArcSight solution is always complex compared to other solutions out there. There are a lot of parameters and dependencies involved. Adding infrastructure complexity will add more complications. Distributed deployment is also difficult to implement.

What's my experience with pricing, setup cost, and licensing?

It is very expensive for larger deployments.

Which other solutions did I evaluate?

We are now working with open-source systems and Splunk solutions. We are decommissioning HPE ArcSight as it is getting impractical to manage and maintain the solution.

What other advice do I have?

There are better products in the market for medium to large-scale deployments. It is recommend to use this product for small-scale deployments, i.e., 200-800 EPS.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Security Expert at a tech services company with 501-1,000 employees
Consultant
With multi-tier hierarchical deployment, we are able to integrate and standardize security incident detection and response.

What is most valuable?

  • High flexibility: There are many custom sources of information that we wouldn't be able to integrate with another SIEM solution, thus compromising our security.
  • High performance: The amount of data fed to the solution is huge (100s of millions of events per day).
  • Capacity for multi-tier hierarchical deployment: We are able to integrate and standardize security incident detection and response over many locations.

How has it helped my organization?

  • Losses from security incidents have significantly decreased.
  • Security incident discovery and mitigation is a matter of hours, rather than days or even months, like it was before.
  • Detailed reports allow for planning and informed decision making.

What needs improvement?

The overall complexity of the product can be overwhelming for some. It's not the type of solution where you just plug it in and it works. Reaping full benefit from it requires quite a lot of custom tuning, qualified IT security personnel, and proper and thorough planning.

Technical support from the vendor can sometimes be quite slow and not very helpful, but it is getting better.

The GUI is outdated. Improvements on this are on the way, according to the vendor.

For how long have I used the solution?

I’ve been using ArcSight for five years.

What do I think about the stability of the solution?

We had stability issues only in a virtual environment, which is not recommended by the vendor for a high-load setup. The main virtual server would crash every now and then. But once we had migrated the setup to a dedicated physical server, we had no major stability issues.

What do I think about the scalability of the solution?

Scalability was one of our main concerns while choosing a solution and, so far, it has satisfied our needs in this area without any issues.

How are customer service and technical support?

Right now, I would call technical support moderately good, since it has improved greatly over the past years. There are still some issues with timeliness every now and then, but the number of critical issues is quite low.

Which solution did I use previously and why did I switch?

We have evaluated several solutions and HPE ArcSight was the only one that satisfied our requirements in performance, scalability, and flexibility.

How was the initial setup?

Initial setup was quite complex and required a lot of planning. That is a downside of the solution being flexible and customizable.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing model has changed dramatically over the last years, so I can't really give much advice on its current state. You need to be ready for the solution to be quite expensive.

Which other solutions did I evaluate?

We evaluated McAfee ESM.

What other advice do I have?

The keys to success with this solution are:

  • Careful deployment planning
  • Readiness to invest time and resources into training your IT security personnel
  • Fine tuning the solution to your specific needs
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.