ArcSight ESM and AlienVault OSSIM are two prominent security management solutions. ArcSight ESM appears to have the upper hand in terms of advanced capabilities, while AlienVault OSSIM stands out as a cost-effective solution.
Features: ArcSight ESM is praised for its scalability, integration with other systems, and powerful correlation engine, offering a robust feature set for large enterprises. AlienVault OSSIM is valued for its unified approach, integrating multiple security tools into a single console, making it accessible for smaller organizations. Although both have valuable features, ArcSight ESM’s advanced capabilities cater to a higher level of enterprise security needs.
Room for Improvement: Users suggest enhancements for ArcSight ESM with a more intuitive operational flow, simplified rule creation, and user interface improvements. For AlienVault OSSIM, feedback highlights the need for better documentation, improved threat intelligence capabilities, and enhanced reporting features.
Ease of Deployment and Customer Service: ArcSight ESM users report a complex deployment process requiring significant expertise and time, yet they rate its customer service as responsive and helpful. AlienVault OSSIM receives positive remarks for its straightforward deployment, albeit with varied feedback on customer support. Users prefer AlienVault OSSIM for ease of deployment, although ArcSight ESM’s strong support is noted.
Pricing and ROI: Users find ArcSight ESM has a higher initial setup cost, but many justify the investment with its advanced features and long-term ROI. AlienVault OSSIM is preferred for its lower cost and favorable ROI for small to medium-sized businesses. AlienVault OSSIM wins on cost-effectiveness, making it a practical choice for budget-conscious organizations.
The integration capabilities, especially concerning log sources, need improvement for more flexibility and simplicity in integrating with nodes.
Network traffic analysis is highly efficient.
AlienVault OSSIM, Open Source Security Information and Event Management (SIEM), provides you with a feature-rich open source SIEM complete with event collection, normalization and correlation. Launched by security engineers because of the lack of available open source products, AlienVault OSSIM was created specifically to address the reality many security professionals face: A SIEM, whether it is open source or commercial, is virtually useless without the basic security controls necessary for security visibility.
ArcSight Enterprise Security Manager (ESM) is a powerful SIEM solution for analyzing, collecting, correlating, and reporting on security event information. ArcSight ESM analyzes information from all of your data sources while helping your organization maintain high security. In addition, the solution is very customizable and enables users to create their own company-specific rule sets to automatically trigger instant alerts.
ArcSight Enterprise Security Manager (ESM) Features
ArcSight Enterprise Security Manager (ESM) Benefits
Some of the benefits of using ESM include:
Reviews from Real Users
Below are some reviews and helpful feedback written by ArcSight Enterprise Security Manager (ESM) users.
A Head of Professional Services at a computer software company says, “The simplicity of the solution is the most valuable aspect of the product. The product is quite mature. It's been around for a long time. The integration is easy for the most part.”
A Managing partner at a tech services company states that the solution is “Good at consolidating logs, fairly stable, and can scale.”
PeerSpot user Abbasi P., Vice President Derivatives Ops IT at a financial services firm, explains, “The user interfaces are quite good and speedy, and I like the consoles too. The typology and the setup are also good.”
A Chief Technological Officer at a tech services company says, "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
An Associate Vice President at a consumer goods company comments, “We primarily use the solution for its technology including its independent logs, and those types of things. The solution offers very good monitoring. The product's log management and event management capabilities are excellent. There are a lot of really good analytical components. It helps us focus on analysis.”
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.