ArcSight Enterprise Security Manager (ESM) and Microsoft Sentinel are both strong competitors in the security information and event management (SIEM) market. Microsoft Sentinel appears to have the upper hand in terms of scalability and cloud-native integrations, while ArcSight ESM is praised for its robust analytical capabilities and customization options.
Features: ArcSight ESM provides detailed threat analysis and sophisticated correlation capabilities, allowing for extensive customization. It is able to handle complex environments and offers robust analytical capabilities. Microsoft Sentinel excels with its seamless integration into the Azure ecosystem, offering high scalability and automated threat detection. It is favored in user reviews for its ease of use and advanced AI capabilities.
Room for Improvement: Users of ArcSight ESM suggest enhancements in performance speed and a more user-friendly setup process. Some also note the need for better multi-cloud support. Microsoft Sentinel users point out the need for better multi-cloud support, more in-depth training resources, and improvements in the user interface.
Ease of Deployment and Customer Service: ArcSight ESM's deployment can be complex and time-consuming, requiring significant configuration according to user reviews. Its customer service is rated highly for responsiveness but can be inconsistent. Microsoft Sentinel is noted for its straightforward cloud-based deployment and excellent customer service, with users appreciating the responsive support and thorough documentation.
Pricing and ROI: ArcSight ESM users mention higher initial setup costs but find value in its long-term ROI due to its powerful features. Microsoft Sentinel offers a pay-as-you-go model, which users find appealing and cost-effective, especially for organizations already utilizing Azure services. Microsoft's flexible pricing and strong ROI make it a preferred option for many users.
ArcSight Enterprise Security Manager (ESM) is a powerful SIEM solution for analyzing, collecting, correlating, and reporting on security event information. ArcSight ESM analyzes information from all of your data sources while helping your organization maintain high security. In addition, the solution is very customizable and enables users to create their own company-specific rule sets to automatically trigger instant alerts.
ArcSight Enterprise Security Manager (ESM) Features
ArcSight Enterprise Security Manager (ESM) Benefits
Some of the benefits of using ESM include:
Reviews from Real Users
Below are some reviews and helpful feedback written by ArcSight Enterprise Security Manager (ESM) users.
A Head of Professional Services at a computer software company says, “The simplicity of the solution is the most valuable aspect of the product. The product is quite mature. It's been around for a long time. The integration is easy for the most part.”
A Managing partner at a tech services company states that the solution is “Good at consolidating logs, fairly stable, and can scale.”
PeerSpot user Abbasi P., Vice President Derivatives Ops IT at a financial services firm, explains, “The user interfaces are quite good and speedy, and I like the consoles too. The typology and the setup are also good.”
A Chief Technological Officer at a tech services company says, "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
An Associate Vice President at a consumer goods company comments, “We primarily use the solution for its technology including its independent logs, and those types of things. The solution offers very good monitoring. The product's log management and event management capabilities are excellent. There are a lot of really good analytical components. It helps us focus on analysis.”
Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution that lets you see and stop threats before they cause harm. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can:
- Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds
- Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft
- Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft
- Respond to incidents rapidly with built-in orchestration and automation of common tasks
To learn more about our solution, ask questions, and share feedback, join our Microsoft Security, Compliance and Identity Community.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.