Splunk Enterprise Security and ArcSight Enterprise Security Manager (ESM) are two prominent security information and event management (SIEM) solutions. Users generally prefer Splunk Enterprise Security for its reliability and user satisfaction, whereas ArcSight ESM is noted for its advanced features.
Features: Splunk Enterprise Security is praised for its intuitive search capabilities and robust scalability. ArcSight ESM is commended for its comprehensive event correlation and monitoring features. While Splunk excels in simplicity and speed, ArcSight's strength lies in its detailed security insights and granularity. Hence, although both have strong feature sets, the choice may depend on user needs for ease versus depth of analysis.
Room for Improvement: Users feel Splunk Enterprise Security could benefit from better integration with third-party tools and more customizable dashboards. ArcSight ESM users suggest improvements in its complex setup process and need for smoother updates. Overall, both products show room for growth in different areas, with Splunk focusing on integration and customization, while ArcSight on ease of use and maintenance.
Ease of Deployment and Customer Service: Splunk Enterprise Security is often highlighted for its relatively straightforward deployment process and active customer support. ArcSight ESM, on the other hand, may present a steeper deployment curve, with users reporting a more challenging initial setup. Both solutions offer commendable customer service, but Splunk's ease of deployment gives it an edge for organizations looking for a quicker setup.
Pricing and ROI: Splunk Enterprise Security users generally view its pricing as premium but justified by a high return on investment, owing to its powerful features. Conversely, ArcSight ESM is perceived as having a more flexible pricing model but may require higher initial setup costs. Despite this, many users feel ArcSight’s extensive capabilities provide substantial ROI over time. Thus, while Splunk offers immediate value, ArcSight may yield higher long-term returns based on its feature robustness.
ArcSight Enterprise Security Manager (ESM) is a powerful SIEM solution for analyzing, collecting, correlating, and reporting on security event information. ArcSight ESM analyzes information from all of your data sources while helping your organization maintain high security. In addition, the solution is very customizable and enables users to create their own company-specific rule sets to automatically trigger instant alerts.
ArcSight Enterprise Security Manager (ESM) Features
ArcSight Enterprise Security Manager (ESM) Benefits
Some of the benefits of using ESM include:
Reviews from Real Users
Below are some reviews and helpful feedback written by ArcSight Enterprise Security Manager (ESM) users.
A Head of Professional Services at a computer software company says, “The simplicity of the solution is the most valuable aspect of the product. The product is quite mature. It's been around for a long time. The integration is easy for the most part.”
A Managing partner at a tech services company states that the solution is “Good at consolidating logs, fairly stable, and can scale.”
PeerSpot user Abbasi P., Vice President Derivatives Ops IT at a financial services firm, explains, “The user interfaces are quite good and speedy, and I like the consoles too. The typology and the setup are also good.”
A Chief Technological Officer at a tech services company says, "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
An Associate Vice President at a consumer goods company comments, “We primarily use the solution for its technology including its independent logs, and those types of things. The solution offers very good monitoring. The product's log management and event management capabilities are excellent. There are a lot of really good analytical components. It helps us focus on analysis.”
Splunk Enterprise Security is widely used for security operations, including threat detection, incident response, and log monitoring. It centralizes log management, offers security analytics, and ensures compliance, enhancing the overall security posture of organizations.
Companies leverage Splunk Enterprise Security to monitor endpoints, networks, and users, detecting anomalies, brute force attacks, and unauthorized access. They use it for fraud detection, machine learning, and real-time alerts within their SOCs. The platform enhances visibility and correlates data from multiple sources to identify security threats efficiently. Key features include comprehensive dashboards, excellent reporting capabilities, robust log aggregation, and flexible data ingestion. Users appreciate its SIEM capabilities, threat intelligence, risk-based alerting, and correlation searches. Highly scalable and stable, it suits multi-cloud environments, reducing alert volumes and speeding up investigations.
What are the key features?Splunk Enterprise Security is implemented across industries like finance, healthcare, and retail. Financial institutions use it for fraud detection and compliance, while healthcare organizations leverage its capabilities to safeguard patient data. Retailers deploy it to protect customer information and ensure secure transactions.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.