Try our new research platform with insights from 80,000+ expert users

ArcSight Intelligence vs Elastic Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.9
ArcSight Intelligence boosts security and ROI by automating threat detection, reducing false positives, and streamlining workflows with advanced analytics.
Sentiment score
5.9
Elastic Security provides positive ROI in 18-24 months, affordable for SMEs, though premium support may be lacking.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
 

Customer Service

Sentiment score
6.7
ArcSight Intelligence has slow but capable customer support, with mixed user satisfaction regarding problem resolution and feedback sufficiency.
Sentiment score
6.4
Elastic Security support varies; open-source praised for community help, commercial support seen as responsive but with some improvement needed.
Most of the time when my team encounters issues, they receive responses within 24 hours.
Support is prompt and helpful.
 

Scalability Issues

Sentiment score
6.3
ArcSight Intelligence is scalable but complex, with user ratings ranging from moderately to highly, influenced by partner support.
Sentiment score
7.3
Elastic Security is praised for scalability, easily supporting small to large businesses and adaptable through configuration adjustments.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
 

Stability Issues

Sentiment score
8.4
ArcSight Intelligence is highly rated for stability and consistent performance, with users giving it a nine out of ten.
Sentiment score
7.7
Elastic Security is stable and reliable, but requires proper setup and resource management; frequent updates can disrupt some users.
In terms of stability, I would rate Elastic a solid eight out of ten.
 

Room For Improvement

ArcSight Intelligence requires frequent updates, improved usability, better speed, enhanced scalability, lower pricing, and higher ranking compared to QRadar and Splunk.
Elastic Security faces challenges in usability, integration, scalability, and awareness, requiring enhancements in features and user support.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
Elastic Security consumes a lot of resources, requiring a substantial deployment setup.
 

Setup Cost

ArcSight Intelligence is costly, suited for enterprises, and offers various licensing options with extra charges for new features.
Elastic Security is cost-effective for SMEs but advanced features and lack of included support can increase costs.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
Elastic Security is considered cost-effective, especially at lower EPS levels.
 

Valuable Features

ArcSight Intelligence offers a powerful log correlation engine, customizable alerts, seamless dashboard, user-friendly interface, and easy rule creation.
Elastic Security offers rapid search, scalability, and affordability with strong machine learning and customizable dashboards for efficient threat detection.
The platform provides more visibility and requires less effort in monitoring.
Elastic Security is as flexible and configurable as Microsoft Sentinel.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
 

Categories and Ranking

ArcSight Intelligence
Ranking in Security Information and Event Management (SIEM)
40th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
5
Ranking in other categories
User Entity Behavior Analytics (UEBA) (14th)
Elastic Security
Ranking in Security Information and Event Management (SIEM)
5th
Average Rating
7.8
Reviews Sentiment
6.8
Number of Reviews
64
Ranking in other categories
Log Management (7th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
 

Mindshare comparison

As of April 2025, in the Security Information and Event Management (SIEM) category, the mindshare of ArcSight Intelligence is 0.3%, down from 0.3% compared to the previous year. The mindshare of Elastic Security is 6.6%, down from 9.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Pravir KumarSinha - PeerSpot reviewer
Has essential threat detection capabilities, but the features for intelligence need enhancement
We integrated this tool with our security infrastructure. We installed it on a Linux server, where we have a Logger and ESM installed. With the Linux server as the hub, we manage all the configurations and rules, including those for email triggers. The logs are routed through a connector to the Logger, allowing us to monitor our infrastructure effectively. The platform helps us improve threat detection capabilities. I recommend it to others and rate it a seven out of ten.
SyedAli17 - PeerSpot reviewer
Centralized monitoring improves security posture through rapid data processing
The processing part of Elastic Security ( /products/elastic-security-reviews ) is very interesting for us since we handle almost 7,000 to 8,000 alerts per minute. We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data. Additionally, Elastic Security helps improve the security posture of Pakistan through centralized visibility and real-time processing.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
847,862 professionals have used our research since 2012.
 

Comparison Review

it_user186927 - PeerSpot reviewer
Feb 16, 2015
Cybereason vs. Interset vs. SQRRL
Capture DB - they all use NoSQL db and hence solve the ad hoc query and 'go back in time' problem with current best of breed SIEM and DLP solutions that rely on real time analysis of incoming logs (and don't store them). This means deeper and quicker iterative threat analysis and assessment…
 

Top Industries

By visitors reading reviews
Government
20%
Computer Software Company
19%
Financial Services Firm
8%
Manufacturing Company
7%
Computer Software Company
16%
Government
10%
Financial Services Firm
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about ArcSight Interset / Intelligence?
The platform helps us improve threat detection capabilities.
What needs improvement with ArcSight Interset / Intelligence?
The product could be improved in several areas; it currently requires significant enhancement. Compared to QRadar and Splunk, ArcSight Intelligence falls behind, placing it as the third choice amon...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Elastic Security is considered cost-effective, especially at lower EPS levels. However, a direct comparison was not made due to different pricing structures.
 

Also Known As

ArcSight Interset / Intelligence, FileTrek, Interset UEBA, Micro Focus Interset UEBA, Micro Focus Interset, ArcSight Interset
Elastic SIEM, ELK Logstash
 

Overview

 

Sample Customers

Accuvant, Splunk Inc., NuTech, Box, rSolutions, Voodoo Technology Limited
Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
Find out what your peers are saying about ArcSight Intelligence vs. Elastic Security and other solutions. Updated: April 2025.
847,862 professionals have used our research since 2012.