What is our primary use case?
All network devices send their logs to the ArcSight logger as Syslog. Logs may include power failure, link failure, multiple failed login attempts, successful user login failure, and more. Security logs are stored in ArcSight's database for up to 90 days (this can be varied depending on the environment). Examples of security logs include authentication and authorization failures, incorrect logins, and wrong passwords; non-security logs such as link and device failure, module failure, STP logs, and unicast/multicast storm problems. These are some of the primary uses of the ArcSight Logger.
How has it helped my organization?
It didn't. It requires a high expertise.
What is most valuable?
The ability to tailor an environment to suit your specific use cases is a major advantage of ArcSight compared to other logging servers such as Splunk. This capability allows us to customize the alerts we receive based on our environment, such as an airport or banking setting. For example, we can configure alerts to be triggered when someone attempts to access a restricted area or forcefully enter a room. This type of customization is not readily available on other logging servers, making ArcSight an ideal choice for businesses and organizations with specialized needs.
What needs improvement?
The dashboard is not user-friendly. Using the system requires specialized knowledge and training, as it includes three consoles, the logger, the central management center, and the ESM. The dashboard is not easy to use and requires a lot of commands, making it difficult for those new to the system. All of the commands may be overwhelming for those just learning the system. Making the dashboard more user-friendly and reducing the reliance on commands, perhaps by using plain English text for filters and searches, would be a great improvement. Everyone we ask would agree that the dashboard needs to be made more user-friendly.
The scalability of the solution can be improved.
For how long have I used the solution?
I have been using the solution for five years.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
The solution has limited scalability. I give the scalability a six out of ten.
How are customer service and support?
I had an awesome support experience.
How would you rate customer service and support?
How was the initial setup?
The initial setup is difficult. Deployment took us approximately 2 weeks to transition from hardware to VM in our existing environment. When starting from scratch, it would take longer since we had to create the use cases, match logs from every device, and ensure that ArcSight was receiving all the logs.
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
The solution is expensive and only suitable for enterprise environments.
What other advice do I have?
I give the solution a seven out of ten.
I suggest that potential users go for Splunk or SolarWinds as ArcSight requires a rich knowledge base and there are only few online resources available. To ensure that we can deploy and set up ArcSight correctly, it is better to attend a training course to get the necessary knowledge. However, SolarWinds has a log server that is easier to learn, with fewer commands, and most of the tasks are done through the GUI. Therefore, I recommend SolarWinds instead of ArcSight.
Which deployment model are you using for this solution?
On-premises