Try our new research platform with insights from 80,000+ expert users
Senior Systems Engineer at a tech services company with 501-1,000 employees
Real User
A mature and well-regarded cyber security solution for big data, network security, and analytics
Pros and Cons
  • "Allows multiple integrations with multiple systems in a stable and flexible fashion."
  • "The GUI interface is not always intuitive and easy for non-technical users to work with."

What is our primary use case?

Our primary use for this product is to cover on DCI (Data Center Interconnect) requirement and design excerpts. It is used to connect all the links from different systems and environments. We also use it to do accommodations between the systems and environments and have multiple use cases between the systems.

How has it helped my organization?

Our organization has improved because ArcSight allows multiple integrations with multiple systems which we did not do before using the product. There can be multiple integrations with different parts of systems that process them. This can include files, XML, how the parts of the system receive connection, a specific API, other different products like anti-virus packages, or risk prediction.

We needed a predictive function that worked with other systems. It is supposed to be possible by using different agents. There is an agent called Smart Connector. Each connector has a specific role and function and launches with specific technologies.

What is most valuable?

All the features are valuable for us because we use all of them. It's like any other ESM (Enterprise Service Management) solution. You can use how you want to. It depends on the reports, on the correlation rule alerts, notifications, dashboards, all of the business rules. It is very important for most of the clients.

Most of the clients need to cover their BPI (Business Process Insight). They generate a lot of records to provide them for BPI department or risk department. That could be including their Instagram, or checking that the system's working fine, and information collected by the SIEM (Security Information and Event Management).

What needs improvement?

The product might be improved in comparison with other products. For example, they need to work with the flexibility of the GUI. It is sometimes considered complex by some of our customers. Also, the ArcSight Analytic is not so easy. The end-users are not supposed to be required to learn the network. Another thing, it only supports through links and the analytic bar, not the network traffic parts. That's the major point that could be more improvement in the system.

Network and network paths could be supported better in integration with other network traffic catchers. It would be great then. 

Buyer's Guide
ArcSight Analytics
May 2025
Learn what your peers think about ArcSight Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.

For how long have I used the solution?

We have been using the product for five years.

What do I think about the stability of the solution?

I find the product to be very stable and we experience no problems with it.

What do I think about the scalability of the solution?

It is scalable based on the fact that licenses could be added-on. There is a part of the solution that requires an upgrade to ArcSight that could provide additional capabilities and many-stepped solutions that could be installed in an ISP provider. 

How are customer service and support?

On occasion, we have contacted customer support. We have bought a support contract just in case there is any failure or other issues that could happen on the system. Sometimes we need their support directly to efficiently solve an issue. Their support is very helpful, and they can help you and provide you good solutions.

Which solution did I use previously and why did I switch?

We sometimes use different solutions. We have RSA and ArcSight implementations. We use RSA to do networking and the use of ArcSight depends on the need of the customer. Sometimes there are customers who ask for RSA. Sometimes there are customers who have knowledge about ArcSight and they like what it provides and the features it has but they want to improve how they use it in their system. There is no need to have a new system to implement a new solution. 

How was the initial setup?

The initial installation has co-integration and settings, so it is mostly straightforward. But sometimes customers need specific co-integration and finer tuning saved on their system.

The base deployment for any system will take around two weeks. With integration and customization, it may be another two weeks to three weeks maximum.

What about the implementation team?

We provide support for our customers in ArcSight and RSA so we do our own installations and installations for clients.

What was our ROI?

The product is not really intended to generate income as it is a security solution.

Which other solutions did I evaluate?

We did not evaluate other solutions as through research we could tell the product was well accepted and had the solutions we needed.

What other advice do I have?

Advice that I would give to other people who are considering using this product is that they need to have a good working knowledge of the system. They might want to consider training. They need to be able to specify exactly what the scope of the project is for the net position and in their implementation and installation. If customers who have common needs, like a solution to cover PCI (Payment Card Industry) only, I sometimes advise them to not invest in this system, because it is not made to only cover your PCI requirements.

If I had to rate this product on a scale from one to ten it would be an eight. It would rate higher if there were better flexibility and the GUI was easier to read and use.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 5Leaderboard
A cost-effective stable solution to consolidate data from logger
Pros and Cons
    • "The customer service could be improved, and additional integrations with other APIs could be added."

    What is our primary use case?

    We use the solution to analyze the logger in the dashboard.

    What is most valuable?

    The solution consolidates the data from the logger on one dashboard. It is easy to use, install, configure, and integrate.

    What needs improvement?

    The customer service could be improved, and additional integrations with other APIs could be added.

    For how long have I used the solution?

    I have been using ArcSight Analytics for two years.

    What do I think about the stability of the solution?

    The product is stable.

    I rate the solution’s stability a nine out of ten.

    What do I think about the scalability of the solution?

    700 users are using this solution.

    I rate the solution’s scalability a nine out of ten.

    How was the initial setup?

    The initial setup is easy and takes three hours to complete.

    What about the implementation team?

    Deployment can be done in-house.

    What's my experience with pricing, setup cost, and licensing?

    The product is cheap and has a yearly license.

    What other advice do I have?

    We have five people, including a manager and four engineers, for the solution’s maintenance.

    I recommend the solution.

    Overall, I rate the solution a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    ArcSight Analytics
    May 2025
    Learn what your peers think about ArcSight Analytics. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
    851,604 professionals have used our research since 2012.
    PeerSpot user
    Cyber Security Consultant at raf
    Real User
    Good log monitoring, but the interface is not user-friendly and it needs better integration with third-party solutions
    Pros and Cons
    • "The most valuable feature is the log monitoring."
    • "ArcSight is not a user-friendly solution and the interface needs to be improved."

    What is our primary use case?

    We use this solution for monitoring our network. It does authentication failure monitoring, VPN log monitoring, internal threat monitoring, and outside threat monitoring. It also looks for IOCs and malicious activity that is originating from internet connections.

    What is most valuable?

    The most valuable feature is the log monitoring.

    What needs improvement?

    ArcSight is not a user-friendly solution and the interface needs to be improved. It is a bit tough to use for people who are inexperienced.

    ArcSight needs better support for integration with third-party applications. It should be able to handle logs from all kinds of different sources.

    The API needs to be improved.

    Which solution did I use previously and why did I switch?

    I have used other log management solutions including Splunk and Elasticsearch. I also use QRadar as a more general SIEM.

    What other advice do I have?

    This is not a solution that I would recommend. Instead, I would recommend Splunk or QRadar. In the case of an organization with a small budget, I would recommend AlientValut or Elasticsearch.

    I would rate this solution a six out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Security7eac - PeerSpot reviewer
    Founder at a tech services company with 1-10 employees
    Real User
    Not easy to use and requires notable training, but integrates well with other products
    Pros and Cons
    • "The data collection and the integration with different products are valuable features."
    • "[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."

    What is our primary use case?

    We use it as a SIEM. We're using the enterprise edition.

    How has it helped my organization?

    We have seen a measurable decrease in the mean time to detect and respond to threats. It has also definitely added to what our customer had. We are integrating a lot of tools for one of our customers and it has really helped to improve their current security posture.

    What is most valuable?

    The data collection and the integration with different products are valuable features.

    What needs improvement?

    I would like to see some advanced analytics.

    What do I think about the scalability of the solution?

    The solution is scalable but it is not easy to use.

    How are customer service and technical support?

    Technical support is average.

    Which solution did I use previously and why did I switch?

    We did not switch. This is the first time we have done such an installation.

    How was the initial setup?

    The initial setup was complex.

    What's my experience with pricing, setup cost, and licensing?

    The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee.

    Which other solutions did I evaluate?

    We looked at Splunk and HelpSystems. There were a few more vendors but I don't recollect all their names. Because of the number of integrations that ArcSight has, it was more applicable to our use case.

    What other advice do I have?

    You can use this solution for limited use cases. But for more advanced use cases, there are other solutions which are better than ArcSight.

    I would rate this solution at five out of ten because of the complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training. It needs better technical support and help with onboarding.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    PeerSpot user
    SocEnginfab7 - PeerSpot reviewer
    SOC Engineer at a transportation company with 1,001-5,000 employees
    Real User
    Scalability is poor; we need the ability to capture larger amounts of data
    Pros and Cons
    • "One of the most valuable features is the alerts."
    • "I would like to see orchestration."
    • "It's a difficult product to navigate, it's complex."

    What is our primary use case?

    Our primary use case for this solution is as a SIEM.

    How has it helped my organization?

    We're leveraging it to detect incidents and attacks. We have seen a measurable decrease, by about 20 percent, in the mean time to detect and respond to risks. It has also helped to increase staff productivity, saving 20 percent in terms of time.

    What is most valuable?

    One of the most valuable features is the alerts.

    What needs improvement?

    I would like to see orchestration.

    What do I think about the stability of the solution?

    It's very stable.

    What do I think about the scalability of the solution?

    The scalability is poor. We need the ability to capture larger amounts of data.

    How are customer service and technical support?

    Technical support is average.

    Which solution did I use previously and why did I switch?

    This is the first solution of its kind that we deployed.

    How was the initial setup?

    The initial setup was complex. It's a difficult product to navigate, it's complex. And the service was poor, back when we started with the product.

    What's my experience with pricing, setup cost, and licensing?

    In addition to the costs of standard licensing fees, there is the cost of labor for maintenance.

    What other advice do I have?

    Understand your data first and then find a solution that handles the data you have.

    I rate the solution at four out of ten because of the complexity and the lack of ability to capture large amounts of data.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer841053 - PeerSpot reviewer
    Cyber Security Team Leader at a tech services company with 501-1,000 employees
    Real User
    Good correlation engine but query functions are sluggish
    Pros and Cons
    • "The correlation engine is good."
    • "It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."

    What is our primary use case?

    We use ArcSight to collect logs from our customers and allocate services.

    What is most valuable?

    The correlation engine is good.

    What needs improvement?

    ArcSight's features are starting to get stale. They haven't added any new features in quite a long time. They could add an easier way for a person to customize log sources. It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow. 

    For how long have I used the solution?

    I've been using ArcSight analytics for more than five years.

    What do I think about the stability of the solution?

    In terms of stability, ArcSight is not very good. I would say it's about average. We've had some issues but overall it's about average. This is the main issues are with reporting. Sometimes on the service end, we stop receiving logs.

    What do I think about the scalability of the solution?

    ArcSight is a scalable solution.

    How are customer service and support?

    Tech support is average. Not bad. Not good.

    How was the initial setup?

    We haven't had any complications with the setup, and it is low maintenance. 

    What other advice do I have?

    I would rate ArcSight six out of 10. If you are going to use ArcSight, I would recommend using it alongside another solution. ArcSight is good for correlation, but you should have another solution to handle the queries. For queries, you need a faster solution and ArcSight will not provide you with that.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer841053 - PeerSpot reviewer
    Cyber Security Team Leader at a tech services company with 501-1,000 employees
    Real User
    Easily creates use cases and reports, but needs improves to the GUI and dashboards
    Pros and Cons
    • "This solution makes it easy to create use cases, and it is easy to move queries from use cases to the report to the dashboard."
    • "I would like to see integration with automation products, such as Phantom Automation."

    What is our primary use case?

    We use this solution for the authentication of software.

    What is most valuable?

    This solution makes it easy to create use cases, and it is easy to move queries from use cases to the report to the dashboard.

    The parallel logic to create queries is very helpful. 

    What needs improvement?

    The GUI and dashboards are very basic and need to be improved.

    The product does not have continuous updates.

    I would like to see easy integration with the Intelligence Suite.

    I would like to see integration with automation products, such as Phantom Automation.

    For how long have I used the solution?

    We have been using this solution for five years.

    What do I think about the stability of the solution?

    This is a very stable solution. It is the most stable ESM that I have worked with.

    What do I think about the scalability of the solution?

    Scalability of this solution is very good.

    We have twenty analysts using this solution, and we do not plan on expanding our usage at this time.

    How are customer service and technical support?

    Technical support for this solution has been very helpful.

    Which solution did I use previously and why did I switch?

    We did not use another solution prior to this one.

    How was the initial setup?

    The initial setup of this solution is straightforward.

    What about the implementation team?

    We used a consultant to assist us with the deployment.

    What other advice do I have?

    This is a solution that I recommend.

    I would rate this solution a seven out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    PeerSpot user