Try our new research platform with insights from 80,000+ expert users
technica402861 - PeerSpot reviewer
Senior Manager - Cyber Security at a comms service provider with 1,001-5,000 employees
Real User
The two most valuable features for us are the deployment strategy and its operational ease.

What is most valuable?

The two most valuable features for us are the deployment strategy and its operational ease.

How has it helped my organization?

As it's an SIEM solution, it won't prove anything overnight. We're still in the implementation stage and filtering out all the noise. It's operationalized, but we're fine tuning it.

What needs improvement?

I'd like to see some threat intelligence out of the box rather than adding it in subscriptions. It also needs more straightforward and simplified correlation rules so that a SOC analyst can dive right in rather than undergo a separate induction program. Right now, the attrition rate is high.

For how long have I used the solution?

We've had it for about eight months now.

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.

What was my experience with deployment of the solution?

We haven't had any issues with deployment.

What do I think about the stability of the solution?

It is a stable product. We've had no issues with instability.

What do I think about the scalability of the solution?

We haven't had a need to scale yet, and maybe not for another two or three years.

How are customer service and support?

System integrated support is there, but we haven't had any need to contact HP support. We will soon, though, because we don't really know how to fine tune the product.

Which solution did I use previously and why did I switch?

The threat landscape was the trigger for needing a SIEM product to correlate everything that is going on within the environment.

How was the initial setup?

We'restill in the implementation stage because it's complex. So the basic things are done, but not the full-scale deployment. It's a process.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1738932 - PeerSpot reviewer
Security Sales Engineer
Real User
Useful real-time alerts for web traffic monitoring
Pros and Cons
  • "Stable solution with good customer service support."
  • "Could benefit from a more modern interface."

What is our primary use case?

We use it to monitor several web traffic sources and to look for compromised indicators within that traffic. The traffic comes from several applications that we've exposed on the internet.

What is most valuable?

The most valuable feature is the real-time alerts. We're also currently looking to incorporate some of the SOAR capabilities that are new to the platform.

What needs improvement?

The interface—the console looks pretty old right now, so could benefit from a more modern design.  It's functional, but not so as visually appealing as it could be.

For additional features, I'd say capabilities regarding the behavioral analytics integrated in the solution. Right now, there's something in place, but it's not integrated on our side of the platform.

For how long have I used the solution?

I've been using ArcSight since 2015, so about six years.

What do I think about the stability of the solution?

My impressions are that it is stable.

What do I think about the scalability of the solution?

On our end it's pretty good. We haven't had any problems adding more sources.

How are customer service and support?

I've used their customer service and support a couple of times. It was a good service.

How was the initial setup?

Setup was relatively easy. The initial deployment was around five hours. For full deployment with all the sources, it took longer.

What other advice do I have?

I would rate this solution an eight out of ten. It's been useful and would recommend it to others. I'd also advise to take just the initial architect for implementation because that was critical for us in making the appropriate selections prior to deployment.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Analyst0909 - PeerSpot reviewer
Analyst at a financial services firm with 10,001+ employees
Real User
Helps our clients with compliance and gives them real-time alerts and monitoring for their server data
Pros and Cons
  • "We do consulting and I get feedback from our clients that the product really helped them with compliance, especially with GDPR."
  • "I would like for them to integrate mobile devices. Integration or any kind of functionality which will act as a substitute for IBM so that we can really track our mobile devices as well as look at SIEM."

What is our primary use case?

We use this solution for clients that want database consulting. They have a lot of general user's data in that demise so they want to have a robust SIEM solution that they trust. They have real-time alerts and monitoring for their data server.

How has it helped my organization?

We do consulting and I get feedback from our clients that the product really helped them with compliance, especially with GDPR. 

What needs improvement?

They should make a user manual for the technical people.

I would like for them to integrate mobile devices. Integration or any kind of functionality which will act as a substitute for IBM so that we can really track our mobile devices as well as look at SIEM.

What do I think about the stability of the solution?

I would rate the stability as a four out of five. 

How was the initial setup?

The initial setup was easy. It was a two-month project plus one month setting up the best practices cost organization. In total, it was around a three month project.

What's my experience with pricing, setup cost, and licensing?

Pricing is average. 

What other advice do I have?

I would rate this solution a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network Security Administrator at a government with 1,001-5,000 employees
Vendor
With the console, I can move between analyzing events and creating content. SmartConnectors are not resilient and sometimes crash.

What is most valuable?

The ESM's interface is really comprehensive. While the ArcSight console is really heavy, and I tend to dislike Java-based Windows GUIs, it's feature-rich and provides a seamless way to move between analyzing events and creating content.

How has it helped my organization?

The ability to correlate such a diverse range of information into a single location is invaluable.

What needs improvement?

SmartConnectors should be resilient, since they ingest directly from sources (often sources that I have no control over). But they're not resilient. The slightest change in the format of an event can cause SmartConnectors to stop working completely, even for other properly formatted events.

For how long have I used the solution?

I have been using ArcSight for two years.

What do I think about the stability of the solution?

I've had stability issues, particularly with SmartConnectors. They sometimes crash. Worse still, they often report that they're working fine but completely stop listening for events.

What do I think about the scalability of the solution?

The ArcSight Logger is extremely limited when it comes to scalability. For a large deployment that could be handled by a single ESM, a dozen Loggers might be required. The cost of such an undertaking is prohibitive, and there are much more scalable solutions available (ES for instance).

How are customer service and technical support?

I would rate this zero, if I could. I have had many incidents opened with HPE Support for ArcSight products, and there has not been a single issue where their support was more valuable than the time it took to deal with them. In most of my experiences with them, I provided a thorough description of the problem including logs, config files, and sometimes .pcap files.

I then heard back from them roughly once or twice a day for a week, during which time they would ask questions that I had already answered, and suggest actions that couldn't possibly relate to my issue. Of course, I tried their suggestions, but they did not work. By then, I had always devised a workaround to reduce impact to production and didn't receive another suggested resolution for weeks or months.

Which solution did I use previously and why did I switch?

I have used many products that cover some of the territory claimed by ArcSight, including: Sourcefire 3D, ELSA, Sguil/Squert, RSA Security Analytics and Splunk. None of these were as comprehensive as ArcSight.

How was the initial setup?

Most of the initial setup is very straightforward, but some event sources require significant effort to integrate.

What's my experience with pricing, setup cost, and licensing?

ArcSight is exclusively an enterprise product and it is priced accordingly.

Which other solutions did I evaluate?

We evaluated QRadar and Splunk.

What other advice do I have?

Evaluate your needs. If you're only looking to integrate logs or do simple correlations, there might be a better choice out there. If you're looking for a single product that will let you aggregate, correlate and analyze many different sources in a single place, then there are few competitors that can come close to ArcSight's features.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user402840 - PeerSpot reviewer
Senior Manager Fraud Services at a financial services firm with 1,001-5,000 employees
Vendor
It's a reliable service and provides our team members with a lot of knowledge.

Valuable Features:

It's a reliable service and provides our team members with a lot of knowledge. In turn, it provides solutions for the needs of the IT department.

Room for Improvement:

There are improvements that could be made to help us insure that we're in compliance with our monitoring requirements.

Use of Solution:

I've been in my group for over eight years and we've used it for the entire time. I'm not sure when the initial implementation was.

Deployment Issues:

We've had no issues with deployment.

Stability Issues:

It's consistently stable. I've not heard any complaints about instability.

Scalability Issues:

HP has delivered for our company and its size.

Initial Setup:

The initial setup was done more than eight years ago before I started with the company.

Implementation Team:

We bring in an HP consultant for development and implementation.

Other Advice:

It's a solid product supported by a solid company.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer2225733 - PeerSpot reviewer
Chief Executive Officer at a tech services company with 11-50 employees
Real User
Top 20
An AI-powered solution that is good enough to cover all cybersecurity activities
Pros and Cons
  • "The solution has gone beyond signature-based monitoring and analysis and is AI-powered. It is good enough to cover the full range of cybersecurity services."
  • "ArcSight ESM is not easy to use and it should be integrated with other tools that have infrastructure capabilities."

What needs improvement?

ArcSight ESM is not easy to use and it should be integrated with other tools that have infrastructure capabilities. 

For how long have I used the solution?

I have been working with the solution for a few months. 

What do I think about the stability of the solution?

ArcSight ESM is stable. 

What do I think about the scalability of the solution?

The tool is scalable and my company has 20,000 users. 

How was the initial setup?

ArcSight ESM is not difficult to deploy. It requires an extensive number of skilled cybersecurity experts.

What other advice do I have?

I would rate the tool a seven out of ten. The solution has gone beyond signature-based monitoring and analysis and is AI-powered. It is good enough to cover the full range of cybersecurity services. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Real User
Network investigation is poor but it's highly customizable

Valuable Features:

  • Powerful Correlation
  • Customization 
  • Integration capabilities

Room for Improvement:

  • Very complex install and management
  • Steep learning curve
  • Poor Network Investigation
  • Poor analytics.

Use of Solution:

Six years.

Stability Issues:

Yes, Logger, ESM and Connector ecosystem if not set up properly, lead to stability issues both in point operations as well as integrations.

Scalability Issues:

No. ArcSight is very scalable.

Customer Service:

3 out of 5.

Implementation Team:

We implemented it in-house.

ROI:

Poor as the product takes more effort to generate value. Its CAPEX cost is high too.

Other Advice:

If you really want the power and flexibility of customizing your Security monitoring and correlation, go with ArcSight, but beware of the effort involved in set up and maintenance.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 5Leaderboard
Great real-time reporting, offers simplicity for implementation and operations
Pros and Cons
  • "Very good real-time reporting with a good dashboard."
  • "Currently lacks SOAR feature."

What is our primary use case?

We deal mainly with enterprise companies - I'm the senior manager and we are partners with ArcSight. 

What is most valuable?

The solution has a good dashboard, very good real-time reporting and it's easy to use, offering simplicity for implementation and operations.

What needs improvement?

I'd like to see an improvement in their training and documentation. SOAR (Security Orchestration, Automation, and Response) would be a good feature to include in the future. 

For how long have I used the solution?

I've been using this solution for six years. 

What do I think about the scalability of the solution?

This solution is stable and scalable. 

How are customer service and support?

They offer 24/7 standby support wherever you are. It's very good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. 

What's my experience with pricing, setup cost, and licensing?

The cost is reasonable for a good solution.

What other advice do I have?

It's important to set up the organization before implementation, checking internal desktops or IT security internals before buying the solution.

I rate this product an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.