Flexibility, high ingestion rate, and complexity of use cases.
CISO and DPO at ValueLabs LLP
Good visibility into end-to-end communications helps discover security threats
Pros and Cons
- "ArcSight gives us better visibility into threats that were unknown earlier."
- "We would like the ability to easily identify either unused resources or those that are being used sub-optimally."
What is our primary use case?
How has it helped my organization?
ArcSight gives us better visibility into threats that were unknown earlier. We now have an ability to assess end-to-end communications, as well as alerts from various security solutions along the path.
What is most valuable?
The most valuable features are lists, correlation, escalation matrix, and customers.
What needs improvement?
The following needs to be improved:
- We would like the ability to easily identify either unused resources or those that are being used sub-optimally.
- ESM should make usage of variables and other such deep customizations, highly intuitive.
- User behavior analytics is too pricey but an essential tool.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
For how long have I used the solution?
We have been using ArcSight for eight years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Network Security Engineer, Security Monitoring Center at a tech services company
FlexConnector collects logs from your own application.
What is most valuable?
The ArcSight solution supports your security team with many SIEM features:
- Monitoring
- Analysis
- Alerts
- Incident response
In my opinion, ArcSight is an open solution. It is easy to:
- Customize components
- Use FlexConnector to collect logs from your own application
- Edit rules and the dashboard
- Create work flows
- Enrich information for events
How has it helped my organization?
I work at an ArcSight distributor in Vietnam. I have deployed the ArcSight solution for many customers. Some organizations are using it for SOC’s core and others for monitoring their information systems, critical assets, and regulatory and policy compliance.
For how long have I used the solution?
I have over two years of experience.
What do I think about the stability of the solution?
It can be overloaded when rules and data monitoring are not optimized and the system receives too many events.
What do I think about the scalability of the solution?
ArcSight can be extended to meet the biggest customers (large enterprise) needs.
How is customer service and technical support?
ArcSight technical support is enthusiastic. They have a lot of experience and many case studies.
How was the initial setup?
ArcSight configuration and deployment is complex, because it has many components.
Which other solutions did I evaluate?
I researched Splunk, QRadar and AlienVault, and I appreciate Splunk and ArcSight.
What other advice do I have?
ArcSight provides many documents and guides for configuration and operation. Also, you can refer to its community at https://www.protect724.hpe.com.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a partner of HPE ArcSight.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Cyber threat Intelligence Manager at CyberLab Africa
Scalable, good technical support, but stability could improve
Pros and Cons
- "We have been satisfied with the support."
- "The solution could be more stable."
What is our primary use case?
We are using ArcSight Enterprise Security Manager (ESM) for data analytics. We monitor the reports on security event information.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
The solution could be more stable.
What do I think about the scalability of the solution?
We have not had any issue with the scalability.
We have approximately 20 users using this solution in my organization.
How are customer service and technical support?
We have been satisfied with the support.
How was the initial setup?
The installation was easy.
What about the implementation team?
We had assistance with the implementation of the solution. We have approximately five individuals that do the maintenance.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution.
What other advice do I have?
I would recommend this solution to others.
I rate ArcSight Enterprise Security Manager (ESM) a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Analyst at a comms service provider with 1,001-5,000 employees
The roadmap is not clear but it has a very good correlation feature
Pros and Cons
- "The correlation feature is good."
- "The roadmap is not clear."
What is our primary use case?
Our primary use case is for security purposes. We are customers of ArcSight and I'm an information security analyst.
What is most valuable?
I think the correlation feature is one of the best features of ArcSight.
What needs improvement?
A lot of improvements could be made in the product. I think the roadmap is not clear, and there is no AI or machine learning solution.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
We haven't had any issues with stability.
How are customer service and technical support?
I think there is good technical skill with the technical support but their attitude and response time is not good.
How was the initial setup?
I recall that the initial setup was quite complex. We took subscription services for two weeks which covered the period of deployment.
Which other solutions did I evaluate?
We are actually moving to another solution because the roadmap is not clear. We are just a small team and we don't need to monitor 24/7. We're looking to replace it with another more intelligent solution like Splunk or Securonix.
What other advice do I have?
Honestly, I won't recommend the ArcSight to another person.
I would rate this solution a four out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Architect at a tech services company with 51-200 employees
Its flexibility is achieved by being easy to use, and at the same time having very sophisticated FlexConnectors.
What is most valuable?
The best feature of ArcSight is its flexibility. Almost no other vendor provides such a good framework to collect, parse, and analyze data. Its flexibility is achieved by being easy to use, and at the same time having very sophisticated FlexConnectors. Also, I've found ArcSight's correlation engine to be the most advanced on the market.
How has it helped my organization?
My customers who use ArcSight report that it becomes very useful in incident detection and forensics. It's really sped up disclosure of inappropriate activity in information systems and on the network. Flexible event collection allows getting crucial events from almost every possible source. And correlation abilities are incredible if you know how to cook it.
What needs improvement?
Many competitors are going down the road of combining their products with other security products, such as vulnerability scanning, configuration control etc. HP's position doesn't change in that area as they offer to use their standalone solutions and integrate them in ArcSight. There are no embedded scanners or network forensics. Maybe it's time for HP to rethink that position.
For how long have I used the solution?
I've been working with HP ArcSight since 2008. All that time, the product has been growing and evolving, trying to give us more profit and a better experience to old and new customers.
What was my experience with deployment of the solution?
We have had no issues with the deployment.
What do I think about the stability of the solution?
If you encounter serious performance problems, you didn't size correctly prior to deployment.
What do I think about the scalability of the solution?
The scalability options are pretty good although costly.
How are customer service and technical support?
Customer Service:
Every product has its stability bugs, and ArcSight is not an exception, though I haven't found anything critical.
Technical Support:I must say that tech support is getting worse and worse every year. Hard cases may "hang" for months. In simple cases, support often demonstrates a lack of deep knowledge. When ArcSight was not HP, its product support was much much better. Even first-line support could help with anything.
Which solution did I use previously and why did I switch?
As a systems integrator, we constantly evaluate different solutions and deploy not one but many of them. My personal opinion is that a crucial feature for a SIEM system is flexibility. The more you can tune, adjust, and develop the system, you will get more profit from it. If we're talking about SIEM solutions, then no one can offer such flexibility as ArcSight. Splunk maybe, but Splunk is not SIEM, and to get SIEM-like features from it you spend more time and money.
What about the implementation team?
As a system integrator, I always say that implementation must be done by an experienced team. SIEM solutions are not easy, so if time is important, do not rely on doing it haphazardly.
What's my experience with pricing, setup cost, and licensing?
We would like it to be cheaper, but the licensing model is pretty simple.
What other advice do I have?
You need to read the documentation - you can then get it fast and working. If you do not read the documentation, you get pain and tears. Look for an experienced team to deploy the solution, or get experience yourself as HP has some good learning courses.
Deep knowledge of the product will come later, but for the correct implementation you need to be prepared. ArcSight has wonderful community, and you can always ask a question or find an interesting use case there. It's a very useful resource indeed, do not hesitate to visit it.
Disclosure: My company has a business relationship with this vendor other than being a customer: We integrate ArcSight for our customers.
System Engineer at a tech services company with 51-200 employees
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation. They need to fix some bugs and increase the search speed.
Valuable Features
The dashboard is the most valuable feature for us as it can show a lot of information about real-time incidents.
Improvements to My Organization
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation.
Room for Improvement
They need to fix some bugs and increase the search performance speed. Sometimes there are issues when I perform log correlations.
Deployment Issues
We have had no issues with the deployment.
Stability Issues
There have been no stability issues.
Scalability Issues
We have had no issues scaling it for our needs.
Customer Service and Technical Support
Customer Service:
5/10
Technical Support:5/10
Initial Setup
The initial setup was quite easy and straightforward.
Implementation Team
I work for a reseller, and we set up ArcSight for our customers, and I am learning a lot about its architecture.
Other Solutions Considered
For SIEM, I think HP ArcSight is a leading competitor alongside Splunk.
Other Advice
You need to learn about architecture and practice more before implementation since this product is not easy to learn and takes time to master.


Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technological Officer at a tech consulting company with 51-200 employees
Very useful tool for intelligence building as it has many use cases and many rule sets
Pros and Cons
- "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
- "It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are."
What is our primary use case?
We use ArcSight Enterprise Security Manager for any type of cyber security attack.
It is in the cloud and on the customer's infrastructure. I am only deploying one agent and the agent is deploying all the information from the customers and then sending it to the cloud.
I am an integrator, but we sell our services. I'm not selling the software directly to customers. I'm selling my service with this product.
What is most valuable?
It is a very useful tool for intelligence building because it has many use cases and many rule sets.
What needs improvement?
It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are.
In the next release, it would be nice if the Logger model and the ESM model would be merged. Right now there are two big models, Logger and ESM, but from a Windows perspective, it is not good because they're sending Logger and ESM separately. So if you need ESM, you have to buy both Logger and ESM but if you only need Logger, you are buying just Logger. You can deploy them on one system, but you have two different systems and different databases. My suggestion would be to merge Logger and ESM together.
For how long have I used the solution?
I have been using ArcSight Enterprise Security Manager for about a year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
Arc Sight Enterprise Security Manager is scalable.
The number of people running it should be based on the organization's size. If you have a company with 500 assets, you should have at least one field engineer for the ESM product and two security analysts to operate this software. This is minimum. One engineer and two security analysts is minimum to start if the organization is midsize.
How are customer service and support?
Their technical support is generally good. On a scale of five, I'd give them four out of five.
How was the initial setup?
The initial setup is complex.
Installation is not complex, but Micro Focus also has different intelligence products. One runs on containers and it is quite complex to install and use, but it is a different product. So maybe if we can remove this wall then we should be all right.
I have two products from Micro Focus. I have this ESM and one for Web. It is for user IT behavior analytics. The second product is quite complex and it's linked to it. Then you have to connect these things together. So the complexity is in the Web product, not in ESM.
Our own site deployment took about one month to deploy and we can deploy services for our customers in about two weeks minimum. But that is a minimum. If the infrastructure is big, it may take up to two or three months. If the infrastructure is not logging or if there are many customer applications, it makes it complex to deploy. Every ESM product will be complex to implement if the organization is big and the logging is not enabled correctly.
What other advice do I have?
My advice to anyone considering Arc Sight Enterprise Security Manager is to just read the manual. Just read the manual and documentation.
On a scale of one to ten, I would rate it a nine.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security and Business Data Protection Specialist at a comms service provider with 1,001-5,000 employees
The webpage algorithm is the most valuable feature because it is the fastest feature for searching logs, events, and correlation
Pros and Cons
- "The webpage algorithm is the most valuable feature because it was the fastest feature for searching the logs, events, and correlation."
- "The security area has room for improvement."
What is our primary use case?
It's the security analyst for incident response, forensic investigations, and security monitoring.
How has it helped my organization?
It has improved our organization because we had many investigations that it helped us with.
What is most valuable?
The webpage algorithm is the most valuable feature because it was the fastest feature for searching the logs, events, and correlation.
What needs improvement?
The security area has room for improvement.
For how long have I used the solution?
More than five years.
What other advice do I have?
I would rate this solution a seven out of ten. To make it a ten they should develop a design for the security operations. It's a SIEM solution and I can see that it has some segregation of the consoles and duties for the different parties when we want to monitor different components like the security operations center.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Google Chronicle Suite
Securonix Next-Gen SIEM
Sumo Logic Security
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?