Try our new research platform with insights from 80,000+ expert users
it_user427377 - PeerSpot reviewer
Senior ICT Security Officer at a financial services firm with 1,001-5,000 employees
Vendor
It provides us with event correlations that are automated and prioritized according to level of security risk and compliance violation.

What is most valuable?

  • Real-time rules for threat detection
  • Event correlations that are automated and prioritized according to level of security risk and compliance violation

How has it helped my organization?

It allows us to be in better compliance with security protocols. It also gives us a better global vision of what is happening in the organization in terms of security threats and how best to analyze and mitigate them.

What needs improvement?

I would like to have native cluster for connectors as a software version and not as an appliance. It also needs a better disaster recovery procedure.

For how long have I used the solution?

We've been using ArcSight since 2007.

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.

What was my experience with deployment of the solution?

We've deployed it without any issues.

What do I think about the stability of the solution?

We haven't had any issues with instability.

What do I think about the scalability of the solution?

It's scaled fine for our needs.

Which other solutions did I evaluate?

We chose ArcSight when they had no real competitor and we stayed with them.

What other advice do I have?

I'm pleased with the current capabilities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user126642 - PeerSpot reviewer
IT Security Consultant at a tech services company with 51-200 employees
Consultant
The ESM and logger are powerful tools but log support needs improvement

What is most valuable?

Too many to name, but here are a few:
  1. Its versatility when it comes to vendor support.
  2. The ESM and logger are powerful tools. If used properly, we can achieve much more than we previously could. The Alert and Case Tracking mechanism contribute to the work of ESM and Logger.
  3. Express, all-in-one component is best for small businesses.
  4. NTP is efficient in blocking identified threats.
  5. ArcSight Flex Connector Development module is an excellent feature if you want to get the logs from unsupported vendor products.

How has it helped my organization?

I am a service provider for this product, so I provide value to the customer based on their requirements. The requirements are generally based on the lines of compliance and better security vision of what is going on in the organization, and who is doing what etc. and to mitigate external threats like port scans, DOS, malware ingestion, phishing etc.

What needs improvement?

Better reporting with the nice look and feel available in the wider market; also more vendor log support. HP should improve their Tech Support status.

For how long have I used the solution?

3+ years

What was my experience with deployment of the solution?

A few, depending on the specific organization's structure and policies.

What do I think about the stability of the solution?

No

What do I think about the scalability of the solution?

The solution itself is very scalable, but it is also a lot more expensive than other players.

How are customer service and technical support?

Customer Service: PoorTechnical Support: Poor

Which solution did I use previously and why did I switch?

No

Which other solutions did I evaluate?

Splunk, RSA Envision, McAfee Nitro and IBM QRadar

What other advice do I have?

Consider the complexity of this solution and choose the right people to deploy it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
PeerSpot user
Sales Engineer at a tech services company with 1,001-5,000 employees
Consultant
Enables you to create a dashboard for analytics and set alerts.

What is most valuable?

It is easy to use when we created some dashboards for analytics. ArcSight allows you to create a dashboard and provides an on-the-fly filter.

How has it helped my organization?

It makes things easy when I create a new alert.

What needs improvement?

They need to improve the Web UI, similar to how it is done with Splunk.

ArcSight is still using a Java app to do analytics.

ArcSight Express is using HTML5, which is good. However, the capabilities of ArcSight Express are not good when the data grows.

What do I think about the stability of the solution?

I did not have any issues with stability.

What do I think about the scalability of the solution?

I did not have any issues with scalability.

How are customer service and technical support?

Technical support responds quickly.

Which solution did I use previously and why did I switch?

We previously used RSA enVision. We had issues with the report generation.

How was the initial setup?

The installation is very easy.

What's my experience with pricing, setup cost, and licensing?

The licensing should come with EPS format, and not with EPD format.

What other advice do I have?

You need to first know the SIEM concept. SIEM can grow significantly, so you need to understand how to use a collector properly.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user730782 - PeerSpot reviewer
Delivery Consultant - Security Solutions with 1,001-5,000 employees
Vendor
By tweaking use case conditions one could identify potential security breaches, but admin is complex
Pros and Cons
  • "Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events."
  • "Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it."

How has it helped my organization?

Recent attacks like Shamoon and WannaCry were under continuous monitoring by using this solution. It is understood that every SIEM is a detective technology and not a preventive, but by tweaking the use case conditions one could identify potential security breaches.

What is most valuable?

Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events. Competitors offer the something similar but ArcSight does gives you more detail.

What needs improvement?

Complexity, administration. Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it.

What do I think about the stability of the solution?

Yes, quite a few times. But that depends on the admin, on how well the tool is maintained. Proper health checks are required on regular basis.

What do I think about the scalability of the solution?

Yes. Storage is an issue. Before deploying the product in the organization, proper scaling has to be done or else you end up losing the oldest data, hence failing to meet the audit.

How are customer service and technical support?

Eight out of 10.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

It was complex a few years. Lately it is all GUI and things are quite straightforward.

What's my experience with pricing, setup cost, and licensing?

ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value.

Which other solutions did I evaluate?

No.

What other advice do I have?

On-boarding is easy but administration is challenging and more fun.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user415854 - PeerSpot reviewer
Senior Information Security Engineer at a tech services company with 501-1,000 employees
Real User
The user has multiple levels of options to generate reports and get alerted based on conditions.

Valuable Features

  • Collection - Collects logs from a wide range of products, even those not supported by default and the users can develop a connector for log collection.
  • Detection - Caliber to detect subtle attacks with a powerful correlation engine.
  • Report/Alert - The user has multiple levels of options to generate reports and get alerted based on conditions.

Improvements to My Organization

By using ArcSight ESM and its correlation technology, it thwarts multiple attacks from external sources before exploitations such as SQL injection, UNIX password file attempt, brute force to published servers, and more.

In addition, internal frauds have been prevented through preventing unauthorized login attempts to the firewall, database, critical servers, etc.

Room for Improvement

ArcSight Connector appliance needs some improvement, as it has some bugs which triggers issues most of the time. I believe that the Connector is going to hit end-of-service.

Deployment Issues

We experienced no issues with the deployment.

Stability Issues

We had the bugs in Connector as detailed in the Areas for Improvement section.

Scalability Issues

We've had no issues with scalability.

Customer Service and Technical Support

Customer Service:

3.5*

Technical Support:

Technical support should be improved. Many times, I've raised a case but none of them solved it and it took the guys from the Protect724 forum so solve my issue. The support team simply collects the logs from end users and makes you wait, and you carry on passing the same information which is available in the Admin guide.

Initial Setup

All you need is proper planning and pre-requisites information, and it's straightforward. Some newbies say that this product is hard to handle, but basically practice makes perfect.

Other Advice

HP are doing their job perfectly by bringing new features in every version, such as RepSM, HA capability, etc. It has never failed me.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Techniqal Lead Enterprise Solution at a tech services company with 51-200 employees
Real User
Arcsight ESM is one of the best SIEM platform having market leading corelation engine, which is the plus point of Arcsight ESM it is very stable by its distributed architecture and scalability.
Pros and Cons
  • "I am satisfied with the solution's stability."
  • "Micro Focus does not have a physical presence here in Pakistan, although IBM does."

What is our primary use case?

We help our customers to implement the solution to detect known threats by state of the art variety of use cased offerings.

How has it helped my organization?

Arcsight ESM help customer in Automation for their complex security use case in order to detect the bad guys.

What is most valuable?

Corelation Engine by corelating the cross domain logs.

What needs improvement?

OOB content is limited Microfocus should release the smart connector update on quaterly basis.

For how long have I used the solution?

I've been working with the Micro Focus ArcSight portfolio for nearly six years.

What do I think about the stability of the solution?

I am satisfied with the solution's stability.

What do I think about the scalability of the solution?

I am satisfied with the solution's scalability. 

How are customer service and technical support?

We are satisfied with technical support and most of our problems have been resolved.

How was the initial setup?

Simple and pretty straight forward.

What about the implementation team?

We provide the implementation and maintenance services of the solution for our customers.

Which other solutions did I evaluate?

According to the Gartner Reports and Gartner Reviews, the main competitors of the solution are IBM and Splunk. They provide their services world-wide and do much implementation in the region. 

the plus point for Arcsight ESM is having cross domain corelation feature.

What other advice do I have?

I rate ArcSight Enterprise Security Manager (ESM) as a 8 out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Solutions Architect- SIEM and Solutions with 1,001-5,000 employees
Vendor
Most devices are covered out-of-the-box. I would like to see high-end, predictive analytics.

What is most valuable?

The most valuable features are flexible setup of the architecture and large coverage of devices. Most devices deployed in enterprise environments are covered out-of-the-box by ArcSight. Unlike a few other solutions, the last-mile connectivity with ArcSight agent servers is free and flexible across all location deployments.

How has it helped my organization?

I have implemented it for a few organizations and they have benefited by early attack detection and usage of the right incident response mechanisms.

What needs improvement?

I would like to see high-end, predictive analytics. ArcSight ESM has some features that help in advanced correlation rules creation. However, intelligence around predictive analytics, understanding the current security posture and ability to map it with possible threats in the future is not something that is present in ArcSight at the moment.

For how long have I used the solution?

We’ve been using ArcSight for 3 years.

What do I think about the stability of the solution?

I have not had any issues with stability.

What do I think about the scalability of the solution?

I have not had any issues with scalability.

How is customer service and technical support?

I have never used technical support much, but will give it 3/5.

How was the initial setup?

The connectors are straightforward. The baselining is where the issues start.

What's my experience with pricing, setup cost, and licensing?

Licensing is straightforward, but the solution is fairly pricey.

Which other solutions did I evaluate?

We looked at QRadar and LogRhythm.

What other advice do I have?

Ensure your scope is very clear and so are the components.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user126648 - PeerSpot reviewer
Senior Security Analyst at a tech services company with 10,001+ employees
Real User
Great Scalability and Adaptability but it's Expensive

What is most valuable?

Scalability and Adaptability. By Scalability, I mean, the number of supported devices by ArcSight. You can make changes to the current deployment if required or add a new region in the scope by adding components of ArcSight. By Adaptability I mean, once the analysts see what can be achieved by utilizing the various resources of ArcSight, it motivates them to come up with new ideas and how to implement them. The interface is quite user friendly compared to other Vendors.

How has it helped my organization?

We could extract meaningful data of the billions of Security Events and relate it with the extra information we had for our assets.

What needs improvement?

Support from the vendor and pricing.

For how long have I used the solution?

3 Years.

What was my experience with deployment of the solution?

No

What do I think about the stability of the solution?

Yes, Oracle bugs mostly.

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

Good.

Which solution did I use previously and why did I switch?

I have worked on multiple SIEM products. I work as a Senior Security Analyst and have a minimal role in deciding the solution. I only work where it is explicitly an HP ArcSight environment or deployment.

How was the initial setup?

Straightforward.

What about the implementation team?

Through an in-house team.

What other advice do I have?

Best SIEM product but it's high on pricing and licensing.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.