We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens.
Information Security Analyst at Banglalink
Other solutions perform better and have a slicker GUI, but this one is cheaper
Pros and Cons
- "We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens."
- "ArcSight ESM needs to improve performance, user interface, and automation."
What is our primary use case?
How has it helped my organization?
ArcSight ESM helps us stop security incidents by detecting them early before they can cause more damage.
What needs improvement?
ArcSight ESM needs to improve performance, user interface, and automation.
What do I think about the stability of the solution?
ArcSight has become more stable with the latest patches that have come out, but we also have had many difficulties applying the patches
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It's costly to scale up ArcSight ESM, but it's scalable. You have to pay for extra storage, licenses, and log processing.
How are customer service and support?
ArcSight support is okay but slow. It isn't provided promptly. There is a vast time difference between American time and East Asian time.
How was the initial setup?
Setting up ArcSight is very complex. Nothing about it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
ArcSight's price is reasonable. That's why our company was forced to buy this. It's cheaper than some of the better solutions.
Which other solutions did I evaluate?
LogRhythm has a better GUI and some automation options, like an automated password writing script. In Exabeam, I can see an event with the user's picture, which Exabeam can draw from the Active Directory. It has a better GUI, better performance, and customization. I expect these things from ArcSight, but it can't deliver yet.
What other advice do I have?
I rate ArcSight three out of 10. I would never recommend it. I would recommend QRadar, LogRhythm, or Exabeam, but they all cost more. Price is its only advantage.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

IT Security Manager at a tech services company with 10,001+ employees
A robust solution that helps us with our internal log and threat analysis
Pros and Cons
- "It is a robust product and has multiple valuable features."
- "The dashboard looks a bit cumbersome."
What is our primary use case?
We use it for our internal and vendor daily base of log analysis and threat analysis.
What is most valuable?
It is a robust product and has multiple valuable features. For example, it has robust threat intelligence built into its customization and great templates that provide ease of use.
What needs improvement?
The dashboard looks a bit cumbersome with the current version. They should work on the dashboard and optimize their integration which currently lags with devices of reputed vendors. So, having these custom integrators sometimes works and sometimes doesn't.
For how long have I used the solution?
We have been using this solution for almost ten years. It is deployed on private cloud.
What do I think about the stability of the solution?
We haven't experienced any stability challenges. It works if we get enough hardware and software provisions for the vendor recommendation.
What do I think about the scalability of the solution?
On-premises is a challenge to scale, and we haven't tried the cloud but we've heard it's quite scalable and robust.
How are customer service and support?
We do not use technical support that often. They are very good, but they should train their L1-level support. Overall, they're a good strong team.
How was the initial setup?
The setup is neither easy nor difficult and depends on the expertise. It requires really good expertise to build from scratch. The setup itself is not a big hassle, and in a week, the system is up and running, but the main challenge is the integration. We keep integrating, and with the password of the integrated direct, it's fine.
What's my experience with pricing, setup cost, and licensing?
It is a licensed product.
What other advice do I have?
I rate this solution an eight out of ten in terms of the inbuilt features and how it has grown into a strong solution over the years. The team has done an excellent job with the features, integrations, and compatibility.
Regarding advice, I think the assessment on currently sizing the product to their need is key. It's an expensive product, so sizing is the most important choice. In addition, I believe moving to cloud has more robust integration features. They are building new custom solutions that can be integrated with ESM for better analysis.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025

Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Senior Cyber Security Analyst at a tech services company with 10,001+ employees
It allows for easy log analysis as well as correlation and alerting.
What is most valuable?
- Logger
- Command Center
How has it helped my organization?
The ArcSight ESM allows for easy log analysis as well as correlation and alerting. Logger is an indexed database which allows for faster, historical searching. The versatility to use SQL queries is helpful.
What needs improvement?
There are some limitations on the functionality of Rules that I would like to see expanded. I would like to see some better support options in the ArcSight community for HP Protect. Unless someone in your organization is an ArcSight SME, you are going to have a difficult time getting answers.
For how long have I used the solution?
I've used it for two years.
What was my experience with deployment of the solution?
There were no issues with the deployment.
What do I think about the stability of the solution?
We've not had any issues with the stability.
What do I think about the scalability of the solution?
We've had no issues scaling it for our needs.
How are customer service and technical support?
I would give it 3/10. A lot of the support is community based. That strategy can work, but the answers are sometimes incomplete, incorrect, and can take a long time to get.
Which solution did I use previously and why did I switch?
I have used QRadar and Splunk. Both have great functionality that make them easy to use, but ArcSight has a very consistent layout and their logic is easy to figure out.
How was the initial setup?
I was not involved in the setup.
What's my experience with pricing, setup cost, and licensing?
I'm not involved in pricing or licensing.
What other advice do I have?
It's a well rounded product especially with the addition of Logger and Command Center. I felt it was easy to understand and use right from the start. There are some companies that do not take advantage of everything ArcSight can offer. A problem I think ArcSight can fix with better support alternatives.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Engineer at Billie
Can write queries fast but visualization isn't good
Pros and Cons
- "On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented."
- "I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards."
What is our primary use case?
I use the solution to implement detection rules based on attack scenarios.
What is most valuable?
On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented.
What needs improvement?
I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards.
For how long have I used the solution?
I have been working with the product for a year.
How are customer service and support?
The tool's support is one of its best parts.
How would you rate customer service and support?
Positive
How was the initial setup?
I wasn't involved in the initial setup and deployment of ArcSight ESM, as it had already been implemented when I joined the company. I worked on implementing dashboards and detection rules. The rule categorization was good and had a good alert system when rules were triggered.
What's my experience with pricing, setup cost, and licensing?
Price-wise, ArcSight ESM was a bit high compared to competitors, which factored into our decision to switch to Splunk. It couldn't cover all our business needs for what we wanted to implement.
What other advice do I have?
I rate the overall solution a five out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Sep 9, 2024
Flag as inappropriateChief Commercial Officer at Yamamah Information Technology & Communication Systems LLC
Easy to manage for anyone, simple cyber security reports, and good support
Pros and Cons
- "The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided."
- "ArcSight ESM could improve the alerts for the storage capacities or actions."
What is our primary use case?
ArcSight ESM is used as a security information and event management (SIEM) solution. It has been used in banks.
What is most valuable?
The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided.
What needs improvement?
ArcSight ESM could improve the alerts for the storage capacities or actions.
For how long have I used the solution?
I have been using ArcSight Enterprise Security Manager (ESM) for approximately six years.
What do I think about the stability of the solution?
ArcSight ESM is stable.
What do I think about the scalability of the solution?
The scalability of ArcSight ESM is very good.
On the client's bank site, there are approximately 1,500 users using the solution.
How are customer service and support?
The support for ArcSight ESM has been very good.
How was the initial setup?
The deployment of ArcSight ESM is easy.
What about the implementation team?
We have approximately six people from our information security department managing ArcSight ESM. The deployment was done by four engineers.
What's my experience with pricing, setup cost, and licensing?
ArcSight ESM is an affordable solution, it cost approximately $200,000 for three years. This price was at a substantial discount.
Which other solutions did I evaluate?
We have evaluated IBM QRadar before choosing ArcSight ESM.
What other advice do I have?
My advice to others is once they evaluate ArcSight ESM they will love it.
I rate ArcSight ESM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Officer IT at Tech Data Limited
Interactive dashboards provide lots of detail, but tough to operate for new users
Pros and Cons
- "I think that the overall experience with this solution is good, but in particular, I think that the dashboards are quite interactive."
- "It would be nice if the interface were more user-friendly, with, for example, a minimal number of tabs to navigate."
What is most valuable?
I think that the overall experience with this solution is good, but in particular, I think that the dashboards are quite interactive.
What needs improvement?
For somebody who is new and just starting with this product, they find it really tough. The software is quite big. It would be nice if the interface were more user-friendly, with, for example, a minimal number of tabs to navigate.
A walkthrough that shows everything a normal user might do would be very helpful.
I would like to see improvements on the Active Channel side of this solution.
For how long have I used the solution?
Between one and two years.
What do I think about the stability of the solution?
The software itself seems to be stable, as we have not actually experienced any bugs. The connection depends on the network side, but overall it seems to be working fine.
What do I think about the scalability of the solution?
This solution would be more scalable if the interface were more user-friendly. There are rules and alerts, and the user has to have the proper knowledge of all of these things. With a walk-through, I think that it would be quite easy to scale.
We have two people using this solution, and we perform monitoring on a daily basis. In our environment, adding users is quite rare.
How are customer service and technical support?
We did have a couple of problems recently where one of the modules was not communicating well. In terms of support, I think that they are quite good.
Which solution did I use previously and why did I switch?
This is the first solution that we have used for monitoring.
How was the initial setup?
I was not involved in the initial setup of this solution.
What other advice do I have?
This is a really good solution and I would recommend it. If you know how to work it, and how to configure it properly, then it can give you lots and lots of information. On the other hand, it provides so much detail that people can miss things. If the interface and reports were minimized and consolidated then it would be better.
I would rate this solution a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Lead Splunk Architect at a financial services firm with 10,001+ employees
CEF log formatting helps with combining events from different sources. It can be quite complicated for the "non-IT" user.
What is most valuable?
Correlation and data normalization via CEF: The speed of ArcSight's correlation engine, together with data enrichment, makes it a great tool for exploring vast amounts of data. Other SIEM tools have a hard time giving the same results at the same speed. Also, thanks to CEF log formatting, combining events from different sources takes minimal effort. Whereas, setting up that normalisation on other SIEM competitors could take countless hours.
What needs improvement?
Ease of use, access and simplicity: HPW ArcSight makes it hard to capitalize on reports without the use of the console. Other SIEM tools have made it clear that event correlation results can be used not only to send out alerts, but also to provide easily accessible results to management.
ArcSight can be quite complicated to use for "non-IT" user. In terms of "ease of use", access and simplicity, HPE could do a better job, since customers acquiring the product should be spending more time on implementing use cases than on understanding the product and the console organization.
Also, in terms of installation, we are no longer in an era where installing a product should be a laborious process. Instead, it should be simple and fast.
Also, when it comes to data onboarding, managing ArcSight connectors in a multi-technology environment, there is no simple way to guarantee that data parsing is happening properly.
Finally, having simple-to-set-up, multi-site high availability, in contrast to single-site HA, would be very welcome.
For how long have I used the solution?
I’ve been using ArcSight for three years.
What do I think about the stability of the solution?
We have had some issues on the SmartConnector layer, since not all parsers provide perfect results (especially in the case of proxy data). Also, there have been some issues on the HA modules, since HA works sort of like a local r-sync (no remote HA).
What do I think about the scalability of the solution?
No scalability issues have been encountered so far. ArcSight's architecture is very scalable, especially when set up in a layered architecture.
How are customer service and technical support?
Support is slow and doesn't always have the required skill set to solve the issues.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
Initial setup was very complex. Any modification to the OS prior to ESM installation may cause errors in installation. Most errors aren't explicit and require a lot of time, effort and sometimes PS help to solve.
What's my experience with pricing, setup cost, and licensing?
Price is fair compared to other SIEMs (Splunk, QRadar, etc.). It's not the go-to product if you are looking for something cheap. Go for ArcSight, if it provides specific features that your IS requires.
Which other solutions did I evaluate?
Before ArcSight, we looked at QRadar and Splunk.
What other advice do I have?
My first advice is "be patient". It takes a lot of time to deploy an ArcSight infrastructure, but the result is worth it. Technically, it’s a very powerful tool. It would be worth it to take the time to learn some of the hidden features.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Specialist at a tech services company with 501-1,000 employees
Correlation and flexibility are valuable. It helped meet compliance requirements for log collection.
What is most valuable?
Correlation and flexibility are the most valuable features.
How has it helped my organization?
ArcSight saved time and effort responding to security incidents with one centralized console and helped to meet compliance requirements for log collection.
What needs improvement?
I would like to see improvement in the complexity involved to create a custom connector (flex). Other SIEM solutions, like QRadar, have addressed this.
For how long have I used the solution?
We have used ArcSight for 6 years.
What do I think about the stability of the solution?
Initial deployment of ArcSight is pretty challenging. It takes at least 3-4 months to install, integrate, define content and fine tune before starting the security operation.
How are customer service and technical support?
Customer service is fast in response, but very standard in their approach, which takes lot of time for simple issues.
Which solution did I use previously and why did I switch?
I have used RSA enVision, QRadar and Splunk. ArcSight is better than them all when it comes to filtering, normalization, aggregation, dashboards, reporting and correlation, multi-tenancy and custom devices support.
How was the initial setup?
Initial setup was complex as the integration of a custom application takes lot of time and effort. Then, fine tuning requires at least 6 weeks to analyze and tune each alert separately.
What about the implementation team?
We implemented through HPE itself and I would advise to go through a vendor as they would hand over the SIEM post-fine tuning which is a mammoth task.
What was our ROI?
ROI can be measured in terms of detected security incidents and compliance positive tests, which in turn boost the business. Our security incident count increased from 3 per month to 46 and all were real security threats. Had those gone undetected and realized, there would have been possible data theft, information stealing, damage of brand reputation, etc.
What other advice do I have?
An organization that has enough budget for SIEM and really cares about security and not only about compliance must go with ArcSight. SMB organizations who want to start a SOC or have just a log management solution for compliance requirements can go for cheaper options such as QRadar, LogRhythm, AlienVault, etc. For MSSP, ArcSight is indeed the best SIEM available in the market, as segregation of logs, access restriction, different log retention, customized view for dashboard and reports to clients are present with ease.
Lastly, ArcSight is like Apple. If you have money, go for iPhone and you will certainly not regret it. But if your budget is the primary constraint, then another SIEM must be explored.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Google Chronicle Suite
Securonix Next-Gen SIEM
Sumo Logic Security
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?