Try our new research platform with insights from 80,000+ expert users
Forensic Consultant at A Cyber 1 Company
Consultant
Good out-of-the-box rules, but the integration and reporting features can be improved
Pros and Cons
  • "The out-of-the-box rules that help us configure functioning rules within the environment are valuable."
  • "Customer service and support is our biggest challenge."

What is our primary use case?

We use this solution in our customers company and we deploy the solution on cloud and on-premises.

What is most valuable?

The out-of-the-box rules that help us configure functioning rules within the environment are valuable. For example, they have good resources to help detect and populate the dashboard if something malicious happens. Additionally, we value a good visual representation of a company and network infrastructure.

What needs improvement?

The solution can be improved regarding integration with other security products, ease of implementing some features, and feeling like we're not utilizing the solution as best as we could. In the next release, the solution should incorporate some threat intel features and integrate well with other network solutions, EDRs, palm solutions and the sorts. Additionally, the reporting can be improved to bring out very insightful reports showing senior management value for the solution.

For how long have I used the solution?

We have been using the solution for approximately six months.

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. I rate it an eight out of ten.

What do I think about the scalability of the solution?

The solution is scalable and has approximately 500 users utilizing it for enterprise businesses.

How are customer service and support?

Customer service and support are one of the biggest challenges we are having. Although it is provided, and once you log tickets, they follow up quickly, sometimes some of the challenges we face drag on for a while because of ironing out specific details about technical support and payments.

How was the initial setup?

The initial setup was a bit complex. Getting things running and configured took a while. Furthermore, some integrations were unavailable, and some had to be custom scripted, so getting the solution up and running was a bit tedious.

What about the implementation team?

We implement in-house, and it takes approximately two months to complete implementation.

What's my experience with pricing, setup cost, and licensing?

The licensing costs are high and the solution is priced through events that come in so the cost tends to be heavy on the client. The price of the license could be lower.

What other advice do I have?

I rate the solution a six out of ten. The solution is good, but its integration and reporting features can be improved. I advise users to have a mature security infrastructure and scale up their technical resources. However, for smaller organizations considering the solution, I advise them to think of other solutions before using ArcSight Enterprise Security Manager.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
reviewer1417383 - PeerSpot reviewer
Presales Manager at a tech services company with 51-200 employees
Real User
The flex connector lets you develop new connectors to integrate homebrew solutions
Pros and Cons
  • "The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector."
  • "When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets."

What is our primary use case?

We use ArcSight primarily to provide logs for the incident response team and cyber security analysts to evaluate everything happening in the network. 

What is most valuable?

The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector.

What needs improvement?

When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets.

What other advice do I have?

I rate ArcSight Enterprise Security Manager nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2025
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
851,823 professionals have used our research since 2012.
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 5Leaderboard
Scalable, with good support and live reporting
Pros and Cons
  • "The most useful features are directories, price, and live reporting."
  • "The customer experience could be improved."

What is our primary use case?

We are resellers. We deal with many vendors to provide and implement solutions for our clients. We primarily use this product for logging data.

What is most valuable?

The most useful features are directories, price, and live reporting.

What needs improvement?

The customer experience could be improved.

I think they can improve the AI and monitoring. Also, they need an updated database.

For how long have I used the solution?

I have been dealing with this solution for approximately three years.

We are working with the last updated version.

What do I think about the stability of the solution?

The stability can be improved. The competitors are more stable.

What do I think about the scalability of the solution?

It's a scalable product and the scalability is good.

Our clients are usually enterprise companies.

How are customer service and technical support?

The technical support is good. They have been able to resolve our issues.

Which solution did I use previously and why did I switch?

We are using SIEM. It has a better dashboard and is more complete.

How was the initial setup?

The initial setup can be simple and also complex. It depends on the client's infrastructure.

What about the implementation team?

We implement the solution and maintain it for the clients.

What's my experience with pricing, setup cost, and licensing?

It's a good price, it's one of the cheaper solutions.

There are no additional costs.

What other advice do I have?

Depending on the size of the companies, I would recommend this solution. It's more suited for small to medium-sized companies.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies
Real User
Easy setup but should offer an entire report listing of integrated devices
Pros and Cons
  • "There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive."
  • "I would like to have a feature that gives us an entire report listing what devices are integrated."

What is most valuable?

There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive. 

What needs improvement?

The security is difficult. 

I would like to have a feature that gives us an entire report listing what devices are integrated.

For how long have I used the solution?

I have been using ArcSight for the last five years. 

How are customer service and technical support?

In the beginning, we got good support but it hasn't been what it used to be. On weekends we get the list of devices that are integrated but if we need to generate the lists of rights, it doesn't send the logs.

How was the initial setup?

The initial setup was simple. The initial setup took five to six days.

What other advice do I have?

I would rate it a seven out of ten. In the next release, I would like for them to include a list of integrated devices. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Security Expert at a tech services company
Consultant
The correlation capabilities are valuable. It is too restrictive to suit the flexibility needs of the infrastructure.

What is most valuable?

Correlation capabilities: This product provides an advanced level of correlations, which is highly valued.

How has it helped my organization?

HPE ArcSight has helped us gain visibility of the solutions across the organization. We have been constantly identifying anomalous activities both internally as well as externally. These include malware proliferation, data loss, proxy bypass attempts, phishing and spear-phishing, port scans, etc

What needs improvement?

It can be more user-friendly. The product is too restrictive to suit the flexibility needs of the infrastructure. It is sometimes hard to implement the solution as recommended by HPE.

For how long have I used the solution?

I have used this solution for around four and a half years. Currently, we are using HPE ArcSight Express 5, ESM 6.8, Connector Appliances and SmartConnectors 7.4.

What do I think about the stability of the solution?

In version 5, I used to experience some issues as it was using Oracle DB. Although, I do not have any problems in version 6+.

What do I think about the scalability of the solution?

This product is not easily scalable. We particularly required skilled personnel to do this activity and it also took a significant amount of time.

How are customer service and technical support?

The technical support is poor.

Which solution did I use previously and why did I switch?

We were not using any other solution before. We started using HPE ArcSight straightaway.

How was the initial setup?

Setting up of the ArcSight solution is always complex compared to other solutions out there. There are a lot of parameters and dependencies involved. Adding infrastructure complexity will add more complications. Distributed deployment is also difficult to implement.

What's my experience with pricing, setup cost, and licensing?

It is very expensive for larger deployments.

Which other solutions did I evaluate?

We are now working with open-source systems and Splunk solutions. We are decommissioning HPE ArcSight as it is getting impractical to manage and maintain the solution.

What other advice do I have?

There are better products in the market for medium to large-scale deployments. It is recommend to use this product for small-scale deployments, i.e., 200-800 EPS.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Consultant
Leaderboard
Has helped us to gather, store, correlate and analyze security log data from many different information systems.

Valuable Features:

Intrusion Detection System (IDS)

Security Information and Event Management (SIEM)

Improvements to My Organization:

To organizations like mine, security information and event management products being introduced in the industry, as an outcome of several vulnerability, are able to provide real-time monitoring reporting and defense against these attacks. It has helped us to gather, store, correlate and analyze security log data from many different information systems.

Room for Improvement:

For this review, ArcSight sent me the Logger 4 7000-series appliance (2U) with six 1TB RADIUS drives, the maximum amount of internal storage available. I will like to see a threat analytics module. Also, the ability to produce reports.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partners
PeerSpot user
PeerSpot user
IT Security Assistant Manager at a insurance company with 5,001-10,000 employees
Real User
It allows us to traceback security threats, to generate usage trends and discover anomalies.

Valuable Features:

For us, there are several valuable features.

  • The ability to correctly parse the most number of products comparing to its competitors;
  • The ability to create very complex scenarios to detect security risks and anomalies;
  • Very stable system components (connectors, logger and correlation engine) combined with satisfactory vendor support; and
  • The ability to create parsers for all kinds of applications and systems is an important differentiator.

Improvements to My Organization:

It greatly changed our work habits in the organization allowing us to not only trace back security threats, but also to generate usage trends, discover anomalies and so many other usages. It quickly became an indispensable tool.

Room for Improvement:

They can definitely provide faster search response and offer larger on-the-box storage support. The predefined correlation ruleset can be improved to cover more security alerts and more products.

There is also still room for improvement for processing speed. An easily accessible documentation such as reference architectures does not exist, more guidance can be provided to customer for such a complex product.

Deployment Issues:

We've had no issues with deployment.

Stability Issues:

We've had no issues with stability.

Scalability Issues:

We've had no issues with scalability.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user147210 - PeerSpot reviewer
Sr Security Engineer at a tech services company with 51-200 employees
Consultant
There are SO MANY things you can do in AS, and there is a lack of really in-depth documentation on a lot of it.

What is most valuable?

Not really a feature, per se, but the ability to do multi-tenant SIEM.

How has it helped my organization?

We help our customers do more than 'check a box' for security and compliance and we are very proud of that. We tend to be more like partners to a lot of our customers, and they rely on us to deliver high-fidelity, relevant security alerts. 

What needs improvement?

There are SO MANY things you can do in AS, and there is a lack of really in-depth documentation on a lot of it. I am not sure why this is, but it is a little hard to be self-sufficient when this is the case. I am sure this is why real ArcSight experts are in demand! Being too feature-rich can be as bad as being oversimplified!

For how long have I used the solution?

I have been working as an analyst using AS for 9 months now. This work involves monitoring the multi-tenant implementation of AS, sending reports to customers, doing investigations on alerts that come in, and implementing new Connectors and content. Connectors are how AS gets events from the devices.

What was my experience with deployment of the solution?

Again, system complexity can be an issue, but not really.

What do I think about the stability of the solution?

None. ArcSight is very stable. Period.

What do I think about the scalability of the solution?

Again, none. It is a system that is more than capable of multi-tenant implementations.

How are customer service and technical support?

They try really, really hard.

Which solution did I use previously and why did I switch?

No, the folks I work for were at ArcSight before HP acquired it and have always been users and proponents of it. It's a powerful product for sure.

How was the initial setup?

Setup is fairly complex, and with so many features, it is difficult to just 'set it and forget it' with ArcSight. It requires a lot of care and feeding, as well as a pretty good amount of ongoing maintenance and configuration to really get good quality alerts out of it.

What about the implementation team?

In-house experts.

Which other solutions did I evaluate?

I've been looking at Open Source SIEM recently, and paying a lot of attention to the others in the commercial market, like IBM and MacAfee, but I don't have any practical experience. I have heard mixed reviews about all of them (including AS from some folks I know).

What other advice do I have?

Implementation advice: this is a big job, and unless you are able to hire and train a dedicated SIEM engineer, I would look at getting staff augmentation from HP or other consulting types. Be prepared to Read The Friendly Manual (RTFM), and do a lot of searches online. Take the entry-level certs that HP offers, and get classes if there is budget.
Disclosure: My company has a business relationship with this vendor other than being a customer: ArcSight partner
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.