ArcSight Enterprise Security Manager (ESM) is used in the customer side, specifically where there is an investment because the solution, when implemented, helps with integration. ArcSight Enterprise Security Manager (ESM) is able to ingest logs and integrate with all the third-party products, so its utility becomes higher. Integration is very important because if the solution isn't able to integrate with others, then data doesn't come under SIEM and becomes incomplete.
Head Global Alliances Director at Tech Mahindra Limited
Has good integration with third-party products; its technical support team is very helpful
Pros and Cons
- "What I found most valuable in ArcSight Enterprise Security Manager (ESM) is its good integration with third-party products. The solution also has good core capabilities."
- "ArcSight Enterprise Security Manager (ESM) also gives you the main reason for the alert so it saves time in terms of investigating all alerts, including false alerts, so it improved my company."
- "What could be improved in ArcSight Enterprise Security Manager (ESM) is its analytics feature. That feature should be more powerful and have more correlation in terms of AI/ML, though MicroFocus has done a good job in adding analytics to ArcSight Enterprise Security Manager (ESM) which has become a big draw to customers. What I'd like to see in the next release of the solution is the addition of AI/ML features."
- "What could be improved in ArcSight Enterprise Security Manager (ESM) is its analytics feature."
What is our primary use case?
How has it helped my organization?
ArcSight Enterprise Security Manager (ESM) helped my company in terms of correlating alerts. The solution also helped in both alert-giving and understanding alerts. It also dismisses repeat alerts and removes false positives. ArcSight Enterprise Security Manager (ESM) also gives you the main reason for the alert so it saves time in terms of investigating all alerts, including false alerts, so it improved my company.
What is most valuable?
What I found most valuable in ArcSight Enterprise Security Manager (ESM) is its good integration with third-party products. The solution also has good core capabilities.
What needs improvement?
What could be improved in ArcSight Enterprise Security Manager (ESM) is its analytics feature. That feature should be more powerful and have more correlation in terms of AI/ML, though MicroFocus has done a good job in adding analytics to ArcSight Enterprise Security Manager (ESM) which has become a big draw to customers.
What I'd like to see in the next release of the solution is the addition of AI/ML features.
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
For how long have I used the solution?
I've been using ArcSight Enterprise Security Manager (ESM) for almost five years, and I'm still using it.
What do I think about the stability of the solution?
ArcSight Enterprise Security Manager (ESM) has great stability.
What do I think about the scalability of the solution?
ArcSight Enterprise Security Manager (ESM) is a scalable solution.
How are customer service and support?
The technical support team of ArcSight Enterprise Security Manager (ESM) is very helpful. I would rate technical support for the solution five out of five.
How was the initial setup?
The initial setup for ArcSight Enterprise Security Manager (ESM) was straightforward and the process was very well-explained. How long the process takes would differ from environment to environment and from customer to customer, but it could take one to two days.
What about the implementation team?
We implemented ArcSight Enterprise Security Manager (ESM) ourselves.
What was our ROI?
I'm unsure on the exact ROI for ArcSight Enterprise Security Manager (ESM) because in cybersecurity you could never predict how much you saved, but my company got good value out of it.
What other advice do I have?
I'm not using the latest version of ArcSight Enterprise Security Manager (ESM).
ArcSight Enterprise Security Manager (ESM) is not being used by the entire organization, but at least a thousand users use it, though I'm not 100% sure. The solution is used daily, and it's integrated and customized and has become part of the internal monitoring and compliance check of my company.
My advice to others who want to implement ArcSight Enterprise Security Manager (ESM) is that it's a great product, especially because it increased its feature sets and it has good integration with third-party solutions, for example, with other OEMs, with CrowdStrike, etc. The value proposition of the solution is also getting better and better, and usage-wise, ArcSight Enterprise Security Manager (ESM) is also good.
I would rate ArcSight Enterprise Security Manager (ESM) nine out of ten because even if it's an old product, it's been working well for quite some time. It has a huge customer base. I've not seen any issues, so I'm rating it a nine, but not a ten because there's always room for improvement.
My company is a reseller of ArcSight Enterprise Security Manager (ESM).
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Sr. Group Manager at WNS Global Services
It provides us the flexibility to write our own passwords and customize the solution.
Pros and Cons
- "ArcSight ESM provides us the flexibility to write our own passwords and customize the solution. It lets us search and log a variety of SmartConnectors. It has 480-plus SmartConnectors."
- "ArcSight was head and shoulders above the rest in features like aggregation filtering, bandwidth, parsing, etc."
- "Sometimes, it takes ages to get an issue resolved. I have ArcSight experience, so I normally try to fix things on my own or find a workaround, but it's tough to get support when I need it."
What is most valuable?
ArcSight ESM provides us the flexibility to write our own passwords and customize the solution. It lets us search and log a variety of SmartConnectors. It has 480-plus SmartConnectors.
What needs improvement?
ArcSight's features are already ahead of many competitors, but may they could offer some more training about how to find tools, how to get them working, and how to optimize them. I'd also like to see a greater focus on cloud content and the ability to write rules from the browser.
For how long have I used the solution?
We've been using ArcSight ESM for around 10 years.
What do I think about the scalability of the solution?
ArcSight is scalable. I started out with three data centers, and now I have it deployed at more than 48 locations.
How are customer service and support?
I rate ArcSight support seven out of 10. Sometimes, it takes ages to get an issue resolved. I have ArcSight experience, so I normally try to fix things on my own or find a workaround, but it's tough to get support when I need it.
It goes on for days. If you call in the morning and explain it to the engineer, but the issue isn't fixed, you have to explain it to another person when the shift changes. It's usually okay, but it can be challenging if you're dealing with an urgent issue and you don't have the proper documentation.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used McAfee Nitro, IBM QRadar, and DNIF HyperCloud. Other solutions aren't as simple to set up or as stable. ArcSight is better in terms of coverage. The technology is more than 20 years old.
How was the initial setup?
The setup is quite simple, and the documentation is thorough.
Which other solutions did I evaluate?
We looked at three other solutions. I was working for a government organization, and there was an Indian company developing its own team. ArcSight was head and shoulders above the rest in features like aggregation filtering, bandwidth, parsing, etc. It was there.
Hopefully, we're still way ahead, but the IT data architecture is getting a bit complex with the introduction of Kubernetes and everything. It will be complicated in terms of resources, deployment, etc., but I think ArcSight can still be what it used to be if we sort this out.
What other advice do I have?
I rate ArcSight ESM seven out of 10. I would recommend ArcSight depending on an organization's needs. I don't have much experience in terms of pricing, but ArcSight can provide a lot of functionality if a company requires it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
Technical Lead Project Individual Contributor at DXC
Used for cyber security by cyber security professionals for incident management and for analysis
Pros and Cons
- "Usability is the most valuable feature. The accessibility is quite good."
- "Usability is the most valuable feature; the accessibility is quite good, and if a new person wants to be trained in this product, it's easy for them to be trained, as opposed to other products like Splunk or Sentinel."
- "The visualization is not very good compared to Splunk."
- "ArcSight's technical support hasn't been as good as it was in the past. I don't find it to be very good."
What is our primary use case?
We use this solution as a SIEM monitoring tool in our enterprise and for customers who have been using it, like shared operations. It's mostly used for cyber security by cyber security professionals for incident management and analysis.
The solution can be deployed on-prem and on the cloud. It depends on the requirements. We mainly use AWS, but Azure is also used.
We have analysts and architects using this solution. There are more than 20 people who are specialists and are using it. The team can be as large as more than 100 people. It all depends upon infrastructure and the clients that the particular infrastructure is supporting.
What is most valuable?
Usability is the most valuable feature. The accessibility is quite good. If a new person wants to be trained in this product, it's easy for them to be trained, as opposed to other products like Splunk or Sentinel.
ArcSight is good, and it's also scaling up.
What needs improvement?
The visualization is not very good compared to Splunk.
The dashboard and the comparability with new devices could be better. For example, we have a lot of cloud infrastructure that's coming around. Nowadays, most of the appliances are cloud-based. So, the comparability of Splunk is more with cloud infrastructure. With ArcSight, we have to build FlexConnectors to integrate multiple data sources, and we need visualization in that with FlexConnectors. If you go to Splunk, they have their own apps developed, and they work more proactively compared to ArcSight.
The performance and speed could be better. Technical support could be improved.
For how long have I used the solution?
I have been using this solution for six years.
What do I think about the stability of the solution?
The solution is stable because we have been using this product for quite a number of clients. They use ArcSight as a primary tool for SIEM. We have been using it in the cyber security space for quite a long time. It is stable, but people are needed to manage this tool.
How are customer service and support?
ArcSight's technical support hasn't been as good as it was in the past. I don't find it to be very good. My queries are not being properly resolved.
Which solution did I use previously and why did I switch?
I also use Splunk and sometimes Sentinel.
This is the oldest SIM I have been working on. After that, Splunk came into the market. I worked for Accenture, and Splunk gave free training because of the partnership with Accenture. Their training framework was good compared to ArcSight. A lot of people started switching to Splunk. Nobody's support is perfect, but Splunk's support is almost perfect and better than ArcSight.
The primary factor is the cost. ArcSight is cost-effective, but Splunk is not because it charges for UBA, and ArcSight charges on EPS. Splunk is also in automation and machine-learning tools. So, if a customer is willing to spend big so they can switch to Splunk, that's what I've seen for most of the clients.
How was the initial setup?
Initial setup is complex, not straightforward, because there are some devices that are not supported by ArcSight. So, we have to build a development strategy for each of the devices.
For the implementation strategy, it can be software-based or it can be a multi-side-based also. It depends on the type of clients you have and the agents. They have a central server from which you can deploy the agents and install them, and then they can send to the ESM side on which you can correlate. From there, the incident reporting will be done based on multiple systems.
What about the implementation team?
A consultant is required for smooth setup.
What was our ROI?
We have seen ROI because this space keeps on changing very dynamically. It depends on your customer. There is definitely a return on investment, but it's not large because these types of solutions are for compliance purposes. We see many cyber attacks happen nowadays, but they definitely prevent some of the major incidents. It will give direct results to an organization, maybe in some intangible manner. But because this is a compliance thing, you definitely have to implement at least one SIEM in the infrastructure.
What's my experience with pricing, setup cost, and licensing?
The licensing cost is affordable if you get an enterprise license. The licensing is based on EPS, so you can probably provide a package of license for multiple ESMs with their correlational end fees. It is cost-effective.
Licensing depends on what type of customer you are. There will be licenses for each and every appliance. There will be three types of appliances like ESM, ArcMC, and Logger. For these three components, you need to buy a separate license.
What other advice do I have?
I would rate this solution 7 out of 10.
My advice is to get proper training. It also depends on which component someone is working on. ArcSight support will not be able to help every time because ArcSight professional services are pretty costly. I haven't seen any organization taking ArcSight professional support. We only have normal support. It needs a bunch of experts to support these kind of operations.
You will need a strategy for how deployment is going to be, how much the capacity planning will be, what the configuration of servers will be, how they will architect it, etc.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Architects at VaporVM
Provides more granular data compared to solutions like Azure or Splunk
Pros and Cons
- "We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities."
- "We have pricing issues. ArcSight ESM may not be the most user-friendly option, and its interface is quite traditional. However, despite these aspects, we find it a good cybersecurity solution. It needs to improve the dashboards, documentation, and support as well."
What is our primary use case?
We use the product for everything. It serves as our company's management platform, handling our tech needs, block systems, alerts, custom rules, triggered events, analytics, investigations, incident closures, case creations, whitelists, and various other tasks.
What is most valuable?
We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities.
It provides more granular data compared to solutions like Azure or Splunk. While ArcSight ESM may be considered less user-friendly, it offers a high level of customization, allowing for configuration and adaptation to specific use cases, especially regarding alerting and incident response.
Its integrations are working well. Though I haven't used the solution for an extended period, it seems highly customizable. This level of customization is not commonly found in many solutions. While solutions like Kubernetes offer a variety of apps through app extensions, it allows users to build their features to a considerable extent.
What needs improvement?
We have pricing issues. ArcSight ESM may not be the most user-friendly option, and its interface is quite traditional. However, despite these aspects, we find it a good cybersecurity solution. It needs to improve the dashboards, documentation, and support as well.
The documentation and community support for ArcSight ESM is not as strong as other solutions. Finding resources and analysts who have experience with ArcSight can be challenging. The solution is less user-friendly than alternatives like Splunk, QRadar, or Sentinel. The technical nature of ArcSight may make analysts hesitant to dive into it, contributing to a steeper learning curve.
For how long have I used the solution?
I have been using the product for two months.
What do I think about the stability of the solution?
During the pandemic, there were challenges related to stability, particularly with the discrepancy in events being pulled in. The issue was attributed to connectors, and there were problems with certificates that needed updating. As a result, events were regularly stopped by these connectors. I rate the tool's stability a seven out of ten.
What do I think about the scalability of the solution?
The solution is scalable. My company has 20 users.
How are customer service and support?
I haven't contacted the tool's technical support yet.
What other advice do I have?
I would recommend ArcSight ESM to others depending on the organization's size and specific requirements. For larger organizations, I might not recommend it, but for SMEs, it could be a suitable choice. If it meets your organization's specific use cases and requirements, and if you can ensure that you have resources trained to work with it, then it could be a suitable choice.
I rate the overall product a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a financial services firm with 10,001+ employees
Flexible with easy integrations but needs a less complex query language
Pros and Cons
- "It makes maintenance very easy."
- "The UI interface is somewhat complex and needs to be simplified."
What is our primary use case?
We have two connectors. One is a smart connector, and one is a select connector. It's a simple ESM tool.
What is most valuable?
It offers easy integrations.
It's flexible for managing the monitoring of all activities on your network. It offers easy management and good dashboards.
There is good visibility over all of the traffic and logs and the health of the devices. It makes maintenance very easy.
It works with Linux and Mac, and other network devices, including firewalls and proxies.
The solution can take logs from the cloud. That said, we do need to deploy a cloud connector to make that happen.
What needs improvement?
The query language should be less complex.
The UI interface is somewhat complex and needs to be simplified.
The dashboards don't read in a graphical manner. You have to read the logs and the output whenever you run a query. You need to understand the output. You have to export it to a .CSV and then design the visualization as per your requirements.
We're missing visual dashboards and reporting. We'd like to have the reporting of simple histories, and we need dashboards to show details in a presentable format.
In the logs, we're capturing multiple fields, some of which we do not need. There should be an option to just keep the fields you require and discard the rest.
For how long have I used the solution?
I've been using the solution for almost two years.
What do I think about the stability of the solution?
Stability could be better. I would rate it six out of ten. I've seen a lot of crashes for the connector or server.
What do I think about the scalability of the solution?
The scalability is pretty good. I would rate it eight out of ten.
It's an enterprise solution. We have deployed the solution deployed to 30 or 40 clients.
We do not have plans to increase usage.
How are customer service and support?
We have not used technical support. Our team provides support to the customer. I'm not sure how they have assisted, if applicable.
How was the initial setup?
The initial setup can be complex in comparison to other things. It's not difficult. There are just multiple components to consider. Deployment-wise, it is okay, just not simple. It becomes more complex when you have to develop multiple components at the same time.
What was our ROI?
We have witnessed an ROI so far.
What's my experience with pricing, setup cost, and licensing?
The pricing depends on the client. It does have the same price range as other solutions. The pricing we pitch is based on EPS level for management.
What other advice do I have?
I'm not sure which version of the solution I'm using.
Users should have a good knowledge of the management of logging, including how to write log queries and the development of custom connectors. There is some technical skill necessary.
I'd rate the solution seven out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a tech services company with 10,001+ employees
A robust solution that helps us with our internal log and threat analysis
Pros and Cons
- "It is a robust product and has multiple valuable features."
- "It is a robust product and has multiple valuable features, with robust threat intelligence built into its customization and great templates that provide ease of use."
- "The dashboard looks a bit cumbersome with the current version."
What is our primary use case?
We use it for our internal and vendor daily base of log analysis and threat analysis.
What is most valuable?
It is a robust product and has multiple valuable features. For example, it has robust threat intelligence built into its customization and great templates that provide ease of use.
What needs improvement?
The dashboard looks a bit cumbersome with the current version. They should work on the dashboard and optimize their integration which currently lags with devices of reputed vendors. So, having these custom integrators sometimes works and sometimes doesn't.
For how long have I used the solution?
We have been using this solution for almost ten years. It is deployed on private cloud.
What do I think about the stability of the solution?
We haven't experienced any stability challenges. It works if we get enough hardware and software provisions for the vendor recommendation.
What do I think about the scalability of the solution?
On-premises is a challenge to scale, and we haven't tried the cloud but we've heard it's quite scalable and robust.
How are customer service and support?
We do not use technical support that often. They are very good, but they should train their L1-level support. Overall, they're a good strong team.
How was the initial setup?
The setup is neither easy nor difficult and depends on the expertise. It requires really good expertise to build from scratch. The setup itself is not a big hassle, and in a week, the system is up and running, but the main challenge is the integration. We keep integrating, and with the password of the integrated direct, it's fine.
What's my experience with pricing, setup cost, and licensing?
It is a licensed product.
What other advice do I have?
I rate this solution an eight out of ten in terms of the inbuilt features and how it has grown into a strong solution over the years. The team has done an excellent job with the features, integrations, and compatibility.
Regarding advice, I think the assessment on currently sizing the product to their need is key. It's an expensive product, so sizing is the most important choice. In addition, I believe moving to cloud has more robust integration features. They are building new custom solutions that can be integrated with ESM for better analysis.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at Libero
Powerful and comprehensive program but complex and cumbersome for non-experts
Pros and Cons
- "ArcSight ESM allows us to find if someone is doing an administrative operation at inappropriate times of day or trying to do something they're not allowed to."
- "ArcSight ESM allows us to track the logging of our customers or providers through VPN to a security middleware that tracks and allows them to access backend resources."
- "ArcSight ESM's UI is a little cumbersome and complex, especially for first-time and occasional users using the console manager."
What is our primary use case?
I primarily use ArcSight ESM for security and network monitoring. We are dealing with Active Directory, so we use ArcSight ESM to track the actions administrators take on accounts, like disabling and enabling accounts or accounts going expired and why.
How has it helped my organization?
ArcSight ESM allows us to track the logging of our customers or providers through VPN to a security middleware that tracks and allows them to access backend resources. In this way, we can find if someone is doing an administrative operation at inappropriate times of day or trying to do something they're not allowed to.
What needs improvement?
ArcSight ESM's UI is a little cumbersome and complex, especially for first-time and occasional users using the console manager. It's also a very complex product, and new users will require assistance from someone expert to avoid making errors.
For how long have I used the solution?
I've been using ArcSight ESM for three years.
What do I think about the stability of the solution?
ArcSight ESM is stable, except when you're doing very complex correlations, but that's a problem common to all products in this area.
What do I think about the scalability of the solution?
We have not had any problems with ArcSight ESM's scalability.
How are customer service and support?
ArcSight's technical support is very good.
How was the initial setup?
The initial setup was not so easy as it's a very technical product, and anybody who doesn't have a lot of technical knowledge will probably find it difficult to set up. It's important to have a clear understanding of your goals when setting up all the infrastructure, as ESM is so complex. The deployment took around an hour or two.
What about the implementation team?
We used a provider team.
What other advice do I have?
ArcSight ESM is a very powerful platform, but you have to be careful in designing rules and defining an initial set of targets because otherwise, you could end up with high costs or a hugely demanding setup. I would rate ArcSight ESM seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO at Kapstone Technological Services LLP
A stable and scalable enterprise data security manager, but the initial setup could be more straightforward
Pros and Cons
- "ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product."
- "The initial setup could be more straightforward."
- "The initial setup is complex."
What is our primary use case?
I'm an administrator, and I implement ArcSight Enterprise Security Manager (ESM). I use ArcSight SIEM and have all the security information, events, logins, and security logs. We compile all the information so we can file and stop it from happening or provide an alert.
What is most valuable?
ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product.
What needs improvement?
The initial setup could be more straightforward.
What do I think about the stability of the solution?
ArcSight Enterprise Security Manager (ESM) is a stable solution. However, it depends on how well it's deployed in the customer's location.
Because SIEM doesn't have much to do with blocking the traffic, even if it doesn't get deployed well, it doesn't matter to the customer because the work is going on, and the traffic is flowing in.
It's just that the correlation will never happen. The security post of the company goes for all; that's the only problem. Apart from that, there would be no problem with the operations website.
What do I think about the scalability of the solution?
ArcSight Enterprise Security Manager (ESM) is scalable, but you must size it well.
How are customer service and support?
ArcSight technical support is a bit better than the QRadar.
How was the initial setup?
The initial setup is complex. In general, it takes about three months to implement this solution.
What other advice do I have?
I will only make recommendations based on the customer's requirements and environment.
On a scale from one to ten, I would give ArcSight Enterprise Security Manager (ESM) a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Chief Commercial Officer at Yamamah Information Technology & Communication Systems LLC
Easy to manage for anyone, simple cyber security reports, and good support
Pros and Cons
- "The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided."
- "ArcSight ESM could improve the alerts for the storage capacities or actions."
What is our primary use case?
ArcSight ESM is used as a security information and event management (SIEM) solution. It has been used in banks.
What is most valuable?
The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided.
What needs improvement?
ArcSight ESM could improve the alerts for the storage capacities or actions.
For how long have I used the solution?
I have been using ArcSight Enterprise Security Manager (ESM) for approximately six years.
What do I think about the stability of the solution?
ArcSight ESM is stable.
What do I think about the scalability of the solution?
The scalability of ArcSight ESM is very good.
On the client's bank site, there are approximately 1,500 users using the solution.
How are customer service and support?
The support for ArcSight ESM has been very good.
How was the initial setup?
The deployment of ArcSight ESM is easy.
What about the implementation team?
We have approximately six people from our information security department managing ArcSight ESM. The deployment was done by four engineers.
What's my experience with pricing, setup cost, and licensing?
ArcSight ESM is an affordable solution, it cost approximately $200,000 for three years. This price was at a substantial discount.
Which other solutions did I evaluate?
We have evaluated IBM QRadar before choosing ArcSight ESM.
What other advice do I have?
My advice to others is once they evaluate ArcSight ESM they will love it.
I rate ArcSight ESM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Easy to use, reliable, simple implementation
Pros and Cons
- "The most valuable feature of ArcSight ESM is its ease of use."
- "ArcSight ESM could improve by adding more features and documentation. There needs to be more documentation."
What is our primary use case?
We are using ArcSight ESM in our company for security information and event management.
What is most valuable?
The most valuable feature of ArcSight ESM is its ease of use.
What needs improvement?
ArcSight ESM could improve by adding more features and documentation. There needs to be more documentation.
For how long have I used the solution?
I am been using ArcSight Enterprise Security Manager (ESM) for approximately 10 years.
What do I think about the stability of the solution?
ArcSight ESM is stable.
What do I think about the scalability of the solution?
The scalability of ArcSight ESM is good.
We have approximately 10 people using this solution. There are 1,000 devices using the solution. We are using the solution to its full capacity.
How are customer service and support?
The support is not very good.
I rate the support from ArcSight ESM a four out of five.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of ArcSight ESM is easy. The deployment process took approximately one week.
What about the implementation team?
I did the implementation of ArcSight ESM myself. We have two people for maintenance.
What other advice do I have?
I rate ArcSight Enterprise Security Manager an eight out of ten
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
Stellar Cyber Open XDR
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?























