I'm an administrator, and I implement ArcSight Enterprise Security Manager (ESM). I use ArcSight SIEM and have all the security information, events, logins, and security logs. We compile all the information so we can file and stop it from happening or provide an alert.
ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product.
The initial setup could be more straightforward.
ArcSight Enterprise Security Manager (ESM) is a stable solution. However, it depends on how well it's deployed in the customer's location.
Because SIEM doesn't have much to do with blocking the traffic, even if it doesn't get deployed well, it doesn't matter to the customer because the work is going on, and the traffic is flowing in.
It's just that the correlation will never happen. The security post of the company goes for all; that's the only problem. Apart from that, there would be no problem with the operations website.
ArcSight Enterprise Security Manager (ESM) is scalable, but you must size it well.
ArcSight technical support is a bit better than the QRadar.
The initial setup is complex. In general, it takes about three months to implement this solution.
I will only make recommendations based on the customer's requirements and environment.
On a scale from one to ten, I would give ArcSight Enterprise Security Manager (ESM) a seven.