ArcSight monitors any down time with patch management. Whenever any project is on-boarded such as in our security core or asset and wealth management technology, the hardware goes through ArcSight. That is basically our use case whether we're doing the patch management, or the upgrades on that tool, or managing the centralized desktop. ArcSight monitors the failures in the cloud. We have the tech classifications in the CMDB which is integrated with ArcSight and ArcSight pulls out everything on the CMDB and I'm able to see it all - the CMDB database and the CVS scores which are also integrated in ArcSight. I can know that for a particular monitoring track or detected incident, this is the particular CVS score. I'm a VP and enterprise architect, and we're customers of ArcSight.
Chief Enterprise Architect at Alinma Bank
User interface and setup are good and speedy; deployment typology could be improved
Pros and Cons
- "The user interfaces are quite good and speedy, and I like the consoles too."
- "The deployment typology could be improved. If you want to scale across all the different lines of businesses, it should be easy to do that and it's not."
What is our primary use case?
What is most valuable?
The user interfaces are quite good and speedy, and I like the consoles too. The typology and the setup are also good. It's very similar to QRadar, so it's user friendly although I believe QRadar rates better.
What needs improvement?
The deployment typology could be improved. If you want to scale across all the different lines of businesses, it should be easy to do that and it's not. If I'm doing DMX monitoring, I shouldn't need a different SIEM. For the traditional application servers which are RTTR architecture-based, the legacy applications, which might be Java or steam-based applications, require DMX monitoring, currently provided by Nagios. Instead, the monitoring could be different types of monitoring which we could get from ArcSight. It would save the cost of doing the DMX monitoring from Nagios. QRadar has a dashboard which includes most of the monitoring, data and everything. The features in ArcSight could be more like that.
For how long have I used the solution?
I've been using this solution for 10 years.
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Scalability is okay although if we had better typology, we could scale more and performance could be better. It's similar to QRadar. We are onboarded for security core processing or data disk core processing. If I wanted to add another 20 line of businesses under that, it should be okay. There's a trade off between the security and performance so the more secure your typology is, will result in degraded performance. We currently have around 2,000 users but hope to increase that number.
How are customer service and support?
Technical support is available 24/7, They are on a rota basis for the different regions. If I'm looking for support here in India, it's available 2 1/2 hours ahead of Singapore, 3 1/2 hours ahead for the Japanese team. In the UK region, we have support available from 11:00am. And if I'm looking for post 7:00pm in India, then I have the support teams available from the States. They're quite good and they offer other professional services too, including for incident management.
How was the initial setup?
The initial setup doesn't take too much time.
What other advice do I have?
I'm neutral on whether I would recommend this solution. It depends on what typology you are using, and your use cases. If you have a different endpoint, or security tool already doing what this product does and it's already integrated with CMDB, and there's a tool at the endpoint giving the CVS Score, then you don't need an SIEM platform.
On the pricing side, QRadar is much costlier compared to ArcSight. There's a trade off. Anyone aiming for something specific will go for ArcSight monitoring rather than going for Qradar because deployment of the SIEM is not so easy for the larger deployment typologies in the financial services sector. It's not easy to scale up for different lines of businesses unless you have proper planning, methodologies, processes, and your SOPs are in place. If you follow the proper SOPs, things are easier.
I would rate this solution a six out of 10.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Analyst at Banglalink
Other solutions perform better and have a slicker GUI, but this one is cheaper
Pros and Cons
- "We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens."
- "ArcSight ESM helps us stop security incidents by detecting them early before they can cause more damage."
- "ArcSight ESM needs to improve performance, user interface, and automation."
- "I rate ArcSight three out of 10. I would never recommend it."
What is our primary use case?
We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens.
How has it helped my organization?
ArcSight ESM helps us stop security incidents by detecting them early before they can cause more damage.
What needs improvement?
ArcSight ESM needs to improve performance, user interface, and automation.
What do I think about the stability of the solution?
ArcSight has become more stable with the latest patches that have come out, but we also have had many difficulties applying the patches
What do I think about the scalability of the solution?
It's costly to scale up ArcSight ESM, but it's scalable. You have to pay for extra storage, licenses, and log processing.
How are customer service and support?
ArcSight support is okay but slow. It isn't provided promptly. There is a vast time difference between American time and East Asian time.
How was the initial setup?
Setting up ArcSight is very complex. Nothing about it is user-friendly.
What's my experience with pricing, setup cost, and licensing?
ArcSight's price is reasonable. That's why our company was forced to buy this. It's cheaper than some of the better solutions.
Which other solutions did I evaluate?
LogRhythm has a better GUI and some automation options, like an automated password writing script. In Exabeam, I can see an event with the user's picture, which Exabeam can draw from the Active Directory. It has a better GUI, better performance, and customization. I expect these things from ArcSight, but it can't deliver yet.
What other advice do I have?
I rate ArcSight three out of 10. I would never recommend it. I would recommend QRadar, LogRhythm, or Exabeam, but they all cost more. Price is its only advantage.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
Chief Information Officer at Bassein Catholic Co-Op Bank
A fast, stable, and scalable solution with good reporting and log analysis functionalities
Pros and Cons
- "The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data. Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions."
- "The reports that we are from getting from ArcSight are very valuable, the reporting in ArcSight is good, our regulators ask us for the reports on a regular basis, and we have been able to provide the required data."
- "When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform. In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier."
- "ArcSight is a very old and mature product that is running on an old platform."
What is our primary use case?
We have outsourced our SOX management to an IT company because I cannot maintain and manage that in the bank. We had selected them because they were using ArcSight. They are a very professional security company. They came up with this suggestion of switching from ArcSight to LogRhythm. We are currently using ArcSight, but we would be switching to LogRhythm.
They are using the latest version of ArcSight ESM. It is all on-prem. Our production setup cannot be on a public cloud. In India, cloud deployment is not allowed for financial services. It has to be either a co-location or in-house.
What is most valuable?
The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data.
Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions.
What needs improvement?
When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform.
In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier.
For how long have I used the solution?
We have been using this solution for one year.
What do I think about the stability of the solution?
It is pretty stable.
What do I think about the scalability of the solution?
It is pretty scalable.
How are customer service and technical support?
I have not been in touch with ArcSight for technical support. I only talked to my vendor, who monitored my network. My vendor got in touch with ArcSight support.
How was the initial setup?
The setup ran into a couple of months because the configuration of the endpoint devices to collect the logs was really tedious. It took some time to bring the environment into a condition to get it monitored by ArcSight.
What other advice do I have?
It is a very good product. I would rate ArcSight ESM an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information and Cyber Security Analyst at a financial services firm with 10,001+ employees
The best on-prem SIEM solution that lets you do what you want and has good filtering, scalability, and support
Pros and Cons
- "The filters and the ability to do what you want are the most valuable features; there is nothing that you cannot do in this solution, and it has all the features, which makes it very dynamic."
- "I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions. We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved."
- "I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions."
What is our primary use case?
We have many use cases. Our Windows devices, antivirus, and firewall are integrated with ArcSight. I have used ArcSight ESM versions 6.1.1, 6.9, 7.0, and 7.2.
What is most valuable?
The filters and the ability to do what you want are the most valuable features. There is nothing that you cannot do in this solution. It has all the features, which makes it very dynamic.
What needs improvement?
I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions.
We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this.
It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved.
For how long have I used the solution?
I've been using ArcSight for three years. I started using it in February 2019.
What do I think about the stability of the solution?
It is stable, but its stability can be better. I would rate it a four out of five in terms of stability.
What do I think about the scalability of the solution?
It has been good when it comes to scalability. As an MSSP, we provide services to other customers, and we have customers with different capacity requirements. It is good in terms of moving from one particular size to another.
How are customer service and technical support?
They have been great. They are friendly and good.
How was the initial setup?
Its initial setup is straightforward. The deployment duration depends on the environment. It doesn't take time for our own environment, but I've heard some people complaining about the time period for which they have to wait for the deployment to take place.
What's my experience with pricing, setup cost, and licensing?
ArcSight can be a little bit expensive because of the area that we work in and the cost. Licensing is mostly on a yearly basis, not monthly.
What other advice do I have?
I would recommend this solution to anyone looking for an on-prem SIEM solution. It has been the best SIEM solution that I've worked with.
I would rate ArcSight ESM a nine out of ten. It is a great solution.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Security Engineer at Billie
Can write queries fast but visualization isn't good
Pros and Cons
- "On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented."
- "I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards."
What is our primary use case?
I use the solution to implement detection rules based on attack scenarios.
What is most valuable?
On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented.
What needs improvement?
I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards.
For how long have I used the solution?
I have been working with the product for a year.
How are customer service and support?
The tool's support is one of its best parts.
How would you rate customer service and support?
Positive
How was the initial setup?
I wasn't involved in the initial setup and deployment of ArcSight ESM, as it had already been implemented when I joined the company. I worked on implementing dashboards and detection rules. The rule categorization was good and had a good alert system when rules were triggered.
What's my experience with pricing, setup cost, and licensing?
Price-wise, ArcSight ESM was a bit high compared to competitors, which factored into our decision to switch to Splunk. It couldn't cover all our business needs for what we wanted to implement.
What other advice do I have?
I rate the overall solution a five out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
A robust and scalable solution that is good for correlation
Pros and Cons
- "The tool is good for correlation and aggregation. We use it as a collection platform."
- "The tool should improve its UI. It also should make data more searchable."
What is our primary use case?
The tool is good for correlation and aggregation. We use it as a collection platform.
What needs improvement?
The tool should improve its UI. It also should make data more searchable.
For how long have I used the solution?
I have been working with the tool for three to four years.
What do I think about the stability of the solution?
The tool is stable.
What do I think about the scalability of the solution?
The tool is scalable.
Which solution did I use previously and why did I switch?
I have worked with QRadar and McAfee.
How was the initial setup?
The deployment process is similar to the hosting of other applications. The tool's deployment depends on the environment architecture, and your requirements.
What other advice do I have?
I would rate the solution a seven out of ten. The product is very robust.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager at PT Permata Anugerah Abadi
Great real-time reporting, offers simplicity for implementation and operations
Pros and Cons
- "Very good real-time reporting with a good dashboard."
- "Currently lacks SOAR feature."
What is our primary use case?
We deal mainly with enterprise companies - I'm the senior manager and we are partners with ArcSight.
What is most valuable?
The solution has a good dashboard, very good real-time reporting and it's easy to use, offering simplicity for implementation and operations.
What needs improvement?
I'd like to see an improvement in their training and documentation. SOAR (Security Orchestration, Automation, and Response) would be a good feature to include in the future.
For how long have I used the solution?
I've been using this solution for six years.
What do I think about the scalability of the solution?
This solution is stable and scalable.
How are customer service and support?
They offer 24/7 standby support wherever you are. It's very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
The cost is reasonable for a good solution.
What other advice do I have?
It's important to set up the organization before implementation, checking internal desktops or IT security internals before buying the solution.
I rate this product an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Forensic Consultant at A Cyber 1 Company
Good out-of-the-box rules, but the integration and reporting features can be improved
Pros and Cons
- "The out-of-the-box rules that help us configure functioning rules within the environment are valuable."
- "Customer service and support is our biggest challenge."
What is our primary use case?
We use this solution in our customers company and we deploy the solution on cloud and on-premises.
What is most valuable?
The out-of-the-box rules that help us configure functioning rules within the environment are valuable. For example, they have good resources to help detect and populate the dashboard if something malicious happens. Additionally, we value a good visual representation of a company and network infrastructure.
What needs improvement?
The solution can be improved regarding integration with other security products, ease of implementing some features, and feeling like we're not utilizing the solution as best as we could. In the next release, the solution should incorporate some threat intel features and integrate well with other network solutions, EDRs, palm solutions and the sorts. Additionally, the reporting can be improved to bring out very insightful reports showing senior management value for the solution.
For how long have I used the solution?
We have been using the solution for approximately six months.
What do I think about the stability of the solution?
The solution is stable. I rate it an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable and has approximately 500 users utilizing it for enterprise businesses.
How are customer service and support?
Customer service and support are one of the biggest challenges we are having. Although it is provided, and once you log tickets, they follow up quickly, sometimes some of the challenges we face drag on for a while because of ironing out specific details about technical support and payments.
How was the initial setup?
The initial setup was a bit complex. Getting things running and configured took a while. Furthermore, some integrations were unavailable, and some had to be custom scripted, so getting the solution up and running was a bit tedious.
What about the implementation team?
We implement in-house, and it takes approximately two months to complete implementation.
What's my experience with pricing, setup cost, and licensing?
The licensing costs are high and the solution is priced through events that come in so the cost tends to be heavy on the client. The price of the license could be lower.
What other advice do I have?
I rate the solution a six out of ten. The solution is good, but its integration and reporting features can be improved. I advise users to have a mature security infrastructure and scale up their technical resources. However, for smaller organizations considering the solution, I advise them to think of other solutions before using ArcSight Enterprise Security Manager.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior Manager at a tech services company with 51-200 employees
Lacking scalable cloud technology, poor stability, but easy to use
Pros and Cons
- "The most valuable features of ArcSight ESM are ease of use and readily usable components."
- "ArcSight ESM is lacking cloud scalable technology."
- "The support from ArcSight ESM is very poor. We had a negative experience."
What is our primary use case?
We have a large footprint of 25 plus subsidiaries reporting into a consolidated security reporting and action team using ArcSight ESM.
How has it helped my organization?
ArcSight ESM has improved our organization because we have better incident reporting. It was originally deployed in order to fulfill compliance requirements. We were required to have security monitoring, ArcSight ESM was a quick and effective way to be able to meet that minimum requirement.
What is most valuable?
The most valuable features of ArcSight ESM are ease of use and readily usable components.
What needs improvement?
ArcSight ESM is lacking cloud scalable technology.
For how long have I used the solution?
I have been using ArcSight Enterprise Security Manager (ESM) for approximately three years.
What do I think about the stability of the solution?
ArcSight ESM has average capabilities. It's not seen as being particularly robust or usable for advanced threats.
What do I think about the scalability of the solution?
The scalability of ArcSight ESM is average to poor.
We have approximately 60,000 users using the solution.
How are customer service and support?
The support from ArcSight ESM is very poor. We had a negative experience.
I rate the support from ArcSight ESM one out of five.
Which solution did I use previously and why did I switch?
We did not use a solution prior to ArcSight ESM.
How was the initial setup?
The initial setup of ArcSight ESM was relatively straightforward. The full deployment took us approximately six months. The implementation strategy was to get basic monitoring templates as fast as possible.
What about the implementation team?
We used an integrator for the implementation of ArcSight ESM.
What was our ROI?
The ROI was not important at first because we were trying to cover our basic compliance requirement for monitoring.
What's my experience with pricing, setup cost, and licensing?
We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees.
Which other solutions did I evaluate?
We evaluated other solutions prior to choosing ArcSight ESM, such as Splunk and RSA NetWitness. We decided on ArcSight ESM because it was cost-effective.
What other advice do I have?
We are replacing ArcSight ESM with Microsoft Sentinel. We wanted to shift to cloud-based, cloud-scalable technology.
My advice to others is for them to take a hard look at the total cost of ownership, specifically the maintenance and upkeep that's required to maintain the appropriate service levels.
I rate ArcSight ESM a four out of five.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Presales Manager at a tech services company with 51-200 employees
The flex connector lets you develop new connectors to integrate homebrew solutions
Pros and Cons
- "The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector."
- "When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets."
What is our primary use case?
We use ArcSight primarily to provide logs for the incident response team and cyber security analysts to evaluate everything happening in the network.
What is most valuable?
The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector.
What needs improvement?
When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets.
What other advice do I have?
I rate ArcSight Enterprise Security Manager nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
Stellar Cyber Open XDR
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?



















