No more typing reviews! Try our Samantha, our new voice AI agent.
Chief Information Officer at Bassein Catholic Co-Op Bank
Real User
Feb 22, 2021
A fast, stable, and scalable solution with good reporting and log analysis functionalities
Pros and Cons
  • "The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data. Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions."
  • "The reports that we are from getting from ArcSight are very valuable, the reporting in ArcSight is good, our regulators ask us for the reports on a regular basis, and we have been able to provide the required data."
  • "When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform. In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier."
  • "ArcSight is a very old and mature product that is running on an old platform."

What is our primary use case?

We have outsourced our SOX management to an IT company because I cannot maintain and manage that in the bank. We had selected them because they were using ArcSight. They are a very professional security company. They came up with this suggestion of switching from ArcSight to LogRhythm. We are currently using ArcSight, but we would be switching to LogRhythm.

They are using the latest version of ArcSight ESM. It is all on-prem. Our production setup cannot be on a public cloud. In India, cloud deployment is not allowed for financial services. It has to be either a co-location or in-house.

What is most valuable?

The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data.

Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions.

What needs improvement?

When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform. 

In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier. 

For how long have I used the solution?

We have been using this solution for one year.

Buyer's Guide
OpenText Enterprise Security Manager
September 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is pretty stable.

What do I think about the scalability of the solution?

It is pretty scalable.

How are customer service and support?

I have not been in touch with ArcSight for technical support. I only talked to my vendor, who monitored my network. My vendor got in touch with ArcSight support.

How was the initial setup?

The setup ran into a couple of months because the configuration of the endpoint devices to collect the logs was really tedious. It took some time to bring the environment into a condition to get it monitored by ArcSight.

What other advice do I have?

It is a very good product. I would rate ArcSight ESM an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ashraf Abbas - PeerSpot reviewer
Information and Cyber Security Analyst at a financial services firm with 10,001+ employees
Real User
Top 20
Feb 18, 2021
The best on-prem SIEM solution that lets you do what you want and has good filtering, scalability, and support
Pros and Cons
  • "The filters and the ability to do what you want are the most valuable features; there is nothing that you cannot do in this solution, and it has all the features, which makes it very dynamic."
  • "I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions. We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved."
  • "I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions."

What is our primary use case?

We have many use cases. Our Windows devices, antivirus, and firewall are integrated with ArcSight. I have used ArcSight ESM versions 6.1.1, 6.9, 7.0, and 7.2.

What is most valuable?

The filters and the ability to do what you want are the most valuable features. There is nothing that you cannot do in this solution. It has all the features, which makes it very dynamic.

What needs improvement?

I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions.

We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. 

It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved. 

For how long have I used the solution?

I've been using ArcSight for three years. I started using it in February 2019.

What do I think about the stability of the solution?

It is stable, but its stability can be better. I would rate it a four out of five in terms of stability.

What do I think about the scalability of the solution?

It has been good when it comes to scalability. As an MSSP, we provide services to other customers, and we have customers with different capacity requirements. It is good in terms of moving from one particular size to another.

How are customer service and technical support?

They have been great. They are friendly and good.

How was the initial setup?

Its initial setup is straightforward. The deployment duration depends on the environment. It doesn't take time for our own environment, but I've heard some people complaining about the time period for which they have to wait for the deployment to take place.

What's my experience with pricing, setup cost, and licensing?

ArcSight can be a little bit expensive because of the area that we work in and the cost. Licensing is mostly on a yearly basis, not monthly.

What other advice do I have?

I would recommend this solution to anyone looking for an on-prem SIEM solution. It has been the best SIEM solution that I've worked with.

I would rate ArcSight ESM a nine out of ten. It is a great solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
OpenText Enterprise Security Manager
September 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.
Ali Salempanah - PeerSpot reviewer
Security Engineer at Billie
Real User
Sep 9, 2024
Can write queries fast but visualization isn't good
Pros and Cons
  • "On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented."
  • "I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards."

What is our primary use case?

I use the solution to implement detection rules based on attack scenarios.

What is most valuable?

On the positive side, ArcSight ESM's performance was excellent. It was very fast when writing queries. It provided good performance monitoring and had built-in rules to show which rules triggered most often and impacted performance. This performance monitoring was well-implemented.

What needs improvement?

I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards.

For how long have I used the solution?

I have been working with the product for a year. 

How are customer service and support?

The tool's support is one of its best parts. 

How would you rate customer service and support?

Positive

How was the initial setup?

I wasn't involved in the initial setup and deployment of ArcSight ESM, as it had already been implemented when I joined the company. I worked on implementing dashboards and detection rules. The rule categorization was good and had a good alert system when rules were triggered.

What's my experience with pricing, setup cost, and licensing?

Price-wise, ArcSight ESM was a bit high compared to competitors, which factored into our decision to switch to Splunk. It couldn't cover all our business needs for what we wanted to implement.

What other advice do I have?

I rate the overall solution a five out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2159517 - PeerSpot reviewer
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
Real User
Apr 20, 2023
A robust and scalable solution that is good for correlation
Pros and Cons
  • "The tool is good for correlation and aggregation. We use it as a collection platform."
  • "The tool should improve its UI. It also should make data more searchable."

What is our primary use case?

The tool is good for correlation and aggregation. We use it as a collection platform. 

What needs improvement?

The tool should improve its UI. It also should make data more searchable. 

For how long have I used the solution?

I have been working with the tool for three to four years. 

What do I think about the stability of the solution?

The tool is stable. 

What do I think about the scalability of the solution?

The tool is scalable. 

Which solution did I use previously and why did I switch?

I have worked with QRadar and McAfee. 

How was the initial setup?

The deployment process is similar to the hosting of other applications. The tool's deployment depends on the environment architecture, and your requirements. 

What other advice do I have?

I would rate the solution a seven out of ten. The product is very robust. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 20
Jan 27, 2023
Great real-time reporting, offers simplicity for implementation and operations
Pros and Cons
  • "Very good real-time reporting with a good dashboard."
  • "Currently lacks SOAR feature."

What is our primary use case?

We deal mainly with enterprise companies - I'm the senior manager and we are partners with ArcSight. 

What is most valuable?

The solution has a good dashboard, very good real-time reporting and it's easy to use, offering simplicity for implementation and operations.

What needs improvement?

I'd like to see an improvement in their training and documentation. SOAR (Security Orchestration, Automation, and Response) would be a good feature to include in the future. 

For how long have I used the solution?

I've been using this solution for six years. 

What do I think about the scalability of the solution?

This solution is stable and scalable. 

How are customer service and support?

They offer 24/7 standby support wherever you are. It's very good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. 

What's my experience with pricing, setup cost, and licensing?

The cost is reasonable for a good solution.

What other advice do I have?

It's important to set up the organization before implementation, checking internal desktops or IT security internals before buying the solution.

I rate this product an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Forensic Consultant at A Cyber 1 Company
Consultant
Jan 15, 2023
Good out-of-the-box rules, but the integration and reporting features can be improved
Pros and Cons
  • "The out-of-the-box rules that help us configure functioning rules within the environment are valuable."
  • "Customer service and support is our biggest challenge."

What is our primary use case?

We use this solution in our customers company and we deploy the solution on cloud and on-premises.

What is most valuable?

The out-of-the-box rules that help us configure functioning rules within the environment are valuable. For example, they have good resources to help detect and populate the dashboard if something malicious happens. Additionally, we value a good visual representation of a company and network infrastructure.

What needs improvement?

The solution can be improved regarding integration with other security products, ease of implementing some features, and feeling like we're not utilizing the solution as best as we could. In the next release, the solution should incorporate some threat intel features and integrate well with other network solutions, EDRs, palm solutions and the sorts. Additionally, the reporting can be improved to bring out very insightful reports showing senior management value for the solution.

For how long have I used the solution?

We have been using the solution for approximately six months.

What do I think about the stability of the solution?

The solution is stable. I rate it an eight out of ten.

What do I think about the scalability of the solution?

The solution is scalable and has approximately 500 users utilizing it for enterprise businesses.

How are customer service and support?

Customer service and support are one of the biggest challenges we are having. Although it is provided, and once you log tickets, they follow up quickly, sometimes some of the challenges we face drag on for a while because of ironing out specific details about technical support and payments.

How was the initial setup?

The initial setup was a bit complex. Getting things running and configured took a while. Furthermore, some integrations were unavailable, and some had to be custom scripted, so getting the solution up and running was a bit tedious.

What about the implementation team?

We implement in-house, and it takes approximately two months to complete implementation.

What's my experience with pricing, setup cost, and licensing?

The licensing costs are high and the solution is priced through events that come in so the cost tends to be heavy on the client. The price of the license could be lower.

What other advice do I have?

I rate the solution a six out of ten. The solution is good, but its integration and reporting features can be improved. I advise users to have a mature security infrastructure and scale up their technical resources. However, for smaller organizations considering the solution, I advise them to think of other solutions before using ArcSight Enterprise Security Manager.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer987771 - PeerSpot reviewer
Senior Manager at a tech services company with 51-200 employees
Real User
Jul 25, 2022
Lacking scalable cloud technology, poor stability, but easy to use
Pros and Cons
  • "The most valuable features of ArcSight ESM are ease of use and readily usable components."
  • "ArcSight ESM is lacking cloud scalable technology."
  • "The support from ArcSight ESM is very poor. We had a negative experience."

What is our primary use case?

We have a large footprint of 25 plus subsidiaries reporting into a consolidated security reporting and action team using ArcSight ESM.

How has it helped my organization?

ArcSight ESM has improved our organization because we have better incident reporting. It was originally deployed in order to fulfill compliance requirements. We were required to have security monitoring, ArcSight ESM was a quick and effective way to be able to meet that minimum requirement.

What is most valuable?

The most valuable features of ArcSight ESM are ease of use and readily usable components.

What needs improvement?

ArcSight ESM is lacking cloud scalable technology.

For how long have I used the solution?

I have been using ArcSight Enterprise Security Manager (ESM) for approximately three years.

What do I think about the stability of the solution?

ArcSight ESM has average capabilities. It's not seen as being particularly robust or usable for advanced threats.

What do I think about the scalability of the solution?

The scalability of ArcSight ESM is average to poor.

We have approximately 60,000 users using the solution.

How are customer service and support?

The support from ArcSight ESM is very poor. We had a negative experience.

I rate the support from ArcSight ESM one out of five.

Which solution did I use previously and why did I switch?

We did not use a solution prior to ArcSight ESM.

How was the initial setup?

The initial setup of ArcSight ESM was relatively straightforward. The full deployment took us approximately six months. The implementation strategy was to get basic monitoring templates as fast as possible.

What about the implementation team?

We used an integrator for the implementation of ArcSight ESM.

What was our ROI?

The ROI was not important at first because we were trying to cover our basic compliance requirement for monitoring.

What's my experience with pricing, setup cost, and licensing?

We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees.

Which other solutions did I evaluate?

We evaluated other solutions prior to choosing ArcSight ESM, such as Splunk and RSA NetWitness. We decided on ArcSight ESM because it was cost-effective.

What other advice do I have?

We are replacing ArcSight ESM with Microsoft Sentinel. We wanted to shift to cloud-based, cloud-scalable technology.

My advice to others is for them to take a hard look at the total cost of ownership, specifically the maintenance and upkeep that's required to maintain the appropriate service levels.

I rate ArcSight ESM a four out of five.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Subhadip Pakrashi - PeerSpot reviewer
CEO at Kapstone Technological Services LLP
Reseller
Top 5Leaderboard
Jul 22, 2022
A stable and scalable enterprise data security manager, but the initial setup could be more straightforward
Pros and Cons
  • "ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product."
  • "The initial setup could be more straightforward."
  • "The initial setup is complex."

What is our primary use case?

I'm an administrator, and I implement ArcSight Enterprise Security Manager (ESM). I use ArcSight SIEM and have all the security information, events, logins, and security logs. We compile all the information so we can file and stop it from happening or provide an alert. 

What is most valuable?

ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product.

What needs improvement?

The initial setup could be more straightforward. 

What do I think about the stability of the solution?

ArcSight Enterprise Security Manager (ESM) is a stable solution. However, it depends on how well it's deployed in the customer's location. 

Because SIEM doesn't have much to do with blocking the traffic, even if it doesn't get deployed well, it doesn't matter to the customer because the work is going on, and the traffic is flowing in. 

It's just that the correlation will never happen. The security post of the company goes for all; that's the only problem. Apart from that, there would be no problem with the operations website. 

What do I think about the scalability of the solution?

ArcSight Enterprise Security Manager (ESM) is scalable, but you must size it well.

How are customer service and support?

ArcSight technical support is a bit better than the QRadar.

How was the initial setup?

The initial setup is complex. In general, it takes about three months to implement this solution.

What other advice do I have?

I will only make recommendations based on the customer's requirements and environment.

On a scale from one to ten, I would give ArcSight Enterprise Security Manager (ESM) a seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
HungTran2 - PeerSpot reviewer
Technical at HPT Vietnam
MSP
Jul 4, 2022
Easy to use, reliable, simple implementation
Pros and Cons
  • "The most valuable feature of ArcSight ESM is its ease of use."
  • "ArcSight ESM could improve by adding more features and documentation. There needs to be more documentation."

What is our primary use case?

We are using ArcSight ESM in our company for security information and event management.

What is most valuable?

The most valuable feature of ArcSight ESM is its ease of use.

What needs improvement?

ArcSight ESM could improve by adding more features and documentation. There needs to be more documentation.

For how long have I used the solution?

I am been using ArcSight Enterprise Security Manager (ESM) for approximately 10 years.

What do I think about the stability of the solution?

ArcSight ESM is stable.

What do I think about the scalability of the solution?

The scalability of ArcSight ESM is good.

We have approximately 10 people using this solution. There are 1,000 devices using the solution. We are using the solution to its full capacity. 

How are customer service and support?

The support is not very good.

I rate the support from ArcSight ESM a four out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of ArcSight ESM is easy. The deployment process took approximately one week.

What about the implementation team?

I did the implementation of ArcSight ESM myself. We have two people for maintenance.

What other advice do I have?

I rate ArcSight Enterprise Security Manager an eight out of ten

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1417383 - PeerSpot reviewer
Presales Manager at a tech services company with 51-200 employees
Real User
May 26, 2022
The flex connector lets you develop new connectors to integrate homebrew solutions
Pros and Cons
  • "The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector."
  • "When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets."

What is our primary use case?

We use ArcSight primarily to provide logs for the incident response team and cyber security analysts to evaluate everything happening in the network. 

What is most valuable?

The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector.

What needs improvement?

When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets.

What other advice do I have?

I rate ArcSight Enterprise Security Manager nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.