Correlation and flexibility are the most valuable features.
Information Security Specialist at a tech services company with 501-1,000 employees
Correlation and flexibility are valuable. It helped meet compliance requirements for log collection.
Pros and Cons
- "ArcSight is better than them all when it comes to filtering, normalization, aggregation, dashboards, reporting and correlation, multi-tenancy and custom devices support."
- "Initial deployment of ArcSight is pretty challenging. It takes at least 3-4 months to install, integrate, define content and fine tune before starting the security operation."
What is most valuable?
How has it helped my organization?
ArcSight saved time and effort responding to security incidents with one centralized console and helped to meet compliance requirements for log collection.
What needs improvement?
I would like to see improvement in the complexity involved to create a custom connector (flex). Other SIEM solutions, like QRadar, have addressed this.
For how long have I used the solution?
We have used ArcSight for 6 years.
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
What do I think about the stability of the solution?
Initial deployment of ArcSight is pretty challenging. It takes at least 3-4 months to install, integrate, define content and fine tune before starting the security operation.
How are customer service and support?
Customer service is fast in response, but very standard in their approach, which takes lot of time for simple issues.
Which solution did I use previously and why did I switch?
I have used RSA enVision, QRadar and Splunk. ArcSight is better than them all when it comes to filtering, normalization, aggregation, dashboards, reporting and correlation, multi-tenancy and custom devices support.
How was the initial setup?
Initial setup was complex as the integration of a custom application takes lot of time and effort. Then, fine tuning requires at least 6 weeks to analyze and tune each alert separately.
What about the implementation team?
We implemented through HPE itself and I would advise to go through a vendor as they would hand over the SIEM post-fine tuning which is a mammoth task.
What was our ROI?
ROI can be measured in terms of detected security incidents and compliance positive tests, which in turn boost the business. Our security incident count increased from 3 per month to 46 and all were real security threats. Had those gone undetected and realized, there would have been possible data theft, information stealing, damage of brand reputation, etc.
What other advice do I have?
An organization that has enough budget for SIEM and really cares about security and not only about compliance must go with ArcSight. SMB organizations who want to start a SOC or have just a log management solution for compliance requirements can go for cheaper options such as QRadar, LogRhythm, AlienVault, etc. For MSSP, ArcSight is indeed the best SIEM available in the market, as segregation of logs, access restriction, different log retention, customized view for dashboard and reports to clients are present with ease.
Lastly, ArcSight is like Apple. If you have money, go for iPhone and you will certainly not regret it. But if your budget is the primary constraint, then another SIEM must be explored.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Information Security Engineer at a tech services company with 501-1,000 employees
The user has multiple levels of options to generate reports and get alerted based on conditions.
Pros and Cons
- "By using ArcSight ESM and its correlation technology, it thwarts multiple attacks from external sources before exploitations such as SQL injection, UNIX password file attempt, brute force to published servers, and more."
- "Technical support should be improved. Many times, I've raised a case but none of them solved it and it took the guys from the Protect724 forum so solve my issue."
Valuable Features
- Collection - Collects logs from a wide range of products, even those not supported by default and the users can develop a connector for log collection.
- Detection - Caliber to detect subtle attacks with a powerful correlation engine.
- Report/Alert - The user has multiple levels of options to generate reports and get alerted based on conditions.
Improvements to My Organization
By using ArcSight ESM and its correlation technology, it thwarts multiple attacks from external sources before exploitations such as SQL injection, UNIX password file attempt, brute force to published servers, and more.
In addition, internal frauds have been prevented through preventing unauthorized login attempts to the firewall, database, critical servers, etc.
Room for Improvement
ArcSight Connector appliance needs some improvement, as it has some bugs which triggers issues most of the time. I believe that the Connector is going to hit end-of-service.
Deployment Issues
We experienced no issues with the deployment.
Stability Issues
We had the bugs in Connector as detailed in the Areas for Improvement section.
Scalability Issues
We've had no issues with scalability.
Customer Service and Technical Support
Customer Service:
3.5*
Technical Support:Technical support should be improved. Many times, I've raised a case but none of them solved it and it took the guys from the Protect724 forum so solve my issue. The support team simply collects the logs from end users and makes you wait, and you carry on passing the same information which is available in the Admin guide.
Initial Setup
All you need is proper planning and pre-requisites information, and it's straightforward. Some newbies say that this product is hard to handle, but basically practice makes perfect.
Other Advice
HP are doing their job perfectly by bringing new features in every version, such as RepSM, HA capability, etc. It has never failed me.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
OpenText Enterprise Security Manager
June 2026
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
Senior Security Consultant & Solution Architect at a financial services firm with 10,001+ employees
It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.
Pros and Cons
- "Due simply to the user features available out-of-the-box, the convenience it can bring to any organization (when deployed and configured correctly) can greatly assist any enterprise in many facets, from an increased and enhanced security posture, to auditory regulations and even data retention."
- "It needs additional and better user customization for SmartConnectors."
Valuable Features:
- Alert correlation
- Reporting
- Retention
These are the features we find most valuable for us and which we use the most.
Improvements to My Organization:
It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.
Due simply to the user features available out-of-the-box, the convenience it can bring to any organization (when deployed and configured correctly) can greatly assist any enterprise in many facets, from an increased and enhanced security posture, to auditory regulations and even data retention.
Room for Improvement:
It needs additional and better user customization for SmartConnectors. It has additional device support for more obscure log sources.
Also needed is a configuration wizard for organizations lacking the in-depth knowledge required to integrate the solution successfully.
Deployment Issues:
We've had no issues with deployment.
Stability Issues:
We've had no issues with instability. It's been stable for us.
Scalability Issues:
We've been able to scale it for our needs. We've had no issues with scalability.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Solutions Architect at a comms service provider with 10,001+ employees
Scalable though it is not "plug-and-play".
Pros and Cons
- "We use this product for managed SIEM services and its stability and maturity helps with standard deployments (hardly any surprises)."
- "High availability achievable through complicated configurations (i.e. load balancers)."
Valuable Features:
- Scalable though it is not "plug-and-play".
- Various deployment configurations, based on requirements, budget and the EPS/GB per day
- Stable, performance predictable based on used capacity
- Integration with alerting/ticketing systems such as Tivoli
Improvements to My Organization:
- We use this product for managed SIEM services and its stability and maturity helps with standard deployments (hardly any surprises)
Room for Improvement:
- A bit on the slow side for reports requiring query of old data
- High availability achievable through complicated configurations (i.e. load balancers)
- The user interface is a bit dated
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technology Officer (CTO) at a tech company with 501-1,000 employees
It enables us to speed our time to resolution.
Pros and Cons
- "Before we would have to have a large number of staff to be able to go in and do consulting opportunities, to mitigate and remediate security intrusions on given clients, now using ArcSight, albeit there may be a capital upfront cost to buy the software product, it enables us to speed our time to resolution."
- "Today it takes still a lot of consulting dollars to go into trying to deploy ArcSight. You have to have a very powerful technologist or technologist team to deploy ArcSight at scale and be able to actually understand the events coming inbound and make the right tangible decisions from those points of ingress or points of notification."
What is most valuable?
- Security, understanding detection, intrusion, and how to do prevention and take action on an event that occurs from a security layer.
- Having a single solution that can actually manage the entire infrastructure, soup to nuts.
- Ability to detect and then take action on it.
How has it helped my organization?
Reducing my OPEX cost by reducing the overhead and training costs of employees and staff. Before we would have to have a large number of staff to be able to go in and do consulting opportunities, to mitigate and remediate security intrusions on given clients. Now using ArcSight, albeit there maybe a capital upfront cost to buy the software product, it enables us to speed our time to resolution.
What needs improvement?
ArcSight needs to go the same route that HPE's doing with the virtualization engine of the HP 380. Basically making it more of a single pane of glass to be able to deploy and take a tangible action on a security event. Today it takes still a lot of consulting dollars to go into trying to deploy ArcSight. You have to have a very powerful technologist or technologist team to deploy ArcSight at scale and be able to actually understand the events coming inbound and make the right tangible decisions from those points of ingress or points of notification. That today, albeit, not horribly hard, as long as you have a trained professional that knows the product. It would be nice to be able to basically make that a one pane of glass, much like HPE's done with the virtualization concept. It would make that pain point a little less. It's not going to make it perfect, but it would be nice to see improvement in that area.
What do I think about the stability of the solution?
My opinion from a stability's standpoint ... we don't have any issues. The product runs 24/7/365. Whenever HPE introduces a patch or an enhancement for security concerns, we've never had a problem being able to ingest that on the fly with little-to-no downtime outside of what's been expected from the release of the patch.
What do I think about the scalability of the solution?
I've not had any problems with scaling into tens of thousands of nodes. I guess the biggest problem you're going to have with that would be actually the compute power to make the tangible decisions that's needed on large-scale environments where you have hundreds of firewalls coming in from different points of ingress. That would be a concern, but again that's not because of the ArcSight, it's just basically that's compute power.
How are customer service and technical support?
It has improved substantially over the last two years. I'm going to rate them at 3/5 because when you call in the time to remediation is long right now. I'm not going to fault any one person on that. It's a complex security tool, so calling in and trying to get that omission, crystal ball appearance is difficult. I get that. Is there room for improvement? Of course there is.
Which solution did I use previously and why did I switch?
Well we have different tools out there, but the most common ones everybody's going to know about is Splunk. Feature, function and price was why we switched When we're able to actually deliver the similar features and functions, add in additional intellectual property from HPE with respect to decision trees of ArcSight and being able to take tangible actions on the stuff that's coming inbound, that's great. Other tools can do that. Now you're just talking about price in the industry. We're able to deliver the same features and functionality at a lower cost to the client, typically we'll win with ArcSight.
How was the initial setup?
Straightforward for the most part but there are limitations. For example in the virtualization engine of the J80, the Instant On, which is a OneView Instant On product line. It does work great, as long as you have your infrastructure. Our clients give us all the necessary requirements, such as the AD and IP address, the DNS, the subnets and stuff. As long as all that works seamlessly, then we can usually bind that HP 380, the Instant On into the infrastructure seamlessly. Does it always work smooth? No. But that's not necessarily HPE's fault, it's because the infrastructure doesn't always lend itself to easy integration.
What other advice do I have?
I'm going to rate it at a 9. There's always room for improvement, of course, and maybe I'll be fair and give it an 8.5. The only reason I would do that is because, again, coming up with that single pane of glass, easier management style, and more about deployment. You don't have to have that powerhouse technologist that knows every trick of the trade to go in and deploy it and get all the bells and whistles. Is that a perfect model that will ever be achieved? Of course not. Can there be improvement? Sure there can. What I'm shooting for is have an ArcSight solution that can get me 90 percent there, and then the customization of ArcSight will be reduced substantially, so that the customers' adoption of a new security style tool will be easier to swallow, and it will lend itself to a larger footprint over time as the customer builds comfort with the product.
With respect to the software on ArcSight, concept's the same on that. When we actually ask for improvements on the product, they've made those enhancements and made those fixes. Now with respect to me asking for a single pane of glass? I know they're working on it, I'm sure they are. It's a pain point that not only we have, but a lot of our customers have. If we're having the same conversation next year, I'll be disappointed. I'm hoping that the single pane of glass comes out soon.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're a partner and reseller.
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Has helped us to gather, store, correlate and analyze security log data from many different information systems.
Pros and Cons
- "It has helped us to gather, store, correlate and analyze security log data from many different information systems."
- "I will like to see a threat analytics module. Also, the ability to produce reports."
Valuable Features:
Intrusion Detection System (IDS)
Security Information and Event Management (SIEM)
Improvements to My Organization:
To organizations like mine, security information and event management products being introduced in the industry, as an outcome of several vulnerability, are able to provide real-time monitoring reporting and defense against these attacks. It has helped us to gather, store, correlate and analyze security log data from many different information systems.
Room for Improvement:
For this review, ArcSight sent me the Logger 4 7000-series appliance (2U) with six 1TB RADIUS drives, the maximum amount of internal storage available. I will like to see a threat analytics module. Also, the ability to produce reports.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Senior ICT Security Officer at a financial services firm with 1,001-5,000 employees
It provides us with event correlations that are automated and prioritized according to level of security risk and compliance violation.
Pros and Cons
- "It allows us to be in better compliance with security protocols, and it also gives us a better global vision of what is happening in the organization in terms of security threats and how best to analyze and mitigate them."
- "I would like to have native cluster for connectors as a software version and not as an appliance. It also needs a better disaster recovery procedure."
Valuable Features:
- Real-time rules for threat detection
- Event correlations that are automated and prioritized according to level of security risk and compliance violation
Improvements to My Organization:
It allows us to be in better compliance with security protocols. It also gives us a better global vision of what is happening in the organization in terms of security threats and how best to analyze and mitigate them.
Room for Improvement:
I would like to have native cluster for connectors as a software version and not as an appliance. It also needs a better disaster recovery procedure.
Use of Solution:
We've been using ArcSight since 2007.
Deployment Issues:
We've deployed it without any issues.
Stability Issues:
We haven't had any issues with instability.
Scalability Issues:
It's scaled fine for our needs.
Other Solutions Considered:
We chose ArcSight when they had no real competitor and we stayed with them.
Other Advice:
I'm pleased with the current capabilities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Architect at a tech services company with 51-200 employees
Its flexibility is achieved by being easy to use, and at the same time having very sophisticated FlexConnectors.
Pros and Cons
- "The best feature of ArcSight is its flexibility, as almost no other vendor provides such a good framework to collect, parse, and analyze data, and I've found ArcSight's correlation engine to be the most advanced on the market."
- "I must say that tech support is getting worse and worse every year."
What is most valuable?
The best feature of ArcSight is its flexibility. Almost no other vendor provides such a good framework to collect, parse, and analyze data. Its flexibility is achieved by being easy to use, and at the same time having very sophisticated FlexConnectors. Also, I've found ArcSight's correlation engine to be the most advanced on the market.
How has it helped my organization?
My customers who use ArcSight report that it becomes very useful in incident detection and forensics. It's really sped up disclosure of inappropriate activity in information systems and on the network. Flexible event collection allows getting crucial events from almost every possible source. And correlation abilities are incredible if you know how to cook it.
What needs improvement?
Many competitors are going down the road of combining their products with other security products, such as vulnerability scanning, configuration control etc. HP's position doesn't change in that area as they offer to use their standalone solutions and integrate them in ArcSight. There are no embedded scanners or network forensics. Maybe it's time for HP to rethink that position.
For how long have I used the solution?
I've been working with HP ArcSight since 2008. All that time, the product has been growing and evolving, trying to give us more profit and a better experience to old and new customers.
What was my experience with deployment of the solution?
We have had no issues with the deployment.
What do I think about the stability of the solution?
If you encounter serious performance problems, you didn't size correctly prior to deployment.
What do I think about the scalability of the solution?
The scalability options are pretty good although costly.
How are customer service and technical support?
Customer Service:
Every product has its stability bugs, and ArcSight is not an exception, though I haven't found anything critical.
Technical Support:I must say that tech support is getting worse and worse every year. Hard cases may "hang" for months. In simple cases, support often demonstrates a lack of deep knowledge. When ArcSight was not HP, its product support was much much better. Even first-line support could help with anything.
Which solution did I use previously and why did I switch?
As a systems integrator, we constantly evaluate different solutions and deploy not one but many of them. My personal opinion is that a crucial feature for a SIEM system is flexibility. The more you can tune, adjust, and develop the system, you will get more profit from it. If we're talking about SIEM solutions, then no one can offer such flexibility as ArcSight. Splunk maybe, but Splunk is not SIEM, and to get SIEM-like features from it you spend more time and money.
What about the implementation team?
As a system integrator, I always say that implementation must be done by an experienced team. SIEM solutions are not easy, so if time is important, do not rely on doing it haphazardly.
What's my experience with pricing, setup cost, and licensing?
We would like it to be cheaper, but the licensing model is pretty simple.
What other advice do I have?
You need to read the documentation - you can then get it fast and working. If you do not read the documentation, you get pain and tears. Look for an experienced team to deploy the solution, or get experience yourself as HP has some good learning courses.
Deep knowledge of the product will come later, but for the correct implementation you need to be prepared. ArcSight has wonderful community, and you can always ask a question or find an interesting use case there. It's a very useful resource indeed, do not hesitate to visit it.
Disclosure: My company has a business relationship with this vendor other than being a customer. We integrate ArcSight for our customers.
Senior IT Security Consultant, Cybersecurity Technology Services at a consultancy with 1,001-5,000 employees
It has flexible and rich correlation capabilities. It has the capability to manipulate every parameter - sub-strings, indexes, and custom functions.
Pros and Cons
- "This is the best SIEM solution on the market comparing to its competitors."
- "The layout of the analyst's console need improvement. Also, the advanced statistics in visualizations simply don't work, and I've performed an analysis of these functions."
Valuable Features
- It has flexible and rich correlation capabilities. This is the most mature product in this area.
- It has the capability to manipulate every parameter - sub-strings, indexes, and custom functions.
- Active Lists - This is the most powerful feature which supports correlation. It also has multi-column active lists, parameters manipulation, and correlation capabilities that provide great flexibility.
- Full control of correlation flow - There are no black-box closed rules, unlike with McAfee Nitro, and no default aggregation which is hard to analyze, unlike Offenses in QRadar.
Improvements to My Organization
This is the best product to build and supports SOC operations and SOC use cases.
Room for Improvement
The layout of the analyst's console need improvement. It has had no significant changes in at least nine years. Also, the advanced statistics in visualizations simply don't work, and I've performed an analysis of these functions.
Use of Solution
We've been using it for nine years.
Deployment Issues
We have had no issues with the deployment.
Stability Issues
We have had no issues with the stability.
Scalability Issues
We have had no issues scaling it for our needs.
Customer Service and Technical Support
I have not had to use tech support for at least two years now. From what I recall, they were good.
Initial Setup
The initial setup was simple and the implementation was straightforward as the supporting documentation is pretty good. Help for setup, which is available from the analyst console, is really great and complex with diagrams and screens.
Implementation Team
ArcSight makes it easy to achieve ROI because of its great flexibility.
Other Solutions Considered
This is the best SIEM solution on the market comparing to its competitors. I'm also familiar with IBM QRadar, RSA Security Analytics, McAfee Nitro, and Splunk.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer at a tech services company with 51-200 employees
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation. They need to fix some bugs and increase the search speed.
Pros and Cons
- "The dashboard is the most valuable feature for us as it can show a lot of information about real-time incidents."
- "They need to fix some bugs and increase the search performance speed."
Valuable Features
The dashboard is the most valuable feature for us as it can show a lot of information about real-time incidents.
Improvements to My Organization
When I am facing a problem such as transaction fraud, we can investigate using ArcSight by tracing the log through its correlation.
Room for Improvement
They need to fix some bugs and increase the search performance speed. Sometimes there are issues when I perform log correlations.
Deployment Issues
We have had no issues with the deployment.
Stability Issues
There have been no stability issues.
Scalability Issues
We have had no issues scaling it for our needs.
Customer Service and Technical Support
Customer Service:
5/10
Technical Support:5/10
Initial Setup
The initial setup was quite easy and straightforward.
Implementation Team
I work for a reseller, and we set up ArcSight for our customers, and I am learning a lot about its architecture.
Other Solutions Considered
For SIEM, I think HP ArcSight is a leading competitor alongside Splunk.
Other Advice
You need to learn about architecture and practice more before implementation since this product is not easy to learn and takes time to master.


Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
Stellar Cyber Open XDR
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
- Exporting Nessus Data Logs to HP ArcSight ESM
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?















