ArcSight Recon will help us with log management and analytics. We can use ArcSight Recon to perform analytics on the existing data.
What is our primary use case?
What is most valuable?
Since ArcSight Recon gives proper log management for us, it helps me with my compliance purposes and any forensic investigation. I can use the solution to fix any threats immediately, making it a good reporting tool for us.
What needs improvement?
The solution's speed has to be improved because more data analytics makes the application slower.
The application should work faster. For all the event data it collects, the false alarm should be filtered, and the real alarm should be used.
For how long have I used the solution?
I have been using ArcSight Recon for three years.
What do I think about the stability of the solution?
ArcSight Recon is a stable solution.
What do I think about the scalability of the solution?
ArcSight Recon is a scalable solution. ArcSight Recon is used in around 1,000 devices in our organization.
How are customer service and support?
The solution’s technical support is slow.
How was the initial setup?
A skilled person can easily deploy the solution in two days.
What other advice do I have?
Two admins are managing the solution in our organization.
Firstly, you need to prioritize the security threats you are looking for. You also need to know the incident response and compliance activities you are looking for. That can help your organization to have a proper ROI.
Overall, I rate ArcSight Recon an eight out of ten.
Which deployment model are you using for this solution?
On-premises

