Based on my experience with SIEM, 7 years I worked with ArcSight on a daily basis
I would say that there are 3 mains points.
1) Objectives
What you would like to do with the SIEM.
What you have to achieve?
This is very important.
If you just need a solution to manage your…
To be very clear, it depends on the size of the infra and the number of users
I wouldn't choose IBM if there are more than 10000 users I would prefer ArcSight.
Then for Log Management, Splunk is better but same point as above it depends on the size and also the objective…