ArcSight Enterprise Security Manager (ESM) vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 20, 2023
 

Categories and Ranking

ArcSight Enterprise Securit...
Ranking in Security Information and Event Management (SIEM)
12th
Average Rating
7.8
Number of Reviews
93
Ranking in other categories
No ranking in other categories
LogRhythm SIEM
Ranking in Security Information and Event Management (SIEM)
6th
Average Rating
8.4
Number of Reviews
167
Ranking in other categories
Log Management (8th)
 

Mindshare comparison

As of June 2024, in the Security Information and Event Management (SIEM) category, the mindshare of ArcSight Enterprise Security Manager (ESM) is 1.0%, down from 2.8% compared to the previous year. The mindshare of LogRhythm SIEM is 5.0%, down from 6.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
No other categories found
Log Management
5.4%
 

Featured Reviews

Irfan Ali - PeerSpot reviewer
Feb 13, 2024
Offers comprehensive integration with various log sources but lacks integration with various log sources
The deployment does require some effort. ArcSight is one of the most complex, complicated solutions to deploy. It's a large-scale deployment. So, it has full modules to be deployed. The footprint is larger compared to some other platforms where the footprint is in single or two virtual machines, which is not the case in ArcSight. On average, two weeks or three weeks of time for deployment matters. Moreover, deployment involves more than just installing the tools. Integration with it is a second step. That takes longer than just the tool deployment. Then, after integration, you have to onboard the different log sources. Even for that, the combined time of deployment and integration is less than onboarding the different source environments. Once you do all this and then establish the correlation, only then from the customer's point of view, it's a complete deployment. From a product perspective, it is different. Some products are easier to have a fresh installation but difficult to integrate, and then they're very difficult to onboard the log sources. So, from the product point of view, when you consider a deployment, it should be considered an end-to-end deployment from zero to production-ready. And here, ArcSight is a longer platform to deploy. Moreover, it is quite difficult to maintain it because of the different components, and it can be because of the licensing model; it takes longer. It will take more effort to maintain it. Sometimes, the hardware fails, and sometimes the virtual machine fails. Sometimes, the operating system and sometimes the database separately. The more components you have, the more knobs you have to keep an eye on. Two people are required to maintain it.
RC
Oct 16, 2022
Helps with productivity, reduces administrative overhead, and offers useful dashboards
Our previous SIEM did not have dashboards, so there wasn't a starting point. With our previous SIEM, we had to have a specific thing we were looking for, and only then we could find it. The dashboards in the LogRhythm SIEM really help us as a starting point. It gives us a starting point we can go to every day. We walk through several dashboards to see anomalous activity for further investigation. The dashboards, therefore, are our favorite feature of the SIEM. The solution helped with productivity and the ability to process logs. We do Event Log Filtering for certain log types, which we don't want in our SIEM as they're just too noisy. Having too much noise in the SIEM makes it harder to find relevant things. Therefore, we use Log Filtering to limit the noise. It's also given us the ability to bring more logs in, so we bring them all from all of our workstations and servers. Doing the log filtering this way allowed us to bring in other log sources and keep the noise manageable. It's helped reduce our administrative overhead. Before we started doing the log filtering, we exceeded our license capacity for what we were licensed in terms of logs in our SIEM. The filtering allowed us to bring the noise down and helped us with the removal of junk logs that are not useful. We have a lot of firewalls, and anytime you're traversing internally inside of the firewall, it generates a lot of traffic. That kind of traffic is the type of traffic we took out, allowing us to bring our workstation traffic logs in to give us a better view of our environment. It's very big for us that the solution is out-of-the-box. To have the solution be turnkey was significant as it enabled us to ramp up and get the logs onboarded immediately. There wasn't a lot of configuration to get to a point where we could bring logs in. It was essentially turnkey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool is good for correlation and aggregation. We use it as a collection platform."
"We do consulting and I get feedback from our clients that the product really helped them with compliance, especially with GDPR."
"Once the rules are defined, it is capable of detecting minute changes in the systems, which are effectively based on the entries in the log.​"
"The tool sends an automated mail to all the operators, which makes it easy to share the information and reporting.​"
"The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector."
"The most valuable features of ArcSight ESM are ease of use and readily usable components."
"We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities."
"When WannaCry attacks I can minimize the damage. My company had no protection at the time. We get alerts in ArcSight and then whenever a user got a copy of WannaCry and the WannaCry malware wants to connect to the mother ship, it alerts me in the ArcSight dashboard, and that helps us a lot. We then just go to the user and erase the malware."
"NextGen SIEM's best feature is how it presents logs."
"The product is great for medium to large-scale organizations."
"The most valuable features of the solution are network monitoring, user behavior analytics, and log collection."
"The ability to investigate a particular period of time where you can analyze logs is its most valuable feature."
"The security operation center is excellent."
"The artificial intelligence engine."
"Their customer support is friendly and willing to help."
"I have found the Advanced Intelligence Engine has provided the most value to us because we can customize alarms based on our requirements and have created hundreds of alarms that notify different people for different scenarios."
 

Cons

"ArcSight ESM's UI is a little cumbersome and complex, especially for first-time and occasional users using the console manager."
"In other products, I have found that they use some kind of GUI that is drag and drop. While in ArcSight they use still scripting. They should keep scripting because some people prefer scripting but they should have the option for those who prefer using drag and drop."
"HPE ArcSight has a quite steep learning curve."
"Sometimes, it takes ages to get an issue resolved. I have ArcSight experience, so I normally try to fix things on my own or find a workaround, but it's tough to get support when I need it."
"The correlation engine effectively connects different events, significantly improving our detection reach. However, limitations exist with non-default alerts, where additional costs arise for integration."
"ArcSight ESM is not easy to use and it should be integrated with other tools that have infrastructure capabilities."
"The centralized dashboard for the hybrid cloud environment needs to be more focused. It needs to be redefined because it's missing most of the information. It should be a little bit easy to use. Currently, integration with various applications and connectors is not that easy. Deployment is easy, but integration is not that easy. ArcSight also has a very high bandwidth consumption to pull the local servers. It should have some kind of better process or ability to transfer files from on-premises to the cloud, from the cloud to on-premises, and from a cloud to another cloud."
"ArcSight ESM is lacking cloud scalable technology."
"It's not easy for someone new to the solution."
"I would like to see support added for Exchange 2016, and CheckPoint OPSec Lea."
"We're still struggling to get a real return on it and finding something that isn't false noise."
"Technical support could use a little work in the terms of responding back. The feedback that we received is they do need a little more staff."
"I would like to suggest that they should improve their usage of third party tools for making dashboards and reports. If they would create their own tools for dashboard and report, it would be much better in terms of security purposes."
"It should be improved for automated setup and auto-configuration. There should be ease of integration and ease of setup."
"Better integration with different services is needed, as there are quite a few platforms that we use that don't integrate very smoothly with LogRhythm."
"LogRhythm NextGen SIEM is currently based only on the Windows platform. This means that some of our customers have to purchase a Windows license elsewhere. If LogRhythm can move to a Linux platform or a proprietary platform, it would be very helpful."
 

Pricing and Cost Advice

"​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders.​"
"Pricing is good, I'd rate the pricing a seven out of ten, with ten being low price. It's better than Splunk and IBM QRadar because their pricing is based on EPS."
"The pricing model is expensive compared to open-source alternatives."
"The product licenses are inexpensive."
"We're paying a fee for an MSSP, and the cost of the total cost of ArcSight ESM was approximately three to four million dollars a year. The price was less than similar solutions. We did not have additional fees."
"There is a license required for this solution."
"Customers without a ton of resources to dedicate to deployment may be better served by a managed ArcSight service."
"ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value."
"The nice thing about LogRhythm is you can either use the agents, getting a certain number of agents with your license depending on how you want to go, and those agents do a lot of cool things, or you can use CIS Log host, then you have like an unlimited number of them."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"I would recommend talking to the rep. That's the biggest thing because they will know what questions to ask."
"I have seen a measurable decrease in the mean time to detect and respond to threats. We went from not detecting them to detecting them. We can actually pick up what is anomalous in our network now."
"When it comes time to renew, they say, "This is what you are using. This is what we can do for you." So, they work with you on pricing."
"The support which allows more customized to the environment when we are deploying new systems is called Professional Service and is very expensive. The technical annual support and there is an annual fee."
"NextGen SIEM's pricing is moderate."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
789,135 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
9%
Government
9%
Educational Organization
38%
Computer Software Company
9%
Government
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What do you like most about ArcSight Enterprise Security Manager (ESM)?
We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities.
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
The pricing model is expensive compared to open-source alternatives, especially as your needs grow.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What do you like most about LogRhythm NextGen SIEM?
LogRhythm does a very good job of helping SOCs manage their workflows.
What is your experience regarding pricing and costs for LogRhythm NextGen SIEM?
LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform.
 

Also Known As

Micro Focus ArcSight, HPE ArcSight, ArcSight
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Overview

 

Sample Customers

Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about ArcSight Enterprise Security Manager (ESM) vs. LogRhythm SIEM and other solutions. Updated: June 2024.
789,135 professionals have used our research since 2012.