What is our primary use case?
We do work for multiple SIEM solutions such as Splunk, QRadar, LogRhythm. My team and I mostly work on ArcSight Logger and Splunk because we are dealing with projects related to these solutions.
We are discussing Logger for ArcSight Logger, specifically Log Collection.
In companies such as Aramco, SABIC, or electricity companies, they keep the main SIEM solution as Splunk or other LogRhythm solutions, and they use ArcSight Logger to collect the logs from Linux and Windows systems. They then forward these to the SIM solution.
What is most valuable?
ArcSight Logger fulfills compliance requirements and passes audit requirements. It is one of the Aramco standards requirements and is recommended by Aramco for any implementation.
Aramco, SABIC, water companies, and electricity companies are critical infrastructure with air-gapped networks. In an air-gapped network, there is no communication going out from that network area to the outside world, even to the corporate network. ArcSight Logger is installed on minimal resources with minimal requirements. There are not many upgrades or new features that come up frequently, though they do occur occasionally.
What needs improvement?
This decision is made by higher management as they don't want to have multiple solutions for one solution.
ArcSight Logger themselves don't provide good support, but companies such as ours provide comprehensive support.
Splunk is gaining popularity because ArcSight Logger doesn't have certain advanced features.
For how long have I used the solution?
I have been working with ArcSight Logger for quite long, approximately eight plus years, entering the ninth year now.
What was my experience with deployment of the solution?
ArcSight Logger can integrate with any SIM solution without issues.
What do I think about the stability of the solution?
I haven't encountered any stability issues.
What do I think about the scalability of the solution?
ArcSight Logger is primarily designed for enterprise-level businesses.
How are customer service and support?
ArcSight Logger themselves don't provide good support, but companies such as ours provide comprehensive support.
We provide pre-implementation, implementation, and post-implementation support to cover all areas.
If issues are specifically related to the solution, we can resolve them at our level, particularly configuration or integration matters. However, for specific features of the application, such as issues with Microsoft or Oracle, we cannot debug their solution or application, despite having certified and expert staff.
How would you rate customer service and support?
How was the initial setup?
The implementation of ArcSight Logger is very quick and easy. Implementation typically takes only one to two hours maximum.
What about the implementation team?
Implementation is taken care of by the customer unless they have an SLA with a support company. Some organizations now have managed services that cover these aspects.
What was our ROI?
ArcSight Logger is definitely cost-effective.
Which other solutions did I evaluate?
Splunk has more features and advantages compared to ArcSight Logger. While ArcSight Logger's functionality is limited, Splunk offers capabilities beyond SIEM and log analysis, including user behavior analysis, threat intelligence, and customer behavior analysis. Companies such as Aramco have invested in Splunk and are capitalizing on these solutions. They are focusing more on the defense and detection side. With Splunk, they remove ArcSight Logger and add Dragos as part of their strategy. This is why they are migrating all plants from ArcSight Logger to Splunk.
What other advice do I have?
As a department head, my staff uses my credentials and contacts everywhere. Only ArcSight Logger with Splunk was implemented in Aramco, not in other organizations. I rate ArcSight Logger 8 out of 10.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other