ArcSight Logger offers scalability, flexible log collection options, real-time awareness, efficient query capabilities, and excellent device support with multi-tenancy. It provides detailed event visibility, robust log management, and advanced security analytics. Its user-friendly interface allows for complex queries and customization. Additionally, it offers strong data retention and compliance features, integration with SIEM tools, and efficient machine learning for threat detection. Users appreciate its performance, powerful searching tools, and comprehensive log aggregation capabilities.
- "ArcSight Logger is very stable and useful for customers."
- "ArcSight Logger is very stable and useful for customers."
- "We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist."
ArcSight Logger needs improvement in user interface simplicity, speed, and adaptability. Users find it challenging to navigate and suggest enhancing the dashboard and search functionality. They note the lack of advanced features like AI, analytics, and integration with other systems. The platform's complexity requires specialized expertise. Users also criticize its outdated nature, limited reporting abilities, and inadequate connector support. They express concerns about its high cost and reduced technical support quality after corporate changes.
- "They are migrating to Splunk because ArcSight Logger doesn't have those features for user or customer behavior analysis."
- "ArcSight Logger doesn't have features for user or customer behavior analysis."
- "ArcSight has been sold two or three times, and the quality has decreased."