it_user126648 - PeerSpot reviewer
Senior Security Analyst at a tech services company with 10,001+ employees
Real User
Great Scalability and Adaptability but it's Expensive

What is most valuable?

Scalability and Adaptability. By Scalability, I mean, the number of supported devices by ArcSight. You can make changes to the current deployment if required or add a new region in the scope by adding components of ArcSight. By Adaptability I mean, once the analysts see what can be achieved by utilizing the various resources of ArcSight, it motivates them to come up with new ideas and how to implement them. The interface is quite user friendly compared to other Vendors.

How has it helped my organization?

We could extract meaningful data of the billions of Security Events and relate it with the extra information we had for our assets.

What needs improvement?

Support from the vendor and pricing.

For how long have I used the solution?

3 Years.
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

What was my experience with deployment of the solution?

No

What do I think about the stability of the solution?

Yes, Oracle bugs mostly.

What do I think about the scalability of the solution?

No.

How are customer service and support?

Good.

Which solution did I use previously and why did I switch?

I have worked on multiple SIEM products. I work as a Senior Security Analyst and have a minimal role in deciding the solution. I only work where it is explicitly an HP ArcSight environment or deployment.

How was the initial setup?

Straightforward.

What about the implementation team?

Through an in-house team.

What other advice do I have?

Best SIEM product but it's high on pricing and licensing.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Techniqal Lead Enterprise Solution at a tech services company with 51-200 employees
Real User
Arcsight ESM is one of the best SIEM platform having market leading corelation engine, which is the plus point of Arcsight ESM it is very stable by its distributed architecture and scalability.
Pros and Cons
  • "I am satisfied with the solution's stability."
  • "Micro Focus does not have a physical presence here in Pakistan, although IBM does."

What is our primary use case?

We help our customers to implement the solution to detect known threats by state of the art variety of use cased offerings.

How has it helped my organization?

Arcsight ESM help customer in Automation for their complex security use case in order to detect the bad guys.

What is most valuable?

Corelation Engine by corelating the cross domain logs.

What needs improvement?

OOB content is limited Microfocus should release the smart connector update on quaterly basis.

For how long have I used the solution?

I've been working with the Micro Focus ArcSight portfolio for nearly six years.

What do I think about the stability of the solution?

I am satisfied with the solution's stability.

What do I think about the scalability of the solution?

I am satisfied with the solution's scalability. 

How are customer service and technical support?

We are satisfied with technical support and most of our problems have been resolved.

How was the initial setup?

Simple and pretty straight forward.

What about the implementation team?

We provide the implementation and maintenance services of the solution for our customers.

Which other solutions did I evaluate?

According to the Gartner Reports and Gartner Reviews, the main competitors of the solution are IBM and Splunk. They provide their services world-wide and do much implementation in the region. 

the plus point for Arcsight ESM is having cross domain corelation feature.

What other advice do I have?

I rate ArcSight Enterprise Security Manager (ESM) as a 8 out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
Information Security Analyst at a comms service provider with 1,001-5,000 employees
Real User
The roadmap is not clear but it has a very good correlation feature
Pros and Cons
  • "The correlation feature is good."
  • "The roadmap is not clear."

What is our primary use case?

Our primary use case is for security purposes. We are customers of ArcSight and I'm an information security analyst.

What is most valuable?

I think the correlation feature is one of the best features of ArcSight.

What needs improvement?

A lot of improvements could be made in the product. I think the roadmap is not clear, and there is no AI or machine learning solution. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

We haven't had any issues with stability. 

How are customer service and technical support?

I think there is good technical skill with the technical support but their attitude and response time is not good. 

How was the initial setup?

I recall that the initial setup was quite complex. We took subscription services for two weeks which covered the period of deployment. 

Which other solutions did I evaluate?

We are actually moving to another solution because the roadmap is not clear. We are just a small team and we don't need to monitor 24/7. We're looking to replace it with another more intelligent solution like Splunk or Securonix.

What other advice do I have?

Honestly, I won't recommend the ArcSight to another person. 

I would rate this solution a four out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user730782 - PeerSpot reviewer
Delivery Consultant - Security Solutions with 1,001-5,000 employees
Vendor
By tweaking use case conditions one could identify potential security breaches, but admin is complex
Pros and Cons
  • "Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events."
  • "Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it."

How has it helped my organization?

Recent attacks like Shamoon and WannaCry were under continuous monitoring by using this solution. It is understood that every SIEM is a detective technology and not a preventive, but by tweaking the use case conditions one could identify potential security breaches.

What is most valuable?

Customization. ArcSight gives you a platform to on-board out-of-the-box devices with a more accurate way of collecting desired logs/events. Competitors offer the something similar but ArcSight does gives you more detail.

What needs improvement?

Complexity, administration. Administration of ArcSight is not an easy job. The admin needs to be well experienced in it to identify the root cause and fix it.

What do I think about the stability of the solution?

Yes, quite a few times. But that depends on the admin, on how well the tool is maintained. Proper health checks are required on regular basis.

What do I think about the scalability of the solution?

Yes. Storage is an issue. Before deploying the product in the organization, proper scaling has to be done or else you end up losing the oldest data, hence failing to meet the audit.

How are customer service and technical support?

Eight out of 10.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

It was complex a few years. Lately it is all GUI and things are quite straightforward.

What's my experience with pricing, setup cost, and licensing?

ArcSight is pretty expensive compared with its competitors. I believe that is fine as it provides value.

Which other solutions did I evaluate?

No.

What other advice do I have?

On-boarding is easy but administration is challenging and more fun.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Solutions Architect- SIEM and Solutions with 1,001-5,000 employees
Vendor
Most devices are covered out-of-the-box. I would like to see high-end, predictive analytics.

What is most valuable?

The most valuable features are flexible setup of the architecture and large coverage of devices. Most devices deployed in enterprise environments are covered out-of-the-box by ArcSight. Unlike a few other solutions, the last-mile connectivity with ArcSight agent servers is free and flexible across all location deployments.

How has it helped my organization?

I have implemented it for a few organizations and they have benefited by early attack detection and usage of the right incident response mechanisms.

What needs improvement?

I would like to see high-end, predictive analytics. ArcSight ESM has some features that help in advanced correlation rules creation. However, intelligence around predictive analytics, understanding the current security posture and ability to map it with possible threats in the future is not something that is present in ArcSight at the moment.

For how long have I used the solution?

We’ve been using ArcSight for 3 years.

What do I think about the stability of the solution?

I have not had any issues with stability.

What do I think about the scalability of the solution?

I have not had any issues with scalability.

How is customer service and technical support?

I have never used technical support much, but will give it 3/5.

How was the initial setup?

The connectors are straightforward. The baselining is where the issues start.

What's my experience with pricing, setup cost, and licensing?

Licensing is straightforward, but the solution is fairly pricey.

Which other solutions did I evaluate?

We looked at QRadar and LogRhythm.

What other advice do I have?

Ensure your scope is very clear and so are the components.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.