Consultant at a financial services firm with 10,001+ employees
Real User
Top 5Leaderboard
Flexible with easy integrations but needs a less complex query language
Pros and Cons
  • "It makes maintenance very easy."
  • "The UI interface is somewhat complex and needs to be simplified."

What is our primary use case?

We have two connectors. One is a smart connector, and one is a select connector. It's a simple ESM tool. 

What is most valuable?

It offers easy integrations.

It's flexible for managing the monitoring of all activities on your network. It offers easy management and good dashboards.

There is good visibility over all of the traffic and logs and the health of the devices. It makes maintenance very easy.

It works with Linux and Mac, and other network devices, including firewalls and proxies. 

The solution can take logs from the cloud. That said, we do need to deploy a cloud connector to make that happen.

What needs improvement?

The query language should be less complex. 

The UI interface is somewhat complex and needs to be simplified. 

The dashboards don't read in a graphical manner. You have to read the logs and the output whenever you run a query. You need to understand the output. You have to export it to a .CSV and then design the visualization as per your requirements.

We're missing visual dashboards and reporting. We'd like to have the reporting of simple histories, and we need dashboards to show details in a presentable format.

In the logs, we're capturing multiple fields, some of which we do not need. There should be an option to just keep the fields you require and discard the rest. 

For how long have I used the solution?

I've been using the solution for almost two years. 

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.

What do I think about the stability of the solution?

Stability could be better. I would rate it six out of ten. I've seen a lot of crashes for the connector or server.

What do I think about the scalability of the solution?

The scalability is pretty good. I would rate it eight out of ten. 

It's an enterprise solution. We have deployed the solution deployed to 30 or 40 clients. 

We do not have plans to increase usage.

How are customer service and support?

We have not used technical support. Our team provides support to the customer. I'm not sure how they have assisted, if applicable. 

How was the initial setup?

The initial setup can be complex in comparison to other things. It's not difficult. There are just multiple components to consider. Deployment-wise, it is okay, just not simple. It becomes more complex when you have to develop multiple components at the same time. 

What was our ROI?

We have witnessed an ROI so far.

What's my experience with pricing, setup cost, and licensing?

The pricing depends on the client. It does have the same price range as other solutions. The pricing we pitch is based on EPS level for management. 

What other advice do I have?

I'm not sure which version of the solution I'm using. 

Users should have a good knowledge of the management of logging, including how to write log queries and the development of custom connectors. There is some technical skill necessary.

I'd rate the solution seven out of ten overall. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Rikin Rathod - PeerSpot reviewer
Senior Officer IT at Tech Data Limited
Real User
Top 10
Interactive dashboards provide lots of detail, but tough to operate for new users
Pros and Cons
  • "I think that the overall experience with this solution is good, but in particular, I think that the dashboards are quite interactive."
  • "It would be nice if the interface were more user-friendly, with, for example, a minimal number of tabs to navigate."

What is most valuable?

I think that the overall experience with this solution is good, but in particular, I think that the dashboards are quite interactive.

What needs improvement?

For somebody who is new and just starting with this product, they find it really tough. The software is quite big. It would be nice if the interface were more user-friendly, with, for example, a minimal number of tabs to navigate.

A walkthrough that shows everything a normal user might do would be very helpful.

I would like to see improvements on the Active Channel side of this solution.

For how long have I used the solution?

Between one and two years.

What do I think about the stability of the solution?

The software itself seems to be stable, as we have not actually experienced any bugs. The connection depends on the network side, but overall it seems to be working fine.

What do I think about the scalability of the solution?

This solution would be more scalable if the interface were more user-friendly. There are rules and alerts, and the user has to have the proper knowledge of all of these things. With a walk-through, I think that it would be quite easy to scale.

We have two people using this solution, and we perform monitoring on a daily basis. In our environment, adding users is quite rare. 

How are customer service and technical support?

We did have a couple of problems recently where one of the modules was not communicating well. In terms of support, I think that they are quite good.

Which solution did I use previously and why did I switch?

This is the first solution that we have used for monitoring.

How was the initial setup?

I was not involved in the initial setup of this solution.

What other advice do I have?

This is a really good solution and I would recommend it. If you know how to work it, and how to configure it properly, then it can give you lots and lots of information. On the other hand, it provides so much detail that people can miss things. If the interface and reports were minimized and consolidated then it would be better.

I would rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Wessam Altoumi - PeerSpot reviewer
Chief Commercial Officer at Yamamah Information Technology & Communication Systems LLC
Real User
Top 5
Easy to manage for anyone, simple cyber security reports, and good support
Pros and Cons
  • "The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided."
  • "ArcSight ESM could improve the alerts for the storage capacities or actions."

What is our primary use case?

ArcSight ESM is used as a security information and event management (SIEM) solution. It has been used in banks.

What is most valuable?

The most valuable features of ArcSight ESM are the dashboards, ease of management for anyone, and simple for teams to provide reports related to cyber security. There are a lot of good features that are provided.

What needs improvement?

ArcSight ESM could improve the alerts for the storage capacities or actions.

For how long have I used the solution?

I have been using ArcSight Enterprise Security Manager (ESM) for approximately six years.

What do I think about the stability of the solution?

ArcSight ESM is stable.

What do I think about the scalability of the solution?

The scalability of ArcSight ESM is very good.

On the client's bank site, there are approximately 1,500 users using the solution.

How are customer service and support?

The support for ArcSight ESM has been very good.

How was the initial setup?

The deployment of ArcSight ESM is easy.

What about the implementation team?

We have approximately six people from our information security department managing ArcSight ESM. The deployment was done by four engineers.

What's my experience with pricing, setup cost, and licensing?

ArcSight ESM is an affordable solution, it cost approximately $200,000 for three years. This price was at a substantial discount.

Which other solutions did I evaluate?

We have evaluated IBM QRadar before choosing ArcSight ESM.

What other advice do I have?

My advice to others is once they evaluate ArcSight ESM they will love it.

I rate ArcSight ESM an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Soc Cybersecurity Analyst at VaporVM
Real User
Top 20
Provides more granular data compared to solutions like Azure or Splunk
Pros and Cons
  • "We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities."
  • "We have pricing issues. ArcSight ESM may not be the most user-friendly option, and its interface is quite traditional. However, despite these aspects, we find it a good cybersecurity solution. It needs to improve the dashboards, documentation, and support as well."

What is our primary use case?

We use the product for everything. It serves as our company's management platform, handling our tech needs, block systems, alerts, custom rules, triggered events, analytics, investigations, incident closures, case creations, whitelists, and various other tasks.

What is most valuable?

We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities.

It provides more granular data compared to solutions like Azure or Splunk. While ArcSight ESM may be considered less user-friendly, it offers a high level of customization, allowing for configuration and adaptation to specific use cases, especially regarding alerting and incident response.

Its integrations are working well. Though I haven't used the solution for an extended period, it seems highly customizable. This level of customization is not commonly found in many solutions. While solutions like Kubernetes offer a variety of apps through app extensions, it allows users to build their features to a considerable extent.

What needs improvement?

We have pricing issues. ArcSight ESM may not be the most user-friendly option, and its interface is quite traditional. However, despite these aspects, we find it a good cybersecurity solution. It needs to improve the dashboards, documentation, and support as well.

The documentation and community support for ArcSight ESM is not as strong as other solutions. Finding resources and analysts who have experience with ArcSight can be challenging. The solution is less user-friendly than alternatives like Splunk, QRadar, or Sentinel. The technical nature of ArcSight may make analysts hesitant to dive into it, contributing to a steeper learning curve.

For how long have I used the solution?

I have been using the product for two months. 

What do I think about the stability of the solution?

During the pandemic, there were challenges related to stability, particularly with the discrepancy in events being pulled in. The issue was attributed to connectors, and there were problems with certificates that needed updating. As a result, events were regularly stopped by these connectors. I rate the tool's stability a seven out of ten. 

What do I think about the scalability of the solution?

The solution is scalable. My company has 20 users. 

How are customer service and support?

I haven't contacted the tool's technical support yet. 

What other advice do I have?

I would recommend ArcSight ESM to others depending on the organization's size and specific requirements. For larger organizations, I might not recommend it, but for SMEs, it could be a suitable choice. If it meets your organization's specific use cases and requirements, and if you can ensure that you have resources trained to work with it, then it could be a suitable choice.

I rate the overall product a seven out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
it_user410400 - PeerSpot reviewer
Senior Cyber Security Analyst at a tech services company with 10,001+ employees
Consultant
It allows for easy log analysis as well as correlation and alerting.

What is most valuable?

  • Logger
  • Command Center

How has it helped my organization?

The ArcSight ESM allows for easy log analysis as well as correlation and alerting. Logger is an indexed database which allows for faster, historical searching. The versatility to use SQL queries is helpful.

What needs improvement?

There are some limitations on the functionality of Rules that I would like to see expanded. I would like to see some better support options in the ArcSight community for HP Protect. Unless someone in your organization is an ArcSight SME, you are going to have a difficult time getting answers.

For how long have I used the solution?

I've used it for two years.

What was my experience with deployment of the solution?

There were no issues with the deployment.

What do I think about the stability of the solution?

We've not had any issues with the stability.

What do I think about the scalability of the solution?

We've had no issues scaling it for our needs.

How are customer service and technical support?

I would give it 3/10. A lot of the support is community based. That strategy can work, but the answers are sometimes incomplete, incorrect, and can take a long time to get.

Which solution did I use previously and why did I switch?

I have used QRadar and Splunk. Both have great functionality that make them easy to use, but ArcSight has a very consistent layout and their logic is easy to figure out.

How was the initial setup?

I was not involved in the setup.

What's my experience with pricing, setup cost, and licensing?

I'm not involved in pricing or licensing.

What other advice do I have?

It's a well rounded product especially with the addition of Logger and Command Center. I felt it was easy to understand and use right from the start. There are some companies that do not take advantage of everything ArcSight can offer. A problem I think ArcSight can fix with better support alternatives.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user409212 - PeerSpot reviewer
Cyber Security HP Arcsight Dev Ops Lead Developer with 10,001+ employees
Real User
The CORR engine and ability to build complex correlations from simple 'building blocks' are the most valuable features for us.

What is most valuable?

The real-time correlation (CORR) engine and ability to build complex correlations from simple 'building blocks', provided the base 'building blocks' are well throughout in the first place, are the most valuable features for us.

How has it helped my organization?

The ways in which it's improved our organization are too numerous to mention. But you have to have good, steady resources and well worked-out use cases. ArcSight can report on many things and save on repetitious daliy monitoring.

What needs improvement?

There's a lot of improvements that need to be made, too many to mention all of them, but some improvements with the Con App would be a good start.

For how long have I used the solution?

We've used it for over eight years.

What was my experience with deployment of the solution?

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

What do I think about the stability of the solution?

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

What do I think about the scalability of the solution?

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

How are customer service and technical support?

With HP themselves, they need a lot of pushing to get them to get seriously involved with issues, given that they are paid a lot of money to provide support and deliver top SLAs.

Which solution did I use previously and why did I switch?

We mainly use HP ArcSight, but also Splunk. I didn't have a say in making the choices.

How was the initial setup?

The initial setup was fairly straightforward, but the overall architecture planning needs seasoned professionals who understand what ArcSight is and how it needs to be deployed.

What about the implementation team?

The installation had already been implemented by an HP subsidiary who were fairly good when performing the installation. Despite that, they did a poor job of implementing the hardware.

What's my experience with pricing, setup cost, and licensing?

The HP products are expensive.

What other advice do I have?

It's a fantastic product and highly configurable, but it needs nothing less than a seasoned cyber security professional with serious engineering expertise and a real desire to provide meaningful use cases. Anyone that says ArcSight is 'fire and forget' should not be allowed to work in cyber security!

If you want Arcsight implemented correctly, start by sizing your organization, and looking at data flows and the available data streams. Be mindful of regulatory and compliance reporting, Risk and Legal as well, as you may need to factor in any and all of these when working with enterprise solutions.

Disclosure: My company has a business relationship with this vendor other than being a customer: We have a business relationship in place with HP.
PeerSpot user
Mdr of Presales & Customer Success Head at a financial services firm with 1-10 employees
Real User
Top 20
A robust and scalable solution that is good for correlation
Pros and Cons
  • "The tool is good for correlation and aggregation. We use it as a collection platform."
  • "The tool should improve its UI. It also should make data more searchable."

What is our primary use case?

The tool is good for correlation and aggregation. We use it as a collection platform. 

What needs improvement?

The tool should improve its UI. It also should make data more searchable. 

For how long have I used the solution?

I have been working with the tool for three to four years. 

What do I think about the stability of the solution?

The tool is stable. 

What do I think about the scalability of the solution?

The tool is scalable. 

Which solution did I use previously and why did I switch?

I have worked with QRadar and McAfee. 

How was the initial setup?

The deployment process is similar to the hosting of other applications. The tool's deployment depends on the environment architecture, and your requirements. 

What other advice do I have?

I would rate the solution a seven out of ten. The product is very robust. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Subhadip Pakrashi - PeerSpot reviewer
CEO at Kapstone Technological Services LLP
Real User
Top 5Leaderboard
A stable and scalable enterprise data security manager, but the initial setup could be more straightforward
Pros and Cons
  • "ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product."
  • "The initial setup could be more straightforward."

What is our primary use case?

I'm an administrator, and I implement ArcSight Enterprise Security Manager (ESM). I use ArcSight SIEM and have all the security information, events, logins, and security logs. We compile all the information so we can file and stop it from happening or provide an alert. 

What is most valuable?

ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product.

What needs improvement?

The initial setup could be more straightforward. 

What do I think about the stability of the solution?

ArcSight Enterprise Security Manager (ESM) is a stable solution. However, it depends on how well it's deployed in the customer's location. 

Because SIEM doesn't have much to do with blocking the traffic, even if it doesn't get deployed well, it doesn't matter to the customer because the work is going on, and the traffic is flowing in. 

It's just that the correlation will never happen. The security post of the company goes for all; that's the only problem. Apart from that, there would be no problem with the operations website. 

What do I think about the scalability of the solution?

ArcSight Enterprise Security Manager (ESM) is scalable, but you must size it well.

How are customer service and support?

ArcSight technical support is a bit better than the QRadar.

How was the initial setup?

The initial setup is complex. In general, it takes about three months to implement this solution.

What other advice do I have?

I will only make recommendations based on the customer's requirements and environment.

On a scale from one to ten, I would give ArcSight Enterprise Security Manager (ESM) a seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.