Presales Manager at a tech services company with 51-200 employees
Real User
Top 10
The flex connector lets you develop new connectors to integrate homebrew solutions
Pros and Cons
  • "The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector."
  • "When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets."

What is our primary use case?

We use ArcSight primarily to provide logs for the incident response team and cyber security analysts to evaluate everything happening in the network. 

What is most valuable?

The most important feature is ArcSight's event correlation capabilities. It's powerful and easy. I also like the flex connector capability. It's easy to develop a new connector that isn't fully supported out of the box. For example, say you created a solution internally that's completely different, and it's not unsupported by the solution. You can write your own connector using the flex connector.

What needs improvement?

When we need to consume old events, we have to wait for a long time. ArcSight should improve the database capability to reply to queries faster. It would also be interesting if they implemented network visibility. For example, they could add a feature like NetWitness with a model just for looking through the packets.

What other advice do I have?

I rate ArcSight Enterprise Security Manager nine out of 10. 

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior IT security Administrator and solution at scada.ci
Real User
Scalable, reliable, and good support
Pros and Cons
  • "The stability of ArcSight Enterprise Security Manager is good."
  • "The user interface of ArcSight Enterprise Security Manager could improve. It is not very good. Additionally, they could integrate the web interface better."

What is our primary use case?

I use ArcSight Enterprise Security Manager to make some letters, queries, administration of the smart collectors, and logger for deporting.

What needs improvement?

The user interface of ArcSight Enterprise Security Manager could improve. It is not very good. Additionally, they could integrate the web interface better.

For how long have I used the solution?

I have been using ArcSight Enterprise Security Manager(ESM) for approximately five years.

What do I think about the stability of the solution?

The stability of ArcSight Enterprise Security Manager is good.

What do I think about the scalability of the solution?

 ArcSight Enterprise Security Manager has good scalability.

We have three administrators and seven analysts using this solution in my organization.

How are customer service and support?

The support from ArcSight Enterprise Security Manager is very good. However, we have some questions that have not been resolved.

I rate the technical support from ArcSight Enterprise Security Manager a four out of five.

How was the initial setup?

The initial setup is difficult because you need to have some extra knowledge to complete it.

What's my experience with pricing, setup cost, and licensing?

We have a license to use this solution. The price of ArcSight Enterprise Security Manager is expensive.

What other advice do I have?

My advice to others is for them to have some training before they use the solution.

I rate ArcSight Enterprise Security Manager a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,334 professionals have used our research since 2012.
Works at NOOSC Global
Real User
Helpful for detecting malware and intrusions, but needs support for devices that are absent of log files
Pros and Cons
  • "For the typical malware or intrusion, this solution assists us by identifying the symptoms based on network traffic from the application servers."
  • "The weakness in this system comes about because, with so many different logs, it is possible that the security analyst will lose information."

What is our primary use case?

We have a customer who is using this solution for information security monitoring.

How has it helped my organization?

For the typical malware or intrusion, this solution assists us by identifying the symptoms based on network traffic from the application servers. We are then able to prevent others from accessing critical information.

What is most valuable?

I really like the dashboard.

What needs improvement?

One of the problems for the security center is that there are many logs that need to be retrieved from a variety of network devices. The weakness in this system comes about because, with so many different logs, it is possible that the security analyst will lose information. I would like to have better support for wide-area data analytics.

Ideally, I would like to see ArcSight have the ability to consume raw information, or raw data, without being dependent on a log file.

For how long have I used the solution?

Between five and six years.

What do I think about the scalability of the solution?

There are more than six thousand users. However, because it is a log-based system, the scalability is limited. As such, our customer is looking for a solution that can scale better as the number of users and the number of devices in the infrastructure increases.

How are customer service and technical support?

There is not much in terms of support that is available for this solution. There are not many people with the competency for visualization and creating use cases.

How was the initial setup?

The initial setup of this solution is pretty complex. Once this installation is complete, we need to set up the use cases.

Deployment for this solution took between three and six months and was performed with four to five people.

What about the implementation team?

A reseller assisted our customer with the deployment.

What's my experience with pricing, setup cost, and licensing?

The cost of the solution is not very high, although hiring a qualified analyst to work with the product is expensive.

What other advice do I have?

In summary, this solution requires a dedicated person that has specific competency in this product. It is not a plug and play product that allows you to simply focus on the analytics. It is not easy for an amateur.

The suitability of this solution depends on the complexity of the system. If the organization is very large, for example nationwide, then a log-based approach such as this one will be very difficult to implement. 

Obviously, if the device does not generate a log then it is not supported by this solution. Our client has successfully deployed it for use with several devices, including firewalls and IPS, but they have no support for some in-house applications.

I would rate this solution a five out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user142611 - PeerSpot reviewer
Information Security Professional at a financial services firm with 1,001-5,000 employees
Real User
The response is good for Read/Write functions but I've encountered other minor issues. Better than it's competitors.

Valuable Features

Correlation Rules, Dashboards, Active Channels, Active Lists and many more. All these features make this product better than it's competitors.

Improvements to My Organization

ArcSight functions to integrate all network & security logs. It's very easy to use and thus real time monitoring has become easy by implementing active channel with all correlated alerts. SOC can monitor these correlated alerts and take action on them.

Room for Improvement

ArcSight uses Oracle DB, which is a bit slow for read/write functions and the main downside to this product. Recently, HP came up with a custom DB for ArcSight 6.0 which they are calling CORR engine. With these Read/Write functions, response is good but unfortunately I've encountered many other minor issues which have room for improvement.

Use of Solution

I've been using it for the last 6 years.

Deployment Issues

Yes, minor issues were encountered and resolved in a timely manner by HP support.

Stability Issues

Yes, Read/Write functions to DB is the main concern and this slows down the events processing.

Scalability Issues

I don't think there are any issues with Scalability.

Customer Service and Technical Support

Customer Service: GoodTechnical Support: Pretty good and timely.

Initial Setup

Slightly complex, but manageable.

Implementation Team

With the help of a vendor team. They are really helpful and cooperative.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user597606 - PeerSpot reviewer
Associate Manager at a tech services company with 10,001+ employees
Real User
Dashboards and channels provide real-time alerts. Correlation becomes slow if we have more than a certain number of rules.

What is most valuable?

Creating dashboards and real-time channels for real-time monitoring: This feature gives real-time alerts for the monitoring team to act upon. In certain cases, we can also create real-time email alerts for relevant teams for faster actions and resolutions.

How has it helped my organization?

This product has helped us and our customer for monitoring the security of different applications as well as different hardware devices. It helps in keeping an eye on each activity logged into our internal environment. This also helped us and our customer to meet the local regulatory requirement.

What needs improvement?

The correlation and storage have to be improved. The correlation works fine, if we have less amount of rules being written, but it becomes slow if we have more than 200 rules written for any correlation. This created buffer-buckets for all events flowing into the system. There are other ways in which this can be improved.

For how long have I used the solution?

For the last one year, I have been using the current version, i.e., HPE ArcSight ESM, Hardware Appliance L5600, Software Version 6.8.

Before that, I have used the earlier versions, i.e., v4.5 and v5.0 for nearly three years.

What do I think about the stability of the solution?

I have not encountered any stability issues with HPE ESM. It was stable all the time.

What do I think about the scalability of the solution?

We didn't encounter any scalability issues. We were able to scale it as and when required.

How are customer service and technical support?

The technical support needs improvement, as sometimes it takes time to get the actual response on the issue. It takes more than two days to reach a resolution as the support team needs a lot of basic information.

Which solution did I use previously and why did I switch?

I was not using any other solution previously.

How was the initial setup?

The setup was straightforward but it still needs involvement from the support team as sometimes credentials do not work.

What's my experience with pricing, setup cost, and licensing?

This is based on the requirement and budget. I would not like to comment on the pricing or licensing.

Which other solutions did I evaluate?

We looked at other solutions such as Splunk and IBM QRadar.

Disclosure: My company has a business relationship with this vendor other than being a customer: We have an alliance with HPE for their security products.
PeerSpot user
it_user409203 - PeerSpot reviewer
Security Business Analyst at a tech services company with 10,001+ employees
Consultant
It has good options for shaping data and using them in very complex rules. Performance is the product's Achilles' heel.

What is most valuable?

I think the ability to create rules more flexible than in other products (i.e. IBM QRadar) is its most valuable feature. It has good options for shaping data and using them in very complex rules.

How has it helped my organization?

It has increased our detective capabilities in the cybersecurity landscape. We're able to build SOC around it, and make it a central tool for detecting network compromises.

What needs improvement?

Performance is the product's Achilles' heel. The aggregation can't be done for a long period of time, i.e. one week. On top of that, in comparison to the competition, ArcSight works very slowly and the WebUI is not very user-friendly.

For how long have I used the solution?

We've been using it for 10 months and the program is still in the development phase.

What was my experience with deployment of the solution?

There were no issues with the deployment.

What do I think about the stability of the solution?

There have been no stability issues.

What do I think about the scalability of the solution?

We have had no issues scaling it to our needs.

How are customer service and technical support?

The level of technical support is low. I think HP should invest money to train support people. Furthermore, sometimes I feel they are overworked because they used to sending notifications about cases without closing them.

Which solution did I use previously and why did I switch?

Previously, I worked with IBM QRadar.

How was the initial setup?

SIEM in general is not straightforward. I think the initial setup was simple, but to get value from this product, you have to do something more than the initial setup.

What about the implementation team?

We did it in-house with help from the vendor's professional services. My advice is to think first where you would like to put your collectors. Assess if your network will be able to lift extra loads, assess what logging level will be required, and if log sources are capable of delivering it.

Which other solutions did I evaluate?

ArcSight was chosen by my new company management without asking me for my opinion.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Real User
Network investigation is poor but it's highly customizable

Valuable Features:

  • Powerful Correlation
  • Customization 
  • Integration capabilities

Room for Improvement:

  • Very complex install and management
  • Steep learning curve
  • Poor Network Investigation
  • Poor analytics.

Use of Solution:

Six years.

Stability Issues:

Yes, Logger, ESM and Connector ecosystem if not set up properly, lead to stability issues both in point operations as well as integrations.

Scalability Issues:

No. ArcSight is very scalable.

Customer Service:

3 out of 5.

Implementation Team:

We implemented it in-house.

ROI:

Poor as the product takes more effort to generate value. Its CAPEX cost is high too.

Other Advice:

If you really want the power and flexibility of customizing your Security monitoring and correlation, go with ArcSight, but beware of the effort involved in set up and maintenance.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head - Professional Services at a computer software company with 51-200 employees
Real User
A mature and simple to use product, but needs a cloud deployment option
Pros and Cons
  • "The product is quite mature. It's been around for a long time."
  • "The biggest requirement is that there is no cloud solution for this product yet. They need to create a cloud version. It's the biggest thing they can do to make the solution better."

What is our primary use case?

We primarily provide this solution to clients.

What is most valuable?

The simplicity of the solution is the most valuable aspect of the product.

The product is quite mature. It's been around for a long time.

The integration is easy for the most part.

What needs improvement?

Over the past two years, a lot of improvements have been happening.

The biggest requirement is that there is no cloud solution for this product yet. They need to create a cloud version. It's the biggest thing they can do to make the solution better.

The dashboard and user interface need some work. It's my understanding that they are developing better versions of those now.

For how long have I used the solution?

I've been using the solution for eight years or so. I started working on Version Five and have continued to update it from there.

What do I think about the stability of the solution?

The stability of the solution is very good. It's pretty perfect, actually. We don't have crashes. It doesn't freeze. There aren't bugs or glitches. It's completely reliable.

What do I think about the scalability of the solution?

The solution is easily scalable. If an organization needs to expand it, they most certainly can.

What we used to do traditionally, to scale, that each device throws up certain EPS and we size the solution accordingly. Once they have a cloud solution, it will be even easier to scale.

The solution works for any size of organization, from small companies to large enterprises.

How are customer service and technical support?

The solution's technical support is excellent. I'm in India, however, their support is on a global scale.

HP as an organization had one toll-free number. You plug in your requirements. However, by the time it reached the team, it became difficult as everyone was routed centrally. However, once the site was taken over by Micro Focus, we are seeing some great improvements in the support.

How was the initial setup?

The initial setup is not complex. It's very straightforward.

If you have a well-skilled technician, you probably only need a few people to handle the deployment and maintenance.

In terms of how long a deployment takes, a SIEM implementation depends on the number of devices, and which we are integrating with. The kind of dashboards and reports the customer is looking for also come into play in calculating the amount of time that will be needed. Therefore, the duration of the implementation would be purely dependent on the client's specific needs.

A standard deployment is typically four weeks. However, I've seen some deployments take as long as 12 weeks.

What about the implementation team?

We deploy the solution for our clients. We also tend to handle the maintenance for our clients as well.

Which other solutions did I evaluate?

I have some experience with Splunk and Curator.

There are a few differences. Splunk, for example, is a native cloud product. That makes it excellent for scalability. Any on-premise challenges a company might face are answered by Splunk.

In both solutions, you are able to integrate and manage other devices as well, which isn't necessarily true on Arcsight.

What other advice do I have?

We're an authorized partner. We provide this solution to our clients.

In terms of implementation, new users should make a list of the requirements they need in order to have a broad idea of what they want the solution to achieve. Once they understand their requirements, it will be easier to find a solution that will match them.

For Arcsight, users need to go in with the compliance packs. Arcsight has some additional modules called compliance packs, which can get you automatic reports. That needs to be configured pretty well. 

The biggest piece everyone needs to consider is the sizing part. It's an on-premise solution. If you are not buffering the sizing with at least about 25% additional computation and the storage space, then you're in for trouble down the line. Always go bigger than you need.

Overall, I'd rate the solution seven out of ten.

ArcSight, in the last one and a half years, have been delivering on time, in terms of a better dashboard, a better user interface, and now, with an add-on EDA. MailStore is also getting into it. We are seeing that they are catching up with what the market needs. We will have to wait and see what the new release brings. Version Eight is coming in now. They seem to be doing everything now and are committing for some great features in a future release.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.