- Log collecting
- Big Data analytics
- Security analytics
QA Consultant / Security Testing Professional at a tech company with 501-1,000 employees
Its automated functions made it easier so we could concentrate more on real issues instead of standard log collecting and alerting issues.
Pros and Cons
- "This product was used to help us get PCI compliant, and its automated functions made it easier so we could concentrate more on real issues instead of standard log collecting and alerting issues."
- "Overall, it is a good system for what we use it for, but some licensing parts are really annoying."
What is most valuable?
How has it helped my organization?
This product was used to help us get PCI compliant. Its automated functions made it easier so we could concentrate more on real issues instead of standard log collecting and alerting issues.
What needs improvement?
With the connectors, there were some legacy devices that had some problems since support was dropped for those.
For how long have I used the solution?
We've been using it for four years alongside ArcSight Express.
Buyer's Guide
ArcSight Logger
June 2026
Learn what your peers think about ArcSight Logger. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,270 professionals have used our research since 2012.
What was my experience with deployment of the solution?
We had no issues with the deployment.
What do I think about the stability of the solution?
The stability of the system was good except when we had a DDoS attack, when we lost some functions for a short time.
What do I think about the scalability of the solution?
Scalability is good if your need is high enough, but for smaller cases it isn't so good.
How are customer service and support?
Customer Service:
Customer service was very helpful.
Technical Support:Technical support is at a good level.
Which solution did I use previously and why did I switch?
We used an older version that was going to be replaced.
How was the initial setup?
The initial setup was complex, but that was mainly because of customer security reasons.
What about the implementation team?
We used a subcontractor for the first part of the installation, and finished it off in-house.
What's my experience with pricing, setup cost, and licensing?
We had some big licensing issues when there was a DDoS attack. The attack caused a huge amount of extra activity, so it would be nice to have an "emergency level" of licenses when there are these kinds of issues.
I would recommend, from a security point of view, calculating licensing limits according to what incidents could happen and then get 5-10% more licences on top of that.
Which other solutions did I evaluate?
We did an evaluation of major vendors and HP was fastest for us to get in and use.
What other advice do I have?
Overall, it is a good system for what we use it for, but some licensing parts are really annoying.
As always, a pre-calculation and pre-planning will help a lot, and compare it to three to four other vendors. Changes on the system that is running are a bit harder to do., in our case this, of course, might be an issue of our customers strict security requirements.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Architecture Senior Specialist at a comms service provider with 1,001-5,000 employees
We like the compression rates and scalability of the smart connectors.
Pros and Cons
- "The most important thing is the scalability of the product and its ease of use."
- "The only drawback is that without ESM, you are limited."
What is most valuable?
- Scalability of the smart connectors
- Ease of storing billions of events without special storage needs
- Great compression rates
How has it helped my organization?
First of all, the collection of a mass of events is a challenge for enterprise companies. You need a great deal of storage and how you collect them is an issue. The smart connectors and great compression rates of ArcSight helped us a lot.
The other thing is to be able to be competitive as you need to show that you need a logging system that complies to the laws in your country and company policy so that you can continue to do your business. With ArcSight, we easily pass the requirements of the external audits our clients require.
What needs improvement?
I would say that the consolidation should be done only by using ArcSight. We need to use the ESM module to create complex rules and reports as we can only do limited reports with ArcSight.
For how long have I used the solution?
We've used it for about two years.
What was my experience with deployment of the solution?
The main problem is how to collect logs from various resources.
What do I think about the stability of the solution?
The smart connectors are very stable.
What do I think about the scalability of the solution?
We've had no issues scaling it for our needs.
How are customer service and technical support?
Since we work with partners, I can't say too much. However, for every company on this planet there is always room for improvement in the level of support.
Which solution did I use previously and why did I switch?
This was the first solution we've used, and I believe it will be the last solution we need.
How was the initial setup?
We used an appliance, so the setup was very easy. But I must say that even if you use an open server, it is not complex to deploy this product.
What about the implementation team?
We worked with a partner for the implementation.
What was our ROI?
It is really hard to measure ROI financially, but there are some important things to say. First of all, since it's easy to use, our operational time has decreased so that we as technical staff have much more time to spend on other issues. Since we collect all of the logs, we can investigate fraud and find their sources. We can also find the causes of system outages.
What other advice do I have?
It works fast and you can collect just about everything. The only drawback is that without ESM, you are limited. The most important thing is the scalability of the product and its ease of use. Companies like us need some specific connectors, and smart connectors give us a very scalable solution. Also, even though we have billions of events, it is really fast in finding the logs we need. That makes this solution amazing.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free ArcSight Logger Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Log ManagementPopular Comparisons
Splunk Enterprise Security
Dynatrace
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Grafana Loki
Graylog Enterprise
USM Anywhere
Elastic Stack
Sumo Logic Security
Fortinet FortiAnalyzer
NetWitness Platform
Buyer's Guide
Download our free ArcSight Logger Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- When evaluating Log Management tools and software, what aspect do you think is the most important to look for?
- Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
- Which Windows event log monitoring tool do you recommend?
- What is the difference between log management and SIEM?
- Splunk vs. Elastic Stack
- How can Cloudtrail logs be used effectively to improve log monitoring?
- Why hot data and cold data differences in SIEM solutions are not discussed sufficiently?
- When evaluating Log Management solutions, what aspect do you think is the most important to look for?
- When evaluating Log Management solutions, what aspects do you think are the most important to look for?
- Why are Log Management tools important for companies?















