Try our new research platform with insights from 80,000+ expert users

ArcSight Analytics vs Gurucul UEBA comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Analytics
Ranking in User Entity Behavior Analytics (UEBA)
13th
Average Rating
7.0
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Gurucul UEBA
Ranking in User Entity Behavior Analytics (UEBA)
6th
Average Rating
7.2
Reviews Sentiment
6.7
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the User Entity Behavior Analytics (UEBA) category, the mindshare of ArcSight Analytics is 1.2%, down from 1.7% compared to the previous year. The mindshare of Gurucul UEBA is 4.0%, up from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Syed Ubaid Ali Jafri - PeerSpot reviewer
It has improved our system and network policy monitoring
They should improve on the following: * Timely resolution of issues and proper support once a ticket has been generated. * Systems appearing on the network which are not part of the domain controller. These should be monitored. * Inactive connections from servers, which are upgraded or downgraded within a VM, should be automatically revoked. * Logger monitoring should be separated from ESM monitoring. * Ability to integrate with cloud-based applications and monitor cloud-based events. * Ability to log and notify tailored rules via SMS/email. * Provide more ArcSight training and workshops.
Ravi Shekharan - PeerSpot reviewer
Helped reduce our operational costs and increase our efficiency, but it can be more user-friendly
Regarding the prioritization of threats, Gurucul UEBA needs to enhance its alert severity assignment process within the system. This is one area where Gurucul UEBA could improve. Additionally, it would be beneficial if the tool itself could provide or assign user-based or asset-based CI ratings to allow for a more accurate assessment of alert severity. In our environment, we forward these logs, events, and alerts to SIM, where the CI rating is already present. Therefore, if we need to closely investigate a UEBA case directly, it becomes problematic. Gurucul UEBA should proactively incorporate asset-based or user-based CI severity into its design. Gurucul UEBA needs to be more user-friendly. I would like Gurucul UEBA to be able to integrate with legacy-based identity systems and systems that are performing network-based access control. This would require additional integration and playbook models.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is easy to implement."
"This solution makes it easy to create use cases, and it is easy to move queries from use cases to the report to the dashboard."
"The ability to correlate different logs is the solution's most valuable feature."
"The two most valuable features of this solution are its stability and scalability."
"The features I have found most valuable are it capabilities for behavioral analytics and anomaly detection."
"ArcSight Analytics has improved our system and network policy monitoring."
"Allows multiple integrations with multiple systems in a stable and flexible fashion."
"The most valuable features are that you get lots of connectors, which make it easy to log in to my ASM, and lots of prebuilt roles from the company."
"The most valuable feature of Gurucul is the ability to customize and it is on the Hadoop platform that has a lot of flexibility."
"If you are genuinely looking for a UEBA solution, you should choose Gurucul confidently if your need is strictly UEBA."
"The reporting feature was the key differentiator. I also liked the ability to create dynamic rules in the environment."
"I appreciate the comprehensive categorization of devices based on their intended use, such as those for DNS."
 

Cons

"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."
"I would like to see integration with automation products, such as Phantom Automation."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"The customer service could be improved, and additional integrations with other APIs could be added."
"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"I would like to see orchestration."
"ArcSight's features that can be improved include anything related to its visualization capabilities and user friendliness."
"Technical support is good but can improve. I would rate it six to seven out of ten. The main issue is response time, which can take three to four hours even for simple queries."
"It could be more stable."
"Regarding the prioritization of threats, Gurucul UEBA needs to enhance its alert severity assignment process within the system."
"Gurucul can improve on the online documentation. They should educate the end users more to allow them to do everything themselves."
 

Pricing and Cost Advice

"This solution is expensive."
"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"The price is fair. In fact, I believe it was on the cheaper side when compared to the competition."
"The price of Gurucul is competitive."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
19%
Financial Services Firm
10%
Healthcare Company
7%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about ArcSight Analytics?
ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
What is your experience regarding pricing and costs for ArcSight Analytics?
My customers pay a yearly licensing fee for ArcSight Analytics.
What do you like most about Gurucul?
I appreciate the comprehensive categorization of devices based on their intended use, such as those for DNS.
What needs improvement with Gurucul?
For improvement, I have requested three enhancement tickets, which are already lodged with the Gurucul support team. The first request is to add a visualization option in reports for charts or grap...
What is your primary use case for Gurucul?
Regarding the use cases, I have created many use cases in Gurucul UEBA. It's easy to create use cases based on behaviors.
 

Comparisons

No data available
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
No data available
 

Overview

 

Sample Customers

Information Not Available
Global semi-conductor company
Find out what your peers are saying about ArcSight Analytics vs. Gurucul UEBA and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.