Try our new research platform with insights from 80,000+ expert users

ArcSight Analytics vs Gurucul UEBA vs Proofpoint Insider Threat Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of October 2025, in the User Entity Behavior Analytics (UEBA) category, the mindshare of ArcSight Analytics is 1.4%, up from 1.2% compared to the previous year. The mindshare of Gurucul UEBA is 2.8%, up from 2.8% compared to the previous year. The mindshare of Proofpoint Insider Threat Management is 5.6%, up from 3.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
Gurucul UEBA2.8%
Proofpoint Insider Threat Management5.6%
ArcSight Analytics1.4%
Other90.2%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Subhadip Pakrashi - PeerSpot reviewer
A scalable solution that provides a deeper insight and threat analysis about the network
ArcSight Analytics is used to get a deeper insight and threat analysis about the network. The solution's threat analysis gives a good view of the network. We can then compare those vulnerabilities and CVS scores worldwide and get a good understanding of how likely the network is to be hit. The kind of report ArcSight Analytics gives is really good. ArcSight Analytics is a very scalable solution that is easy to deploy.
Ravi Shekharan - PeerSpot reviewer
Helped reduce our operational costs and increase our efficiency, but it can be more user-friendly
Regarding the prioritization of threats, Gurucul UEBA needs to enhance its alert severity assignment process within the system. This is one area where Gurucul UEBA could improve. Additionally, it would be beneficial if the tool itself could provide or assign user-based or asset-based CI ratings to allow for a more accurate assessment of alert severity. In our environment, we forward these logs, events, and alerts to SIM, where the CI rating is already present. Therefore, if we need to closely investigate a UEBA case directly, it becomes problematic. Gurucul UEBA should proactively incorporate asset-based or user-based CI severity into its design. Gurucul UEBA needs to be more user-friendly. I would like Gurucul UEBA to be able to integrate with legacy-based identity systems and systems that are performing network-based access control. This would require additional integration and playbook models.
reviewer1271289 - PeerSpot reviewer
Good value, easy to use, and easy to deploy
In terms of what can be improved, that is a question I think the end users can tell you better. I'm not the end-user for this system. However, I can say that it needs to be more scalable. I think they already have a good value proposition in terms of being a hybrid model, and the reporting is okay, as well. It could have better integration with other SIEMs, but this integration has to come from the SIEM side, not ObserveIT.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"ArcSight Analytics is used to get a deeper insight and threat analysis about the network."
"The correlation engine is good."
"Less resource consumption in terms of memory and processing."
"The features I have found most valuable are it capabilities for behavioral analytics and anomaly detection."
"The ability to correlate different logs is the solution's most valuable feature."
"The data collection and the integration with different products are valuable features."
"The most valuable feature is the log monitoring."
"One of the most valuable features is the alerts."
"The reporting feature was the key differentiator. I also liked the ability to create dynamic rules in the environment."
"The most valuable feature of Gurucul is the ability to customize and it is on the Hadoop platform that has a lot of flexibility."
"I appreciate the comprehensive categorization of devices based on their intended use, such as those for DNS."
"If you are genuinely looking for a UEBA solution, you should choose Gurucul confidently if your need is strictly UEBA."
"ObserveIT is small, easy to use, easy to deploy, and is not complicated, so it's more generally suited for only SMBs. It's a good value with a cheaper price."
 

Cons

"I would like to see orchestration."
"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."
"Network integration is very crucial, and you need to have the knowledge to get it done."
"The interactive dashboard is complicated and you need to have training in order to use it, so I think that it could be made easier to use."
"ArcSight's features that can be improved include anything related to its visualization capabilities and user friendliness."
"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"Gurucul can improve on the online documentation. They should educate the end users more to allow them to do everything themselves."
"It could be more stable."
"Regarding the prioritization of threats, Gurucul UEBA needs to enhance its alert severity assignment process within the system."
"Technical support is good but can improve. I would rate it six to seven out of ten. The main issue is response time, which can take three to four hours even for simple queries."
"ObserveIT is not scalable and it's not for the medium to large corporations. It's for the smaller environments. For the larger corporations, we have other scalable solutions."
 

Pricing and Cost Advice

"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"This solution is expensive."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"The price is fair. In fact, I believe it was on the cheaper side when compared to the competition."
"The price of Gurucul is competitive."
Information not available
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
871,358 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
18%
Financial Services Firm
12%
Healthcare Company
7%
Photography Company
6%
Financial Services Firm
12%
Manufacturing Company
10%
Media Company
8%
Performing Arts
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
No data available
No data available
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about ArcSight Analytics?
ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
What is your experience regarding pricing and costs for ArcSight Analytics?
My customers pay a yearly licensing fee for ArcSight Analytics.
What do you like most about Gurucul?
I appreciate the comprehensive categorization of devices based on their intended use, such as those for DNS.
What needs improvement with Gurucul?
For improvement, I have requested three enhancement tickets, which are already lodged with the Gurucul support team. ...
What is your primary use case for Gurucul?
Regarding the use cases, I have created many use cases in Gurucul UEBA. It's easy to create use cases based on behavi...
Looking for recommendations and a pros/cons template for software to detect insider threats
In addition to responsesfrom Xavier Suriol and reviewer1324719, also consider ObserveIT from Proofpoint.
Looking for recommendations and a pros/cons template for software to detect insider threats
Hello All,I hope you had a merry Christmas.In this case it is as simple as it is.Just take Proofpoint ObserveIT - ma...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
No data available
ObserveIT
 

Overview

 

Sample Customers

Information Not Available
Global semi-conductor company
Coca Cola, Allianz, Premiere League, Xerox, AIG, Cigna, Starbucks, Revlon, Toshiba, Nissan and more.
Find out what your peers are saying about IBM, Exabeam, Cynet and others in User Entity Behavior Analytics (UEBA). Updated: October 2025.
871,358 professionals have used our research since 2012.