No more typing reviews! Try our Samantha, our new voice AI agent.

ArcSight Logger vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Logger
Ranking in Log Management
39th
Average Rating
7.6
Reviews Sentiment
5.8
Number of Reviews
32
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Log Management
38th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Security Information and Event Management (SIEM) (39th)
 

Mindshare comparison

As of May 2026, in the Log Management category, the mindshare of ArcSight Logger is 0.9%, up from 0.8% compared to the previous year. The mindshare of NetWitness Platform is 1.0%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Mindshare Distribution
ProductMindshare (%)
NetWitness Platform1.0%
ArcSight Logger0.9%
Other98.1%
Log Management
 

Featured Reviews

MA
Sr. Cybersecurity Consultant IT/OT at EJADA
Compliance and cost-effectiveness have improved while critical infrastructure security adapts to evolving needs
ArcSight Logger fulfills compliance requirements and passes audit requirements. It is one of the Aramco standards requirements and is recommended by Aramco for any implementation. Aramco, SABIC, water companies, and electricity companies are critical infrastructure with air-gapped networks. In an air-gapped network, there is no communication going out from that network area to the outside world, even to the corporate network. ArcSight Logger is installed on minimal resources with minimal requirements. There are not many upgrades or new features that come up frequently, though they do occur occasionally.
reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We check a lot of logs in ArcSight Logger because we're running a massive database platform."
"This is a solution that is straightforward and easy to use."
"It's a robust, mature product and you can do some really complex operations and analytics."
"It's a robust, mature product and you can do some really complex operations and analytics."
"ArcSight has improved incident response from days to minutes."
"ArcSight provides the basic information that we want."
"We haven't had any crashes or bugs. It is stable."
"ArcSight Logger is very stable and useful for customers."
"The most valuable feature is the security that it provides."
"Their customer service is excellent, one of the best."
"This solution has a very good dashboard with a separate tab for incidents and alerts."
"Setting up NetWitness is straightforward. There are multiple connectors, including standard and specialized connectors. One purpose of the connectors is the enhanced capability integrate the custom applications. NetWitness comes with E6 appliances and application images that we use for the initial configurations and for the OS stack information. From there, you can consider the correlation rules, integrate the different log sources, and easily create correlation rules and backlog reports."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The newer 11.5 version that my team is using has found it to have good mapping."
"Overall, it is easy to implement."
"Possibility to investigate incidents based on logs and raw packets, such as extracting files sent over the network"
 

Cons

"The solution must provide readymade connectors for different applications."
"The solution could be improved in maintenance settings."
"The speed of Logger indexing and searching for certain bugs for some queries that we provide could be improved. It can handle a huge number of logs but it can be improved."
"I had some latency issues for two months. I had to increase our storage capacity significantly to reduce the latency."
"It would be better if the product is cheaper."
"ArcSight Logger doesn't have features for user or customer behavior analysis."
"The solution should make it possible to integrate network analysis features."
"You have limited reporting capabilities and I wouldn't choose ArcSight Logger for this purpose."
"RSA NetWitness Logs and Packets is far behind the competition."
"The solution is pretty complex to set up. Comparatively, I have worked on IBM QRadar and Splunk; they are much easier to set up."
"The implementation needs assistance."
"Technical support could be improved."
"The threat detection capability and centralizing and upgrading capability need to be improved. The threat alert capability needs to be improved as well because there is some lag time at present. They need to work on their database search too."
"The solution should have more integration capabilities with different platforms."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"The initial setup is very complex and should be simplified."
 

Pricing and Cost Advice

"Pricing is reasonable compared to similar tools on the market. They offer perpetual licenses."
"It's not cheap at all as it's a big product and has been in the market for quite some time now."
"I would rate the product a seven out of ten since it's an enterprise product."
"We have a lifetime license, so we don't pay a monthly fee."
"The pricing is quite harsh."
"ArcSight Logger is very expensive compared to their competitors, but when we talk to the customer and explain what the features are and how we can scale, they understand. Still, ArcSight is more expensive than the competition."
"I rate the product’s pricing a seven out of ten, where one is inexpensive, and ten is expensive."
"ArcSight is an expensive solution."
"It provides tools to assist in selecting the appropriate license and usage scenarios."
"The licenses are good but the cost is very expensive."
"Our license is for one year."
"It is cheap."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
893,438 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
8%
Marketing Services Firm
7%
Manufacturing Company
7%
Financial Services Firm
11%
Comms Service Provider
9%
Construction Company
8%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise9
Large Enterprise17
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What do you like most about ArcSight Logger?
We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
What is your experience regarding pricing and costs for ArcSight Logger?
The pricing isn't the problem. We have a lifetime license, so we don't pay a monthly fee.
What needs improvement with ArcSight Logger?
This decision is made by higher management as they don't want to have multiple solutions for one solution. ArcSight Logger themselves don't provide good support, but companies such as ours provide ...
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
 

Also Known As

Micro Focus Arcsight Logger, HPE Arcsight Logger
RSA Security Analytics
 

Overview

 

Sample Customers

China Merchants Bank, Bank AlJazira, Banca Intesa
Los Angeles World Airports, Reply
Find out what your peers are saying about ArcSight Logger vs. NetWitness Platform and other solutions. Updated: April 2026.
893,438 professionals have used our research since 2012.