Try our new research platform with insights from 80,000+ expert users

ArcSight Logger vs NetWitness Platform comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Logger
Ranking in Log Management
26th
Average Rating
7.6
Reviews Sentiment
5.8
Number of Reviews
32
Ranking in other categories
No ranking in other categories
NetWitness Platform
Ranking in Log Management
33rd
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Security Information and Event Management (SIEM) (30th)
 

Mindshare comparison

As of October 2025, in the Log Management category, the mindshare of ArcSight Logger is 0.7%, down from 0.9% compared to the previous year. The mindshare of NetWitness Platform is 0.4%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management Market Share Distribution
ProductMarket Share (%)
ArcSight Logger0.7%
NetWitness Platform0.4%
Other98.9%
Log Management
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
A scalable and stable solution that enables users to see all the event logs in one place
The technical support team is very slow. The support persons do not take prompt action. They take too much time to implement new changes. Even if we tell them that we are not able to get critical logs, they take almost three to four days to provide a resolution. The support is not good.
MOTASHIM Al Razi - PeerSpot reviewer
It is a stable solution, but they should make the user interface easier to understand
The solution's initial setup takes work. We have to organize multiple paths and many features. The deployment process takes less than a week. But it takes a month to complete if we want to make the solution smarter by integrating it with various devices. I rate the process as a six out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The log digestion features from threat intelligence platforms like Recorded Future or Talos are valuable."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"In terms of ArcSight Logger's most valuable feature, it is their scalability. ArcSight's real advantage is its scalability because they have two layers, including the logger layer."
"The ability to customize the solution in great detail is its most valuable features. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive."
"We haven't had any crashes or bugs. It is stable."
"We check a lot of logs in ArcSight Logger because we're running a massive database platform."
"Some of the most valuable features I really appreciate are the performance, how quick the solution is, and how easy it is to create a query."
"We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist."
"It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets."
"Offers a good wireless feature."
"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The most valuable features are the integration and ease of use."
"The newer 11.5 version that my team is using has found it to have good mapping."
"The packet capture aspect of it is a valuable feature because it is quite different from a traditional SIEM solution that only carries out investigations based on captured logs."
"The most valuable features are the packet decoder, log decoder, and concentrator."
 

Cons

"ArcSight has been sold two or three times, and the quality has decreased."
"The initial setup was a little bit complex."
"We find that the search and access functionality is quite slow."
"The product's connectors should work better and the user manuals need an update."
"The platform is quite expensive. They should reduce its cost."
"It would be better if the product is cheaper."
"The next release should have AI capabilities."
"Using the ArcSight Logger dashboard is not particularly intuitive or efficient, so it is important to be trained in its use."
"The initial setup is complex. There are other solutions that are easier to implement."
"The solution should have more integration capabilities with different platforms."
"The log system is a bit complex and has room for improvement."
"The initial setup is very complex and should be simplified."
"The system architecture is complex and sometimes it’s hard to troubleshoot potential problems."
"Lots of competing products have vulnerability protection built into their products, and this solution would be improved by including that support."
"I believe that integrating the solution with other products such as Oracle would be beneficial."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
 

Pricing and Cost Advice

"We have a lifetime license, so we don't pay a monthly fee."
"The pricing is quite harsh."
"Pricing is reasonable compared to similar tools on the market. They offer perpetual licenses."
"ArcSight is an expensive solution."
"I rate the product’s pricing a seven out of ten, where one is inexpensive, and ten is expensive."
"It's not cheap at all as it's a big product and has been in the market for quite some time now."
"I would rate the product a seven out of ten since it's an enterprise product."
"ArcSight Logger is very expensive compared to their competitors, but when we talk to the customer and explain what the features are and how we can scale, they understand. Still, ArcSight is more expensive than the competition."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The product is expensive."
"Compared to the competition, the is price is not that high."
"Our license is for one year."
"It is cheap."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"The product price was reasonable for my region and the market."
"It’s cheaper to run virtual machines in a VMware environment."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
869,513 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
10%
Government
8%
Educational Organization
7%
Financial Services Firm
13%
Computer Software Company
11%
Comms Service Provider
7%
Performing Arts
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise10
Large Enterprise16
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise20
 

Questions from the Community

What do you like most about ArcSight Logger?
We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
What is your experience regarding pricing and costs for ArcSight Logger?
The pricing isn't the problem. We have a lifetime license, so we don't pay a monthly fee.
What needs improvement with ArcSight Logger?
This decision is made by higher management as they don't want to have multiple solutions for one solution. ArcSight Logger themselves don't provide good support, but companies such as ours provide ...
What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
 

Also Known As

Micro Focus Arcsight Logger, HPE Arcsight Logger
RSA Security Analytics
 

Overview

 

Sample Customers

China Merchants Bank, Bank AlJazira, Banca Intesa
Los Angeles World Airports, Reply
Find out what your peers are saying about ArcSight Logger vs. NetWitness Platform and other solutions. Updated: September 2025.
869,513 professionals have used our research since 2012.