Try our new research platform with insights from 80,000+ expert users

ArcSight Logger vs Splunk Cloud Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Logger
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
31
Ranking in other categories
Log Management (30th)
Splunk Cloud Platform
Average Rating
8.2
Reviews Sentiment
6.0
Number of Reviews
58
Ranking in other categories
Data Visualization (3rd), IT Alerting and Incident Management (3rd)
 

Mindshare comparison

While both are Systems Management solutions, they serve different purposes. ArcSight Logger is designed for Log Management and holds a mindshare of 0.8%, down 1.1% compared to last year.
Splunk Cloud Platform, on the other hand, focuses on Data Visualization, holds 0.8% mindshare, up 0.3% since last year.
Log Management
Data Visualization
 

Featured Reviews

Geraldo Freitas - PeerSpot reviewer
Enhances our security incident investigation but not good for correlation
Investigation is good when you know what you want to search for in Logger. The most difficult part is parsing the logs and configuring the parsers. For investigation, it's good. For correlation, it's not good. We use Sentinel, and Sentinel has pre-built use cases that are much easier to configure. So, it enhances our security incident investigation. We have inbound integration, but configuring the parsers is sometimes very difficult. We only have two use cases where we have a correlation set up. We send the information to Check Point to block IP addresses when we see a lot of blocks from the same source. We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist. So, it offers the ease of integration.
Ian Gatundu - PeerSpot reviewer
It improves our visibility and decision-making while helping us meet compliance standards
The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function. It's easy to monitor multiple cloud environments because you can create custom dashboards for any use case you may have. It offers good visibility because it integrates with the ITSI app, providing a clear overview of your environment. Integrating Splunk with other components on the cloud and network resources is effortless because it can collect data from various sources, including stored data from long-term storage. Splunk's reporting offers a good visualization of your data. You can visualize the statistics based on your searches. It produces some helpful graphs that enable you to easily compare what's happening in your search. It's very comprehensive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a brilliant log collection tool, and it can handle hundreds of thousands of servers in a single shot to ingest the data."
"Our return on investment for implementing ArcSight Logger over the past 12 months has been positive."
"I am impressed with the product's ability to pick up logs. It also has UEBA which has reduced the time to take charge of the events."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"In our country we are a little bit private in terms of solutions, so we are just starting to use the basic data capture. Now some users can start to use additional features that come with Micro Focus ArcSight like user behavior analytics for investigating."
"It's an efficient solution."
"In terms of ArcSight Logger's most valuable feature, it is their scalability. ArcSight's real advantage is its scalability because they have two layers, including the logger layer."
"We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist."
"I have done health checks several times now, and those have been very valuable in getting more information about what is going on in my platform. There are also recommendations on what is going on in my environment."
"There is definitely the ease of the infrastructure administration. It frees up a lot of time."
"The Splunk search is powerful compared to similar solutions. We get millions of data points within seconds."
"The Cloud Platform interface is cleaner than Splunk Enterprise's monitoring console. You can easily understand what's happening with your indexes. It's more refined than Splunk Enterprise's console, but they have the same feel and function."
"We only buy the services we need. We don't have to pay for other things we don't."
"Not having to maintain any infrastructure is valuable. That frees up a lot of time as well."
"The most valuable feature of Splunk Cloud Platform is the ability to correlate events together and combine the data into one event."
"The most valuable feature is we don't have to deal with any back-end server maintenance because the solution is cloud-based."
 

Cons

"I would rate the technical support only 5 out of 10. The technical support is not satisfactory."
"The solution should make it possible to integrate network analysis features."
"ArcSight has been sold two or three times, and the quality has decreased."
"In the next release, I want to see more intelligence."
"The next release should have AI capabilities."
"I think the ArcSight team should try to simplify legacy products for the customers, because that product is not easy to use or to work with. It needs more more competency or appeal to use. We hope Micro Focus is trying to resolve this."
"The product's connectors should work better and the user manuals need an update."
"Using the ArcSight Logger dashboard is not particularly intuitive or efficient, so it is important to be trained in its use."
"The search for bulk data needs to be improved. When we were looking for the flow, we had to search really hard. I wanted to request the Splunk team to add some features for better search because getting the flow of the bulk data was sometimes hard."
"There could be better searches, but mainly, it needs to improve the performance with a vast amount of data. That will make it better and easier to use."
"In the case of knowledge objects, even a Splunk admin does not have access to delete them. If we want to remove a knowledge object, we need to contact Splunk support and raise a case. After that, they delete it. They should give us access to delete knowledge objects."
"There can be more modules and more integration with other areas in the cloud and on-prem. I am not sure whether it includes network devices and things like that."
"First-time users may struggle with the user interface. When I first used Splunk, I entered my username and password. After that, we get a dashboard on the left side with apps. At the top, you can click the gear icon to view the settings. Within those settings, there's a distributed console option with several settings. It's a bit overwhelming for a beginner. The user knows what they want and can search for it in the search bar. If I see several apps, my first instinct is to scroll down to find the app, or perhaps you will find that search and report. That bugged me when I was learning."
"They can streamline the process of creating custom apps."
"When it comes to the integrations with the other platforms, there is a little bit of a lag in the observability part, making it an area where improvements are required."
"From an enterprise standpoint, we are more limited in terms of what data we can export and how we can present it."
 

Pricing and Cost Advice

"I rate the product’s pricing a seven out of ten, where one is inexpensive, and ten is expensive."
"Pricing is reasonable compared to similar tools on the market. They offer perpetual licenses."
"It's not cheap at all as it's a big product and has been in the market for quite some time now."
"I would rate the product a seven out of ten since it's an enterprise product."
"ArcSight Logger is very expensive compared to their competitors, but when we talk to the customer and explain what the features are and how we can scale, they understand. Still, ArcSight is more expensive than the competition."
"ArcSight is an expensive solution."
"The pricing is quite harsh."
"We have a lifetime license, so we don't pay a monthly fee."
"Splunk Cloud Platform is an expensive solution."
"The lack of transparency around the SVC licensing makes it difficult to explain the costs to our clients."
"I do not know what that is anymore. I have not been involved with that for a couple of years, but I know we are paying a lot."
"It is not that expensive."
"The pricing model makes this an expensive solution."
"Splunk Cloud Platform's pricing is a little on the higher end."
"The price is something that people complain about."
"The licensing costs depend on the state of your environment and the fees are paid on a monthly basis."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
850,760 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
17%
Government
9%
Educational Organization
6%
Computer Software Company
30%
Financial Services Firm
12%
Retailer
5%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ArcSight Logger?
We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
What is your experience regarding pricing and costs for ArcSight Logger?
The pricing isn't the problem. We have a lifetime license, so we don't pay a monthly fee.
What needs improvement with ArcSight Logger?
The solution has room for improvement. We're currently upgrading to the newer version, where they have something like Kafka, a hub for all solutions feeding information into Logger. However, I thin...
What do you like most about Splunk Cloud Platform?
Splunk has sped up our response and reduced the time we spend manually monitoring any logs for ticketing tools or servers. It saves us around two hours daily.
What is your experience regarding pricing and costs for Splunk Cloud Platform?
Splunk Cloud is considered too expensive, with its two product offerings both being costly. I would rate the cost an eight out of ten, with ten being the most costly.
What needs improvement with Splunk Cloud Platform?
Splunk Cloud Platform needs improvement in its security offerings, specifically in cybersecurity. It has not kept pace with competitors over recent years, and integration with the Cisco ecosystem a...
 

Also Known As

Micro Focus Arcsight Logger, HPE Arcsight Logger
No data available
 

Overview

 

Sample Customers

China Merchants Bank, Bank AlJazira, Banca Intesa
Mindtouch
Find out what your peers are saying about ArcSight Logger vs. Splunk Cloud Platform and other solutions. Updated: March 2023.
850,760 professionals have used our research since 2012.