

ArcSight Logger and syslog-ng by One Identity compete in log management and compliance solutions. ArcSight Logger has the upper hand in compliance capabilities due to its integration with other ArcSight solutions, making it suitable for businesses with strict regulatory needs, while syslog-ng offers flexibility across various environments.
Features: ArcSight Logger provides robust search capabilities, integration with ArcSight SIEM, and powerful reporting tools. Syslog-ng supports a broad array of log formats, offers modular architecture facilitating integration, and includes built-in alerting features.
Room for Improvement: ArcSight Logger could enhance its update frequency and user interface, as well as reduce false positives. Syslog-ng may benefit from improved SIEM capabilities, more straightforward setup for complex environments, and enhanced support for larger log volumes.
Ease of Deployment and Customer Service: ArcSight Logger offers straightforward deployment within Hewlett Packard Enterprise environments and comprehensive support, while syslog-ng provides efficient integration across diverse platforms due to its modular architecture and reliable support resources.
Pricing and ROI: ArcSight Logger's price reflects its advanced capabilities, offering high ROI for comprehensive security analytics, often involving significant upfront investment. Syslog-ng presents more competitive pricing, appealing to budget-conscious buyers while still offering solid ROI through flexibility and customization.
| Product | Mindshare (%) |
|---|---|
| syslog-ng | 1.3% |
| ArcSight Logger | 0.9% |
| Other | 97.8% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 9 |
| Large Enterprise | 17 |
| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 2 |
| Large Enterprise | 3 |
ArcSight Logger effectively manages vast log data volumes, streamlining complex query execution and data compression while supporting various devices to meet compliance needs.
ArcSight Logger, known for scalability, simplifies handling extensive log data and executes complex queries swiftly. Its data compression features, coupled with versatile device support, allow for smooth security analytics and log collection. Users appreciate its real-time network insights and intuitive interface. However, improvements are needed in indexing speed, user navigation simplification, enhanced system integration, advanced analytics, and comprehensive threat management. Companies leverage ArcSight Logger for on-premises log management, vital for IT asset event monitoring and compliance within telecom and enterprise sectors.
What are the key features?In industries like telecom and enterprise, ArcSight Logger facilitates on-premises deployments to manage logs, process queries, and integrate with security tools, essential for incident response. It aids in retaining logs, monitoring Windows events, overseeing communications, and is employed in fraud prevention and security monitoring involving syslog servers.
Syslog-ng is recognized for its proficiency in log extraction, storage, and secure TLS connections. Its efficient configuration and real-time monitoring integration make it a preferred option for large-scale log processing, ensuring compliance with regulatory standards.
Syslog-ng offers powerful log management capabilities, accommodating complex search needs while maintaining simplicity with user-friendly documentation and real-time monitoring features. The C-style configuration enhances readability, allowing users to easily comprehend and implement changes. Designed for high performance, Syslog-ng scales effectively to handle extensive logging demands. Despite its strengths, areas for improvement include integration with protocols and filtering methods. Users advocate for better Kafka integration and a graphical configuration interface to simplify setup. While historical dissatisfaction led to custom patches, subsequent updates have addressed these concerns. Currently, users seek an advanced version to access premium functionalities.
What are the most important features of syslog-ng?
What benefits should users look for when evaluating syslog-ng?
Organizations frequently use syslog-ng for log aggregation, filtering, and regulatory compliance, serving as a crucial component in enterprise security audits and data regulation adherence in Brazil and Italy. By allowing logs to be stored in raw format, syslog-ng provides versatility in data manipulation and user activity tracking, making it user-friendly for installation, maintenance, and updates. Logs can be transmitted over TLS or plain text to central servers, supporting varied transmission needs.
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.