Try our new research platform with insights from 80,000+ expert users

Cribl vs OpenText Enterprise Security Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 19, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
Cribl enhanced data management efficiency, delivering cost savings, improved processing speed, system performance, and operational flexibility for users.
Sentiment score
8.9
OpenText Enterprise Security Manager's ROI is challenging to quantify but enhances threat detection, compliance, and organizational security efficiency.
 

Customer Service

Sentiment score
6.8
Cribl customer service is praised for prompt responses, effective support, and community assistance, with a high satisfaction rating.
Sentiment score
5.7
OpenText Enterprise Security Manager's service is satisfactory but faces issues with technical support consistency and problem management resolution.
The community, including the engineering and sales teams, is available on Slack and is very supportive.
If I raise a P1 or P0 ticket, the response time is often delayed by four to eight hours.
 

Scalability Issues

Sentiment score
7.9
Cribl is scalable and easily integrates with CI/CD pipelines, receiving praise for efficient deployment and seamless cloud management.
Sentiment score
7.1
OpenText Enterprise Security Manager offers strong scalability but is costly, requiring expertise and careful budgeting for extensive deployments.
It lacks some capabilities compared to other tools available in the market.
 

Stability Issues

Sentiment score
7.3
Cribl is generally rated 7-8 for stability, with minor bugs quickly addressed and continuous development enhancing reliability.
Sentiment score
7.1
OpenText Enterprise Security Manager is reliable but depends on proper setup; issues are rare when optimized correctly.
The stability of ArcSight Enterprise Security Manager (ESM) is not very robust.
 

Room For Improvement

Cribl needs better legacy compatibility, intuitive logging, enhanced documentation, improved onboarding, and desktop server functionality for developers.
OpenText Enterprise Security Manager needs UI upgrades, performance improvements, better integration, support, deployment, analytics, and scalability enhancements.
Perhaps more flexibility in terms of metrics would be helpful.
The integration aspect of ArcSight Enterprise Security Manager (ESM) needs improvement.
 

Setup Cost

Cribl offers a cost-effective, scalable pricing model with up to 30% cost reductions, appealing to mid-level and large enterprises.
OpenText Enterprise Security Manager pricing, while high, is justified by its robust features and deemed competitive for enterprise needs.
ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools.
 

Valuable Features

Cribl streamlines real-time data transformation, log collection, and routing with user-friendly features, security, and extensive integration support.
OpenText Enterprise Security Manager offers powerful integration, real-time threat detection, customization, and robust event management for security teams.
The community on Slack is excellent for solving questions and getting ideas.
The ability to interpret data is highly valued.
 

Categories and Ranking

Cribl
Ranking in Security Information and Event Management (SIEM)
12th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
10
Ranking in other categories
Application Performance Monitoring (APM) and Observability (14th), Log Management (8th), Observability Pipeline Software (1st)
OpenText Enterprise Securit...
Ranking in Security Information and Event Management (SIEM)
21st
Average Rating
7.8
Reviews Sentiment
7.5
Number of Reviews
97
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Security Information and Event Management (SIEM) category, the mindshare of Cribl is 1.0%, up from 0.1% compared to the previous year. The mindshare of OpenText Enterprise Security Manager is 1.2%, down from 1.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Phanindra Ponnada - PeerSpot reviewer
Provides good documentation and worth the investment
As of now, there are some environments where some organizations are still on legacy infrastructure, so they are still in virtual environments and are using old versions of devices. Some companies bought Splunk, while others bought Cribl for a very low-priced license. There are some protocols to connect from Cribl to Splunk. I understand Cribl has come into the market very recently, but the tool might have had a picture in its mind where organizations might also have some legacy infrastructure. In the future, with our protocols or our level of architecture, Cribl should not come and say that it is not compatible with them. If Cribl is the reason because I have to change my environment, then I will have to end up investing more. There are some organizations where the end machines have forwarders that forward the data to Cribl, and from it, the data is forwarded to Splunk. This is how general architecture works. There are two methods of connection between Cribl and Splunk. One is the S2S protocol, which collects logs from Cribl or sends data between Cribl and Splunk. There is another method called HTTP Event Collector (HEC) and HTTPS protocol. With Cribl, connecting to Splunk mostly uses the S2S protocol. The tool supports all the latest devices and platform devices, like all the latest operating systems. There are some organizations where there is legacy infrastructure or if they are still on the old platforms. Companies using old platforms have to consider HTTP Event Collector (HEC), and then they have to change their infrastructure setup in order to fulfill that setup. In order to have Google and Splunk set up in my organization, if I have to change my existing infrastructure connectivity or setup, that might incur more cost or more investment for me to have Cribl and Splunk. Cribl should provide compatibility, or else the tool's developers should speak to the people of such organizations and understand the challenges. Cribl could have developed some version that can give backward compatibility.
Gaurav Ranade - PeerSpot reviewer
Excels at performing regression and correlation on the data
ArcSight is a legacy technology, and many customers want AI-powered technologies integrated with it. That hasn't been done yet, but ArcSight needs to catch up with the newer solutions and technologies available in the market. It can't just rely on the legacy technology from 2010 or 2012. You can't run that in 2024. It's a legacy technology with its own limitations. Customers often face issues that other software or newer solutions can resolve easily. That's the main challenge we face from customers right now. So, the only concerns are that AI needs to be integrated and scalability improved. Those are the main areas to be improved.
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
10%
Healthcare Company
8%
Government
7%
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Cribl?
I am not aware of the pricing details, however, I know they use a credit format for billing.
What needs improvement with Cribl?
At the moment, I don't have specific feedback on what can be improved as I do not work with Cribl daily. Perhaps more flexibility in terms of metrics would be helpful.
What is your primary use case for Cribl?
I am using Cribl to have everything centralized in one tool in terms of data collection. We were working with different Splunk customers, and Cribl helps collect data and then send it to an S3 buck...
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What do you like most about ArcSight Enterprise Security Manager (ESM)?
We utilize ArcSight ESM for real-time threat detection in our organization. We have custom rules that we've developed on top of the WAN services, along with scheduled licensing activities.
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools. It is worth the investment if you are considering the cost.
 

Also Known As

No data available
Micro Focus ArcSight, HPE ArcSight, ArcSight
 

Overview

 

Sample Customers

Information Not Available
Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Find out what your peers are saying about Cribl vs. OpenText Enterprise Security Manager and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.