No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness Platform vs OpenText Enterprise Security Manager comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
39th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
Log Management (38th)
OpenText Enterprise Securit...
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
99
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 0.9%, up from 0.6% compared to the previous year. The mindshare of OpenText Enterprise Security Manager is 1.5%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
OpenText Enterprise Security Manager1.5%
NetWitness Platform0.9%
Other97.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer2256927 - PeerSpot reviewer
Head of Information Security, Cyber Defense and IT Risk Management at HCT. at a transportation company with 201-500 employees
A solid SIEM solution that should improve technical support and online resources to be easier to use
A big problem with the product is that we don't have much professional experience in Israel installing, implementing, and integrating this product. There is not enough of a knowledge base. There is no support for this product in this country, so problems have to be resolved through global technical teams. We like to work locally because of the language, and when the product is only supported outside the country, it's a little difficult to implement and use this product. Moreover, AI is something that must be added immediately. Artificial intelligence is a part of the competitors' products, and it's not been implemented for us.
SM
Cloud Security Archirect at IBM
Unified log analysis has strengthened incident detection and supports continuous attack simulation
I do not have any areas for improvement in ArcSight Enterprise Security Manager (ESM) as I have not delved deeply into it; overall, it is a good package. I would like to see the detection and response features included in the next release of ArcSight Enterprise Security Manager (ESM), as security orchestration and automation are increasingly important.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the security that it provides."
"NetWitness Platform is valuable for creating rules that the solution must detect."
"The most valuable feature is the correlation. It can report in real-time and monitor the management."
"Thanks to this tool, we have a small SOC running in our company."
"The most valuable feature of RSA NetWitness Logs and Packets are the alerts and correlations tools."
"It gives the ability to investigate into network traffic in the Net and the organization what we couldn't do before."
"The product's initial setup phase was not at all difficult."
"I can have enterprise security, email security, next generation firewall security log, HIDS and NIDS logs, etc. all on the same dashboard. It makes it easy to pinpoint or correlate our server to this. I can find out if there is lateral movement. This is the biggest advantage of this solution."
"It has helped us to gather, store, correlate and analyze security log data from many different information systems."
"We use this product for managed SIEM services and its stability and maturity helps with standard deployments (hardly any surprises)."
"Correlation and data normalization via CEF: The speed of ArcSight's correlation engine, together with data enrichment, makes it a great tool for exploring vast amounts of data."
"For large scale installations with multiple users and (sub) companies, ArcSight is the best option."
"It has absolutely improved the efficiency of our security team. We use it internally as well. It is such a powerful tool that our internal security team became a customer of our ArcSight managed service."
"ArcSight Enterprise Security Manager (ESM) works perfectly. It's a stable and scalable product."
"ArcSight helps to track all configuration changes and correlates with corresponding service tickets, helping a lot in auditing system and network admins with minimal time and cost."
"The stability of the solution is very good; it's pretty perfect, actually, as we don't have crashes, it doesn't freeze, there aren't bugs or glitches, and it's completely reliable."
 

Cons

"If we have the ability to run a dynamic analysis through malware in the same suite, it would be great to have a sandbox solution to analyze malware through dynamic analysis."
"The system looks like it is a mix of a bunch of different systems, and nothing looked like it was quite together."
"I'd like to see improvement in its ease of use. It's basically unusable. It's overly complex."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"It is overly complicated. It has taken years to implement and the return on investment just isn't there."
"Advance monitoring and alerting feature is not stable (Event Stream Analysis)."
"The initial setup is complex. It requires some knowledge in order to set it up."
"Nowadays, their support is a little subpar compared to other solutions. I rate RSA support six out of 10."
"I faced some problems implementing certain attacks, which was my biggest concern. The visualization wasn't very good, and I couldn't create good monitoring dashboards."
"The API integration could be better, and I'd like to see more machine-learning capabilities in the future."
"There are several improvements that we would like to see, including: Building a system based on a log collection (SOC), a scenario for external encroachment, and Operator training."
"ArcSight ESM could improve by adding more features and documentation. There needs to be more documentation."
"The stability isn't quite perfect. We occasionally run into problems."
"I would like for them to integrate mobile devices. Integration or any kind of functionality which will act as a substitute for IBM so that we can really track our mobile devices as well as look at SIEM."
"The roadmap is not clear."
"Technical support has been so frustrating that we've brought in an intermediary, LiveQuest, to deal with HP support for us."
 

Pricing and Cost Advice

"The new pricing and licensing mechanisms are fair. I would advise always to get the full solution (i.e., not only Logs)."
"Many clients are not able to purchase the packet capability because there is a huge amount of data, and the cost depends on the number of EPS (Events per second), as well as the number of gigabytes of data per day."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"The licenses are good but the cost is very expensive."
"The product is expensive."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"There is a licensing fee and the customer can choose whether he wishes this to be subscription-based or perpetual."
"RSA NetWitness Logs and Packets do not have a subscription model, it's a one-time purchase. There is only a perpetual license."
"The product licenses are inexpensive."
"Price-wise, ArcSight ESM was a bit high compared to competitors, which factored into our decision to switch to Splunk. It couldn't cover all our business needs for what we wanted to implement."
"The solution is super expensive. At our organization size and license model, I think the price is average to what anyone else would charge us."
"Aggregation can help a lot in pushing down licensing costs."
"The pricing is great compared to others."
"HPE ArcSight pricing might be more expensive than other SIEM solutions, but in my opinion it has powerful features and great flexibility in developing complex use cases."
"It's a good price, it's one of the cheaper solutions."
"The licensing cost is affordable if you get an enterprise license. The licensing is based on EPS, so you can probably provide a package of license for multiple ESMs with their correlational end fees. It is cost-effective."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
894,668 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
8%
Performing Arts
7%
Financial Services Firm
15%
Marketing Services Firm
10%
Manufacturing Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise20
By reviewers
Company SizeCount
Small Business37
Midsize Enterprise14
Large Enterprise59
 

Questions from the Community

What is your experience regarding pricing and costs for NetWitness Platform?
The pricing is comparable to others, and I consider the cost to be intermediate. Specific cost details are unknown to me.
What needs improvement with NetWitness Platform?
There is currently no need for improvement in the SIEM ( /categories/security-information-and-event-management-siem ), though there could be potential enhancements by integrating with AI.
What is your primary use case for NetWitness Platform?
I use NetWitness Platform ( /products/netwitness-platform-reviews ) in the financial industry as a good product with excellent capabilities and integration with various devices.
Which is the best SIEM tool for a mid-sized financial services firm: Arcsight or Securonix?
In my market, a lot of financial companies had or have an ArcSight installation. Just because in former times it was pretty good. Now a lot of them are looking for a more effective solution due to ...
What is your experience regarding pricing and costs for ArcSight Enterprise Security Manager (ESM)?
ArcSight Enterprise Security Manager (ESM) is very cheap compared to other tools. It is worth the investment if you are considering the cost.
What needs improvement with ArcSight Enterprise Security Manager (ESM)?
Regarding threat detection capabilities, I think OpenText Enterprise Security Manager covers the MITRE ATT&CK framework at an average level, and on a scale of one to ten, I would rate it only f...
 

Also Known As

RSA Security Analytics
Micro Focus ArcSight, HPE ArcSight, ArcSight
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
Lake Health, U.S. Department of Health and Human Services, Bank AlJazira, Banca Intesa, and Obrela.
Find out what your peers are saying about NetWitness Platform vs. OpenText Enterprise Security Manager and other solutions. Updated: April 2026.
894,668 professionals have used our research since 2012.