Try our new research platform with insights from 80,000+ expert users
reviewer1751472 - PeerSpot reviewer
Chief Technological Officer at a tech consulting company with 51-200 employees
Real User
Very useful tool for intelligence building as it has many use cases and many rule sets
Pros and Cons
  • "It is a very useful tool for intelligence building because it has many use cases and many rule sets."
  • "It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are."

What is our primary use case?

We use ArcSight Enterprise Security Manager for any type of cyber security attack.

It is in the cloud and on the customer's infrastructure. I am only deploying one agent and the agent is deploying all the information from the customers and then sending it to the cloud.

I am an integrator, but we sell our services. I'm not selling the software directly to customers. I'm selling my service with this product.

What is most valuable?

It is a very useful tool for intelligence building because it has many use cases and many rule sets.

What needs improvement?

It is quite complex and could use a better UI. So the improvement would be a simplification. It is pretty complicated to use. The architecture is not complex but the setup and use are. 

In the next release, it would be nice if the Logger model and the ESM model would be merged. Right now there are two big models, Logger and ESM, but from a Windows perspective, it is not good because they're sending Logger and ESM separately. So if you need ESM, you have to buy both Logger and ESM but if you only need Logger, you are buying just Logger. You can deploy them on one system, but you have two different systems and different databases. My suggestion would be to merge Logger and ESM together.

For how long have I used the solution?

I have been using ArcSight Enterprise Security Manager for about a year.

Buyer's Guide
OpenText Enterprise Security Manager
August 2025
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

Arc Sight Enterprise Security Manager is scalable.

The number of people running it should be based on the organization's size. If you have a  company with 500 assets, you should have at least one field engineer for the ESM product and two security analysts to operate this software. This is minimum. One engineer and two security analysts is minimum to start if the organization is midsize.

How are customer service and support?

Their technical support is generally good. On a scale of five, I'd give them four out of five.

How was the initial setup?

The initial setup is complex.

Installation is not complex, but Micro Focus also has different intelligence products. One runs on containers and it is quite complex to install and use, but it is a different product. So maybe if we can remove this wall then we should be all right.

I have two products from Micro Focus. I have this ESM and one for Web. It is for user IT behavior analytics. The second product is quite complex and it's linked to it. Then you have to connect these things together. So the complexity is in the Web product, not in ESM.

Our own site deployment took about one month to deploy and we can deploy services for our customers in about two weeks minimum. But that is a minimum. If the infrastructure is big, it may take up to two or three months. If the infrastructure is not logging or if there are many customer applications, it makes it complex to deploy. Every ESM product will be complex to implement if the organization is big and the logging is not enabled correctly.

What other advice do I have?

My advice to anyone considering Arc Sight Enterprise Security Manager is to just read the manual. Just read the manual and documentation. 

On a scale of one to ten, I would rate it a nine.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1738932 - PeerSpot reviewer
Security Sales Engineer
Real User
Useful real-time alerts for web traffic monitoring
Pros and Cons
  • "Stable solution with good customer service support."
  • "Could benefit from a more modern interface."

What is our primary use case?

We use it to monitor several web traffic sources and to look for compromised indicators within that traffic. The traffic comes from several applications that we've exposed on the internet.

What is most valuable?

The most valuable feature is the real-time alerts. We're also currently looking to incorporate some of the SOAR capabilities that are new to the platform.

What needs improvement?

The interface—the console looks pretty old right now, so could benefit from a more modern design.  It's functional, but not so as visually appealing as it could be.

For additional features, I'd say capabilities regarding the behavioral analytics integrated in the solution. Right now, there's something in place, but it's not integrated on our side of the platform.

For how long have I used the solution?

I've been using ArcSight since 2015, so about six years.

What do I think about the stability of the solution?

My impressions are that it is stable.

What do I think about the scalability of the solution?

On our end it's pretty good. We haven't had any problems adding more sources.

How are customer service and support?

I've used their customer service and support a couple of times. It was a good service.

How was the initial setup?

Setup was relatively easy. The initial deployment was around five hours. For full deployment with all the sources, it took longer.

What other advice do I have?

I would rate this solution an eight out of ten. It's been useful and would recommend it to others. I'd also advise to take just the initial architect for implementation because that was critical for us in making the appropriate selections prior to deployment.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
OpenText Enterprise Security Manager
August 2025
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,295 professionals have used our research since 2012.
Cyber threat Intelligence Manager at CyberLab Africa
Real User
Scalable, good technical support, but stability could improve
Pros and Cons
  • "We have been satisfied with the support."
  • "The solution could be more stable."

What is our primary use case?

We are using ArcSight Enterprise Security Manager (ESM) for data analytics. We monitor the reports on security event information.

For how long have I used the solution?

I have been using this solution for approximately one year.

What do I think about the stability of the solution?

The solution could be more stable.

What do I think about the scalability of the solution?

We have not had any issue with the scalability.

We have approximately 20 users using this solution in my organization.

How are customer service and technical support?

We have been satisfied with the support.

How was the initial setup?

The installation was easy.

What about the implementation team?

We had assistance with the implementation of the solution. We have approximately five individuals that do the maintenance.

What's my experience with pricing, setup cost, and licensing?

There is a license required for this solution.

What other advice do I have?

I would recommend this solution to others.

I rate ArcSight Enterprise Security Manager (ESM) a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1511343 - PeerSpot reviewer
Security Engineer at a tech services company with 1,001-5,000 employees
Real User
A stable and scalable solution with good correlation and parsing
Pros and Cons
  • "I really like the correlation part and the way the logs are correlated. I have never faced issues with parsing in this product. I like the way it parses, and everything is so clear to me."
  • "Its search part can be improved. When I go to the console and search for a few logs or something else, it takes a lot of time. When I try to search for three days or one week, it takes too much time. This is a major area of improvement. I wanted them to include features like SOAR, threat intelligence, and automation, and they seem to have included all these features in version 7.3 or 7.4."

What is most valuable?

I really like the correlation part and the way the logs are correlated. I have never faced issues with parsing in this product. I like the way it parses, and everything is so clear to me.

What needs improvement?

Its search part can be improved. When I go to the console and search for a few logs or something else, it takes a lot of time. When I try to search for three days or one week, it takes too much time. This is a major area of improvement.

I wanted them to include features like SOAR, threat intelligence, and automation, and they seem to have included all these features in version 7.3 or 7.4.

For how long have I used the solution?

I have been using this solution for approximately three to four years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is scalable.

How are customer service and technical support?

I have experience with their technical support, and I would rate them 4.5 out of 5. Whenever I have raised a ticket, I got an appropriate response. They were able to solve my problem.

What other advice do I have?

I would rate ArcSight Enterprise Security Manager (ESM) an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1501149 - PeerSpot reviewer
Managing partner at a tech services company with 11-50 employees
Real User
Good at consolidating logs, fairly stable, and can scale
Pros and Cons
  • "The solution is pretty stable."
  • "The way that scaling is set up isn't very cost-effective."

What is our primary use case?

We primarily use the solution for consolidating the logs from all the applications and databases and different centers.

What is most valuable?

The solution is very good at consolidating logs from a variety of sources.

The solution is pretty stable.

The solution can scale.

What needs improvement?

The way that scaling is set up isn't very cost-effective.

The automation needs to be improved. Everybody needs automation as there is a lack of analysts these days in all of our security diagnostic accounts. There's too much noise in the data they push to you. It's a lot of white noise, and it takes a lot of time to sort through the all false positives that ArcSight triggers to you.

It's very complicated to see if something is a real case and if it's a threat or not. It's very difficult to be able to check that the information sent as they are sending you thousands of messages per day regarding threats. It's very difficult for an analyst to be able to pinpoint the real root cause of the problem. 

I would suggest that they offer full automation and filtering for white noise. By white noise I mean the bulk of messaging and alerts they have been sending to the security analysts. It's difficult for them to realize if it's a threat or not in the end, and you need to spend a lot of time among other systems that you also need to manage. Maybe only 10% of this information is useful for a security analyst.

The product should improve its ease of use.

They should work to have a more let's say intuitive dashboard, a real-time intuitive dashboard, and to focus it on the most important, critical assets in the company. 

The solution requires a lot of expertise and manpower to deploy the solution.

For how long have I used the solution?

We've been using the solution for nine years. It's been just under a decade.

What do I think about the stability of the solution?

The solution is pretty stable. However, they've got some problems in terms of interacting with APIs. To try to make ArcSight speak with other solutions and try to correlate information from IPS/IDS solutions looks pretty complicated. 

What do I think about the scalability of the solution?

The solution can scale if you need it too. It's just an expensive process.

Regarding the scalability, it was a problem that their license model was EPS. If you're familiar with EPS licensing model, events per second, it is not a very good idea as a model as you cannot foresee what's in 2021 or what will be in 2022. From our point, it causes a lack of proper budgeting due to the fact that it's very difficult to budget how many events per second you will generate in all your systems. 

How are customer service and technical support?

We haven't really dealt with technical support. I wouldn't be able to speak to the quality of their services.

How was the initial setup?

The initial setup is very, very complex, and requires a lot of consultancy and professional services associated with it. It's not at all easy to install the solution as per my knowledge. It's very complicated. 

What's my experience with pricing, setup cost, and licensing?

The licensing model is based on EPS - Events Per Second - and it makes it hard to budget how much the solution will cost.

The solution is pretty expensive.

Which other solutions did I evaluate?

At a marketing level, we've checked out Splunk. We have not tested it internally on our servers. We simply took a closer look at their marketing and their strategic messaging.

What other advice do I have?

We have used on-premises previously. We have never tested the cloud option if they have one. 

I would rate the solution seven out of ten. I consider Splunk and LogRhythm to be the number one solutions in the market.

I would advise others to try to be very careful when they got a quote from ArcSight, as, in the end, what they offer to you initially is not what you will end up in the end in terms of budgeting and pricing, and the level of expectations.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Manager at PT Permata Anugerah Abadi
Real User
Top 5Leaderboard
Scalable, with good support and live reporting
Pros and Cons
  • "The most useful features are directories, price, and live reporting."
  • "The customer experience could be improved."

What is our primary use case?

We are resellers. We deal with many vendors to provide and implement solutions for our clients. We primarily use this product for logging data.

What is most valuable?

The most useful features are directories, price, and live reporting.

What needs improvement?

The customer experience could be improved.

I think they can improve the AI and monitoring. Also, they need an updated database.

For how long have I used the solution?

I have been dealing with this solution for approximately three years.

We are working with the last updated version.

What do I think about the stability of the solution?

The stability can be improved. The competitors are more stable.

What do I think about the scalability of the solution?

It's a scalable product and the scalability is good.

Our clients are usually enterprise companies.

How are customer service and technical support?

The technical support is good. They have been able to resolve our issues.

Which solution did I use previously and why did I switch?

We are using SIEM. It has a better dashboard and is more complete.

How was the initial setup?

The initial setup can be simple and also complex. It depends on the client's infrastructure.

What about the implementation team?

We implement the solution and maintain it for the clients.

What's my experience with pricing, setup cost, and licensing?

It's a good price, it's one of the cheaper solutions.

There are no additional costs.

What other advice do I have?

Depending on the size of the companies, I would recommend this solution. It's more suited for small to medium-sized companies.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Sandeep Sehrawat - PeerSpot reviewer
Information Technology Security Consultant at Sify Technologies
Real User
Easy setup but should offer an entire report listing of integrated devices
Pros and Cons
  • "There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive."
  • "I would like to have a feature that gives us an entire report listing what devices are integrated."

What is most valuable?

There are many features that are good for clients who are looking for a good SIEM solution. They like the ease of creating a business that is effective and impressive. 

What needs improvement?

The security is difficult. 

I would like to have a feature that gives us an entire report listing what devices are integrated.

For how long have I used the solution?

I have been using ArcSight for the last five years. 

How are customer service and technical support?

In the beginning, we got good support but it hasn't been what it used to be. On weekends we get the list of devices that are integrated but if we need to generate the lists of rights, it doesn't send the logs.

How was the initial setup?

The initial setup was simple. The initial setup took five to six days.

What other advice do I have?

I would rate it a seven out of ten. In the next release, I would like for them to include a list of integrated devices. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1342554 - PeerSpot reviewer
Associate Vice President at a consumer goods company with 201-500 employees
Real User
Good monitoring and analytics components with pretty good technical support
Pros and Cons
  • "The solution offers very good monitoring."
  • "The stability isn't quite perfect. We occasionally run into problems."

What is our primary use case?

We primarily use the solution for its technology including its independent logs, and those types of things. The technology we leverage is for third parties.

What is most valuable?

The solution offers very good monitoring.

The product's log management and event management capabilities are excellent.

There are a lot of really good analytical components. It helps us focus on analysis.

What needs improvement?

We need to have more data to work with. The more data you have the more you will be able to give off the right information based on the historical information allows you to take more action. When you don't have enough data, you can't really get the right insights.

The stability isn't quite perfect. We occasionally run into problems.

For how long have I used the solution?

I've been using the solution for almost three years ow. It's been a while.

What do I think about the stability of the solution?

The solution is more or less stable. It's okay. However, from time to time, we do actually have some problems with it. It's not perfect. 

What do I think about the scalability of the solution?

We haven't tried to scale the solution at this point.

We have about 2,100 people on within the company, and five of those are focused on this solution specifically. We don't have plans to increase the usage of ArcSight at this time.

How are customer service and technical support?

I definitely have been in contact with technical support multiple times. They do provide device guidance. I'd say that they do work quite efficiently and our tickets are always responded to. We're pretty satisfied with their level of support.

Which solution did I use previously and why did I switch?

We didn't previously use a different solution. This is the first product for us that we use in this particular way.

How was the initial setup?

I didn't handle the initial setup personally. My team handled it, however, and I do not recall them saying that it was complex. My understanding is that it is straightforward.

Our teams also handle the maintenance.

What about the implementation team?

We handled the implementation in-house.

What's my experience with pricing, setup cost, and licensing?

I don't have too much information about the licensing costs at this time. I don't really handle them. I'm not sure if there are additional costs over and above the license itself.

What other advice do I have?

We're just a customer. We don't have a business relationship with the company.

We're using the latest version of the solution. I'm not sure of the exact version number.

I'd rate the solution eight out of ten. Due to the technology inherant the background of the product. Overall, it's quite good, although we have run into stability issues in the past.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2025
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.