Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Network Security Engineer, Security Monitoring Center at a tech services company
Real User
FlexConnector collects logs from your own application.

What is most valuable?

The ArcSight solution supports your security team with many SIEM features:

  • Monitoring
  • Analysis
  • Alerts
  • Incident response

In my opinion, ArcSight is an open solution. It is easy to:

  • Customize components
  • Use FlexConnector to collect logs from your own application
  • Edit rules and the dashboard
  • Create work flows
  • Enrich information for events

How has it helped my organization?

I work at an ArcSight distributor in Vietnam. I have deployed the ArcSight solution for many customers. Some organizations are using it for SOC’s core and others for monitoring their information systems, critical assets, and regulatory and policy compliance.

For how long have I used the solution?

I have over two years of experience.

What do I think about the stability of the solution?

It can be overloaded when rules and data monitoring are not optimized and the system receives too many events.

Buyer's Guide
OpenText Enterprise Security Manager
September 2025
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.

What do I think about the scalability of the solution?

ArcSight can be extended to meet the biggest customers (large enterprise) needs.

How are customer service and support?

ArcSight technical support is enthusiastic. They have a lot of experience and many case studies.

How was the initial setup?

ArcSight configuration and deployment is complex, because it has many components.

Which other solutions did I evaluate?

I researched Splunk, QRadar and AlienVault, and I appreciate Splunk and ArcSight.

What other advice do I have?

ArcSight provides many documents and guides for configuration and operation. Also, you can refer to its community at https://www.protect724.hpe.com.

Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a partner of HPE ArcSight.
PeerSpot user
PeerSpot user
Security Expert at a tech services company with 501-1,000 employees
Consultant
With multi-tier hierarchical deployment, we are able to integrate and standardize security incident detection and response.

What is most valuable?

  • High flexibility: There are many custom sources of information that we wouldn't be able to integrate with another SIEM solution, thus compromising our security.
  • High performance: The amount of data fed to the solution is huge (100s of millions of events per day).
  • Capacity for multi-tier hierarchical deployment: We are able to integrate and standardize security incident detection and response over many locations.

How has it helped my organization?

  • Losses from security incidents have significantly decreased.
  • Security incident discovery and mitigation is a matter of hours, rather than days or even months, like it was before.
  • Detailed reports allow for planning and informed decision making.

What needs improvement?

The overall complexity of the product can be overwhelming for some. It's not the type of solution where you just plug it in and it works. Reaping full benefit from it requires quite a lot of custom tuning, qualified IT security personnel, and proper and thorough planning.

Technical support from the vendor can sometimes be quite slow and not very helpful, but it is getting better.

The GUI is outdated. Improvements on this are on the way, according to the vendor.

For how long have I used the solution?

I’ve been using ArcSight for five years.

What do I think about the stability of the solution?

We had stability issues only in a virtual environment, which is not recommended by the vendor for a high-load setup. The main virtual server would crash every now and then. But once we had migrated the setup to a dedicated physical server, we had no major stability issues.

What do I think about the scalability of the solution?

Scalability was one of our main concerns while choosing a solution and, so far, it has satisfied our needs in this area without any issues.

How are customer service and technical support?

Right now, I would call technical support moderately good, since it has improved greatly over the past years. There are still some issues with timeliness every now and then, but the number of critical issues is quite low.

Which solution did I use previously and why did I switch?

We have evaluated several solutions and HPE ArcSight was the only one that satisfied our requirements in performance, scalability, and flexibility.

How was the initial setup?

Initial setup was quite complex and required a lot of planning. That is a downside of the solution being flexible and customizable.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing model has changed dramatically over the last years, so I can't really give much advice on its current state. You need to be ready for the solution to be quite expensive.

Which other solutions did I evaluate?

We evaluated McAfee ESM.

What other advice do I have?

The keys to success with this solution are:

  • Careful deployment planning
  • Readiness to invest time and resources into training your IT security personnel
  • Fine tuning the solution to your specific needs
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
OpenText Enterprise Security Manager
September 2025
Learn what your peers think about OpenText Enterprise Security Manager. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
ProductS9907 - PeerSpot reviewer
Product Specialist Security Solutions at a tech services company with 201-500 employees
Real User
The feature list allows us to input data dynamically to list it as a rule action.

How has it helped my organization?

Having a SIEM solution in general improves the way an organization functions, especially in the SOC part. With HPE ArcSight, we were able to deploy multiple dashboards, reports, and use case views that combine different views, data, and variables.

What is most valuable?

One of the most valuable features is the Active List/Session List capability.

Multiple use cases were only possible to be created due to this feature list. The feature list allows us to input data dynamically to list it as a rule action.

For example: If you need to take a Source IP from an IPS event and put it in an ActiveList suspicious IP, you can create another rule for AntiVirus events where it only matches IPs within that list.

What needs improvement?

The main area is the GUI interface. Although a lot of improvements were made on the GUI in the last version (6.9.1), there are still a lot of configurations that need to be done using the console.

The console is not a bad tool to use. I personally like to use it. However, compared to competitive solutions (Splunk, QRadar), it appears to be a weakness.

What do I think about the stability of the solution?

In general, it is a very stable product. We did multiple implementations, and we never had any major issues.

As with any other solution that handles a large number of logs/data, regular fine-tuning is required. This fine-tuning makes sure that the system is doing what is supposed to do, with the capacity load that it was designed/sized to do

What do I think about the scalability of the solution?

There were no scalability issues. A single Express/ESM Appliance is usually enough to support most of the enterprise’s needs. Only package upgrades need to be purchased. No hardware changes are necessary.

As for the loggers for long retention, you can add multiple loggers and cluster them as one virtual appliance. This provides for an easy scalability feature.

For the connectors part, you can implement as many connectors as you need so you can cover all your zones/branches. At a later time, a load-balanced connector for syslog can be introduced to make sure that logs for sensitive UDP packets are lost.

How are customer service and technical support?

We barely used the technical support assistance except for licensing. The times when we did use it, they were very good.

Which solution did I use previously and why did I switch?

We worked with RSA enVision/RSA SA as a partner:

  • RSA enVision was very basic and was very hard to fine-tune.
  • RSA SA (logs/packets) is more oriented towards packets/investigation and lacks multiple features when only using it for log management/SIEM.

How was the initial setup?

The initial setup was very easy. A fresh ESM/Express Installation with a connector can be up and running within a few hours.

With all of the best SIEM solutions, the biggest chunk of work comes later in creating customized rules, dashboards, use cases, and flex connectors for non-supported devices.

What's my experience with pricing, setup cost, and licensing?

In general, ArcSight solutions can cost a lot in big deployments. That comes as a result of having a big, scalable, stable, and feature-rich solution.

Which other solutions did I evaluate?

As a partner, we sell the product. We shifted from RSA to ArcSight based on our internal evaluations.

We tested McAfee Nitro, which was not mature enough at the time compared to ArcSight.

What other advice do I have?

Do a live PoC to test all needed features.

Think of use cases that you would like to deploy and make sure they are doable on the system, without additional licenses/appliances.

Choose a mature partner who is able to deliver the implementation even if it costs a bit more. The most common factor of failed SIEM experiences are due to bad implementations from non-experienced partners/engineers.

Disclosure: My company has a business relationship with this vendor other than being a customer. We are partners with HPE.
PeerSpot user
Dr Trust Tshepo Mapoka - PeerSpot reviewer
Dr Trust Tshepo MapokaSenior Cybersecurity Consultant at CIA Botswana
Top 20Real User

Thanks I agree.

See all 2 comments
PeerSpot user
Solutions Architect- SIEM and Solutions with 1,001-5,000 employees
Vendor
Most devices are covered out-of-the-box. I would like to see high-end, predictive analytics.

What is most valuable?

The most valuable features are flexible setup of the architecture and large coverage of devices. Most devices deployed in enterprise environments are covered out-of-the-box by ArcSight. Unlike a few other solutions, the last-mile connectivity with ArcSight agent servers is free and flexible across all location deployments.

How has it helped my organization?

I have implemented it for a few organizations and they have benefited by early attack detection and usage of the right incident response mechanisms.

What needs improvement?

I would like to see high-end, predictive analytics. ArcSight ESM has some features that help in advanced correlation rules creation. However, intelligence around predictive analytics, understanding the current security posture and ability to map it with possible threats in the future is not something that is present in ArcSight at the moment.

For how long have I used the solution?

We’ve been using ArcSight for 3 years.

What do I think about the stability of the solution?

I have not had any issues with stability.

What do I think about the scalability of the solution?

I have not had any issues with scalability.

How is customer service and technical support?

I have never used technical support much, but will give it 3/5.

How was the initial setup?

The connectors are straightforward. The baselining is where the issues start.

What's my experience with pricing, setup cost, and licensing?

Licensing is straightforward, but the solution is fairly pricey.

Which other solutions did I evaluate?

We looked at QRadar and LogRhythm.

What other advice do I have?

Ensure your scope is very clear and so are the components.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Security Specialist at a tech services company with 501-1,000 employees
MSP
Correlation and flexibility are valuable. It helped meet compliance requirements for log collection.

What is most valuable?

Correlation and flexibility are the most valuable features.

How has it helped my organization?

ArcSight saved time and effort responding to security incidents with one centralized console and helped to meet compliance requirements for log collection.

What needs improvement?

I would like to see improvement in the complexity involved to create a custom connector (flex). Other SIEM solutions, like QRadar, have addressed this.

For how long have I used the solution?

We have used ArcSight for 6 years.

What do I think about the stability of the solution?

Initial deployment of ArcSight is pretty challenging. It takes at least 3-4 months to install, integrate, define content and fine tune before starting the security operation.

How are customer service and technical support?

Customer service is fast in response, but very standard in their approach, which takes lot of time for simple issues.

Which solution did I use previously and why did I switch?

I have used RSA enVision, QRadar and Splunk. ArcSight is better than them all when it comes to filtering, normalization, aggregation, dashboards, reporting and correlation, multi-tenancy and custom devices support.

How was the initial setup?

Initial setup was complex as the integration of a custom application takes lot of time and effort. Then, fine tuning requires at least 6 weeks to analyze and tune each alert separately.

What about the implementation team?

We implemented through HPE itself and I would advise to go through a vendor as they would hand over the SIEM post-fine tuning which is a mammoth task.

What was our ROI?

ROI can be measured in terms of detected security incidents and compliance positive tests, which in turn boost the business. Our security incident count increased from 3 per month to 46 and all were real security threats. Had those gone undetected and realized, there would have been possible data theft, information stealing, damage of brand reputation, etc.

What other advice do I have?

An organization that has enough budget for SIEM and really cares about security and not only about compliance must go with ArcSight. SMB organizations who want to start a SOC or have just a log management solution for compliance requirements can go for cheaper options such as QRadar, LogRhythm, AlienVault, etc. For MSSP, ArcSight is indeed the best SIEM available in the market, as segregation of logs, access restriction, different log retention, customized view for dashboard and reports to clients are present with ease.

Lastly, ArcSight is like Apple. If you have money, go for iPhone and you will certainly not regret it. But if your budget is the primary constraint, then another SIEM must be explored.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user415854 - PeerSpot reviewer
Senior Information Security Engineer at a tech services company with 501-1,000 employees
Real User
The user has multiple levels of options to generate reports and get alerted based on conditions.

Valuable Features

  • Collection - Collects logs from a wide range of products, even those not supported by default and the users can develop a connector for log collection.
  • Detection - Caliber to detect subtle attacks with a powerful correlation engine.
  • Report/Alert - The user has multiple levels of options to generate reports and get alerted based on conditions.

Improvements to My Organization

By using ArcSight ESM and its correlation technology, it thwarts multiple attacks from external sources before exploitations such as SQL injection, UNIX password file attempt, brute force to published servers, and more.

In addition, internal frauds have been prevented through preventing unauthorized login attempts to the firewall, database, critical servers, etc.

Room for Improvement

ArcSight Connector appliance needs some improvement, as it has some bugs which triggers issues most of the time. I believe that the Connector is going to hit end-of-service.

Deployment Issues

We experienced no issues with the deployment.

Stability Issues

We had the bugs in Connector as detailed in the Areas for Improvement section.

Scalability Issues

We've had no issues with scalability.

Customer Service and Technical Support

Customer Service:

3.5*

Technical Support:

Technical support should be improved. Many times, I've raised a case but none of them solved it and it took the guys from the Protect724 forum so solve my issue. The support team simply collects the logs from end users and makes you wait, and you carry on passing the same information which is available in the Admin guide.

Initial Setup

All you need is proper planning and pre-requisites information, and it's straightforward. Some newbies say that this product is hard to handle, but basically practice makes perfect.

Other Advice

HP are doing their job perfectly by bringing new features in every version, such as RepSM, HA capability, etc. It has never failed me.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user418164 - PeerSpot reviewer
Senior Security Consultant & Solution Architect at a financial services firm with 10,001+ employees
Real User
It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.

Valuable Features:

  • Alert correlation
  • Reporting
  • Retention

These are the features we find most valuable for us and which we use the most.

Improvements to My Organization:

It's able to track down security incidents faster and make for a more efficient investigation of a user's network activity based on the log data available.

Due simply to the user features available out-of-the-box, the convenience it can bring to any organization (when deployed and configured correctly) can greatly assist any enterprise in many facets, from an increased and enhanced security posture, to auditory regulations and even data retention.

Room for Improvement:

It needs additional and better user customization for SmartConnectors. It has additional device support for more obscure log sources.  

Also needed is a configuration wizard for organizations lacking the in-depth knowledge required to integrate the solution successfully.

Deployment Issues:

We've had no issues with deployment.

Stability Issues:

We've had no issues with instability. It's been stable for us.

Scalability Issues:

We've been able to scale it for our needs. We've had no issues with scalability.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Security Solutions Architect at a comms service provider with 10,001+ employees
Real User
Scalable though it is not "plug-and-play".

Valuable Features:

- Scalable though it is not "plug-and-play". 
- Various deployment configurations, based on requirements, budget and the EPS/GB per day
- Stable, performance predictable based on used capacity
- Integration with alerting/ticketing systems such as Tivoli

Improvements to My Organization:

- We use this product for managed SIEM services and its stability and maturity helps with standard deployments (hardly any surprises)

Room for Improvement:

- A bit on the slow side for reports requiring query of old data

- High availability achievable through complicated configurations (i.e. load balancers)

- The user interface is a bit dated

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2025
Buyer's Guide
Download our free OpenText Enterprise Security Manager Report and get advice and tips from experienced pros sharing their opinions.