ArcSight Review

The CORR engine and ability to build complex correlations from simple 'building blocks' are the most valuable features for us.


Valuable Features

The real-time correlation (CORR) engine and ability to build complex correlations from simple 'building blocks', provided the base 'building blocks' are well throughout in the first place, are the most valuable features for us.

Improvements to My Organization

The ways in which it's improved our organization are too numerous to mention. But you have to have good, steady resources and well worked-out use cases. ArcSight can report on many things and save on repetitious daliy monitoring.

Room for Improvement

There's a lot of improvements that need to be made, too many to mention all of them, but some improvements with the Con App would be a good start.

Use of Solution

We've used it for over eight years.

Deployment Issues

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

Stability Issues

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

Scalability Issues

We did have issues at the start, but this comes down to having good HP ArcSight architects to start with, which we didn't when the project started.

Customer Service and Technical Support

With HP themselves, they need a lot of pushing to get them to get seriously involved with issues, given that they are paid a lot of money to provide support and deliver top SLAs.

Previous Solutions

We mainly use HP ArcSight, but also Splunk. I didn't have a say in making the choices.

Initial Setup

The initial setup was fairly straightforward, but the overall architecture planning needs seasoned professionals who understand what ArcSight is and how it needs to be deployed.

Implementation Team

The installation had already been implemented by an HP subsidiary who were fairly good when performing the installation. Despite that, they did a poor job of implementing the hardware.

Pricing, Setup Cost and Licensing

The HP products are expensive.

Other Advice

It's a fantastic product and highly configurable, but it needs nothing less than a seasoned cyber security professional with serious engineering expertise and a real desire to provide meaningful use cases. Anyone that says ArcSight is 'fire and forget' should not be allowed to work in cyber security!

If you want Arcsight implemented correctly, start by sizing your organization, and looking at data flows and the available data streams. Be mindful of regulatory and compliance reporting, Risk and Legal as well, as you may need to factor in any and all of these when working with enterprise solutions.

Disclosure: My company has a business relationship with this vendor other than being a customer: We have a business relationship in place with HP.
Add a Comment
Guest
Sign Up with Email