ArcSight Competitors and Alternatives

Get our free report covering Splunk, IBM, and other competitors of ArcSight.
309,677 professionals have used our research since 2012.
Read reviews of ArcSight competitors and alternatives
Horacio Agustin Lo Brutto
Real User
Senior System Administrator at a tech services company with 11-50 employees
Apr 13 2017

What is most valuable?

In my understanding, the best features are: * DSMs (Device Support Modules), * Device auto-discovery, and * Hundreds of rules and reports... more»

How has it helped my organization?

I have implemented QRadar in a big airline company, where they needed to get all their security information in one place. It helped in reducing... more»

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing policies are really competitive. These solutions are not for a really small business, but having just one license... more»

Which solutions did we use previously?

I had the opportunity to use other SIEM solutions, but no one can provide what QRadar does, i.e., in terms of its simplicity, support or... more»

What other advice do I have?

You should ask the sales representative to give you the Excel sheet to calculate EPS. Keep in mind that the firewalls, proxies and networking... more»
RaulLapaz
Real User
Senior IT Security Operations at a pharma/biotech company with 10,001+ employees
May 25 2017

What is most valuable?

* The speed of the search engine * All the types of data sources that you configure can be forwarded to Splunk. * The... more»

How has it helped my organization?

The network department, for example, has improved its efficiency by 30%. Security relies on this for event correlation... more»

What needs improvement?

Cluster management can only be done via a command line. I would like them to add some GUI options for that. Permissions... more»

What's my experience with pricing, setup cost, and licensing?

It is not cheap :-)

Which solutions did we use previously?

We previously used ArcSight. Splunk is at another level. It is easier, more stable, and faster.

What other advice do I have?

My advice is to go ahead with it. The administration of the cluster and app deployment to indexers or search heads can... more»
Rohit Mazumdar
Real User
Security Specialist at a tech services company with 201-500 employees
Jul 04 2017

What is most valuable?

In the investigation panel, you can drill down to any specific metadata values for any event source.

How has it helped my organization?

The custom dashboard and correlation alerts in this solution improved our incident response process.

What needs improvement?

Sometimes the investigation panel and reporting engine work very slowly.

What's my experience with pricing, setup cost, and licensing?

If you get a good discount on the product, or if you feel you need a less expensive solution compared to QRadar or... more»

Which solutions did we use previously?

We used Envision. It was outdated, so we switched to this solution.

What other advice do I have?

It's very simple to implement. The only problem is with the high availability mode for VLC. If you want this, work with... more»
Vagner Araujo Silva
Real User
Information Security Analyst at a tech services company with 501-1,000 employees
May 11 2017

What is most valuable?

The easy interface is the most valuable feature.

How has it helped my organization?

Through correlation rules, it finds malware that compromised the computer that anti-virus and other security solutions... more»

What needs improvement?

I had a couple of problems collecting Windows events. The local plugin should be easier to use, because when ESM is... more»

What's my experience with pricing, setup cost, and licensing?

The product is worth the price. There are other cheaper tools in the market, but it is harder to work with them.

Which solutions did we use previously?

I used different solutions, but for different clients.

What other advice do I have?

Stay focused, read the documentation, plan it well, and the project will be a success.

Sign Up with Email