Chief Information Officer at Bassein Catholic Co-Op Bank
Real User
A fast, stable, and scalable solution with good reporting and log analysis functionalities
Pros and Cons
  • "The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data. Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions."
  • "When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform. In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier."

What is our primary use case?

We have outsourced our SOX management to an IT company because I cannot maintain and manage that in the bank. We had selected them because they were using ArcSight. They are a very professional security company. They came up with this suggestion of switching from ArcSight to LogRhythm. We are currently using ArcSight, but we would be switching to LogRhythm.

They are using the latest version of ArcSight ESM. It is all on-prem. Our production setup cannot be on a public cloud. In India, cloud deployment is not allowed for financial services. It has to be either a co-location or in-house.

What is most valuable?

The reports that we are from getting from ArcSight are very valuable. The reporting in ArcSight is good. Our regulators ask us for the reports on a regular basis, and we have been able to provide the required data.

Its overall functionality in terms of log analysis and the speed at which it does that is also valuable. It is very quick. Whatever alerts we had configured were extremely fast. We immediately get alerts when there is unauthorized access or unknown access, or even positive access. This is where we found the difference between ArcSight and other solutions.

What needs improvement?

When I asked our networking juniors for a comparison between LogRhythm and ArcSight, they said that both platforms are almost the same. It is just that LogRhythm is more modern with a digital platform, which probably gives it some advantage over ArcSight. ArcSight is a very old and mature product that is running on an old platform. It is an old legacy platform. 

In terms of new features, it just requires platform upgrades so that it becomes lighter and easily adaptable, specifically in the cloud. It would be a good thing if they can also make reporting easier. 

For how long have I used the solution?

We have been using this solution for one year.

Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is pretty stable.

What do I think about the scalability of the solution?

It is pretty scalable.

How are customer service and support?

I have not been in touch with ArcSight for technical support. I only talked to my vendor, who monitored my network. My vendor got in touch with ArcSight support.

How was the initial setup?

The setup ran into a couple of months because the configuration of the endpoint devices to collect the logs was really tedious. It took some time to bring the environment into a condition to get it monitored by ArcSight.

What other advice do I have?

It is a very good product. I would rate ArcSight ESM an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Riccardo Rosso - PeerSpot reviewer
Consultant at Libero
Consultant
Top 20
Powerful and comprehensive program but complex and cumbersome for non-experts
Pros and Cons
  • "ArcSight ESM allows us to find if someone is doing an administrative operation at inappropriate times of day or trying to do something they're not allowed to."
  • "ArcSight ESM's UI is a little cumbersome and complex, especially for first-time and occasional users using the console manager."

What is our primary use case?

I primarily use ArcSight ESM for security and network monitoring. We are dealing with Active Directory, so we use ArcSight ESM to track the actions administrators take on accounts, like disabling and enabling accounts or accounts going expired and why.

How has it helped my organization?

ArcSight ESM allows us to track the logging of our customers or providers through VPN to a security middleware that tracks and allows them to access backend resources. In this way, we can find if someone is doing an administrative operation at inappropriate times of day or trying to do something they're not allowed to.

What needs improvement?

ArcSight ESM's UI is a little cumbersome and complex, especially for first-time and occasional users using the console manager. It's also a very complex product, and new users will require assistance from someone expert to avoid making errors. 

For how long have I used the solution?

I've been using ArcSight ESM for three years.

What do I think about the stability of the solution?

ArcSight ESM is stable, except when you're doing very complex correlations, but that's a problem common to all products in this area.

What do I think about the scalability of the solution?

We have not had any problems with ArcSight ESM's scalability.

How are customer service and support?

ArcSight's technical support is very good.

How was the initial setup?

The initial setup was not so easy as it's a very technical product, and anybody who doesn't have a lot of technical knowledge will probably find it difficult to set up. It's important to have a clear understanding of your goals when setting up all the infrastructure, as ESM is so complex. The deployment took around an hour or two.

What about the implementation team?

We used a provider team.

What other advice do I have?

ArcSight ESM is a very powerful platform, but you have to be careful in designing rules and defining an initial set of targets because otherwise, you could end up with high costs or a hugely demanding setup. I would rate ArcSight ESM seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Sr. Group Manager at WNS Global Services
Real User
It provides us the flexibility to write our own passwords and customize the solution.
Pros and Cons
  • "ArcSight ESM provides us the flexibility to write our own passwords and customize the solution. It lets us search and log a variety of SmartConnectors. It has 480-plus SmartConnectors."
  • "Sometimes, it takes ages to get an issue resolved. I have ArcSight experience, so I normally try to fix things on my own or find a workaround, but it's tough to get support when I need it."

What is most valuable?

ArcSight ESM provides us the flexibility to write our own passwords and customize the solution. It lets us search and log a variety of SmartConnectors. It has 480-plus SmartConnectors. 

What needs improvement?

ArcSight's features are already ahead of many competitors, but may they could offer some more training about how to find tools, how to get them working, and how to optimize them. I'd also like to see a greater focus on cloud content and the ability to write rules from the browser.

For how long have I used the solution?

We've been using ArcSight ESM for around 10 years.

What do I think about the scalability of the solution?

ArcSight is scalable. I started out with three data centers, and now I have it deployed at more than 48 locations.

How are customer service and support?

I rate ArcSight support seven out of 10. Sometimes, it takes ages to get an issue resolved. I have ArcSight experience, so I normally try to fix things on my own or find a workaround, but it's tough to get support when I need it.

It goes on for days. If you call in the morning and explain it to the engineer, but the issue isn't fixed, you have to explain it to another person when the shift changes. It's usually okay, but it can be challenging if you're dealing with an urgent issue and you don't have the proper documentation.  

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used McAfee Nitro, IBM QRadar, and DNIF HyperCloud. Other solutions aren't as simple to set up or as stable. ArcSight is better in terms of coverage. The technology is more than 20 years old.

How was the initial setup?

The setup is quite simple, and the documentation is thorough. 

Which other solutions did I evaluate?

We looked at three other solutions. I was working for a government organization, and there was an Indian company developing its own team. ArcSight was head and shoulders above the rest in features like aggregation filtering, bandwidth, parsing, etc. It was there.

Hopefully, we're still way ahead, but the IT data architecture is getting a bit complex with the introduction of Kubernetes and everything. It will be complicated in terms of resources, deployment, etc., but I think ArcSight can still be what it used to be if we sort this out.

What other advice do I have?

I rate ArcSight ESM seven out of 10. I would recommend ArcSight depending on an organization's needs. I don't have much experience in terms of pricing, but ArcSight can provide a lot of functionality if a company requires it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
PeerSpot user
Senior Manager of System Security with 501-1,000 employees
Vendor
4 stars, not 5 due to the sheer magnitude of work and understanding to have a highly functioning implementation.

What is most valuable?

Custom data parsers and custom event / asset categorization.

How has it helped my organization?

Allowing for non conventional data feeds from HR into our overall security monitoring practice has allowed us to catch gaps in our exit checklist for employees among other things.

What needs improvement?

The network modeling and asset categorization needs to be simplified to facilitate wider adaptation amongst customers.

For how long have I used the solution?

I have been working with ArcSight for over 8 years.

What was my experience with deployment of the solution?

I have never deployed an ArcSight installation without encountering several issues, I have over 40 deployments to my credit.

What do I think about the stability of the solution?

Absolutely, the new CORR engine is a vast improvement but was pushed out to customers too quickly. Several key components of our analysis workflow broke due to the new event processing scheme.

What do I think about the scalability of the solution?

Not so much on the ESM level, but it gets expensive to scale at the logger level.

How are customer service and technical support?

Customer Service: Support can use vast improvements, but your technical account managers are great. No complaints there.Technical Support: Lacking.

Which solution did I use previously and why did I switch?

I am a Sr. Principal Architect and design and go with the best solution for the customer, currently deploying a solution around Logstash, elasticsearch and kibana.

How was the initial setup?

Lots of moving parts.

What was our ROI?

Hard to determine, ArcSight is a product that costs millions to implement and takes several months to years before the ROI is clear.

What's my experience with pricing, setup cost, and licensing?

For this particular project $2.4 million USD.

What other advice do I have?

Understanding of your environment and data sources is key before correlation can occur. You make sure your environment is at a point that augmentation of the existing analysis workflow is required and not using a SIEM to establish one.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user215616 - PeerSpot reviewer
it_user215616IT Architect | ITSM ; IT GRC Leader at a tech company with 51-200 employees
Consultant

Thanks !! Review is useful and truly looks like given by someone who has actually worked with the product.

Seshi Dumpa - PeerSpot reviewer
IT Security Manager at a tech services company with 10,001+ employees
Real User
Top 5
A robust solution that helps us with our internal log and threat analysis
Pros and Cons
  • "It is a robust product and has multiple valuable features."
  • "The dashboard looks a bit cumbersome."

What is our primary use case?

We use it for our internal and vendor daily base of log analysis and threat analysis.

What is most valuable?

It is a robust product and has multiple valuable features. For example, it has robust threat intelligence built into its customization and great templates that provide ease of use.

What needs improvement?

The dashboard looks a bit cumbersome with the current version. They should work on the dashboard and optimize their integration which currently lags with devices of reputed vendors. So, having these custom integrators sometimes works and sometimes doesn't.

For how long have I used the solution?

We have been using this solution for almost ten years. It is deployed on private cloud.

What do I think about the stability of the solution?

We haven't experienced any stability challenges. It works if we get enough hardware and software provisions for the vendor recommendation.

What do I think about the scalability of the solution?

On-premises is a challenge to scale, and we haven't tried the cloud but we've heard it's quite scalable and robust.

How are customer service and support?

We do not use technical support that often. They are very good, but they should train their L1-level support. Overall, they're a good strong team.

How was the initial setup?

The setup is neither easy nor difficult and depends on the expertise. It requires really good expertise to build from scratch. The setup itself is not a big hassle, and in a week, the system is up and running, but the main challenge is the integration. We keep integrating, and with the password of the integrated direct, it's fine.

What's my experience with pricing, setup cost, and licensing?

It is a licensed product.

What other advice do I have?

I rate this solution an eight out of ten in terms of the inbuilt features and how it has grown into a strong solution over the years. The team has done an excellent job with the features, integrations, and compatibility.

Regarding advice, I think the assessment on currently sizing the product to their need is key. It's an expensive product, so sizing is the most important choice. In addition, I believe moving to cloud has more robust integration features. They are building new custom solutions that can be integrated with ESM for better analysis.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Abbasi Poonawala - PeerSpot reviewer
Chief Enterprise Architect at a financial services firm with 10,001+ employees
Real User
Top 5Leaderboard
User interface and setup are good and speedy; deployment typology could be improved
Pros and Cons
  • "The user interfaces are quite good and speedy."
  • "Deployment typology could be improved. Difficult to scale across all the different lines of businesses."

What is our primary use case?

ArcSight monitors any down time with patch management. Whenever any project is on-boarded such as in our security core or asset and wealth management technology, the hardware goes through ArcSight. That is basically our use case whether we're doing the patch management, or the upgrades on that tool, or managing the centralized desktop. ArcSight monitors the failures in the cloud. We have the tech classifications in the CMDB which is integrated with ArcSight and ArcSight pulls out everything on the CMDB and I'm able to see it all - the CMDB database and the CVS scores which are also integrated in ArcSight. I can know that for a particular monitoring track or detected incident, this is the particular CVS score. I'm a VP and enterprise architect, and we're customers of ArcSight. 

What is most valuable?

The user interfaces are quite good and speedy, and I like the consoles too. The typology and the setup are also good. It's very similar to QRadar, so it's user friendly although I believe QRadar rates better. 

What needs improvement?

The deployment typology could be improved. If you want to scale across all the different lines of businesses, it should be easy to do that and it's not. If I'm doing DMX monitoring, I shouldn't need a different SIEM. For the traditional application servers which are RTTR architecture-based, the legacy applications, which might be Java or steam-based applications, require DMX monitoring, currently provided by Nagios. Instead, the monitoring could be different types of monitoring which we could get from ArcSight. It would save the cost of doing the DMX monitoring from Nagios. QRadar has a dashboard which includes most of the monitoring, data and everything. The features in ArcSight could be more like that.

For how long have I used the solution?

I've been using this solution for 10 years. 

What do I think about the scalability of the solution?

Scalability is okay although if we had better typology, we could scale more and performance could be better. It's similar to QRadar. We are onboarded for security core processing or data disk core processing. If I wanted to add another 20 line of businesses under that, it should be okay. There's a trade off between the security and performance so the more secure your typology is, will result in degraded performance. We currently have around 2,000 users but hope to increase that number. 

How are customer service and support?

Technical support is available 24/7, They are on a rota basis for the different regions. If I'm looking for support here in India, it's available 2 1/2 hours ahead of Singapore, 3 1/2 hours ahead for the Japanese team. In the UK region, we have support available from 11:00am. And if I'm looking for post 7:00pm in India, then I have the support teams available from the States. They're quite good and they offer other professional services too, including for incident management. 

How was the initial setup?

The initial setup doesn't take too much time. 

What other advice do I have?

I'm neutral on whether I would recommend this solution. It depends on what typology you are using, and your use cases. If you have a different endpoint, or security tool already doing what this product does and it's already integrated with CMDB, and there's a tool at the endpoint giving the CVS Score, then you don't need an SIEM platform. 

On the pricing side, QRadar is much costlier compared to ArcSight. There's a trade off. Anyone aiming for something specific will go for ArcSight monitoring rather than going for Qradar because deployment of the SIEM is not so easy for the larger deployment typologies in the financial services sector. It's not easy to scale up for different lines of businesses unless you have proper planning, methodologies, processes, and your SOPs are in place. If you follow the proper SOPs, things are easier.

I would rate this solution a six out of 10. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Md. Shahriar Hussain - PeerSpot reviewer
Cybersecurity and Compliance Lead Engineer at Banglalink
Real User
Top 5Leaderboard
Other solutions perform better and have a slicker GUI, but this one is cheaper
Pros and Cons
  • "We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens."
  • "ArcSight ESM needs to improve performance, user interface, and automation."

What is our primary use case?

We use ArcSight ESM for log analysis and security alerts. It warns us of threats and then helps us conduct a forensic investigation of a cyber attack or internal incident after it happens.

How has it helped my organization?

ArcSight ESM helps us stop security incidents by detecting them early before they can cause more damage. 

What needs improvement?

ArcSight ESM needs to improve performance, user interface, and automation.

What do I think about the stability of the solution?

ArcSight has become more stable with the latest patches that have come out, but we also have had many difficulties applying the patches

What do I think about the scalability of the solution?

It's costly to scale up ArcSight ESM, but it's scalable. You have to pay for extra storage, licenses, and log processing.

How are customer service and support?

ArcSight support is okay but slow. It isn't provided promptly. There is a vast time difference between American time and East Asian time. 

How was the initial setup?

Setting up ArcSight is very complex. Nothing about it is user-friendly.

What's my experience with pricing, setup cost, and licensing?

ArcSight's price is reasonable. That's why our company was forced to buy this. It's cheaper than some of the better solutions. 

Which other solutions did I evaluate?

LogRhythm has a better GUI and some automation options, like an automated password writing script. In Exabeam, I can see an event with the user's picture, which Exabeam can draw from the Active Directory. It has a better GUI, better performance, and customization. I expect these things from ArcSight, but it can't deliver yet.

What other advice do I have?

I rate ArcSight three out of 10. I would never recommend it. I would recommend QRadar, LogRhythm, or Exabeam, but they all cost more. Price is its only advantage.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Ashraf Abbas - PeerSpot reviewer
Information and Cyber Security Analyst at a financial services firm with 10,001+ employees
Real User
Top 20
The best on-prem SIEM solution that lets you do what you want and has good filtering, scalability, and support
Pros and Cons
  • "The filters and the ability to do what you want are the most valuable features. There is nothing that you cannot do in this solution. It has all the features, which makes it very dynamic."
  • "I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions. We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved."

What is our primary use case?

We have many use cases. Our Windows devices, antivirus, and firewall are integrated with ArcSight. I have used ArcSight ESM versions 6.1.1, 6.9, 7.0, and 7.2.

What is most valuable?

The filters and the ability to do what you want are the most valuable features. There is nothing that you cannot do in this solution. It has all the features, which makes it very dynamic.

What needs improvement?

I am having issues with report generation with older versions. I don't know if this is because of compatibility issues, but report generation has been a little bit difficult in older versions. It is not similar to the newer and current versions.

We are looking at moving to the cloud. It would be good if ArcSight ESM can move to the cloud. They already seem to be working on this. 

It would also be very helpful and great if we can integrate external threat intelligence, machine learning, and AI into this solution. It has good dashboards, but they can always be better. Its stability can also be improved. 

For how long have I used the solution?

I've been using ArcSight for three years. I started using it in February 2019.

What do I think about the stability of the solution?

It is stable, but its stability can be better. I would rate it a four out of five in terms of stability.

What do I think about the scalability of the solution?

It has been good when it comes to scalability. As an MSSP, we provide services to other customers, and we have customers with different capacity requirements. It is good in terms of moving from one particular size to another.

How are customer service and technical support?

They have been great. They are friendly and good.

How was the initial setup?

Its initial setup is straightforward. The deployment duration depends on the environment. It doesn't take time for our own environment, but I've heard some people complaining about the time period for which they have to wait for the deployment to take place.

What's my experience with pricing, setup cost, and licensing?

ArcSight can be a little bit expensive because of the area that we work in and the cost. Licensing is mostly on a yearly basis, not monthly.

What other advice do I have?

I would recommend this solution to anyone looking for an on-prem SIEM solution. It has been the best SIEM solution that I've worked with.

I would rate ArcSight ESM a nine out of ten. It is a great solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free ArcSight Enterprise Security Manager (ESM) Report and get advice and tips from experienced pros sharing their opinions.