ArcSight Enterprise Security Manager (ESM) Implementation Team

DB
Security Operations Director at Axon Technologies

We used two architects and three engineers on our team for deployment, and the team from ArcSight had nearly an equivalent amount. We handled deployment in-house, and we fully deployed it enterprise-wide in about six months. We had HP ArcSight certified engineers and architects, and then we sent a handful of our own engineers to HP so they could become fully ArcSight certified. Their engineers and our certified engineers then worked hand in hand in kind of a mentor, mentee relationship to ensure that our team had full knowledge and capability going forward.

The first step of deployment was scoping and sizing for five-year growth, based on what we were currently running in the older product, which was QRadar, and so then once we determined what size infrastructure we needed, we deployed that infrastructure. That took about a month. From there, we then on-sourced non-critical assets for testing and piloting. Once we had that done, we deployed the agents for the use to our SOC, and then we ran both systems in parallel to make sure that use cases reported over correctly, and they were all fine-tuned.

Once we had them working on our test samples, we then did a rapid deployment across the entire environment. We ingested everything from the old system into the new one to the log collector. Once all the old logs were in there, we then switched over to real-time and transferred the real-time logging from the old system to ArcSight, and then that system was live. We did one after the other, and that's what took the six-month window, because after about a three-month deployment of getting all 35,000 log sources ingested and up and running, it took about another three months to do the rest.

View full review »
AbhishekMishra - PeerSpot reviewer
Technical Lead Project Individual Contributor at DXC

A consultant is required for smooth setup.

View full review »
it_user858882 - PeerSpot reviewer
Business Development Manager- Threat Management Services at Insight Enterprises, Inc.

We implemented it in-house.

View full review »
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,995 professionals have used our research since 2012.
Anand-Dutta - PeerSpot reviewer
Head Global Alliances Director at Tech Mahindra Limited

We implemented ArcSight Enterprise Security Manager (ESM) ourselves.

View full review »
Riccardo Rosso - PeerSpot reviewer
Consultant at Libero

We used a provider team.

View full review »
Wessam Altoumi - PeerSpot reviewer
Chief Commercial Officer at Yamamah Information Technology & Communication Systems LLC

We have approximately six people from our information security department managing ArcSight ESM. The deployment was done by four engineers.

View full review »
it_user409212 - PeerSpot reviewer
Cyber Security HP Arcsight Dev Ops Lead Developer with 10,001+ employees

The installation had already been implemented by an HP subsidiary who were fairly good when performing the installation. Despite that, they did a poor job of implementing the hardware.

View full review »
HungTran2 - PeerSpot reviewer
Technical at HPT Vietnam

I did the implementation of ArcSight ESM myself. We have two people for maintenance.

View full review »
it_user417483 - PeerSpot reviewer
Senior IT Security Consultant, Cybersecurity Technology Services at a consultancy with 1,001-5,000 employees

ArcSight makes it easy to achieve ROI because of its great flexibility.

View full review »
it_user147210 - PeerSpot reviewer
Sr Security Engineer at a tech services company with 51-200 employees
In-house experts. View full review »
TB
IT Manager at Royal Cemerlang

We used a partner for the implementation. 

View full review »
it_user409143 - PeerSpot reviewer
Security Manager at a tech services company with 10,001+ employees

We had an in-house implementation. I would recommend a dedicated team for implementation, support, and operation.

View full review »
it_user401874 - PeerSpot reviewer
Information Security Specialist at a tech services company with 501-1,000 employees

We implemented through HPE itself and I would advise to go through a vendor as they would hand over the SIEM post-fine tuning which is a mammoth task.

View full review »
JA
Forensic Consultant at A Cyber 1 Company

We implement in-house, and it takes approximately two months to complete implementation.

View full review »
LH
Works at NOOSC Global

A reseller assisted our customer with the deployment.

View full review »
it_user142611 - PeerSpot reviewer
Information Security Professional at a financial services firm with 1,001-5,000 employees
With the help of a vendor team. They are really helpful and cooperative. View full review »
it_user409203 - PeerSpot reviewer
Security Business Analyst at a tech services company with 10,001+ employees

We did it in-house with help from the vendor's professional services. My advice is to think first where you would like to put your collectors. Assess if your network will be able to lift extra loads, assess what logging level will be required, and if log sources are capable of delivering it.

View full review »
VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees

We implemented it in-house.

View full review »
BS
Head - Professional Services at a computer software company with 51-200 employees

We deploy the solution for our clients. We also tend to handle the maintenance for our clients as well.

View full review »
SW
Senior Manager at a tech services company with 51-200 employees

We used an integrator for the implementation of ArcSight ESM.

View full review »
it_user402840 - PeerSpot reviewer
Senior Manager Fraud Services at a financial services firm with 1,001-5,000 employees

We bring in an HP consultant for development and implementation.

View full review »
AB
Associate Vice President at a consumer goods company with 201-500 employees

We handled the implementation in-house.

View full review »
VN
Senior Manager at PT Permata Anugerah Abadi

We implement the solution and maintain it for the clients.

View full review »
it_user661260 - PeerSpot reviewer
Security Consultant at a tech services company with 5,001-10,000 employees

We did not use a vendor team to do the implementation. Our in-house teams could roll out ArcSight very well. Cooperation of a lot of teams is often needed to implement SIEM solutions: networking, OS, and compliancy. Depending on your company structure, cooperation between teams can cost the most time.

View full review »
it_user597603 - PeerSpot reviewer
Manager at a financial services firm with 1,001-5,000 employees

We carried out a pilot implementation based on the initial SOW, including several basic use cases. This allowed us to understand what is really happening in the environment and we learned that most of the default rules are not appropriate for us. After the pilot was successful, we bought the solution.

View full review »
it_user417585 - PeerSpot reviewer
Information Security Architect at a tech services company with 51-200 employees

As a system integrator, I always say that implementation must be done by an experienced team. SIEM solutions are not easy, so if time is important, do not rely on doing it haphazardly.

View full review »
OO
Cyber threat Intelligence Manager at CyberLab Africa

We had assistance with the implementation of the solution. We have approximately five individuals that do the maintenance.

View full review »
it_user428250 - PeerSpot reviewer
System Engineer at a tech services company with 51-200 employees

I work for a reseller, and we set up ArcSight for our customers, and I am learning a lot about its architecture.

View full review »
it_user126918 - PeerSpot reviewer
Information Security Consultant with 1,001-5,000 employees
Vendor. They had a good amount of ArcSight implementation experience. View full review »
it_user126648 - PeerSpot reviewer
Senior Security Analyst at a tech services company with 10,001+ employees
Through an in-house team. View full review »
MJ
Techniqal Lead Enterprise Solution at a tech services company with 51-200 employees

We provide the implementation and maintenance services of the solution for our customers.

View full review »
Buyer's Guide
ArcSight Enterprise Security Manager (ESM)
April 2024
Learn what your peers think about ArcSight Enterprise Security Manager (ESM). Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,995 professionals have used our research since 2012.