ArcSight Logger Valuable Features

Nagendra Nekkala. - PeerSpot reviewer
Senior Manager ICT & Innovations at Bangalore International Airport Limited

The solution provides information about the risk factors. It also provides information on our security exposure.

View full review »
Subhadip Pakrashi - PeerSpot reviewer
CEO at Kapstone Technological Services LLP

It is a proven technology. It is one of the best products available in the market. Loggers generally pull the logs and send them to the main orchestration device. Loggers connect to the SIEM tools, and the solutions speak to each other. It is pretty good.

If we want to increase the capacity of the SIEM tool, the events per second can be increased. Loggers are the only way to fetch the logs. It depends on the customers’ requirements. ArcSight Logger sends the logs. The SIEM system is the main component.

Less false positives will lead to a better solution. If there are more false positives, the solutions provided by the SIEM tool will be diluted. The data retention capabilities depend upon the size of the hard disk. The bigger the hard disk, the more the data can be stored. The integration with other security solutions is good. It's a proven solution in the market.

View full review »
Mohammad Sabah - PeerSpot reviewer
Senior Security Analyst at a government with 201-500 employees

We check a lot of logs in ArcSight Logger because we're running a massive database platform.

View full review »
Buyer's Guide
ArcSight Logger
April 2024
Learn what your peers think about ArcSight Logger. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
Rikin Rathod - PeerSpot reviewer
Senior Officer IT at Tech Data Limited

ArcSight Logger’s most valuable feature is visibility. It provides in-depth information on business activities once we log into the system.

View full review »
Ben Nnatuanya - PeerSpot reviewer
Manager, Security Operations Centre at Phillips Consulting Limited

The machine learning is a good feature. 

View full review »
Ademayokun Daini - PeerSpot reviewer
Cyber Security Engineer at MTN

The log digestion features from threat intelligence platforms like Recorded Future or Talos are valuable.

View full review »
Hassan Moussafir - PeerSpot reviewer
Information Security Senior Expert at Wafaassurance

The solution offers very good performance and is efficient.

The provider offered excellent training to help us successfully launch the project.

The interface is user-friendly.

The solution passed compliance thresholds and standard requirements which we hoped to satisfy at the time of launch. At our first audit, we presented the roadmap to our auditor and on the second audit, we presented plans to help us re-conduct our certification. They were able to verify the parameters and reporting. It was very successful.

View full review »
MA
Senior ArcSight and IBM resileint (SOAR) administrator at a comms service provider with 1,001-5,000 employees

The provisioning engine is a valuable feature of the solution.


View full review »
it_user915744 - PeerSpot reviewer
Vulnerability Assessor at Telenor Common Operation

The ESM use cases are the most valuable. It enables us to use the big data collection inside our company. We are able to create use cases for whatever it suits and I find that the most interesting part of any SIEM solution.

View full review »
Prischal Bahgoo - PeerSpot reviewer
General Manager at VIC IT

I am impressed with the product's ability to pick up logs. It also has UEBA which has reduced the time to take charge of the events. 

View full review »
it_user417534 - PeerSpot reviewer
Network Specialist with 1,001-5,000 employees

The functionalities of this particular server is absolutely phenomenal. The server has the ability to provide in-depth, real-time awareness of all actives on the network.

The platform also gives the administrators the ability to turn off some of the options displayed in case they don't need to see those specific sections.

The ability to query anything at any time using any specific field required, and the ability to automate the logger storage capabilities are great features.

View full review »
Olajide Olusegun - PeerSpot reviewer
Network Team Lead at Atlas Security

ArcSight's robustness is its most valuable feature. The solution is specifically designed to manage and aggregate large amounts of log data, making it an ideal solution for Syslog servers with a large environment of network devices and servers (both VM and physical appliances).

View full review »
PN
Senior Information Security Analyst – GRC at a transportation company with 1,001-5,000 employees

ArcSight provides the basic information that we want.

View full review »
SV
Founder & CEO at a security firm with 10,001+ employees

It's a robust, mature product and you can do some complex operations and analytics.

For correlation and structuring data, it's very good.

It's a secure platform.

View full review »
HF
CISO at a financial services firm with 1,001-5,000 employees

The ability to customize the solution in great detail is its most valuable feature. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive. 

View full review »
SA
Security Professional at a tech services company with 501-1,000 employees

As the name suggests, it's a brilliant log collection tool, and it can handle hundreds of thousands of servers in a single shot to ingest the data.

The search operations are very fast, and you can get reports very easily for a huge number of events. You can export the search operations.

It's very easy when you want to further forward the logs as well. For example, from the end device if I'm receiving logs in an outside logger and I want to forward those to some other product, which will do something for me, I can easily do it. That's one thing that I like about it.

View full review »
it_user159090 - PeerSpot reviewer
Senior Security and Compliance Engineer at a retailer with 501-1,000 employees

It has excellent query syntax and response. Complex queries of large volumes of data generally take seconds if not minutes.

View full review »
it_user409197 - PeerSpot reviewer
Security Architecture Senior Specialist at a comms service provider with 1,001-5,000 employees
  • Scalability of the smart connectors
  • Ease of storing billions of events without special storage needs
  • Great compression rates
View full review »
SS
Security Engineer at a tech services company with 1,001-5,000 employees

Some of the most valuable features I really appreciate are the performance, how quick the solution is, and how easy it is to create a query. Additionally, it is user friendly and the automatic graph creation feature is beneficial. 

View full review »
it_user414390 - PeerSpot reviewer
QA Consultant / Security Testing Professional at a tech company with 501-1,000 employees
  • Log collecting
  • Big Data analytics
  • Security analytics
View full review »
it_user418134 - PeerSpot reviewer
IT Security, Associate Consultant - On-location at a tech company with 501-1,000 employees

Several features are valuable to us, including --

  • Log management in general
  • Security options
  • Integration with ArcSight SIEM as it uses the same connectors
  • Simple GUI
  • Powerful searching and reporting tools
View full review »
AR
Technical Consultant at a tech services company with 11-50 employees

In our country we are a little bit private in terms of solutions, so we are just starting to use the basic data capture. Now some users can start to use additional features that come with Micro Focus ArcSight like user behavior analytics for investigating.

View full review »
it_user417555 - PeerSpot reviewer
IT Security Operations Manager at a recruiting/HR firm with 1,001-5,000 employees

Data correlation, which unfortunately only comes with an ESM module, is the most valuable feature for us.

View full review »
MS
Senior Security Analyst at a government with 201-500 employees

The most valuable feature is the search capability, which is simple to use. We can easily search for certain events.

View full review »
it_user1141698 - PeerSpot reviewer
Team Lead at a tech services company with 51-200 employees


Various log collecting methods helps customers to route logs from almost every application or device.In terms of ArcSight Logger's most valuable feature, it is their scalability and flexible log collecting options. ArcSight's real advantage is its scalability because they have two layers, Logger layer and correlation layer. So customers may benefit from this when it comes to licensing and designing. For example, let's say the customer wants to only have a logger requirement, they have the flexibility to only use the logger layer, instead of suggesting all the other layers. I don't see this kind of flexibility in other vendors.

View full review »
it_user1052814 - PeerSpot reviewer
SOC Analyst at a tech services company with 11-50 employees

The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console.

The searching is very good, where you can search for the larger part of the event.

View full review »
it_user417468 - PeerSpot reviewer
Security Solutions Delivery Engineer at a tech services company with 1,001-5,000 employees
  • Real-time correlation
  • Long-term log storage
View full review »
it_user417453 - PeerSpot reviewer
SIEM Administrator at a tech services company with 1,001-5,000 employees

The most valuable features for us are the out-of-the-box device support capability and multi-tenancy maturity compared to other SIEM OEMs.

View full review »
Buyer's Guide
ArcSight Logger
April 2024
Learn what your peers think about ArcSight Logger. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.