ArcSight Analytics vs Aruba IntroSpect comparison

Cancel
You must select at least 2 products to compare!
OpenText Logo
308 views|149 comparisons
66% willing to recommend
HPE Aruba Networking Logo
252 views|159 comparisons
100% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between ArcSight Analytics and Aruba IntroSpect based on real PeerSpot user reviews.

Find out what your peers are saying about IBM, Splunk, Rapid7 and others in User Entity Behavior Analytics (UEBA).
To learn more, read our detailed User Entity Behavior Analytics (UEBA) Report (Updated: April 2024).
767,667 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"ArcSight Analytics has improved our system and network policy monitoring.""The two most valuable features of this solution are its stability and scalability.""One of the most valuable features is the alerts.""ArcSight Analytics is used to get a deeper insight and threat analysis about the network.""The correlation engine is good.""The ability to correlate different logs is the solution's most valuable feature.""This solution makes it easy to create use cases, and it is easy to move queries from use cases to the report to the dashboard.""The most valuable features are that you get lots of connectors, which make it easy to log in to my ASM, and lots of prebuilt roles from the company."

More ArcSight Analytics Pros →

"I haven't heard of any issues with stability.""The most valuable feature is the end-user monitoring. If there is any abnormal behavior on the machine, the administrator will be alerted.""Roaming feature, application control and firewall features."

More Aruba IntroSpect Pros →

Cons
"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training.""Inactive connections from servers, which are upgraded or downgraded within a VM, should be automatically revoked.""ArcSight is not a user-friendly solution and the interface needs to be improved.""Network integration is very crucial, and you need to have the knowledge to get it done.""The customer service could be improved, and additional integrations with other APIs could be added.""Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors.""Their support team could be better.""There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."

More ArcSight Analytics Cons →

"Technical support is a little slow.""I would like to see improvements made to the dashboard, where you can get the information with a simple click.""The packet analyzer needs improvement."

More Aruba IntroSpect Cons →

Pricing and Cost Advice
  • "ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
  • "The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
  • "In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
  • "It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
  • "This solution is expensive."
  • "My customers pay a yearly licensing fee for ArcSight Analytics."
  • More ArcSight Analytics Pricing and Cost Advice →

  • "The license is based on the number of users. The evaluation license is free, you can download it from the website and try it out first."
  • More Aruba IntroSpect Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
    767,667 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:For tools I’d recommend:  -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also,… more »
    Top Answer:ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
    Top Answer:My customers pay a yearly licensing fee for ArcSight Analytics.
    Top Answer:Aruba Introspect has two licenses - advanced and standard. While we found the price of the advanced license to be a bit high, the standard license is reasonably priced and costs less than half the… more »
    Ranking
    Views
    308
    Comparisons
    149
    Reviews
    4
    Average Words per Review
    315
    Rating
    7.8
    Views
    252
    Comparisons
    159
    Reviews
    0
    Average Words per Review
    0
    Rating
    N/A
    Comparisons
    Also Known As
    ArcSight User Behavior Analytics, ArcSight UBA
    IntroSpect
    Learn More
    Overview

    ArcSight User Behavior Analytics offers enterprises the ability to monitor and detect from internal and external security threats and fraud.

    Aruba IntroSpect is a User Behavior Analytics (UEBA) tool that uses supervised and unsupervised machine learning to automatically baseline user and device behavior while actively looking for anomalous activity that may indicate a threat. The solution detects compromised users’ systems by identifying changes in typical IT access and usage. By accelerating alert prioritization, incident investigation, and threat-hunting efforts, Aruba IntroSpect can automate the detection of attacks and risky behaviors. In addition, the solution allows security teams to stay ahead of malicious activity and also insecure or negligent users, so they can manage threats before they become damaging. Aruba IntroSpect is suitable for IT organizations of every size and enables businesses to easily and rapidly scale machine-learned behavior detection from small projects to full enterprise deployments.

    Aruba IntroSpect can detect:

    • Account abuse
    • Account takeover
    • Command and control
    • Data exfiltration
    • Lateral movement
    • Password sharing
    • Privilege escalation
    • Flight risk
    • Phishing
    • Ransomware

    Aruba IntroSpect Deployment Options

    • On-premise VM or appliance for Packet Processor
    • AWS or on-premise deployment for Analyzer

    Aruba IntroSpect Data Sources

    The IntroSpect platform can process data sources, including:

    • VPN, FW, IPS/IDS, web proxy, email logs
    • NTA sources: Packets and NetFlow
    • DNS logs
    • Active Directory logs
    • DHCP logs
    • External threat feeds
    • Alerts from third-party security infrastructure

    Aruba IntroSpect Features

    Aruba IntroSpect has many valuable key features. Some of the most useful ones include:

    • Advanced analytics
    • 100+ supervised and unsupervised machine learning models
    • Continuously updated risk scoring
    • Accelerated investigations
    • Packets
    • Flows
    • Logs and alerts
    • Enterprise scale
    • Spark/Hadoop platform

    Aruba IntroSpect Benefits

    There are many benefits to implementing Aruba IntroSpect. Some of the biggest advantages the solution offers include:

    • Fast deployment: Besides having different options for deployment (on-prem or cloud), the solution offers a standalone or integrated platform. For fast deployment, users can ingest data natively or from SIEM, log management, or a packet broker.
    • Efficient: The Aruba IntroSpect solution reduces the time and effort that is required to understand, diagnose, and respond to an attack.
    • Deep insights: Security teams can triage better, make more informed decisions, and respond before damage occurs.
    • Machine learning-based analytics: The solution builds baselines for normal behavior of both individual entities and groups by continuously monitoring IT activities.
    • Comprehensive security profile: When users implement Aruba IntroSpect, they gain access to a security profile with continuous risk scoring and enriched security information.
    • Automatic risk profiles: Aruba IntroSpect automatically creates a risk profile for every user, system, and IoT device connected to the network, saving users an additional step.
    • Proactive threat hunting: Through its query interface, Aruba IntroSpect proactively spots threats without the overhead of finding, searching, and summarizing isolated data stores.
    • Prioritize security risks: Risk scores are based on machine learning that can account for key factors like the order and time of incidents across various attack stages as well as time since detection and business context. Accurate, normalized scores mean security analysts can confidently prioritize their efforts.
    • Instant visibility: When using the solution, users get instant visibility to high-risk activity. Aruba IntroSpect provides access to complete investigative records.
    Sample Customers
    Information Not Available
    Sage Hotel, Centara Hotels and Resorts, Asda, The Dolder Grand,
    Top Industries
    VISITORS READING REVIEWS
    Financial Services Firm21%
    Educational Organization14%
    Computer Software Company10%
    Government6%
    VISITORS READING REVIEWS
    Computer Software Company15%
    Construction Company8%
    Retailer8%
    Educational Organization7%
    Company Size
    REVIEWERS
    Small Business20%
    Midsize Enterprise33%
    Large Enterprise47%
    VISITORS READING REVIEWS
    Small Business37%
    Midsize Enterprise6%
    Large Enterprise56%
    VISITORS READING REVIEWS
    Small Business48%
    Midsize Enterprise10%
    Large Enterprise42%
    Buyer's Guide
    User Entity Behavior Analytics (UEBA)
    April 2024
    Find out what your peers are saying about IBM, Splunk, Rapid7 and others in User Entity Behavior Analytics (UEBA). Updated: April 2024.
    767,667 professionals have used our research since 2012.

    ArcSight Analytics is ranked 17th in User Entity Behavior Analytics (UEBA) with 15 reviews while Aruba IntroSpect is ranked 24th in User Entity Behavior Analytics (UEBA). ArcSight Analytics is rated 7.0, while Aruba IntroSpect is rated 8.6. The top reviewer of ArcSight Analytics writes "It has improved our system and network policy monitoring". On the other hand, the top reviewer of Aruba IntroSpect writes "A straightforward setup for technical users and an overall good product". ArcSight Analytics is most compared with Securonix UEBA, whereas Aruba IntroSpect is most compared with Arista NDR, Cisco Secure Network Analytics, LogRhythm UEBA, Darktrace and SolarWinds NetFlow Traffic Analyzer.

    See our list of best User Entity Behavior Analytics (UEBA) vendors.

    We monitor all User Entity Behavior Analytics (UEBA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.