Likelihood to Recommend In the current lot of hundreds of SIEM solutions out there in the market, ArcSight ESM is fairly less expensive with strong fundamentals in place. The log ingestion, correlation are very well performing and totally worth ROI. However, the tool has lost its way when it comes to staying abreast with current feature curve of SIEM technology and the evolution has not been done by MicroFocus. Search times are high and there is no major plug-in that has been introduced as part of the product life cycle.
Read full review Rapid7 InsightVM is perfect for a scenario where IT admin or CISO wants to scan its infrastructure to be sure that there is no vulnerability that could be exploited from outside or inside the company. It also could be used to automate patching and dealing with vulnerabilities. It's also adapted for users that need cloud security management
Read full review Pros Integration with smart logger and ESM to create rules and easy management of the same. Easy integration with all end point security management tool(IPS/IDS, Firewall, Anti-Virus) and their consolidated output at a single place to effectively rectifying true and false positives. Read full review Being a vulnerability scanner tool, its purpose is to scan the systems to find the vulnerabilities. We can define the assets like IP address for the scans and it also allows to either schedule the scan at a preferred time or start the scan immediately. Upon completion of the scan, this tool can result provide the details like host type, OS information, hardware address, along with the vulnerabilities. Rapid7 Nexpose has a list of templates to perform the scan. Once the templates are defined then the scans are performed accordingly. It also contains an option to add credentials/authentication using passwords, usernames, private keys to perform the credential-based scans which I think is a great feature. Read full review Cons Even though integration is good but not complete yet as there are a lot of new popular apps which Arcsight can't integrate with natively. UI can be improved. Read full review In comparison to Tenable SecurityCenter we saw it didn't exactly find the same vulnerabilities which we would assume it should have We rely on a ticketing system and not our VM tool to assign tasks so wasn't too useful having that in there Filtering capabilities aren't as good as its competitors Read full review Usability Overall, it is a good investment in order for an organization to stay compliant and stay secure from all the wild things happening. It is definitely a cost effective tool with some good features including correlation, log storage, reporting and dashboards. If a customer is looking for advanced set of features, then I would highly not recommend this.
Read full review Support Rating I personally haven't reached the support team, however, the engineers never complained about the Arcsight support team. We had some issues with the tool in the past but every time we reached the support, all issues were resolved in a timely manner.
Read full review I gave it a seven due to the functionality and general ease of use after the initial setup headaches, but compared to Qualys, Rapid7 Nexpose falls short on features and ease of use. Their support drags this rating down a point as well. I have gone weeks with no update on semi-critical issues and typically have to make call after call to get a semi-coherent response.
Read full review Alternatives Considered ArcSight Intelligence easily provides visibility to understand the logs and monitor the different devices .have features to manage multiple client with asingle console.searching is little bit hectic but we can mange these thing while using its filter creation process. It costs low comparing to any other SIEM tool and nearly scan satisfied any clients requirements.
Read full review Nessus Pro does scans, but does not maintain an inventory from scan to scan. There is no history for a specific device, you have to look inside the results of each scan. Search across inventory is non-existent. There are no dashboards for data analysis. This is no tracking for remediation
Read full review Return on Investment It's a good SIEM solution. Doesn't have much negative impact. Customization is the best part. Good reporting features. Does require good hardware configuration. Read full review Can reduce time to patch most critical vulnerabilities Can help to identify who is spending time patching things of lower risk thus keeping the organization in a more vulnerable position Easily provides the patch team with a work plan to enhance security more quickly Read full review ScreenShots