ArcSight Intelligence SIEM(provides visibility over any devices)
Use Cases and Deployment Scope
ArcSight Intelligence here use as a SIEM tool.Through this we are able to integrated several devices through connectors and easily parse and analyze all the log sources with a single console.Our analyst easily monitor all the log sources and analyze the alerts also easily create filters according to their needs and nearly cover all kind of alerts .
Pros
- It provide a single console to monitor several connectors.
- It helps us to integrate all kind of log sources .
- It helps us to create filters and manage the specific search according to usecases.
- We can create several filter at the same time and manage all the device activity also create a parser to parse the logs from different devices.
Cons
- It is slow comparing to any other SIEM Tool.
- We have to create filter for each alerts need some custom filter .
- Here we dont have any single tab for see all the alerts .also need some attractive features for dashboard.
Most Important Features
- Any device integration with this tool.
- Coalescing the logs easily helps analysts to check all kind of alerts.
- It has the feature to notify critical alerts directly to senior analysts.
- Easily understand and parse the logs from different devices.
Return on Investment
- It is recommended for handle small enterprises.
- Cant integrate any threat intel tool so we majorly works through filters.
- It is slow takes time for large searches.
Alternatives Considered
IBM Security QRadar SIEM
Other Software Used
IBM Security QRadar SIEM, Fortinet FortiGate, Trend Micro Deep Security Smart Check

