Skip to main content
TrustRadius
Arcsight by OpenText

Arcsight by OpenText

Overview

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Read more
Recent Reviews

TrustRadius Insights

Users have successfully utilized this product to effectively manage their customer relationships, track interactions, and maintain a …
Continue reading

A great SIEM solution

9 out of 10
April 16, 2018
Incentivized
It was being used across the whole IT organization. It fully covers the all of the security and the other IT products in a good way. When …
Continue reading
Read all reviews

Popular Features

View all 13 features
  • Correlation (5)
    9.0
    90%
  • Centralized event and log data collection (5)
    8.0
    80%
  • Event and log normalization/management (5)
    8.0
    80%
  • Deployment flexibility (5)
    6.0
    60%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

55 people also want pricing

Alternatives Pricing

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

What is Blumira?

Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more defend against cybersecurity threats in near real-time. It's goal is to ease the burden of alert fatigue, complexity of log management and lack of IT visibility.

Return to navigation

Product Demos

ArcSight Training | ArcSight Online Certification Course | ArcSight Demo - Mindmajix

YouTube
Return to navigation

Features

Security Information and Event Management (SIEM)

Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools

5.5
Avg 7.8
Return to navigation

Product Details

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Arcsight by OpenText Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Reviewers rate Correlation highest, with a score of 9.

The most common users of Arcsight by OpenText are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(32)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Users have successfully utilized this product to effectively manage their customer relationships, track interactions, and maintain a comprehensive database of customer information. According to reviewers, this software streamlines sales processes by providing easy lead tracking, opportunity management, and deal closure. Customers have reported significant improvements in project management capabilities, allowing efficient planning, tracking, and collaboration on tasks and deliverables.

The product's reporting and analytics features have received praise from users for providing valuable insights into business performance and facilitating data-driven decision-making. Reviewers have also emphasized the seamless integration capabilities, which enhance overall productivity and efficiency by connecting with other tools and systems. By automating marketing campaigns, customers have experienced improved lead generation, personalized communication, and increased customer engagement.

For prompt issue resolution, users have relied on the reliable and responsive customer support features. The product's ease of use and intuitive interface have minimized the learning curve for new users, as noted by reviewers. Additionally, inventory management has been streamlined through efficient stock level tracking, order management, and optimization of supply chain operations.

Effective communication, document sharing, and task coordination among team members have been facilitated through the project collaboration features of this product.

User-Friendly Interface: Many users have praised the product for its user-friendly interface, stating that it is easy to navigate and perform tasks efficiently. They have found the interface to be intuitive, allowing them to quickly understand how to use the product without any difficulties. The user-friendly design has greatly contributed to the overall satisfaction of these reviewers.

Helpful Customer Support: Several users have appreciated the helpful customer support provided by the company. They have mentioned that whenever they encountered any issues or had questions about the product, they received prompt assistance from the support team. This positive experience with customer support has enhanced their overall perception of both the product and the company's commitment to providing excellent service.

Intuitive Product Usage: Many reviewers have expressed their satisfaction with how easily they were able to grasp and utilize the product's features. They mentioned that they quickly understood how to use different functionalities without any confusion or steep learning curve. This intuitive usage of the product has been a significant factor in their positive experiences and overall satisfaction.

Disappointing Overall Experience: Several users have expressed their disappointment with the overall experience of the product. They have found it to be underwhelming and unsatisfactory in meeting their expectations.

Lack of Intuitive User Interface: Many users have mentioned frustration with the lack of an intuitive user interface, making it difficult for them to navigate and perform tasks efficiently. This has led to a less than optimal user experience.

Unhelpful Customer Support: Some users have felt that the customer support provided by the company was unhelpful and did not provide satisfactory solutions to their issues. This has left them feeling unsupported and frustrated when seeking assistance.

Attribute Ratings

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
Rajat Singh | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
ArcSight Intelligence here use as a SIEM tool.Through this we are able to integrated several devices through connectors and easily parse and analyze all the log sources with a single console.Our analyst easily monitor all the log sources and analyze the alerts also easily create filters according to their needs and nearly cover all kind of alerts .
  • It provide a single console to monitor several connectors.
  • It helps us to integrate all kind of log sources .
  • It helps us to create filters and manage the specific search according to usecases.
  • We can create several filter at the same time and manage all the device activity also create a parser to parse the logs from different devices.
  • It is slow comparing to any other SIEM Tool.
  • We have to create filter for each alerts need some custom filter .
  • Here we dont have any single tab for see all the alerts .also need some attractive features for dashboard.
For multiple client we can create filters to analyze the logs and monitor through out the day.
It covers all kind of devices so easily integrate any device and analyze their activity.
Can manage multiple client and minimze the false positive easily according to organizations needs and requirements.
Its provide facility to merge any of the SOAR tool .we can also see connectors status on a single pane that helps us in troubleshooting

  • Any device integration with this tool.
  • Coalescing the logs easily helps analysts to check all kind of alerts.
  • It has the feature to notify critical alerts directly to senior analysts.
  • Easily understand and parse the logs from different devices.
  • It is recommended for handle small enterprises.
  • Cant integrate any threat intel tool so we majorly works through filters.
  • It is slow takes time for large searches.
ArcSight Intelligence easily provides visibility to understand the logs and monitor the different devices .have features to manage multiple client with asingle console.searching is little bit hectic but we can mange these thing while using its filter creation process. It costs low comparing to any other SIEM tool and nearly scan satisfied any clients requirements.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Arcsight is being used in the security department in our organization. It is used as a SIEM (Security Event and Incident Manager) tool in our organization. As any other SIEM tool, we used Arcsight Enterprise security manager for managing security on all of our endpoint devices, It was one of the best and demanding tool at the time we have implemented in our organization and provide a number of features which help us to have a quick check and easy handling of security event and incidents on all the endpoint devices. To be specific, Arcsight Enterprise security manager is used for integrating all endpoint safety management tool be it IPS, IDS, Firewall, Anti-virus etc. and help to reduce the redundant and false-positive alerts which may not be useful from the security perspective and help us to have a quick check of a lot devices in an effective way.
It also help us to check the complete activity that has been perform on any of the endpoint device integrated with it, creating own rule and filters and creating active channel dashboards that help us to keep a vigil watch in case any big event happens on any devices.
  • Integration with smart logger and ESM to create rules and easy management of the same.
  • Easy integration with all end point security management tool(IPS/IDS, Firewall, Anti-Virus) and their consolidated output at a single place to effectively rectifying true and false positives.
  • There is a storage problem that should be improved for better management.
  • There is need to improve the search mechanism.
Arcsight was one of the best SIEM tools at the time it entered the market and has advanced features that make it a favorite for a number of organizations, but they lack to upgrade it with the time. Some of there features are still at their best but required timely update to manage with the other competitor present in the market.
If I have to choose the key points, they would be :
  1. User management.
  2. Smart Logger.

And if I were to point out where it is currently lagging :
  1. UI needs improvement.
  2. Slow search functionality.
Security Information and Event Management (SIEM) (7)
81.42857142857142%
8.1
Centralized event and log data collection
80%
8.0
Correlation
80%
8.0
Event and log normalization/management
90%
9.0
Deployment flexibility
80%
8.0
Integration with Identity and Access Management Tools
80%
8.0
Custom dashboards and workspaces
80%
8.0
Host and network-based intrusion detection
80%
8.0
  • It helps us a lot which managing security event and incidents.
  • It is also very useful to have a dashboard for an quick overview and scheduled reports for timely checks of all activities.
  • It requires more space and search management to be one of the favorites on the market.
We are currently using Elastic search as well for better management of our devices and to keep all the loopholes filled that have been created around the non-upgraded version of Arcsight Enterprise Manager. Elastic searches have the latest mechanism to fetch logs and correlated data, as well as process them in a more useful way.
Let's go here point by point:

1) Better logs management.
2) An effective way of managing the user and their roles.
3) Easy to handle and manage end-point user machines.
4) Better logs collection mechanism(still there is a lot of scopes to improve)
5) Easy to create scheduled reports and Dashboards for a quick check.
6) Easy to implement and handle all the services provide by the ArcSight.
7) User-friendly UI.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Arcsight is used as a whole. Every piece of technology can be integrated with Arcsight & it can be used for monitoring from a security point of view. We can keep track of trends of alerts & configure rules as per our requirements. Whitelisting also can be done which is a very good feature. An overall good tool to work with. Customized connectors can also be built for software/tech that is not supported by HP.
  • Data management.
  • Security rules.
  • Reports can be fetched & scheduled.
  • User & role management.
  • Storage.
  • User console is a bit heavy & takes time for loading.
  • Flex development of connector.

You can have customized rules & trends as per company requirements. You can integrate devices that you want even if no smart connector is present for that particular device. You can also have a list for dynamic requirements. We've created customized fieldsets & populated it with data we want with multiple data formats so that monitoring can be made easy instead of going into event details every time.

The only problem is that every time any old events are retrieved, it takes a long time to load.

Security Information and Event Management (SIEM) (6)
93.33333333333334%
9.3
Centralized event and log data collection
90%
9.0
Correlation
90%
9.0
Event and log normalization/management
90%
9.0
Deployment flexibility
100%
10.0
Integration with Identity and Access Management Tools
100%
10.0
Custom dashboards and workspaces
90%
9.0
  • It's a good SIEM solution. Doesn't have much negative impact.
  • Customization is the best part.
  • Good reporting features.
  • Does require good hardware configuration.
Multiple platforms are already supported by Arcsight. Support is good. Scripts can be used to get data from multiple threat intel sources & the same can be used in correlation rules to detect any suspicious activity. Reporting features are good & you can check any backdated information within new clicks.
If you go for platinum support, it's good as you have priority for support. They will take remote control of your machines and troubleshoot. Also, they arrange requirement SEM depending on the issue.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
Arcsight is currently being used in our SIOC department for the whole organization. It is a well rounded tool for standard event detection, logging, normalization and correlation. It does a fairly good job at freeing up analysts by providing real time correlation and helping detect events fast so they don't waste time hunting for a needle in a haystack.
  • Good integration with IT infrastructure like ticketing systems, web applications and threat feeds etc.
  • Real time correlation works very well.
  • Dashboards and visualization is done well.
  • Even though integration is good but not complete yet as there are a lot of new popular apps which Arcsight can't integrate with natively.
  • UI can be improved.
Honestly, there are newer and better competitors for this tool and I'd recommend those over this as I've had the opportunity to recently to work with some others. If you work with older applications then integration might work but newer and cutting edge app support is nowhere near completion.
Security Information and Event Management (SIEM) (6)
78.33333333333333%
7.8
Centralized event and log data collection
80%
8.0
Correlation
80%
8.0
Event and log normalization/management
80%
8.0
Deployment flexibility
70%
7.0
Integration with Identity and Access Management Tools
80%
8.0
Custom dashboards and workspaces
80%
8.0
  • A few years ago this would have been the best buy on the market but with applications like Splunk I'd say its not giving you as much ROI.
  • Still does the job and gives us a positive ROI as we bought this over 6 years ago.
Splunk is way better, faster and has more integration than Arcsight has. Arcsight doesn't seem like the leader of the market as it was many years ago and I'd not recommend getting this now unless you absolutely require it for some reason.
IBM QRadar, LogRhythm, SolarWinds Log & Event Manager
April 16, 2018

A great SIEM solution

Score 9 out of 10
Vetted Review
Verified User
Incentivized
It was being used across the whole IT organization. It fully covers the all of the security and the other IT products in a good way. When we needed a simple log to show to anyone, we were used ArcSight Logger.
  • User friendly interface.
  • Easy to create queries and rules to make all the things automatic.
  • Backup, maintenance and support of this product are always nearly perfect.
  • Current version 6.90 is still very clunky.
  • High complex architecture needs to be improved.
  • HP support team or exclusive support team must understand your needs.
You can use HP ArcSight Logger in every type of firm size. If the organization does not have an already established Security/Risk culture, it's better to prepare that before implementing a SIEM or SOC entity. If it's not, it's not possible to feed the Logger with the proper data.
  • Logger helps us to decrease incident response times.
  • It also decreased our project times with the man/day calculations. Before this solution, it may take up to 10 men/days to do something. After this, it becomes nearly half of the time.
Actually we weren't [in a] decisive situation at that time. We had only a few weeks to make a decision and our firm has good relationships with the HP Support team. That's why I can't compare them all properly, but we searched these 2 different solutions to show differences.
Return to navigation