Skip to main content
TrustRadius
Arcsight by OpenText

Arcsight by OpenText

Overview

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Read more
Recent Reviews

TrustRadius Insights

Users have successfully utilized this product to effectively manage their customer relationships, track interactions, and maintain a …
Continue reading

A great SIEM solution

9 out of 10
April 16, 2018
Incentivized
It was being used across the whole IT organization. It fully covers the all of the security and the other IT products in a good way. When …
Continue reading
Read all reviews

Popular Features

View all 13 features
  • Correlation (5)
    9.0
    90%
  • Centralized event and log data collection (5)
    8.0
    80%
  • Event and log normalization/management (5)
    8.0
    80%
  • Deployment flexibility (5)
    6.0
    60%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

55 people also want pricing

Alternatives Pricing

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. It is presented as a security information and event management (SIEM) solution for proactive threat detection, investigation, and response.

What is Blumira?

Blumira’s cloud SIEM platform offers both automated threat detection and response, enabling organizations of any size to more defend against cybersecurity threats in near real-time. It's goal is to ease the burden of alert fatigue, complexity of log management and lack of IT visibility.

Return to navigation

Product Demos

ArcSight Training | ArcSight Online Certification Course | ArcSight Demo - Mindmajix

YouTube
Return to navigation

Features

Security Information and Event Management (SIEM)

Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools

5.5
Avg 7.8
Return to navigation

Product Details

What is Arcsight by OpenText?

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Arcsight by OpenText Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.

Reviewers rate Correlation highest, with a score of 9.

The most common users of Arcsight by OpenText are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(32)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Users have successfully utilized this product to effectively manage their customer relationships, track interactions, and maintain a comprehensive database of customer information. According to reviewers, this software streamlines sales processes by providing easy lead tracking, opportunity management, and deal closure. Customers have reported significant improvements in project management capabilities, allowing efficient planning, tracking, and collaboration on tasks and deliverables.

The product's reporting and analytics features have received praise from users for providing valuable insights into business performance and facilitating data-driven decision-making. Reviewers have also emphasized the seamless integration capabilities, which enhance overall productivity and efficiency by connecting with other tools and systems. By automating marketing campaigns, customers have experienced improved lead generation, personalized communication, and increased customer engagement.

For prompt issue resolution, users have relied on the reliable and responsive customer support features. The product's ease of use and intuitive interface have minimized the learning curve for new users, as noted by reviewers. Additionally, inventory management has been streamlined through efficient stock level tracking, order management, and optimization of supply chain operations.

Effective communication, document sharing, and task coordination among team members have been facilitated through the project collaboration features of this product.

User-Friendly Interface: Many users have praised the product for its user-friendly interface, stating that it is easy to navigate and perform tasks efficiently. They have found the interface to be intuitive, allowing them to quickly understand how to use the product without any difficulties. The user-friendly design has greatly contributed to the overall satisfaction of these reviewers.

Helpful Customer Support: Several users have appreciated the helpful customer support provided by the company. They have mentioned that whenever they encountered any issues or had questions about the product, they received prompt assistance from the support team. This positive experience with customer support has enhanced their overall perception of both the product and the company's commitment to providing excellent service.

Intuitive Product Usage: Many reviewers have expressed their satisfaction with how easily they were able to grasp and utilize the product's features. They mentioned that they quickly understood how to use different functionalities without any confusion or steep learning curve. This intuitive usage of the product has been a significant factor in their positive experiences and overall satisfaction.

Disappointing Overall Experience: Several users have expressed their disappointment with the overall experience of the product. They have found it to be underwhelming and unsatisfactory in meeting their expectations.

Lack of Intuitive User Interface: Many users have mentioned frustration with the lack of an intuitive user interface, making it difficult for them to navigate and perform tasks efficiently. This has led to a less than optimal user experience.

Unhelpful Customer Support: Some users have felt that the customer support provided by the company was unhelpful and did not provide satisfactory solutions to their issues. This has left them feeling unsupported and frustrated when seeking assistance.

Attribute Ratings

Reviews

(1-4 of 4)
Companies can't remove reviews or game the system. Here's why
Score 8 out of 10
Vetted Review
Verified User
Incentivized
I use ArcSight ESM to provide security monitoring services to several customers cutting across different verticals like Finance, Oil and Gas, Retail to name a few. Our company is one of the largest Managed Security Services provider in the region and we use multiple SIEM tools to cater to the ever-growing MSSP market and ArcSight Enterprise Security Manager is one of them.
  • Industry standard log parsing using CEF (Common Event Format)
  • Excellent correlation capabilities
  • Good overall vendor support when it comes to supporting on operational issues
  • Search times are very slow and this is due to their archaic CORR database, an immediate overhaul is needed
  • New plug-ins related to niche features are not rolled out timely, for example feature rich dashboards
  • Featured like Machine Learning and Artificial Intelligence which are industry talks are completely missing
In the current lot of hundreds of SIEM solutions out there in the market, ArcSight ESM is fairly less expensive with strong fundamentals in place. The log ingestion, correlation are very well performing and totally worth ROI. However, the tool has lost its way when it comes to staying abreast with current feature curve of SIEM technology and the evolution has not been done by MicroFocus. Search times are high and there is no major plug-in that has been introduced as part of the product life cycle.
Security Information and Event Management (SIEM) (14)
57.142857142857146%
5.7
Centralized event and log data collection
80%
8.0
Correlation
90%
9.0
Event and log normalization/management
80%
8.0
Deployment flexibility
60%
6.0
Integration with Identity and Access Management Tools
60%
6.0
Custom dashboards and workspaces
50%
5.0
Host and network-based intrusion detection
80%
8.0
Log retention
80%
8.0
Data integration/API management
50%
5.0
Behavioral analytics and baselining
20%
2.0
Rules-based and algorithmic detection thresholds
80%
8.0
Response orchestration and automation
20%
2.0
Reporting and compliance management
40%
4.0
Incident indexing/searching
10%
1.0
  • The overall impact is neutral since it balances the investment and returns.
  • Since it is less expensive compared to its competitors, it is fairly suited in an environment with less expectations and less budget.
  • It does not fit in at all where the security monitoring is at an elevated level and there are routing threat hunting exercises that need to be performed daily.
ArcSight ESM scores well when it comes to parsing, ingestion, asset modelling, correlation and log storage. It is fairly inexpensive and has some good vendor support for operational issues. Scalability is also easy and cost-effective as compared to other SIEM solutions out there is the market.
On the flip-side, the product life-cycle management by the vendor has been very disappointing as no new features or modules have been added that can add value to operations.
Overall, it is a good investment in order for an organization to stay compliant and stay secure from all the wild things happening. It is definitely a cost effective tool with some good features including correlation, log storage, reporting and dashboards. If a customer is looking for advanced set of features, then I would highly not recommend this.
Score 6 out of 10
Vetted Review
Verified User
Incentivized
As a managed SOC provider, ArcSight is the base of our SOC team. We deploy event receivers (connectors and brokers) in each of our clients and the data is aggregated on our ESM. We then are able to monitor the client environment from our SOC and investigate incidents in the client environment.
  • Really robust tool, as it can expand to millions of EPS.
  • Support clustering.
  • ArcSight is a really complex tool, but it's not that easy to implement and maintain.
  • Troubleshooting issues on ArcSight can be hard if you have a large environment.
I do recommend Arcsight for clients that have a large environment and requires tons of customization. For example, if you have 10.000+ log sources, and you want to do a custom integration with ElasticSearch, then Arcsight is for you. If you have a medium-sized company, with no requirements for complex customizations, and if you're looking for an easy tool to deploy and maintain, then you should check another solution.
Security Information and Event Management (SIEM) (6)
55%
5.5
Centralized event and log data collection
70%
7.0
Correlation
70%
7.0
Event and log normalization/management
60%
6.0
Deployment flexibility
80%
8.0
Integration with Identity and Access Management Tools
N/A
N/A
Custom dashboards and workspaces
50%
5.0
  • ArcSight allows us to monitor all of our clients in a centralized environment.
  • We had to hire two engineers just to maintain/troubleshoot the Arcsight environment.
I personally haven't reached the support team, however, the engineers never complained about the Arcsight support team. We had some issues with the tool in the past but every time we reached the support, all issues were resolved in a timely manner.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Arcsight is being used in the security department in our organization. It is used as a SIEM (Security Event and Incident Manager) tool in our organization. As any other SIEM tool, we used Arcsight Enterprise security manager for managing security on all of our endpoint devices, It was one of the best and demanding tool at the time we have implemented in our organization and provide a number of features which help us to have a quick check and easy handling of security event and incidents on all the endpoint devices. To be specific, Arcsight Enterprise security manager is used for integrating all endpoint safety management tool be it IPS, IDS, Firewall, Anti-virus etc. and help to reduce the redundant and false-positive alerts which may not be useful from the security perspective and help us to have a quick check of a lot devices in an effective way.
It also help us to check the complete activity that has been perform on any of the endpoint device integrated with it, creating own rule and filters and creating active channel dashboards that help us to keep a vigil watch in case any big event happens on any devices.
  • Integration with smart logger and ESM to create rules and easy management of the same.
  • Easy integration with all end point security management tool(IPS/IDS, Firewall, Anti-Virus) and their consolidated output at a single place to effectively rectifying true and false positives.
  • There is a storage problem that should be improved for better management.
  • There is need to improve the search mechanism.
Arcsight was one of the best SIEM tools at the time it entered the market and has advanced features that make it a favorite for a number of organizations, but they lack to upgrade it with the time. Some of there features are still at their best but required timely update to manage with the other competitor present in the market.
If I have to choose the key points, they would be :
  1. User management.
  2. Smart Logger.

And if I were to point out where it is currently lagging :
  1. UI needs improvement.
  2. Slow search functionality.
Security Information and Event Management (SIEM) (7)
81.42857142857142%
8.1
Centralized event and log data collection
80%
8.0
Correlation
80%
8.0
Event and log normalization/management
90%
9.0
Deployment flexibility
80%
8.0
Integration with Identity and Access Management Tools
80%
8.0
Custom dashboards and workspaces
80%
8.0
Host and network-based intrusion detection
80%
8.0
  • It helps us a lot which managing security event and incidents.
  • It is also very useful to have a dashboard for an quick overview and scheduled reports for timely checks of all activities.
  • It requires more space and search management to be one of the favorites on the market.
We are currently using Elastic search as well for better management of our devices and to keep all the loopholes filled that have been created around the non-upgraded version of Arcsight Enterprise Manager. Elastic searches have the latest mechanism to fetch logs and correlated data, as well as process them in a more useful way.
Let's go here point by point:

1) Better logs management.
2) An effective way of managing the user and their roles.
3) Easy to handle and manage end-point user machines.
4) Better logs collection mechanism(still there is a lot of scopes to improve)
5) Easy to create scheduled reports and Dashboards for a quick check.
6) Easy to implement and handle all the services provide by the ArcSight.
7) User-friendly UI.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Arcsight is used as a whole. Every piece of technology can be integrated with Arcsight & it can be used for monitoring from a security point of view. We can keep track of trends of alerts & configure rules as per our requirements. Whitelisting also can be done which is a very good feature. An overall good tool to work with. Customized connectors can also be built for software/tech that is not supported by HP.
  • Data management.
  • Security rules.
  • Reports can be fetched & scheduled.
  • User & role management.
  • Storage.
  • User console is a bit heavy & takes time for loading.
  • Flex development of connector.

You can have customized rules & trends as per company requirements. You can integrate devices that you want even if no smart connector is present for that particular device. You can also have a list for dynamic requirements. We've created customized fieldsets & populated it with data we want with multiple data formats so that monitoring can be made easy instead of going into event details every time.

The only problem is that every time any old events are retrieved, it takes a long time to load.

Security Information and Event Management (SIEM) (6)
93.33333333333334%
9.3
Centralized event and log data collection
90%
9.0
Correlation
90%
9.0
Event and log normalization/management
90%
9.0
Deployment flexibility
100%
10.0
Integration with Identity and Access Management Tools
100%
10.0
Custom dashboards and workspaces
90%
9.0
  • It's a good SIEM solution. Doesn't have much negative impact.
  • Customization is the best part.
  • Good reporting features.
  • Does require good hardware configuration.
Multiple platforms are already supported by Arcsight. Support is good. Scripts can be used to get data from multiple threat intel sources & the same can be used in correlation rules to detect any suspicious activity. Reporting features are good & you can check any backdated information within new clicks.
If you go for platinum support, it's good as you have priority for support. They will take remote control of your machines and troubleshoot. Also, they arrange requirement SEM depending on the issue.
Return to navigation