ArcSight Intelligence SIEM(provides visibility over any devices)
Use Cases and Deployment Scope
ArcSight Intelligence here use as a SIEM tool.Through this we are able to integrated several devices through connectors and easily parse and analyze all the log sources with a single console.Our analyst easily monitor all the log sources and analyze the alerts also easily create filters according to their needs and nearly cover all kind of alerts .
Pros
- It provide a single console to monitor several connectors.
- It helps us to integrate all kind of log sources .
- It helps us to create filters and manage the specific search according to usecases.
- We can create several filter at the same time and manage all the device activity also create a parser to parse the logs from different devices.
Cons
- It is slow comparing to any other SIEM Tool.
- We have to create filter for each alerts need some custom filter .
- Here we dont have any single tab for see all the alerts .also need some attractive features for dashboard.
Likelihood to Recommend
For multiple client we can create filters to analyze the logs and monitor through out the day.
It covers all kind of devices so easily integrate any device and analyze their activity.
Can manage multiple client and minimze the false positive easily according to organizations needs and requirements.
Its provide facility to merge any of the SOAR tool .we can also see connectors status on a single pane that helps us in troubleshooting
