Arcsight needs to up its game.
December 17, 2018
Arcsight needs to up its game.
Score 7 out of 10
Vetted Review
Verified User
Overall Satisfaction with Arcsight Enterprise Security Manager (formerly HP Arcsight)
Arcsight is currently being used in our SIOC department for the whole organization. It is a well rounded tool for standard event detection, logging, normalization and correlation. It does a fairly good job at freeing up analysts by providing real time correlation and helping detect events fast so they don't waste time hunting for a needle in a haystack.
- Good integration with IT infrastructure like ticketing systems, web applications and threat feeds etc.
- Real time correlation works very well.
- Dashboards and visualization is done well.
- Even though integration is good but not complete yet as there are a lot of new popular apps which Arcsight can't integrate with natively.
- UI can be improved.
- A few years ago this would have been the best buy on the market but with applications like Splunk I'd say its not giving you as much ROI.
- Still does the job and gives us a positive ROI as we bought this over 6 years ago.
Splunk is way better, faster and has more integration than Arcsight has. Arcsight doesn't seem like the leader of the market as it was many years ago and I'd not recommend getting this now unless you absolutely require it for some reason.