Worth having SIEM Arcsight
October 22, 2019

Worth having SIEM Arcsight

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Arcsight Enterprise Security Manager (formerly HP Arcsight)

Arcsight is used as a whole. Every piece of technology can be integrated with Arcsight & it can be used for monitoring from a security point of view. We can keep track of trends of alerts & configure rules as per our requirements. Whitelisting also can be done which is a very good feature. An overall good tool to work with. Customized connectors can also be built for software/tech that is not supported by HP.
  • Data management.
  • Security rules.
  • Reports can be fetched & scheduled.
  • User & role management.
  • Storage.
  • User console is a bit heavy & takes time for loading.
  • Flex development of connector.
  • It's a good SIEM solution. Doesn't have much negative impact.
  • Customization is the best part.
  • Good reporting features.
  • Does require good hardware configuration.
Multiple platforms are already supported by Arcsight. Support is good. Scripts can be used to get data from multiple threat intel sources & the same can be used in correlation rules to detect any suspicious activity. Reporting features are good & you can check any backdated information within new clicks.
If you go for platinum support, it's good as you have priority for support. They will take remote control of your machines and troubleshoot. Also, they arrange requirement SEM depending on the issue.

Do you think Arcsight by OpenText delivers good value for the price?

Yes

Are you happy with Arcsight by OpenText's feature set?

Yes

Did Arcsight by OpenText live up to sales and marketing promises?

Yes

Did implementation of Arcsight by OpenText go as expected?

Yes

Would you buy Arcsight by OpenText again?

Yes

You can have customized rules & trends as per company requirements. You can integrate devices that you want even if no smart connector is present for that particular device. You can also have a list for dynamic requirements. We've created customized fieldsets & populated it with data we want with multiple data formats so that monitoring can be made easy instead of going into event details every time.

The only problem is that every time any old events are retrieved, it takes a long time to load.

Arcsight by OpenText Feature Ratings

Centralized event and log data collection
9
Correlation
9
Event and log normalization/management
9
Deployment flexibility
10
Integration with Identity and Access Management Tools
10
Custom dashboards and workspaces
9