A good, but complex, SIEM tool
December 16, 2019

A good, but complex, SIEM tool

Anonymous | TrustRadius Reviewer
Score 6 out of 10
Vetted Review
Verified User

Overall Satisfaction with Arcsight Enterprise Security Manager (formerly HP Arcsight)

As a managed SOC provider, ArcSight is the base of our SOC team. We deploy event receivers (connectors and brokers) in each of our clients and the data is aggregated on our ESM. We then are able to monitor the client environment from our SOC and investigate incidents in the client environment.
  • Really robust tool, as it can expand to millions of EPS.
  • Support clustering.
  • ArcSight is a really complex tool, but it's not that easy to implement and maintain.
  • Troubleshooting issues on ArcSight can be hard if you have a large environment.
  • ArcSight allows us to monitor all of our clients in a centralized environment.
  • We had to hire two engineers just to maintain/troubleshoot the Arcsight environment.
I personally haven't reached the support team, however, the engineers never complained about the Arcsight support team. We had some issues with the tool in the past but every time we reached the support, all issues were resolved in a timely manner.

Do you think Arcsight by OpenText delivers good value for the price?

Yes

Are you happy with Arcsight by OpenText's feature set?

Yes

Did Arcsight by OpenText live up to sales and marketing promises?

No

Did implementation of Arcsight by OpenText go as expected?

No

Would you buy Arcsight by OpenText again?

No

I do recommend Arcsight for clients that have a large environment and requires tons of customization. For example, if you have 10.000+ log sources, and you want to do a custom integration with ElasticSearch, then Arcsight is for you. If you have a medium-sized company, with no requirements for complex customizations, and if you're looking for an easy tool to deploy and maintain, then you should check another solution.

Arcsight by OpenText Feature Ratings

Centralized event and log data collection
7
Correlation
7
Event and log normalization/management
6
Deployment flexibility
8
Integration with Identity and Access Management Tools
Not Rated
Custom dashboards and workspaces
5