Solved

arcsight

Posted on 2011-03-03
2
995 Views
Last Modified: 2012-05-11
Anyone have experience using ArcSight and if so, what is your opinion of the product?
0
Comment
Question by:samrog777
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 35034518
i see one of the strong area (out of their many suite) is in log management. it ranked among the top for SIEM domain especially in aggregation and correlation of the intelligence source (which you define and they can customised connector to it - or they called it flexconnector). it has also geared towards the emerging threat such as advanced persistent threat - the key is to identify the indicator and shorten the actionable response (which they also include upon detecting anomalies in the log). There is a cascaded chaining of the appliance for the scale up (or down) support depending on the environment (or sensor deployed). it does not really go into sensor but "collect" from them as typical SIEM product does. I would not drill into their spec details but can check out this link for comparison (not latest but have the parameter for consideration in SIEM)

http://www.networkcomputing.com/print_entry.php?eid=68126

having said that, nothing comes free and they can be steep but it depends on your business requirement and security needs. maybe for a security operation centre that is running 24x7, the ROI is justifiable but for SME, there can be other options (such as splunk etc). of course, I am not saying they are the best SIEM solution but would be already been deployed by many (based on their case study and partners). they also have research projects with public sectors which show motivation to innovate and contribute back.

nonetheless, it depends on what solution you are looking at and simply ask who are their competitors and have comparison checks, can be easily googled too. primarily, have the business needs satisfy and scale down according based on the security appetite (have some risk assessment)

the question which we may want to ask them is what role do they play in a cloud environment and handle the increasing big chunks of data and log (balancing with security needs) .... just some thoughts

0
 

Author Closing Comment

by:samrog777
ID: 35059907
Thanks for the input. Much appreciated.  We have ArcSight ESM & Logger installed and I am finding it to be a beast to maintiain. For us, it is just yet another application we  have to use and this product appears to require a dedicated person.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question