OpenText ArcSight
OpenText ArcSight: SIEM (Security Information and Event Management) platform. Enterprise Security Manager, Log Analytics, Threat Intelligence. Real-time threat detection.

Key Features
- Enterprise Security Manager - event correlation, real-time monitoring
- Intelligence (SOAR) - response automation, playbooks
- Logger - centralized logging, compliance
- Threat Intelligence - threat feeds, IOC matching
- User Behavior Analytics - anomaly detection
Table of Contents
What is OpenText ArcSight?
OpenText ArcSight (formerly Micro Focus ArcSight) is a SIEM (Security Information and Event Management) platform - a system for collecting, correlating, and analyzing security logs from across the entire infrastructure. It detects threats in real-time and automates response.
Main components:
- Enterprise Security Manager (ESM) - correlation, dashboards, alerts
- ArcSight Intelligence (SOAR) - automation, playbooks
- Logger - high-performance log storage
- Threat Intelligence - threat feeds, IOC
What problem does it solve?
flowchart LR
subgraph Without SIEM
A[Logs in 100 places] --> B[No correlation]
B --> C[Alert fatigue]
C --> D[Missed threats]
end
subgraph With ArcSight
E[Centralized logs] --> F[Real-time correlation]
F --> G[Prioritization]
G --> H[Fast response]
end
style A fill:#dc2626,stroke:#b91c1c,color:#fff
style B fill:#dc2626,stroke:#b91c1c,color:#fff
style C fill:#dc2626,stroke:#b91c1c,color:#fff
style D fill:#dc2626,stroke:#b91c1c,color:#fff
style E fill:#22c55e,stroke:#16a34a,color:#fff
style F fill:#22c55e,stroke:#16a34a,color:#fff
style G fill:#22c55e,stroke:#16a34a,color:#fff
style H fill:#22c55e,stroke:#16a34a,color:#fff
Common problems:
- Logs scattered across hundreds of systems
- No correlation between events
- Too many alerts - unclear what’s important
- Slow incident response
- Compliance requires retention and reports
How does ArcSight work?
flowchart TD
subgraph Sources
A[Firewall]
B[IDS/IPS]
C[Servers]
D[Applications]
E[Cloud]
end
subgraph ArcSight
F[Connectors] --> G[Logger]
G --> H[ESM]
H --> I[Correlation Engine]
I --> J{Threat?}
J -->|Yes| K[Alert + Case]
J -->|No| L[Archive]
K --> M[SOAR Playbook]
end
A --> F
B --> F
C --> F
D --> F
E --> F
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#6366f1,stroke:#4f46e5,color:#fff
style C fill:#6366f1,stroke:#4f46e5,color:#fff
style H fill:#f59e0b,stroke:#d97706,color:#fff
style I fill:#8b5cf6,stroke:#7c3aed,color:#fff
style K fill:#dc2626,stroke:#b91c1c,color:#fff
style M fill:#22c55e,stroke:#16a34a,color:#fff
ArcSight Components
Enterprise Security Manager
Core SIEM
- Real-time correlation
- 400+ correlation rules
- Dashboards and reporting
- Case management
ArcSight Intelligence
SOAR + UEBA
- Automated playbooks
- User behavior analytics
- ML-based detection
- Threat hunting
Logger
Log management
- 1M+ EPS ingestion
- Compression 10:1
- Long-term retention
- Fast search
Connectors
Integrations
- 450+ out-of-box
- Syslog, CEF, LEEF
- Cloud connectors
- Custom FlexConnector
Threat Intelligence
IOC and threat feeds
- STIX/TAXII support
- Commercial feeds
- IOC correlation
- Threat context
Network Detection
NDR
- Network traffic analysis
- Lateral movement detection
- Encrypted traffic
- NetFlow/IPFIX
Use Cases - Correlation Rules
ArcSight has 400+ built-in correlation rules:
| Category | Detection examples |
|---|---|
| Brute Force | Failed logins > threshold over time |
| Privilege Escalation | User added to admin group |
| Data Exfiltration | Unusual outbound data volume |
| Malware | Known C2 communication |
| Insider Threat | After-hours access + sensitive data |
| Lateral Movement | RDP/SSH between servers |
flowchart LR
A[Event: Failed login] --> B[ESM]
C[Event: Failed login] --> B
D[Event: Failed login] --> B
E[Event: Success login] --> B
B --> F{5 fails + 1 success < 1min?}
F -->|Yes| G[Alert: Brute Force Success]
F -->|No| H[No alert]
style A fill:#6366f1,stroke:#4f46e5,color:#fff
style B fill:#f59e0b,stroke:#d97706,color:#fff
style F fill:#8b5cf6,stroke:#7c3aed,color:#fff
style G fill:#dc2626,stroke:#b91c1c,color:#fff
Scalability
ArcSight is designed for enterprise:
| Parameter | Value |
|---|---|
| EPS (events per second) | 1M+ (Logger) |
| Retention | Years (compressed) |
| Correlation | 100k+ EPS real-time |
| Connectors | 450+ |
| Deployment | On-prem, AWS, Azure |
Who is it for?
ArcSight MAKES sense when:
- • You have a SOC (Security Operations Center)
- • Enterprise scale - thousands of log sources
- • Compliance requires retention and reports
- • You need advanced correlation
- • On-premises requirement
ArcSight DOESN'T make sense when:
- • Small company without dedicated security
- • Cloud-native - consider cloud SIEM
- • Just log storage - ELK may suffice
- • No team to operate SIEM
ArcSight vs competition
| Aspect | ArcSight | Splunk | Microsoft Sentinel | QRadar |
|---|---|---|---|---|
| Type | Traditional SIEM | Data platform | Cloud SIEM | Traditional SIEM |
| Scale | Very high | Very high | High | High |
| On-prem | Yes | Yes | No | Yes |
| Correlation | 400+ rules | SPL queries | KQL + ML | Rules |
| SOAR | Built-in | Add-on | Built-in | Add-on |
| Pricing | EPS-based | Data volume | Data volume | EPS-based |
| Learning curve | Steep | Medium | Medium | Steep |
ArcSight advantage:
- Best real-time correlation in the industry
- Proven in the world’s largest SOCs
- On-premises for regulated industries
- Integrated SOAR
Specifications
| Parameter | Value |
|---|---|
| Deployment | On-premises, AWS, Azure, Hybrid |
| Scale | 1M+ EPS |
| Correlation rules | 400+ out-of-box |
| Connectors | 450+ |
| Standards | CEF, Syslog, STIX/TAXII |
| Compliance | PCI DSS, HIPAA, SOX, GDPR |
| HA | Active-passive, clustering |
FAQ
What’s the difference between ESM and Logger? Logger is high-performance log storage (collection, compression, search). ESM is the correlation engine (rules, alerts, dashboards). Often used together.
How much EPS do I need? Depends on infrastructure. Typically: 1000 users = 5-10k EPS. Licensing per EPS or per source.
How long does deployment take? Basic: 1-2 months. Full with custom rules and integrations: 3-6 months.
Do I need a SOC? SIEM requires analysts to handle alerts. Without a SOC, alerts will be ignored. Consider MSSP if lacking resources.
What about cloud? ArcSight has connectors for AWS, Azure, GCP. Can also run in cloud (marketplace).
How does ArcSight Intelligence differ from ESM? Intelligence adds ML/UEBA (anomaly detection) and SOAR (automated response). ESM is rule-based correlation.
Does nFlo implement ArcSight? Yes. ESM, Logger deployments, correlation configuration, source integration, tuning, SOC training.
Inquire about OpenText ArcSight
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Security Operations Center (SOC)
Cybersecurity
Detect threats 24/7 without the cost of your own SOC. Average response time 15 minutes.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist