Skip to content
Cybersecurity OpenText

OpenText ArcSight

OpenText ArcSight: SIEM (Security Information and Event Management) platform. Enterprise Security Manager, Log Analytics, Threat Intelligence. Real-time threat detection.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • Enterprise Security Manager - event correlation, real-time monitoring
  • Intelligence (SOAR) - response automation, playbooks
  • Logger - centralized logging, compliance
  • Threat Intelligence - threat feeds, IOC matching
  • User Behavior Analytics - anomaly detection
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

What is OpenText ArcSight?

OpenText ArcSight (formerly Micro Focus ArcSight) is a SIEM (Security Information and Event Management) platform - a system for collecting, correlating, and analyzing security logs from across the entire infrastructure. It detects threats in real-time and automates response.

Main components:

  • Enterprise Security Manager (ESM) - correlation, dashboards, alerts
  • ArcSight Intelligence (SOAR) - automation, playbooks
  • Logger - high-performance log storage
  • Threat Intelligence - threat feeds, IOC

What problem does it solve?

flowchart LR
    subgraph Without SIEM
        A[Logs in 100 places] --> B[No correlation]
        B --> C[Alert fatigue]
        C --> D[Missed threats]
    end

    subgraph With ArcSight
        E[Centralized logs] --> F[Real-time correlation]
        F --> G[Prioritization]
        G --> H[Fast response]
    end

    style A fill:#dc2626,stroke:#b91c1c,color:#fff
    style B fill:#dc2626,stroke:#b91c1c,color:#fff
    style C fill:#dc2626,stroke:#b91c1c,color:#fff
    style D fill:#dc2626,stroke:#b91c1c,color:#fff
    style E fill:#22c55e,stroke:#16a34a,color:#fff
    style F fill:#22c55e,stroke:#16a34a,color:#fff
    style G fill:#22c55e,stroke:#16a34a,color:#fff
    style H fill:#22c55e,stroke:#16a34a,color:#fff

Common problems:

  • Logs scattered across hundreds of systems
  • No correlation between events
  • Too many alerts - unclear what’s important
  • Slow incident response
  • Compliance requires retention and reports

How does ArcSight work?

flowchart TD
    subgraph Sources
        A[Firewall]
        B[IDS/IPS]
        C[Servers]
        D[Applications]
        E[Cloud]
    end

    subgraph ArcSight
        F[Connectors] --> G[Logger]
        G --> H[ESM]
        H --> I[Correlation Engine]
        I --> J{Threat?}
        J -->|Yes| K[Alert + Case]
        J -->|No| L[Archive]
        K --> M[SOAR Playbook]
    end

    A --> F
    B --> F
    C --> F
    D --> F
    E --> F

    style A fill:#6366f1,stroke:#4f46e5,color:#fff
    style B fill:#6366f1,stroke:#4f46e5,color:#fff
    style C fill:#6366f1,stroke:#4f46e5,color:#fff
    style H fill:#f59e0b,stroke:#d97706,color:#fff
    style I fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style K fill:#dc2626,stroke:#b91c1c,color:#fff
    style M fill:#22c55e,stroke:#16a34a,color:#fff

ArcSight Components

Enterprise Security Manager

Core SIEM

  • Real-time correlation
  • 400+ correlation rules
  • Dashboards and reporting
  • Case management

ArcSight Intelligence

SOAR + UEBA

  • Automated playbooks
  • User behavior analytics
  • ML-based detection
  • Threat hunting

Logger

Log management

  • 1M+ EPS ingestion
  • Compression 10:1
  • Long-term retention
  • Fast search

Connectors

Integrations

  • 450+ out-of-box
  • Syslog, CEF, LEEF
  • Cloud connectors
  • Custom FlexConnector

Threat Intelligence

IOC and threat feeds

  • STIX/TAXII support
  • Commercial feeds
  • IOC correlation
  • Threat context

Network Detection

NDR

  • Network traffic analysis
  • Lateral movement detection
  • Encrypted traffic
  • NetFlow/IPFIX

Use Cases - Correlation Rules

ArcSight has 400+ built-in correlation rules:

CategoryDetection examples
Brute ForceFailed logins > threshold over time
Privilege EscalationUser added to admin group
Data ExfiltrationUnusual outbound data volume
MalwareKnown C2 communication
Insider ThreatAfter-hours access + sensitive data
Lateral MovementRDP/SSH between servers
flowchart LR
    A[Event: Failed login] --> B[ESM]
    C[Event: Failed login] --> B
    D[Event: Failed login] --> B
    E[Event: Success login] --> B
    B --> F{5 fails + 1 success < 1min?}
    F -->|Yes| G[Alert: Brute Force Success]
    F -->|No| H[No alert]

    style A fill:#6366f1,stroke:#4f46e5,color:#fff
    style B fill:#f59e0b,stroke:#d97706,color:#fff
    style F fill:#8b5cf6,stroke:#7c3aed,color:#fff
    style G fill:#dc2626,stroke:#b91c1c,color:#fff

Scalability

ArcSight is designed for enterprise:

ParameterValue
EPS (events per second)1M+ (Logger)
RetentionYears (compressed)
Correlation100k+ EPS real-time
Connectors450+
DeploymentOn-prem, AWS, Azure

Who is it for?

ArcSight MAKES sense when:

  • You have a SOC (Security Operations Center)
  • Enterprise scale - thousands of log sources
  • Compliance requires retention and reports
  • You need advanced correlation
  • On-premises requirement

ArcSight DOESN'T make sense when:

  • Small company without dedicated security
  • Cloud-native - consider cloud SIEM
  • Just log storage - ELK may suffice
  • No team to operate SIEM

ArcSight vs competition

AspectArcSightSplunkMicrosoft SentinelQRadar
TypeTraditional SIEMData platformCloud SIEMTraditional SIEM
ScaleVery highVery highHighHigh
On-premYesYesNoYes
Correlation400+ rulesSPL queriesKQL + MLRules
SOARBuilt-inAdd-onBuilt-inAdd-on
PricingEPS-basedData volumeData volumeEPS-based
Learning curveSteepMediumMediumSteep

ArcSight advantage:

  • Best real-time correlation in the industry
  • Proven in the world’s largest SOCs
  • On-premises for regulated industries
  • Integrated SOAR

Specifications

ParameterValue
DeploymentOn-premises, AWS, Azure, Hybrid
Scale1M+ EPS
Correlation rules400+ out-of-box
Connectors450+
StandardsCEF, Syslog, STIX/TAXII
CompliancePCI DSS, HIPAA, SOX, GDPR
HAActive-passive, clustering

FAQ

What’s the difference between ESM and Logger? Logger is high-performance log storage (collection, compression, search). ESM is the correlation engine (rules, alerts, dashboards). Often used together.

How much EPS do I need? Depends on infrastructure. Typically: 1000 users = 5-10k EPS. Licensing per EPS or per source.

How long does deployment take? Basic: 1-2 months. Full with custom rules and integrations: 3-6 months.

Do I need a SOC? SIEM requires analysts to handle alerts. Without a SOC, alerts will be ignored. Consider MSSP if lacking resources.

What about cloud? ArcSight has connectors for AWS, Azure, GCP. Can also run in cloud (marketplace).

How does ArcSight Intelligence differ from ESM? Intelligence adds ML/UEBA (anomaly detection) and SOAR (automated response). ESM is rule-based correlation.

Does nFlo implement ArcSight? Yes. ESM, Logger deployments, correlation configuration, source integration, tuning, SOC training.

Inquire about OpenText ArcSight

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist