10 years of ArcSight - Still enjoy it
What do you like best?
The breadth of resources available for searching out and gathering data. The ability to customize user accounts based on access needs. The focus on web-based interfaces versus Java-based.
What do you dislike?
The need for database tuning for optimal performance. Out-of-box heavy usage results in terrible performance.
Recommendations to others considering the product:
Initial upfront costs can seem high compared with something like Splunk. In the long run costs end up being lower not mention the flexibility of ArcSight and the larger scope with the entire ADP suite which continues to grow. Some of the most recent developments in 2017 have taken the usefulness of the ADP for a Security Operations Center to a whole new level.
What problems are you solving with the product? What benefits have you realized?
Consolidation of multiple log types across multiple environments. We've been able to shrink the footprint of servers needed for data collection.