Cofense Vision stores emails offline and provides threat hunting analytics. Cofense Vision allows the user to search and quarantine emails in minutes — across an entire organization, and is designed to provide threat hunting at speed.
N/A
Arcsight by OpenText
Score 5.3 out of 10
N/A
A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.
N/A
Pricing
Cofense Vision
Arcsight by OpenText
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cofense Vision
Arcsight by OpenText
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Cofense Vision
Arcsight by OpenText
Features
Cofense Vision
Arcsight by OpenText
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Cofense Vision
-
Ratings
Arcsight by OpenText
5.5
Ratings
34% below category average
Centralized event and log data collection
00 Ratings
8.00 Ratings
Correlation
00 Ratings
9.00 Ratings
Event and log normalization/management
00 Ratings
8.00 Ratings
Deployment flexibility
00 Ratings
6.00 Ratings
Integration with Identity and Access Management Tools
It is well suited in environments where there is a high mail traffic to handle. [Cofense] Vision basically journals the exchange server and keeps a copy of the mail received in the environment. Really beneficial to revoke and quarantine the mail reported by one user, but footprint is there in other mailboxes as well. Less appropriate in the cases where there is no proper segregation of duties within the organization. As it is possible to see contents of the mail. Only authorized personnel should be able to use it.
In the current lot of hundreds of SIEM solutions out there in the market, ArcSight ESM is fairly less expensive with strong fundamentals in place. The log ingestion, correlation are very well performing and totally worth ROI. However, the tool has lost its way when it comes to staying abreast with current feature curve of SIEM technology and the evolution has not been done by MicroFocus. Search times are high and there is no major plug-in that has been introduced as part of the product life cycle.
Overall, it is a good investment in order for an organization to stay compliant and stay secure from all the wild things happening. It is definitely a cost effective tool with some good features including correlation, log storage, reporting and dashboards. If a customer is looking for advanced set of features, then I would highly not recommend this.
If you go for platinum support, it's good as you have priority for support. They will take remote control of your machines and troubleshoot. Also, they arrange requirement SEM depending on the issue.
Agari Phishing Defense is extremely easy to use software, with an immediate response capacity in the presence of phishing, but Cofense Vision is a tool with flexible implementation and a great capacity to adapt to the needs of each company, as well as having a high level of integration with other software and its great capacity to carry out searches, detection and give rapid responses to incidents that is why we have chosen Cofense Vision.
We are currently using Elastic search as well for better management of our devices and to keep all the loopholes filled that have been created around the non-upgraded version of Arcsight Enterprise Manager. Elastic searches have the latest mechanism to fetch logs and correlated data, as well as process them in a more useful way.