ArcSight Intelligence SIEM(provides visibility over any devices)
Use Cases and Deployment Scope
Pros
- It provide a single console to monitor several connectors.
- It helps us to integrate all kind of log sources .
- It helps us to create filters and manage the specific search according to usecases.
- We can create several filter at the same time and manage all the device activity also create a parser to parse the logs from different devices.
Cons
- It is slow comparing to any other SIEM Tool.
- We have to create filter for each alerts need some custom filter .
- Here we dont have any single tab for see all the alerts .also need some attractive features for dashboard.
Likelihood to Recommend
It covers all kind of devices so easily integrate any device and analyze their activity.
Can manage multiple client and minimze the false positive easily according to organizations needs and requirements.
Its provide facility to merge any of the SOAR tool .we can also see connectors status on a single pane that helps us in troubleshooting
