Cyberattacks are growing in sophistication, and traditional cybersecurity tools have struggled to keep pace, especially as global supply chains and private organizations remain fragile due to the Covid-19 pandemic and geopolitical instability. In this context, organizations need strong security foundations, resilient operations, and the ability to detect and respond to incidents through real-time monitoring and analysis. Many have therefore built or expanded Security Operations Centers (SOCs), historically centered on SIEM solutions for collecting, storing, and investigating security events across diverse sources.
SIEM, coined in 2005, initially promised comprehensive security monitoring but often delivered overwhelming false positives, alert fatigue, high deployment and maintenance costs, limited real-time response, and scalability constraints. As IT environments grew more complex, legacy SIEMs struggled to adapt. Over the last decade, SIEM capabilities improved by incorporating machine learning, UEBA, SOAR, NDR, and EDR-aligned workflows, enabling more automation, better analytics, and more streamlined incident handling. Next-generation SIEMs are expected to reduce dependence on scarce expert operators through actionable alerts, automation, risk scoring, threat hunting, and easier forensic investigation via integration with other security tools.
Micro Focus (founded 1976) owns ArcSight following a 2017 spin-merger with HPE software. ArcSight, established in 2000, is now part of Micro Focus’ CyberRes portfolio and is positioned as an end-to-end SecOps platform integrating SIEM (ESM), native SOAR, Recon for log management and hunting, Galaxy threat intelligence (GTAP feeds), ArcSight Intelligence for ML-driven anomaly detection and risk scoring, and SODP for real-time data collection and transformation with smart connectors for extensive source coverage. ArcSight emphasizes layered analytics (correlation plus supervised and unsupervised ML), multiple deployment models (SaaS, cloud-hosted, on-prem), MITRE ATT&CK dashboards, and modernization toward a unified interface, data model, and storage—while acknowledging ongoing modernization work, on-prem maintenance burden, and lack of EDR.
See All Locations
See All Locations