OpenText ArcSight
Long-running enterprise SIEM and UEBA platform from OpenText’s Cybersecurity division, providing real-time correlation and behavioral threat detection for large security operations centers.
Visit Website ↗ + Add to CompareOverview
ArcSight is OpenText’s enterprise SIEM (security information and event management) platform, built around a high-throughput correlation engine that ingests and normalizes log and event data from across an organization’s infrastructure to detect threats in real time. It originated as an independent company, was acquired by HP in 2010, passed through HP Enterprise’s spin-merger with Micro Focus in 2017, and landed at OpenText when it acquired Micro Focus for roughly $6 billion in 2023. ArcSight Intelligence, a companion UEBA (user and entity behavior analytics) module, layers unsupervised machine learning on top of the core SIEM to flag anomalous account and data-access behavior without requiring analysts to hand-write correlation rules.
The platform remains one of the longest-running SIEM products still in active enterprise use, which cuts both ways: it has a large installed base and deep integration ecosystem in industries like financial services, government, and healthcare, but it also competes against a wave of cloud-native SIEM and AI-SOC challengers that do not carry ArcSight’s on-premises-era architecture. OpenText has continued to invest in the product post-acquisition, marketing it alongside NetIQ (identity), Voltage (data protection), and Fortify (application security) as the four pillars of its Cybersecurity division.
For CISOs already running ArcSight, the case for staying is operational continuity and the depth of existing rule and content libraries; for net-new buyers, it competes on breadth of integration and behavioral analytics rather than modern cloud-native deployment simplicity.
Innovation Matrix Assessment
Product investment continues under OpenText, but ArcSight's release cadence and public roadmap communication are far less visible than younger, VC-backed SIEM/UEBA challengers; this reflects steady maintenance rather than fast iteration.
ArcSight's correlation engine and ArcSight Intelligence UEBA module cover core SIEM and insider-threat detection needs at enterprise scale, though its architecture originated in the on-premises era and requires more operational overhead than newer cloud-native SIEM tools.
Continues to be sold and supported as one of four flagship product lines in OpenText's Cybersecurity division following the ~$6B Micro Focus acquisition, but OpenText has not published independent growth figures for ArcSight specifically, and the brand has changed hands three times since 2010.
A 20+ year old SIEM incumbent with a large historical installed base; per this site's convention, mature, already-scaled incumbents are scored low on disruption regardless of continued relevance.
Long operating history and broad deployment across regulated industries (a customer story from Bernicia Homes describes ArcSight Intelligence surfacing behavioral anomalies), but OpenText has not published independent third-party detection benchmark results for the current ArcSight release.
SIEM and behavioral analytics remain foundational SOC infrastructure, but ArcSight increasingly competes with cloud-native SIEM and AI-driven detection platforms built without its on-premises legacy.
Why CISOs Should Care
Gives security teams already standardized on ArcSight continuity of correlation rules and UEBA behavioral detection without a platform migration, backed by OpenText's ongoing investment in the Cybersecurity division.
What Makes It Different
One of the few SIEM platforms with two-decade production history across regulated industries, now paired with unsupervised-ML behavioral analytics (ArcSight Intelligence) rather than rule-only correlation.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A durable, still-supported SIEM incumbent whose main value is depth and continuity for existing customers; new deployments increasingly favor cloud-native alternatives, which caps its innovation and disruption scoring even as its operational relevance persists.
Editorial Note: Claims vs. Verified Findings
The Bernicia Homes quote and other customer references are vendor-published case studies on OpenText's site and are not independently verified. The Micro Focus acquisition value (~$6B) and corporate ownership history are independently reported. No independent third-party SIEM benchmark or MITRE ATT&CK evaluation data for ArcSight was found.
Sources
Alternatives to OpenText ArcSight
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Anvilogic
Palo Alto-based AI security operations platform that automates SOC detection engineering across existing SIEMs and data lakes without…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…