Support
 
Support Get Quote
 
 
 
 

EventLog Analyzer vs. HP ArcSight ESM

 
Vs.
 

This document provides a feature-wise comparison report between ManageEngine EventLog Analyzer and HP ArcSight Enterprise Security Manager. Comparison done here is based on the information available in the competitor’s website and so the details may vary with the real product.

This document provides a feature-wise comparison report between ManageEngine EventLog Analyzer and HP ArcSight.

Feature Comparison

Feature Description [ Close All ] [ Expand All ]
 
 
  Log Collection
Agent-less    
Agent based    
Cross platform log collection    
Heterogeneous server/ device support    
Import logs    
Log filter    
Universal Log Parsing and Indexing(ULPI)    
Log collection rate 20,000 Syslogs/second with peak event handling capacity of 25,000 Sylogs/second. For Windows Event logs, the EPS is 2000 logs/second. Depends on the type of software model. Log collection rate ranges from 1,000 events per second to 12,500 events per second.
  Log formats supported
Windows event log    
Syslog    
Amazon Web Services (AWS) EC2 Windows instances   Not specified
Any format – with Universal Log Parsing and Indexing (ULPI) technology    
  Application logs supported
Proprietary applications [Microsoft IIS Web Server, FTP Server (W3C logs), Apache Web Server, DHCP Windows, DHCP Linux]   Available in add-on: HP ArcSight Application View
Database applications [Oracle Audit, MS SQL Server]   Available in add-on: HP ArcSight Application View
Any application – with Universal Log Parsing and Indexing (ULPI) technology   Available in add-on: HP ArcSight Application View
  Other devices supported
Custom devices [IBM iSeries (AS/400), VMware]    
Custom devices
  •  Firewalls
  •  Intrusion Detection System/ Intrusion Prevention System (IDS/IPS)
  •  Anti-virus application
  •  Mail and web application
  •  Vulnerability Scanners
  •  Unified threat management solutions
    •  Symantec DLP Application
    •  FireEye
    •  Symantec Endpoint Solution
  Available in add-on: HP ArcSight Application View
  Alerts & Notification
Real-time alert    
Notification – Email, SMS, Run program    
Compliance alerts   Available in add-on: HP ArcSight Compliance Insight Package
  Reports
File Integrity Monitoring    
Canned reports    
Custom reports    
Scheduled reports    
Report distribution via Email    
Reports in PDF, CSV & HTML formats    
Drill down to raw logs    
Filter using mouse gesture    
Management specific reports (Ask ME)    
Trend reports    
Privileged user activity monitoring reports   Available in add-on: HP ArcSight IdentityView
  Log Search
Advanced Search using Boolean, Wildcards, Grouped Search, Range search, Phrase search    
Formatted logs    
Raw logs   Available in USM Logger component
Save search result as report    
  Compliance Reports
Canned reports   Available in add-on: HP ArcSight Compliance Insight Package
Customizable report   Available in add-on: HP ArcSight Compliance Insight Package
Reports for new compliance   Available in add-on: HP ArcSight Compliance Insight Package
PCI-DSS   Available in add-on: HP ArcSight Compliance Insight Package
ISO 27001:2013   Available in add-on: HP ArcSight Compliance Insight Package
HIPAA   Available in add-on: HP ArcSight Compliance Insight Package
FISMA   Available in add-on: HP ArcSight Compliance Insight Package
SOX   Available in add-on: HP ArcSight Compliance Insight Package
GLBA   Available in add-on: HP ArcSight Compliance Insight Package
  Real-time Event Correlation
Event correlation    
User Session monitoring    
  File Integrity Monitoring
Reports on File Integrity Monitoring   Not Specified
Report Scheduling   Not Specified
Real-time alerts upon critical changes to files/folders being monitored   Not Specified
Audit trial reports on files/folders changes   Not Specified
  Log Archiving
Flexible periodicity    
Flexible retention    
Secured (Encrypted)    
Tamper-proof    
  Service Provider features
User based views    
User based dashboards    
Rebranding    
  User Management
Realm & user based access   Not specified
Active Directory based user authentication   Not specified
RADIUS server based user authentication   Not specified
  Implementation
Easy to install    
Web based Client    
Appliance    
  System Requirements
Bundled database (PostgreSQL/MySQL)   Not Specified
Windows & Linux platforms support   Supports only Linux platform
64 Bit support    
Pricing
Based on number of servers, devices & applications    Based on volume of log data collected each day.
Annual Subscription Model   Not Specified
Perpetual Model   Not Specified
Cost Economical.
Server/application based licensing. Annual Subscription License Premium Edition 10 log sources pack starts at $495. Yearly renewal includes upgrade, maintenance, and support.
Expensive.
Starts at $175,000

Though every care has been taken to ensure the correctness of the information provided herein, minor variations might be found in the feature set. In case, you find any discrepancies, please write to us at: eventlog-support@manageengine.com

Still undecided? Try it for your self.

EventLog Analyzer Trusted By

Los Alamos National Bank Michigan State University
Panasonic Comcast
Oklahoma State University IBM
Accenture Bank of America
Infosys
Ernst Young

Customer Speaks

  • Credit Union of Denver has been using EventLog Analyzer for more than four years for our internal user activity monitoring. EventLog Analyzer provides great value as a network forensic tool and for regulatory due diligence. This product can rapidly be scaled to meet our dynamic business needs.
    Benjamin Shumaker
    Vice President of IT / ISO
    Credit Union of Denver
  • The best thing, I like about the application, is the well structured GUI and the automated reports. This is a great help for network engineers to monitor all the devices in a single dashboard. The canned reports are a clever piece of work.
    Joseph Graziano, MCSE CCA VCP
    Senior Network Engineer
    Citadel
  • EventLog Analyzer has been a good event log reporting and alerting solution for our information technology needs. It minimizes the amount of time we spent on filtering through event logs and provides almost near real-time notification of administratively defined alerts.
    Joseph E. Veretto
    Operations Review Specialist
    Office of Information System
    Florida Department of Transportation
  • Windows Event logs and device Syslogs are a real time synopsis of what is happening on a computer or network. EventLog Analyzer is an economical, functional and easy-to-utilize tool that allows me to know what is going on in the network by pushing alerts and reports, both in real time and scheduled. It is a premium software Intrusion Detection System application.
    Jim Lloyd
    Information Systems Manager
    First Mountain Bank

Awards and Recognitions

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  
A Single Pane of Glass for Comprehensive Log Management