A failed VPN login, a new admin account, an odd outbound connection. Three consoles shouldn’t hide one attack — OpenText Enterprise Security Manager, formerly ArcSight ESM, correlates events from 480+ source types as they arrive, scores their priority and starts SOAR playbooks — on servers you run, so your logs stay where you put them.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers OpenText Enterprise Security Manager — the correlation SIEM, with Security Log Analytics and Threat Detection and Response as sibling products. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A SIEM gathers events from every system, and a correlation engine links related ones into a single alert as they arrive.
What consolidation actually replaces, dimension by dimension.
| Dimension | Logs on every device, alerts by email | OpenText Enterprise Security Manager |
|---|---|---|
| Spotting a multi-step attack | Three consoles, read by three people | One rule joins the steps as events arrive |
| Which alert first | Whichever arrived last | A priority formula weighs asset and severity |
| Known bad addresses | A list someone pastes in weekly | A native threat-intelligence feed enriches events |
| First response | Email the network team and wait | A SOAR playbook runs the first steps |
| Proving log retention | Exports pulled from each device | Security Log Analytics keeps logs with reports |
| What it is NOT | — | SaaS, UEBA on its own, or a published price |
The cheapest test is three sources: connect your firewall, directory and VPN, turn on the default content, and see which alerts it joins.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Connectors read logs from 480+ source types, normalise and categorise each event, and forward it to the Manager; import connectors load asset and actor models too.
The Manager runs rules against the live stream; the CORR-Engine, OpenText’s own Correlation Optimized Retention and Retrieval store, writes and searches events at high rates.
Compact mode runs everything on one server; distributed correlation mode spreads correlators and aggregators across a cluster that shares a message bus and cache.
Security Log Analytics, formerly ArcSight Logger, keeps raw logs in columnar storage with immutability safeguards and 100+ prebuilt reports, beside ESM’s working set.
Connectors normalise every event, a Manager correlates the live stream — on one server or a cluster you run yourself.
OpenText Enterprise Security Manager turns events from every system into prioritised alerts the moment they arrive.
SmartConnectors gather events from firewalls, servers, directories and clouds; the 26.2 release line is current in 2026.
Each event is normalised and categorised on arrival, so a rule written once matches the same action from any vendor.
Asset Model and Actor Model import connectors bring CMDB and directory data, so rules know who and what is involved.
Hundreds of adjustable correlation rules match patterns across sources in the live stream, not in a scheduled search.
OpenText’s priority formula weighs several data points and criteria per event, so the riskiest alert rises first.
ESM 7.9 installs Security Threat Monitoring and Threat Intelligence Platform content at 4.8, with ATT&CK views.
OpenText lists a native SOAR with out-of-the-box playbooks, incident management and SOC analytics as part of ESM.
A native threat-intelligence feed with open-source data enriches events, so known bad addresses raise priority.
Personal dashboards and scheduled reports serve analysts and auditors; FIPS 140-2 mode suits stricter installs.
ESM’s default content, detecting known threats, real-time correlation and distributed correlation mode. All from OpenText’s official Security Operations channel, recorded in 2021 and 2024 under the former ArcSight name.
What ships in ESM’s default content and how it is organised — recorded in 2024, when the product was still called ArcSight ESM.
How the default rules catch known threats from intelligence feeds — a 2024 recording under the former ArcSight name.
Correlation on the live event stream, explained in 2021, before the product was renamed Enterprise Security Manager.
The distributed correlation mode that still scales ESM today, introduced in the Micro Focus era (2021 upload).
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
ESM matches rules against events as they arrive, so a login failure on a VPN, a new admin account and an odd outbound connection join into one alert within seconds rather than in a search scheduled for later. OpenText rates the engine at 100,000+ events a second; your hardware sets your figure.
OpenText lists a native SOAR with playbooks and incident management, and a native threat-intelligence feed, as part of ESM. Many rivals sell automation as a separate product. Rheinmetall, an OpenText customer, cites 35% cost savings from what OpenText calls flexible licensing.
ESM is installed and run by you, in compact mode on one server or distributed across a cluster, so events are stored and processed wherever you put it. For an Indian bank or insurer that has to keep logs in the country, that is a design fact rather than a vendor promise to verify.
There is no public price, no SaaS edition of ESM itself, and no current Gartner SIEM placement. You run, patch and size the servers. Long retention needs Security Log Analytics, and behavioural analytics needs Threat Detection and Response. The newest official videos still say ArcSight.
List every log source, its daily event rate and peak, and the retention each regulator asks of you, before any sizing.
Match your sustained events per second to one server or a correlation cluster, and decide where Log Analytics sits.
Install connectors for firewalls, directory and VPN, load the asset model from your CMDB, and check normalisation.
Turn on the 4.8 packages, tune noisy rules, map them to ATT&CK and wire the first SOAR playbook to a ticket.
Add the remaining sources in waves, schedule compliance reports, and agree the upgrade cadence with OpenText.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A brute-force run on our VPN and a new domain admin a minute later became one high-priority case. That join is why we stayed.”
“Connectors covered our old mainframe gateway and our cloud firewalls alike. Normalisation meant one rule for all three firewall brands.”
“Moving from compact mode to distributed correlation took a professional-services week, but month-end peaks no longer queue.”
“Loading the asset model from our CMDB changed triage: a hit on a payment server now outranks the same hit on a lab box.”
“Auditors wanted logs kept in India for 180 days. Our own racks plus Log Analytics answered that without a cloud attestation.”
“Strong engine, dated console in places, and every upgrade needs a plan. Budget admin time, not only licences.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted; long-installed base, no public price.
The grid nobody publishes — how fully you can run the SIEM on your own servers, in India included, vs how much correlation and prioritisation it does on the live stream.
Self-hosted only; stream correlation with priority scoring.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Splunk Enterprise Security, Microsoft Sentinel, LogRhythm SIEM, Fortinet FortiSIEM and ManageEngine Log360 — on deployment, coverage, price, scale, detection, compliance, support and India.
| Dimension | OpenText Enterprise Security Manager | Splunk Enterprise Security | Microsoft Sentinel | LogRhythm SIEM | Fortinet FortiSIEM | ManageEngine Log360 |
|---|---|---|---|---|---|---|
| What it is | Real-time SIEM | Cisco’s flagship SIEM | Azure-native SIEM | Self-hosted SIEM | SIEM plus CMDB | India-built SIEM |
| Deployment | Self-hosted, 2 modes | Cloud, on-prem, hybrid | SaaS on Azure only | On-prem only | Appliance, VM or cloud | On-prem or cloud |
| Sources and coverage | 480+ source types | Any machine data | Microsoft logs free | Estate-wide, in-house | Multi-vendor + CMDB | Sources, AD, cloud |
| Pricing model | EPS or GB/day (reported) | Ingest or workload | Per GB ingested | Subscription/perpetual | Device/EPS or GB/day | Per log source |
| Published entry price | Not published | No list price | ~$4.30/GB PAYG | Quote only | Quote only | From ~$300 a year |
| Included vs add-on | SOAR and intel included | SOAR is separate | Logic Apps billed apart | Cloud UEBA add-on | FortiSOAR separate | UEBA, SOAR built in |
| Scale | 100,000+ EPS (claim) | Largest estates | Up to 50,000 GB/day | You size the iron | Multi-tenant for MSSPs | Mid-market scale |
| Detection depth | Correlation + priority | Risk-based alerting | KQL rules + UEBA | 1,100+ prebuilt rules | Context from CMDB | Rules, UEBA and Zia |
| Integrations | OpenText security stack | Cisco XDR, Splunkbase | Defender and Copilot | Sync with New-Scale | Security Fabric | ManageEngine suite |
| Governance and compliance | FIPS 140-2 mode | Roles, ESCU content | Azure RBAC | Compliance mapped | Compliance reports | Thousands of templates |
| India data | Your own servers | AWS Mumbai listed | Stored in India only | Yours by design | Mumbai cloud or on-prem | Indian DCs or on-prem |
| Support | Quoted contract | Quoted, billed in USD | Paid plan from $29 | Vendor plus your team | FortiCare, quoted | Indian vendor |
| Lock-in and exit | Rules in ESM’s model | SPL content | Azure-bound | Ask for the roadmap | Fabric gravity | Easy to scope out |
| Best fit | Ex-ArcSight estates | Detection engineers | Microsoft estates | No-SaaS mandates | Fortinet networks | Indian mid-market |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
OpenText Enterprise Security Manager is one of 35 siem & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (log sources feeding the SIEM; analyst-hour cost). Estimates model analyst time spent chasing each source’s alerts by hand and stitching events across consoles, at an assumed 1.5 hours per source a year, with 70% of it removed by real-time correlation and playbooks. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote only. OpenText publishes no price for Enterprise Security Manager and no rupee price for any security product. Third-party guides describe ESM licences by sustained events per second or by GB a day, quoted with support and services; OpenText says Rheinmetall saved 35% through flexible licensing. Security Log Analytics, for long retention, and Threat Detection and Response, for behavioural analytics, are separate products. TechBag measures your event rate first, then quotes in INR with GST.
Best for real-time correlation on your own servers
Best for a broader rollout
Best for long log retention and audit reports
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your sustained and peak events per second, measured, not estimated? It decides servers and licence.
Is the quote by events per second or GB a day, and what happens when a busy month exceeds it?
Compact mode on one server, or distributed correlation across a cluster? Ask who designs and supports it.
Where do logs live after ESM’s working set: Security Log Analytics, and for how many days in India?
Which default packages and rules will run on day one, and who tunes them in the first ninety days?
Which playbooks ship ready, and do they reach your ticketing, firewall and directory tools?
Are you on 7.6.4 or later? Older installs need a staged path before they can reach 7.9.
Does it itemise ESM, Log Analytics, connectors, support and services? Ask for INR with GST.
Measure your event rate and retention first, or let a TechBag advisor size compact or distributed mode, plan India-hosted retention and get the quote itemised in INR.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.