ArcSight version 3.5.2.
The ArcSight product is a security management solution that allows a user to manage all enterprise activity from one centralized view. ArcSight integrates existing multi-vendor devices throughout the enterprise into its scope and gathers all generated events. ArcSight allows users to monitor events in real-time, correlate events for in-depth investigation and analysis, and resolve events with automated escalation procedures and actions. ArcSight product gathers events generated by multi-vendor devices, normalizes, and stores those events in the centralized ArcSight Database, and then filters and cross-correlates those events with rules to generate meta-events.