Tüm satıcılar

Vendor lineage

ArcSight

Decided in advance what mattered, which is the opposite of what its main rival decided.

ArcSight was incorporated in Delaware on 3 May 2000 under the name Wahoo Technologies, and renamed before it shipped anything. Hugh Njemanze was its founding chief technology officer and is the one name every account agrees on - he has been described as the initial architect of security information and event management, and holds more than twenty patents in the field. Alex Daly is recorded as founding chief executive. Other sources name other founders, and they do not reconcile, so only the consistent names appear here.

The problem it existed to solve is worth stating in plain terms. A large network produces millions of log lines a day from firewalls, servers, applications and intrusion sensors, each in its own format, none of which means anything alone. A failed login is noise. Four hundred failed logins from one address, followed by one success, followed by an outbound transfer, is an incident. Somebody has to notice the difference at three in the morning.

ArcSight's answer was ESM, and the architecture is the interesting part. It normalised every event into a common schema first, so a Cisco denial and a Windows audit failure became comparable objects, and then ran correlation rules over that stream. The rules encode what you already know matters. That is a real commitment: you decide in advance what an incident looks like, and the system watches for it continuously.

Set that against Splunk, which is also on this timeline, and you have two opposite bets. Splunk indexed the raw data and let you search it afterwards, deciding what mattered once you had a reason to ask. ArcSight decided first and watched. Rules catch what you anticipated, at the moment it happens; search finds what you did not anticipate, after you know to look. Neither is wrong, and most mature security teams eventually run something of each - but the two designs pulled the market in different directions for a decade.

The company's backing is a detail worth noticing: alongside Kleiner Perkins, its early investors included In-Q-Tel, the venture arm of the CIA. It went public in 2008, and by its 2010 fiscal year was reporting $181.4M of revenue from over a thousand customers with 512 employees, having grown at roughly forty per cent a year.

HP acquired it in 2010 at $43.50 a share, all cash, about $1.5B, completing on 22 October. Then the ownership chain that this timeline keeps producing: the 2015 HP split sent it to Hewlett Packard Enterprise; HPE merged its software business into Micro Focus, finalised 1 September 2017; and OpenText acquired Micro Focus in 2023. Four owners in thirteen years, none of whom wrote it.

And that is the contrast that makes the pair worth reading together. Splunk stayed independent for two decades and was bought by Cisco in 2024 for around $28B as a strategic centrepiece. ArcSight was bought early, then carried along through three further transactions as one line item in somebody else's portfolio. Same market, same era, comparable technical achievement - and the difference in outcome had far more to do with when each sold than with which architecture was better.

Njemanze went on to run engineering and research for HP's enterprise security group, and later became chief executive of ThreatStream, which became Anomali.

Founding stories

2000

ArcSight

Cupertino, California · Founders:

Alex Daly, the founding chief executive, arrived having run Cygnus Solutions - the company that commercialised GNU tooling and was bought by Red Hat. That is a relevant background for the problem: Cygnus sold support and integration around software everybody already had, and the security event problem is also one of making other people's output useful.

Founder attributions vary widely across sources and are not reconciled here; Daly's prior role is the one detail consistently reported.

The timeline

  1. A visionary in a quadrant with no leaders

    Gartner placed it as a visionary in its IT security management assessment that year - in which nobody at all was placed as a leader. The category was too new for anyone to have led it, which is the clearest possible statement of how early this was.

  2. The only one

    It listed on NASDAQ on 14 February, the only Silicon Valley company to do so that year, in the middle of the financial crisis. Tom Reilly became chief executive the same year.

  3. Ten years a leader

    By May it had been in the leaders' section of the SIEM Magic Quadrant for ten consecutive years - a decade at the top of a category it had been called visionary for inventing.

Flagship products and solutions

  • ESMThe Enterprise Security Manager: normalise every event into one schema, then run correlation rules across the combined stream. The normalisation is the unglamorous half and the reason the correlation is possible at all.
  • ConnectorsThe parsers for each source device, and the actual moat. Supporting hundreds of products' log formats is years of tedious work that a competitor must repeat in full, and it is why incumbency in this category is durable.
  • LoggerLong-term storage of the raw events for compliance and investigation, sold alongside the correlation engine because auditors and analysts want different things from the same data.
  • Threat detection and SOARLater additions including automated response, some of it acquired - the same consolidation every vendor in this market has made.

Key innovations

  • Normalising before analysingDeciding that every event from every device would be translated into one schema before anything looked at it is the architectural commitment the product rests on. It is expensive, it must be maintained for every device that ever changes its log format, and it is what allows a rule to reason about a firewall and a directory server in the same sentence.
  • Connector coverage as the real productThe correlation engine is the thing customers buy and the connector library is the thing that keeps them. Any competitor can write a rules engine; nobody wants to re-parse four hundred devices. It is a moat made entirely of work nobody enjoys.
  • Creating a category from the buyer's sideBeing called a visionary in a quadrant with no leaders is what genuine category creation looks like on an analyst's chart: the buyers had the problem, the analysts had the segment, and nobody had yet built something they were willing to call finished.
  • Selling to the organisations with the worst problem firstThe strategy was high-end accounts in retail and financial services - the sectors with the most regulatory obligation and the most to lose. Starting where the pain is greatest funds the engineering, and it also sets the product's shape permanently: this was never going to be software a small company could run.

Main markets

Large enterprises and government, with a bias toward regulated sectors from the beginning. It reported over a thousand customers before the HP acquisition, and its installed base is the reason the product has survived three subsequent changes of owner.

Its competitors were the other early SIEM vendors and, structurally, the opposite architecture - which this timeline records at Splunk. Later entrants including the cloud-native platforms compete on cost of ingestion, which is the axis a normalise-everything design is least comfortable on.

Analyst standing

  • Ten consecutive years in the leaders' section of the SIEM Magic Quadrant is among the longest runs in any security category, and it covers exactly the period between the category's invention and its commoditisation.
  • The current position is harder to state, because what is assessed now is a product line inside a large software portfolio rather than a company. That is the honest end of this entry: the technology is still sold, still deployed and still maintained, and there has been nobody whose primary business it is since 2010.
From the company

This company no longer trades under this name. Now part of OpenText, which holds the ArcSight portfolio.