Talk to us
by OpenTextTechBag Intel Page

OpenText Enterprise Security Manager

A failed VPN login, a new admin account, an odd outbound connection. Three consoles shouldn’t hide one attack — OpenText Enterprise Security Manager, formerly ArcSight ESM, correlates events from 480+ source types as they arrive, scores their priority and starts SOAR playbooks — on servers you run, so your logs stay where you put them.

Correlation on the live event streamNative SOAR and threat intelligenceSelf-hosted, quoted, no public price

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
OpenText prints no price; third-party guides describe EPS or GB-a-day licences
Quote
Throughput
OpenText’s own figure for events analysed per second; your hardware decides yours
100,000+ EPS
Analysts
No OpenText placement was found in Gartner’s 2025 SIEM Magic Quadrant
No current rank
India
Self-hosted, so storage and processing sit wherever you install the Manager
Your servers

Quick answer

OpenText Enterprise Security Manager (formerly ArcSight ESM) is a SIEM you run yourself that correlates events as they arrive; OpenText rates it at 100,000+ events a second from 480+ source types, with a native SOAR and threat-intelligence feed. Version 7.9 shipped in November 2025. It is quote-only, and because you host it, logs stay in India if your servers do. Read more ↓ Show less ↑
Part 01 · Orient

The OpenText platform family

This page covers OpenText Enterprise Security Manager — the correlation SIEM, with Security Log Analytics and Threat Detection and Response as sibling products. The rest:

OpenText Content Management
Enterprise content management, formerly Extended ECM.
View page →
OpenText Fortify
Application security testing: SAST, DAST and SCA.
View page →
NetIQ Identity Governance
Access reviews, provisioning and identity lifecycle.
View page →
NetIQ Access Manager
Single sign-on, federation and adaptive MFA.
View page →
NetIQ Privileged Access Manager
Privileged session control and credential vaulting.
View page →
OpenText Voltage SecureData
Format-preserving encryption and tokenisation.
View page →
OpenText Enterprise Security Manager
This page.
You’re here
OpenText Service Management
ITSM and asset management, formerly SMAX.
View page →
OpenText AI Operations Management
Event and performance monitoring, formerly Operations Bridge.
View page →
OpenText ZENworks
Endpoint management, patching and disk encryption.
View page →
OpenText Data Protector
Enterprise backup for servers, VMs and applications.
View page →
OpenText Availability
Real-time replication and failover, formerly Carbonite.
View page →
OpenText Cloudally Backup
Microsoft 365, Google, Salesforce, Box and Dropbox backup.
View page →
OpenText Performance Engineering
Load and performance testing, formerly LoadRunner.
View page →
OpenText Functional Testing
Automated functional testing, formerly UFT One.
View page →
OpenText Core Endpoint Protection
Cloud endpoint security for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core DNS Protection
DNS filtering for SMBs and MSPs, ex-Webroot.
View page →
OpenText Core Email Threat Protection
Email security and encryption, ex-Zix.
View page →

Quick facts

30-second orientation
Product
Real-time correlation SIEM, formerly ArcSight ESM, with native SOAR and threat intelligence
Maker
Open Text Corporation, Waterloo, Ontario; NASDAQ and TSX: OTEX; CEO Ayman Antoun since April 2026
Status
Version 7.9, released November 2025, with default content packages at version 4.8
Price
Not published; quoted by OpenText and partners, with no rupee price anywhere
Throughput
OpenText claims 100,000+ events per second from 480+ event source types
Deployment
Self-hosted on your servers or a G10 appliance, in compact or distributed correlation mode
Includes
Correlation rules, priority-based risk scoring, MITRE ATT&CK mapping, SOAR playbooks
Siblings
Security Log Analytics (formerly ArcSight Logger) for retention; Threat Detection and Response for UEBA
India
OpenText hosts nothing here; events stay in the data centre or cloud account where you install it
In India via
TechBag — sizing, quote in INR with GST, first correlation-rule review
Part 02 · Learn

Understand correlation SIEMs before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a correlation SIEM?

A SIEM gathers events from every system, and a correlation engine links related ones into a single alert as they arrive.

Logs on every device and alerts by email vs OpenText ESM — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionLogs on every device, alerts by emailOpenText Enterprise Security Manager
Spotting a multi-step attackThree consoles, read by three peopleOne rule joins the steps as events arrive
Which alert firstWhichever arrived lastA priority formula weighs asset and severity
Known bad addressesA list someone pastes in weeklyA native threat-intelligence feed enriches events
First responseEmail the network team and waitA SOAR playbook runs the first steps
Proving log retentionExports pulled from each deviceSecurity Log Analytics keeps logs with reports
What it is NOT—SaaS, UEBA on its own, or a published price

The cheapest test is three sources: connect your firewall, directory and VPN, turn on the default content, and see which alerts it joins.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where events are collected and normalised

Connectors

SmartConnectors and FlexConnectors

Connectors read logs from 480+ source types, normalise and categorise each event, and forward it to the Manager; import connectors load asset and actor models too.

02
Where correlation and storage happen

Manager

ESM Manager and CORR-Engine

The Manager runs rules against the live stream; the CORR-Engine, OpenText’s own Correlation Optimized Retention and Retrieval store, writes and searches events at high rates.

03
How ESM scales out

Modes

Compact or distributed correlation

Compact mode runs everything on one server; distributed correlation mode spreads correlators and aggregators across a cluster that shares a message bus and cache.

04
Where the long tail of logs lives

Retention

Security Log Analytics alongside

Security Log Analytics, formerly ArcSight Logger, keeps raw logs in columnar storage with immutability safeguards and 100+ prebuilt reports, beside ESM’s working set.

Connectors normalise every event, a Manager correlates the live stream — on one server or a cluster you run yourself.

Part 03 · Evaluate

Nine capabilities. Collect, correlate, respond.

OpenText Enterprise Security Manager turns events from every system into prioritised alerts the moment they arrive.

Collect
Connectors

480+ event source types

SmartConnectors gather events from firewalls, servers, directories and clouds; the 26.2 release line is current in 2026.

Collect
Normalise

One schema for every log

Each event is normalised and categorised on arrival, so a rule written once matches the same action from any vendor.

Collect
Context

Assets and actors loaded in

Asset Model and Actor Model import connectors bring CMDB and directory data, so rules know who and what is involved.

Correlate
Real time

Rules fire as events land

Hundreds of adjustable correlation rules match patterns across sources in the live stream, not in a scheduled search.

Correlate
Priority

Risk scored, not just counted

OpenText’s priority formula weighs several data points and criteria per event, so the riskiest alert rises first.

Correlate
Content

Default packages, ATT&CK mapped

ESM 7.9 installs Security Threat Monitoring and Threat Intelligence Platform content at 4.8, with ATT&CK views.

Respond
SOAR

Playbooks in the box

OpenText lists a native SOAR with out-of-the-box playbooks, incident management and SOC analytics as part of ESM.

Respond
Intel feed

Threat intelligence included

A native threat-intelligence feed with open-source data enriches events, so known bad addresses raise priority.

Respond
Reports

Dashboards for each audience

Personal dashboards and scheduled reports serve analysts and auditors; FIPS 140-2 mode suits stricter installs.

See it, don’t just read it

Watch OpenText ESM in action

ESM’s default content, detecting known threats, real-time correlation and distributed correlation mode. All from OpenText’s official Security Operations channel, recorded in 2021 and 2024 under the former ArcSight name.

OpenText Security Operations Unplugged (official)·Walkthrough, January 2024

Default Content: ArcSight ESM | Mastering ArcSight Series

What ships in ESM’s default content and how it is organised — recorded in 2024, when the product was still called ArcSight ESM.

OpenText Security Operations Unplugged (official)·Walkthrough, January 2024

Default Content: Detecting Known Threats | Mastering ArcSight Series

How the default rules catch known threats from intelligence feeds — a 2024 recording under the former ArcSight name.

OpenText Security Operations Unplugged (official)·Explainer, February 2021

Real Time Correlation with ArcSight by OpenText

Correlation on the live event stream, explained in 2021, before the product was renamed Enterprise Security Manager.

OpenText Security Operations Unplugged (official)·Explainer, February 2021

Micro Focus ArcSight Introduces ESM 7 with Distributed Correlation

The distributed correlation mode that still scales ESM today, introduced in the Micro Focus era (2021 upload).

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why OpenText Enterprise Security Manager

Attacks cross many systems. ESM joins their events into one alert as they happen.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Correlation on the stream, not after it

ESM matches rules against events as they arrive, so a login failure on a VPN, a new admin account and an odd outbound connection join into one alert within seconds rather than in a search scheduled for later. OpenText rates the engine at 100,000+ events a second; your hardware sets your figure.

02

SOAR and intelligence without a second contract

OpenText lists a native SOAR with playbooks and incident management, and a native threat-intelligence feed, as part of ESM. Many rivals sell automation as a separate product. Rheinmetall, an OpenText customer, cites 35% cost savings from what OpenText calls flexible licensing.

03

Your servers, your residency answer

ESM is installed and run by you, in compact mode on one server or distributed across a cluster, so events are stored and processed wherever you put it. For an Indian bank or insurer that has to keep logs in the country, that is a design fact rather than a vendor promise to verify.

04

Where it stops

There is no public price, no SaaS edition of ESM itself, and no current Gartner SIEM placement. You run, patch and size the servers. Long retention needs Security Log Analytics, and behavioural analytics needs Threat Detection and Response. The newest official videos still say ArcSight.

The idea
Correlate events as they arrive
The residency
Self-hosted, so logs stay with you
The price
Quoted; no public list
Proof, not promises

The numbers behind the platform

100000+ EPS
events per second OpenText says ESM can analyse; sizing decides what your cluster does
— Vendor
480+ types
event source types its connectors collect from, by OpenText’s count
— Vendor
90%
fewer daily alerts needing investigation, a result OpenText cites for ESM customers
— Vendor
35%
cost saving Rheinmetall attributes to OpenText’s flexible licensing
— Customer
3 hours
saved per security team each day, another outcome OpenText cites for ESM
— Vendor
7 languages
supported by ESM 7.9, from English and Japanese to Simplified and Traditional Chinese
— Vendor

What your OpenText ESM rollout looks like

Week 1Model

Count sources and events

List every log source, its daily event rate and peak, and the retention each regulator asks of you, before any sizing.

Week 2Decide

Pick compact or distributed

Match your sustained events per second to one server or a correlation cluster, and decide where Log Analytics sits.

Week 3Pilot

Connect the first sources

Install connectors for firewalls, directory and VPN, load the asset model from your CMDB, and check normalisation.

Month 2Prove

Tune the default content

Turn on the 4.8 packages, tune noisy rules, map them to ATT&CK and wire the first SOAR playbook to a ticket.

Month 3Commit

Onboard the rest, then report

Add the remaining sources in waves, schedule compliance reports, and agree the upgrade cadence with OpenText.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
46+ reviews*
78% would recommend
Real-time correlation4.4
Connector coverage4.3
Built-in SOAR3.8
Ease of administration3.4
Value for money3.7
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“A brute-force run on our VPN and a new domain admin a minute later became one high-priority case. That join is why we stayed.”
SOC Lead
BFSI
Manufacturing
“Connectors covered our old mainframe gateway and our cloud firewalls alike. Normalisation meant one rule for all three firewall brands.”
Security Engineer
Manufacturing
Telecom
“Moving from compact mode to distributed correlation took a professional-services week, but month-end peaks no longer queue.”
SIEM Administrator
Telecom
Fintech
“Loading the asset model from our CMDB changed triage: a hit on a payment server now outranks the same hit on a lab box.”
Threat Analyst
Fintech
Insurance
“Auditors wanted logs kept in India for 180 days. Our own racks plus Log Analytics answered that without a cloud attestation.”
CISO
Insurance
Government
“Strong engine, dated console in places, and every upgrade needs a plan. Budget admin time, not only licences.”
Head of Security Operations
Government
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag SIEM Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
OpenText Enterprise Security ManagerThis page

Quoted; long-installed base, no public price.

Grid 02 · The architecture

Deployment Control × Correlation Depth

The grid nobody publishes — how fully you can run the SIEM on your own servers, in India included, vs how much correlation and prioritisation it does on the live stream.

Cloud-bound correlatorsSelf-hosted correlation enginesCloud log searchSelf-hosted log tools
OpenText Enterprise Security ManagerThis page

Self-hosted only; stream correlation with priority scoring.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

OpenText ESM vs the SIEM field

Against Splunk Enterprise Security, Microsoft Sentinel, LogRhythm SIEM, Fortinet FortiSIEM and ManageEngine Log360 — on deployment, coverage, price, scale, detection, compliance, support and India.

DimensionOpenText Enterprise Security ManagerSplunk Enterprise SecurityMicrosoft SentinelLogRhythm SIEMFortinet FortiSIEMManageEngine Log360
What it isReal-time SIEMCisco’s flagship SIEMAzure-native SIEMSelf-hosted SIEMSIEM plus CMDBIndia-built SIEM
DeploymentSelf-hosted, 2 modesCloud, on-prem, hybridSaaS on Azure onlyOn-prem onlyAppliance, VM or cloudOn-prem or cloud
Sources and coverage480+ source typesAny machine dataMicrosoft logs freeEstate-wide, in-houseMulti-vendor + CMDBSources, AD, cloud
Pricing modelEPS or GB/day (reported)Ingest or workloadPer GB ingestedSubscription/perpetualDevice/EPS or GB/dayPer log source
Published entry priceNot publishedNo list price~$4.30/GB PAYGQuote onlyQuote onlyFrom ~$300 a year
Included vs add-onSOAR and intel includedSOAR is separateLogic Apps billed apartCloud UEBA add-onFortiSOAR separateUEBA, SOAR built in
Scale100,000+ EPS (claim)Largest estatesUp to 50,000 GB/dayYou size the ironMulti-tenant for MSSPsMid-market scale
Detection depthCorrelation + priorityRisk-based alertingKQL rules + UEBA1,100+ prebuilt rulesContext from CMDBRules, UEBA and Zia
IntegrationsOpenText security stackCisco XDR, SplunkbaseDefender and CopilotSync with New-ScaleSecurity FabricManageEngine suite
Governance and complianceFIPS 140-2 modeRoles, ESCU contentAzure RBACCompliance mappedCompliance reportsThousands of templates
India dataYour own serversAWS Mumbai listedStored in India onlyYours by designMumbai cloud or on-premIndian DCs or on-prem
SupportQuoted contractQuoted, billed in USDPaid plan from $29Vendor plus your teamFortiCare, quotedIndian vendor
Lock-in and exitRules in ESM’s modelSPL contentAzure-boundAsk for the roadmapFabric gravityEasy to scope out
Best fitEx-ArcSight estatesDetection engineersMicrosoft estatesNo-SaaS mandatesFortinet networksIndian mid-market
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose OpenText ESM if…

  • ✓You need correlation on the live event stream across many log sources, with SOAR playbooks and a threat feed in the same product
  • ✓Your regulator, contract or board rules out SaaS, so the SIEM has to run on servers you own in India
  • ✓You already run ESM and want to stay current on 7.9 rather than re-write every rule for a new platform

Compare alternatives if…

  • ✓You would rather rent the SIEM than run it — Microsoft Sentinel and Splunk Cloud take the servers off your hands
  • ✓You want a price you can read before a call — Sentinel publishes per-GB rates and Log360 starts at a reported $300 a year
  • ✓Your network is mostly Fortinet — FortiSIEM adds CMDB and device health to the same correlation job

Do not expect…

  • ✓A published price, a SaaS edition of ESM itself, or an OpenText-hosted India region
  • ✓Behavioural analytics inside ESM — that is Threat Detection and Response, sold separately
  • ✓A current Gartner SIEM Magic Quadrant placement — none was found for OpenText in 2025

OpenText Enterprise Security Manager is one of 35 siem & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does stitching alerts by hand cost you?

Drag the sliders (log sources feeding the SIEM; analyst-hour cost). Estimates model analyst time spent chasing each source’s alerts by hand and stitching events across consoles, at an assumed 1.5 hours per source a year, with 70% of it removed by real-time correlation and playbooks. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual alert-triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. OpenText publishes no price for Enterprise Security Manager and no rupee price for any security product. Third-party guides describe ESM licences by sustained events per second or by GB a day, quoted with support and services; OpenText says Rheinmetall saved 35% through flexible licensing. Security Log Analytics, for long retention, and Threat Detection and Response, for behavioural analytics, are separate products. TechBag measures your event rate first, then quotes in INR with GST.

Enterprise Security Manager

Best for real-time correlation on your own servers

  • Quoted; no public price
  • Native SOAR and threat-intelligence feed
  • Compact or distributed correlation mode

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Security Log Analytics

Best for long log retention and audit reports

  • Formerly ArcSight Logger; quoted separately
  • 100+ prebuilt reports and dashboards
  • 480+ connectors with data enrichment

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Event volume

What is your sustained and peak events per second, measured, not estimated? It decides servers and licence.

2
Licence meter

Is the quote by events per second or GB a day, and what happens when a busy month exceeds it?

3
Architecture

Compact mode on one server, or distributed correlation across a cluster? Ask who designs and supports it.

4
Retention

Where do logs live after ESM’s working set: Security Log Analytics, and for how many days in India?

5
Content

Which default packages and rules will run on day one, and who tunes them in the first ninety days?

6
SOAR

Which playbooks ship ready, and do they reach your ticketing, firewall and directory tools?

7
Upgrades

Are you on 7.6.4 or later? Older installs need a staged path before they can reach 7.9.

8
Quote

Does it itemise ESM, Log Analytics, connectors, support and services? Ask for INR with GST.

FAQ

Questions buyers ask

It is OpenText’s security information and event management product, formerly ArcSight ESM. Connectors collect events from 480+ source types, and the Manager correlates them in real time, scores their priority and maps them to MITRE ATT&CK. A native SOAR and threat feed come with it.

Ready to evaluate OpenText ESM?

Measure your event rate and retention first, or let a TechBag advisor size compact or distributed mode, plan India-hosted retention and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.