ArcSight IdentityView monitors user activity across all your accounts, applications and systems. ArcSight IdentityView combines the broad activity collection and correlation of SIEM with user and role data from identity and access management (IAM) technologies. It enriches log events with user and role information, giving you a complete picture of user activity, including shared, high-risk and privileged accounts. The result is lower insider threat risk, better access governance and faster forensic investigations.
- Analyzes activity to user role to detect violations
- Identity threat scoring to pinpoint the riskiest users and departments
- Faster forensic investigations
- Executive dashboards to capture group and departmental security metrics
- Out-of-the-box integration with leading IAM technologies
ArcSight IdentityView Overview
What It Does
ArcSight IdentityView combines the broad activity collection and correlation of SIEM with user and role data from identity and access management (IAM) and directory technologies. ArcSight IdentityView enriches log events with user information, and as a result, organizations get a complete picture of user activity, including monitoring high risk privileged and shared accounts.
How It's Different
Making sure employees, contractors, and third parties have only the access they need is a difficult process. IAM solutions typically take a top down “role modeling” approach, but ArcSight IdentityView works differently. Using identity-enriched log events, organizations see what different types of users are actually doing, establishing baselines to detect anomalous, risky activity and improve access governance.
- ArcSight IdentityView provides a complete user activity monitoring framework, making it easy to develop reports, correlation rules, and dashboards for specific users or user groups
- Identity threat scoring enables organizations to pinpoint their riskiest users and departments by linking repeated suspicious activity to individuals and groups
- Forensics investigations are now faster than ever – with ArcSight IdentityView, organizations immediately see whether a specific user caused a security alert, and can then report on all of that user’s activity across accounts
- ArcSight IdentityView executive dashboards capture group and departmental security metrics, allowing management to see which users and departments are creating the most security and compliance risk
- ArcSight IdentityView integrates with leading IAM technologies such as Active Directory and Oracle Identity Manager out of the box, while offering the flexibility to connect to other sources of identity and access information