Just finished a 3-week migration from our old ArcSight ESM box to a cloud-hosted version. I thought my Grafana/Prometheus migrations were tough, but this was another level 😅
Biggest hurdles were the log source reconfiguration and making sure all our parsers and rules carried over. Had to manually re-map a ton of network device syslog targets. Also, the cost model in the cloud is... eye-opening. Anyone else been through this? Would love to hear about your gotchas or if you found any clever automation for the connector re-registration.
I haven't done this migration myself, but I've been looking at cloud SIEM costs for our own planning. When you say the cost model is eye-opening, do you mean the connector-based licensing or the data ingestion fees? Our team is worried about unpredictable spikes from syslog sources flooding in.
I'm also curious about the parser and rule carry-over. Did the cloud version have any compatibility issues with your existing rules, or was it just a tedious manual export/import?
Three weeks sounds optimistic. With our on-prem setup, the pain at least had a predictable capital expense curve. The cloud's "eye-opening" cost model is the real migration, just deferred. You're trading a one-time reconfiguration nightmare for a perpetual, variable-rate one.
Did your contract at least lock in the connector pricing, or are you now at the mercy of their quarterly "feature-based" re-tiering? I've seen bills double after the first year once the initial migration discounts vanish. The manual re-mapping you mentioned is just the first invoice.
Buyer beware.
It's both, but the ingestion fees are the real variable cost. Connectors are predictable; your syslog volume rarely is. We saw a 40% increase in parsed EPS (events per second) post-migration, not from new sources, but because the cloud processing pipeline applied slightly different normalization. That directly hit the bill.
On parser and rule carry-over, it was mostly tedious export/import, but we did hit a few edge cases. Certain legacy flex connector parsers referencing on-prem file paths for lookup tables broke. The cloud instance couldn't resolve them. We had to migrate those to internal resource objects, which added about a day of scripting.
I'd recommend you run a parallel ingest test with a subset of your noisiest sources for a week before committing. Capture the EPS delta between your on-prem ESM and the cloud tenant's reported ingested volume. That gap is your new baseline cost.
Three weeks and you're already calling it done? That's the setup phase, not the survival phase. The real pain starts when the first true-up invoice arrives and you discover your "clever automation" just accelerated your budget burn.
The manual re-mapping of syslog targets is a classic vendor move. They sell you on the cloud's elasticity, but fail to mention the brittle, manual labor required to plug your old infrastructure into it. There's no clever automation because they have no incentive to provide it; the billable professional services for that re-registration are a feature, not a bug.
Wait until you try to run a year-over-year cost comparison. On-prem had a fixed cost curve, as someone else noted. Cloud ArcSight replaces that with a financial black box where "events per second" becomes a meter you can't read. Let us know how that eye-opening cost model looks after Q2.
cg