This document provides an overview of the key concepts and components of ArcSight Enterprise Security Management (ESM) software:
ESM enables security analysts to gain situational awareness of their network security through collection, normalization, and correlation of event data from various sources. It includes SmartConnectors that collect data, a Manager that processes events and models the network, and user interfaces like the Console for analysis. Events are written to storage and evaluated against filters and correlations to detect potential threats. Analysts can then investigate further using workflow tools like annotations, cases, and notifications.