HomeArticles › ArcSight cloud and SaaS migration entitlements
ArcSight & Security · Track 03

ArcSight cloud and SaaS migration entitlements

By ·

Moving ArcSight to the cloud changes how the platform is deployed, but it does not automatically change what you are entitled to, or how a vendor will measure it. ArcSight cloud and SaaS migration entitlements become an audit risk when on premise rights, cloud rights, and a parallel running period are read as three separate consumptions rather than one estate in transition.

ArcSight reached the OpenText estate through the Micro Focus acquisition that closed on January 31, 2023, and like the rest of the security portfolio it is governed by Additional License Authorizations rather than the OpenText EULA. A migration to a hosted or SaaS deployment usually runs the old and new environments in parallel for a period, and that overlap is exactly where a finding can inflate if the migration terms are not read carefully. The defensive principle is that a transition is not duplicate consumption, and the entitlement that covers it is whatever the agreement and the authorization actually say.

The migration overlap and where it inflates

During a migration the same security data is often processed in two places at once: the legacy on premise ArcSight environment that has not yet been decommissioned, and the new cloud or hosted deployment that is being validated before cutover. An audit that measures both environments and adds them together counts the same operational load twice, treating a temporary parallel state as though the buyer permanently doubled its footprint. The corrective is to document the migration timeline and to establish that the overlap was transitional, not a standing increase in licensed use.

The mechanic

A cloud migration that runs old and new in parallel is one estate in motion, not two estates in use. A finding that sums both sides of the cutover, or that ignores migration rights in the agreement, measures a transition state the buyer never licensed as permanent.

Dual rights and metric translation

Two questions decide most of the cloud migration argument. The first is whether the agreement grants any form of dual or transition rights that permit running both environments during a defined cutover window, a structure that is familiar from the way OpenPass handles dual entitlements for migration. The second is whether the metric translates cleanly from the on premise model to the cloud or SaaS model. An on premise EPS or data volume figure does not necessarily map one to one onto a hosted metric, and a finding that carries the wider of the two figures across the boundary is not measuring the entitlement that governs the cloud deployment.

Reconstruct the transition, not the snapshot

The four Rs apply with a timeline emphasis. Respond inside the seven day notice window and route every data request through a single controlled channel so the migration is described once, consistently. Reconstruct the effective position as a transition: what was live on premise, what was live in the cloud, and over what window the two overlapped, mapped against the authorization and any migration rights in the agreement. Rebut the finding line by line, removing double counted load and stranded legacy capacity. Resolve on terms that fix the cloud metric unambiguously so the post migration baseline is settled rather than assumed.

A recent engagement

In a recent engagement an ArcSight finding had been assembled during a cloud cutover and counted both the legacy on premise environment and the new hosted deployment as full standing consumption. Documenting the migration timeline and showing that the overlap was a transitional validation period, not a permanent increase, corrected the finding without inventing any new facts about the deployment. The discipline mirrors the way a decommissioned connector is removed from a count: load that is in transition, or already retired, does not belong in a steady state measurement.

Settle the post migration baseline

The most durable outcome of a cloud migration matter is not just removing the double count. It is settling, in writing, which metric governs the cloud or SaaS deployment going forward, so the next measurement does not relitigate the translation question. A finding that paraphrases an on premise metric and applies it to a hosted environment, without quoting the authorization that governs the cloud entitlement, is inviting the buyer to accept an interpretation. The defensive discipline is to insist on the language that actually applies to the cloud deployment and to read the transition as a transition. Most of the reduction in a migration matter comes from establishing that the audit measured an overlap the agreement never treated as permanent consumption.

Audited during an ArcSight cloud or SaaS migration?

We document the transition timeline, separate parallel running from permanent use, and hold the cloud metric to the authorization that governs it. To get a defense team on the file, open a case or download the ArcSight EPS defense briefing.

Get The Number Down →

Related field notes

These notes from the ArcSight and Security audit defense cluster cover deployment, metrics, and decommissioning. Each links back to the complete OpenText audit defense playbook for 2026.

If an OpenText or Micro Focus audit notice has arrived, the opening seven days set the course for everything after. OpenText Audit Defense is an independent, buyer side practice founded in 2020 by former vendor compliance leadership. We have defended more than 200 audits, lowered the average finding by 68 percent, and mitigated more than $90M in claims against vendor positions. We do not resell OpenText software and we are not affiliated with OpenText Corporation. To open a case, use the contact form on this site.