Try our new research platform with insights from 80,000+ expert users

Elastic Security vs Trellix ESM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024
 

Categories and Ranking

Elastic Security
Ranking in Security Information and Event Management (SIEM)
5th
Average Rating
7.6
Number of Reviews
61
Ranking in other categories
Log Management (5th), Endpoint Detection and Response (EDR) (16th), Security Orchestration Automation and Response (SOAR) (6th), Extended Detection and Response (XDR) (8th)
Trellix ESM
Ranking in Security Information and Event Management (SIEM)
22nd
Average Rating
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of November 2024, in the Security Information and Event Management (SIEM) category, the mindshare of Elastic Security is 7.3%, down from 9.1% compared to the previous year. The mindshare of Trellix ESM is 0.8%, down from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Gajewski Marek - PeerSpot reviewer
Aug 13, 2024
Provides good anomaly detection and connectivity reporting
I use Elastic Security to aggregate all logs from different devices in one place. It works pretty well and provides one overview of everything The solution's most valuable features are anomaly detection and connectivity reporting. Elastic Security also has many automation capabilities, which can…
Daniel Durian - PeerSpot reviewer
Aug 19, 2024
Helps to monitor and detect cyberattacks
I use Trellix ESM to monitor inbound communication from known threat hosts and detect cyberattacks. It's also useful for outbound communication, but we block threat communication via a firewall The tool's effectiveness depends on how you define your log sources. To build visibility of incoming…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the machine learning capability."
"The solution is compatible with the cloud-native environment and they can adapt to it faster."
"Elastic Security is a highly flexible platform that can be implemented anywhere."
"It is the best open-source product for people working in SO, managing and analyzing logs."
"Enables monitoring of application performance and the ability to predict behaviors."
"The performance is good and it is faster than IBM QRadar."
"It's very stable and reliable."
"The stability of the solution is good."
"The most valuable feature in ESM is its search and reporting feature. It's really nice."
"It is a good central viewpoint for issues. These can then be investigated in more detail on the subnet server(s)/endpoints."
"The most valuable feature is that if the scanning does find something, it quarantines it. Then you can decide what you are going to do with it."
"The most valuable features of McAfee ESM are intrusion detection, malware protection, and the device controller."
"Trellix ESM is very user-friendly."
"It is easy to use."
"Trellix ESM utilizes fewer human resources and improves security and visibility."
"The most valuable feature for us is that it comes with many correlations, reports, and dashboards already available. It's also very easy to use."
 

Cons

"Improvements in Elastic Security could include refining and normalizing queries to make them more user-friendly, enhancing the user experience with better documentation, and addressing any latency issues."
"Email notification should be done the same way as Logentries does it."
"The setup process is complex. You need a solid working knowledge of networking, operating systems, and a little programming."
"Elastic Security could improve the documentation. It would help if they were more simple and clean."
"They don't provide user authentication and authorisation features (Shield) as a part of their open-source version."
"The solution could offer better reporting features."
"Better integration with third-party APMs would be really good."
"It's a little bit of a learning curve to understand the logic of searching for things and trying to find what you're looking for in Elastic Security."
"The only issue I have with McAfee is the amount of computer resources that it takes... it's definitely impacting some of the other applications that are running on a computer at the same time."
"The disk space needed for events is not clear. In all clients, we had at least more than 100GB free that we could not use."
"Update to user interface from version 9 is cosmetic in some aspects, and after a few clicks you are back on the old interface."
"It is more difficult to operate Trellix ESM than other solutions."
"McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support. It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better."
"We cannot add new data sources to the most recent version."
"Tech support is required each time there is a system update of the solution."
"Product-wise, adding accounts on a single data source by batch would be a really great help."
 

Pricing and Cost Advice

"We use the open-source version, so there is no charge for this solution."
"Affordable but with additional costs"
"The solution is free."
"The base product is open-source but if you need advanced security features then you need to pay for the subscription. Elastic Security's price is reasonable in some cases and in other cases it's not."
"It's a monthly cost with Elastic SIEM, but I am not sure of the exact cost."
"Compared to other tools, Elastic Security is a cheaper solution."
"Elastic Stack is an open-source tool. You don't have to pay anything for the components."
"Elastic Security is free to use."
"The price is good. It's moderate. We follow a pay-as-you-go model. There are different models available, and they can also be monthly. You can choose monthly or yearly. It's very flexible. If our existing customers exceed the current plan, you can just call McAfee and get it extended."
"We pay for our licensing fees on a yearly basis, and there are no costs in addition to the standard licensing fees."
"The cost is dependent on the customer's environment and requirements."
"The licensing cost is based on EPS."
"We renew our license annually."
"The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar."
"When compared to IBM Security QRadar and other similar platforms, the pricing of McAfee ESM is reasonable and comparatively less expensive."
"Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
814,763 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
10%
Government
10%
University
7%
Educational Organization
74%
Financial Services Firm
4%
Computer Software Company
4%
Government
3%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
What do you like most about Elastic Security?
Elastic provides the capability to index quickly due to the reverse indexes it offers. This data is crucial as it contains critical information. The reverse index allows fast data indexing because ...
What is your experience regarding pricing and costs for Elastic Security?
Compared to other tools, Elastic Security is a cheaper solution.
What do you like most about McAfee ESM?
The solution's technical support is great.
What is your experience regarding pricing and costs for McAfee ESM?
Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar.
What needs improvement with McAfee ESM?
The product is mature and needs little improvement, but we could enhance the customized dashboarding based on use cases.
 

Also Known As

Elastic SIEM, ELK Logstash
McAfee ESM, NitroSecurity, McAfee Enterprise Security Manager
 

Learn More

Video not available
 

Overview

 

Sample Customers

Texas A&M, U.S. Air Force, NuScale Power, Martin's Point Health Care
San Francisco Police Credit Union, Wªstenrot Gruppe, Volusion, California Department of Corrections & Rehabilitation, Government of New Brunswick, State of Colorado, Macquarie Telecom, Texas Tech University Health Sciences Center, Cologne Bonn Airport
Find out what your peers are saying about Elastic Security vs. Trellix ESM and other solutions. Updated: October 2024.
814,763 professionals have used our research since 2012.