Try our new research platform with insights from 80,000+ expert users

NetWitness Platform vs Trellix ESM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

NetWitness Platform
Ranking in Security Information and Event Management (SIEM)
23rd
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Log Management (22nd)
Trellix ESM
Ranking in Security Information and Event Management (SIEM)
28th
Average Rating
7.4
Reviews Sentiment
7.4
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of March 2025, in the Security Information and Event Management (SIEM) category, the mindshare of NetWitness Platform is 0.6%, down from 0.8% compared to the previous year. The mindshare of Trellix ESM is 0.8%, down from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

MdZaman - PeerSpot reviewer
Really scalable for enterprise customers
The solution should have more integration capabilities with different platforms. The API is nearly open and scalable, so the solution can integrate with many platforms. The solution has more than 200 log sources in the scalability to support, but this is its limit. Installation is pretty easy. However, there are a couple of modules involved, so it is not as easy as it could be. We are talking about a distributed module, not a single-module type. This is what makes things a bit complex, instead of easier. I rate it as a seven out of ten on its installation and configuration capabilities.
Daniel Durian - PeerSpot reviewer
Helps to monitor and detect cyberattacks
The tool's effectiveness depends on how you define your log sources. To build visibility of incoming and outgoing traffic, you need logs from perimeter defense, firewalls, web application firewalls, and endpoint protection. With good traffic visibility, incident response time is really quick. Trellix ESM provides situation awareness. On the dashboard, I can see outbound and inbound communications to known threat hosts, IPS/IDS activity, and threat intelligence of the perimeter defense in the firewall. This information helps preempt attacks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product has a user-friendly interface and a valuable feature for threat intelligence integration."
"The most valuable feature is the hunting ability to work in a CERT."
"The newer 11.5 version that my team is using has found it to have good mapping."
"Offers a good wireless feature."
"It's quite economical compared to other solutions in the market."
"It gives the capability for the incident response team to correlate logs to identify any kind of problem like malware and incidents in a general sense, both for logs and packets."
"NetWitness can be highly beneficial for incident detection and response."
"The most valuable feature is that we can create our own connectors for any application, and NetWitness provides the training and tools to do it."
"It enables us to detect malicious threats, issues, or vulnerabilities in our network."
"McAfee as a whole is a good solution."
"Trellix ESM is very user-friendly."
"Trellix ESM utilizes fewer human resources and improves security and visibility."
"This solution integrates easily and very well with other technologies."
"The tool's effectiveness depends on how you define your log sources. To build visibility of incoming and outgoing traffic, you need logs from perimeter defense, firewalls, web application firewalls, and endpoint protection. With good traffic visibility, incident response time is really quick."
"We are now able to completely monitor our environment so we can review what is there, which is a big win for us."
"It can be easily deployed with the other solutions."
 

Cons

"Technical support could be improved."
"The log system is a bit complex and has room for improvement."
"The initial setup is very complex and should be simplified."
"The solution should have more integration capabilities with different platforms."
"An area for improvement would be better automation and more inbuilt use cases."
"The tool's integration capability isn't so great."
"There is no support for this product in this country, so problems have to be resolved through global technical teams."
"The initial setup was complex because it takes a lot of time to complete the implementation."
"It seems McAfee does test its product before releasing. When we - not only us, other companies also - deploy McAfee, we face multiple issues from the customer side, after which, McAfee reacts and fixes the bugs."
"There should be support for multitenancy in the product."
"The initial setup is difficult and could improve."
"The product is mature and needs little improvement, but we could enhance the customized dashboarding based on use cases."
"Tech support is required each time there is a system update of the solution."
"There are always multiple bugs in the product. For example, the console page was hanging multiple times. Afterwards, they released multiple upgrades for the same, multiple patches from McAfee."
"The product’s alert response feature needs improvement. It could be more flexible and secure."
"The user interface could be more user-friendly."
 

Pricing and Cost Advice

"This is a pricey solution; it's not cheap."
"The tool is very expensive, so I rate the pricing a ten out of ten. The solution has an annual subscription."
"Compared to the competition, the is price is not that high."
"Our license is for one year."
"We have yearly licensing costs. The license fee can be based on the volume of EPS. Some organizations may have, as a gentlemanly gesture, 10,000 EPS and get a 3,000 EPS license but actually use 5,000 EPS."
"We have a perpetual license, so the total cost of ownership is not very expensive. It's a good investment."
"The NetWitness Platform may be affordable only for enterprise-level customers, as it may not be within the budget of small and medium-sized businesses."
"In comparison to other SIEM solutions such as Splunk, NetWitness is less costly."
"The price is good. It's moderate. We follow a pay-as-you-go model. There are different models available, and they can also be monthly. You can choose monthly or yearly. It's very flexible. If our existing customers exceed the current plan, you can just call McAfee and get it extended."
"The pricing is fair."
"The product is slightly expensive."
"The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it."
"Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar."
"We renew our license annually."
"The price of McAfee ESM is higher than some of the other solutions. There are additional features that can be added at an additional fee."
"The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
842,651 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
17%
Government
6%
Insurance Company
6%
Educational Organization
76%
Financial Services Firm
4%
Computer Software Company
3%
Comms Service Provider
3%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about NetWitness Platform?
The product's initial setup phase was not at all difficult.
What is your experience regarding pricing and costs for NetWitness Platform?
The product price was reasonable for my region and the market.
What needs improvement with NetWitness Platform?
From an improvement perspective, the NetWitness Platform needs to release new features and improve in areas like log correlation. The tool needs to have easier integrations with the cloud. Building...
What do you like most about McAfee ESM?
The solution's technical support is great.
What is your experience regarding pricing and costs for McAfee ESM?
Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar.
What needs improvement with McAfee ESM?
The product is mature and needs little improvement, but we could enhance the customized dashboarding based on use cases.
 

Also Known As

RSA Security Analytics
McAfee ESM, NitroSecurity, McAfee Enterprise Security Manager
 

Overview

 

Sample Customers

Los Angeles World Airports, Reply
San Francisco Police Credit Union, Wªstenrot Gruppe, Volusion, California Department of Corrections & Rehabilitation, Government of New Brunswick, State of Colorado, Macquarie Telecom, Texas Tech University Health Sciences Center, Cologne Bonn Airport
Find out what your peers are saying about NetWitness Platform vs. Trellix ESM and other solutions. Updated: March 2025.
842,651 professionals have used our research since 2012.