Trellix ESM is very user-friendly.
Systems Engineer at First Datacorp
A user-friendly solution that is easy to implement
Pros and Cons
- "Trellix ESM is very user-friendly."
- "Product-wise, adding accounts on a single data source by batch would be a really great help."
What is most valuable?
What needs improvement?
Trellix's resource consumption is too high, and it could be lower. It would be nice if Trellix could reduce the requirements for RAM and storage.
Product-wise, adding accounts on a single data source by batch would be a really great help. Then for the support, it would be a lot better if customer support from Trellix would reach out to us as partners.
For how long have I used the solution?
I have been testing Trellix ESM for a few months.
How was the initial setup?
Trellix ESM is easy to implement. In addition, it would be better if I had enough hardware resources to run or implement it.
Buyer's Guide
Trellix ESM
December 2024
Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
What other advice do I have?
I am working with the free trial version of Trellix ESM. I am very satisfied with Trellix ESM. There are minor additional features that we need to add to it, but for now, I'm very satisfied with it.
I would advise users to learn NQL so that they can understand how the data goes from raw data to normalized data and how to create their custom rules.
Overall, I rate Trellix ESM an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Systems-Engineer at a tech services company with 10,001+ employees
I like the vendor support from McAfee and the overall architecture looks simple. The version I worked on had a bug in the alarm system.
Valuable Features
This is the first SIEM product that I have used. My impressions so far are that I like the vendor support from McAfee and the overall architecture looks simple.
Improvements to My Organization
I helped a client of ours implement and deploy it.
Room for Improvement
The product documentation is good, but could be better. Also a bug-free version would be nice as the version I worked on had a bug in the alarm system.
Use of Solution
I've used it for five months.
Deployment Issues
We had bug alarm issues during deployment. The bug, I think, was part of the product.
Stability Issues
We had no issues with the stability.
Scalability Issues
We have had no issues scaling it for our needs.
Customer Service and Technical Support
Customer Service:
Customer service is very good.
Technical Support:Technical support is very good.
Initial Setup
The initial setup was straightforward.
Implementation Team
You will have a better implementation if you get support from the vendor.
Pricing, Setup Cost and Licensing
Overall, it was expensive, as it has split components.
Other Solutions Considered
We have now started using ArcSigh as well. I don't have much experienced with it, but the overall architecture looks similar to McAfee.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Trellix ESM
December 2024
Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
831,265 professionals have used our research since 2012.
Threat Intelligence Engineer (Security Engineering Team) at a government with 10,001+ employees
Biggest benefit is its easy scalability. It doesn't restrict you to a particular hardware or storage solution.
What is most valuable?
It's SIEM. Obviously, normalization of data is the biggest factor.
How has it helped my organization?
We perform security event monitoring for over 700 individual servers, firewalls, and applications. It's not possible to monitor over 500 million events per day with SIEM.
What needs improvement?
McAfee is working on a newer ELS product for a faster search which will change everything about how a SIEM can perform.
For how long have I used the solution?
I have been using this product for the past eight years.
What do I think about the stability of the solution?
Just like any other software/hardware platform, once in awhile we have issues with software bugs, but McAfee's support is good in helping to fix these issues in a timely manner.
What do I think about the scalability of the solution?
Biggest benefit of McAfee SIEM is its easy scalability. It doesn't restrict you to a particular hardware or storage solution.
How are customer service and technical support?
Mcafee's SIEM support team is very good.
Which solution did I use previously and why did I switch?
I used ArcSight at a different job, but when we bought SIEM at my current job, it was NitroView. Later, McAfee acquired them.
How was the initial setup?
It had a few hurdles initially, but in its current versions and offerings McAfee SIEM is sort of plug and play. It has so many offerings out-of-the-box.
What's my experience with pricing, setup cost, and licensing?
McAfee's pricing is competitive in the industry and their licensing model is for hardware only.
Which other solutions did I evaluate?
We checked ArcSight, but their pricing was expensive.
What other advice do I have?
McAfee ESM is the perfect SIEM tool, and it provides best results based on data intake and rule based configuration.
I would suggest users identify the data sources they want to interject into SIEM for monitoring, correlation, and work with the sales team to understand the total EPS and choose the right set of hardware, especially the ESM which will perform majority of work for your organization. With the right specs for hardware, it will help you achieve your goal.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Analyst at a tech services company with 501-1,000 employees
Through correlation rules, it finds malware that anti-virus and other security solutions do not find.
What is most valuable?
The easy interface is the most valuable feature.
How has it helped my organization?
Through correlation rules, it finds malware that compromised the computer that anti-virus and other security solutions do not find.
What needs improvement?
I had a couple of problems collecting Windows events. The local plugin should be easier to use, because when ESM is collecting through the manager, many performance issues occur.
For how long have I used the solution?
I have been using McAfee for over three years.
What do I think about the stability of the solution?
We did have stability issues, but they were resolved by McAfee support.
What do I think about the scalability of the solution?
We have not had scalability issues.
How are customer service and technical support?
I would give technical support a rating of 8/10.
Which solution did I use previously and why did I switch?
I used different solutions, but for different clients.
How was the initial setup?
This was the easiest initial setup that I have made.
What's my experience with pricing, setup cost, and licensing?
The product is worth the price. There are other cheaper tools in the market, but it is harder to work with them.
Which other solutions did I evaluate?
We looked at HPE ArcSight, Splunk, RSA Analytics, and IBM QRadar.
What other advice do I have?
Stay focused, read the documentation, plan it well, and the project will be a success.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
ICT Security Officer at a healthcare company with 1,001-5,000 employees
We now have a better view of our security posture from an external and internal point of view. The reporting could use some improvement.
What is most valuable?
Dashboards, which can be customized to display alerts and queries, and rules, which trigger alerts, are the most valuable features for us.
How has it helped my organization?
We now have a better view of our security posture from an external and internal point of view. We are able to do forensic investigations and stop attacks before they occur.
What needs improvement?
The reporting could use some improvement. Also, while the dashboard can be customized to an extent, I'd like to have the ability to do even more customization.
For how long have I used the solution?
We've used it for two years.
What was my experience with deployment of the solution?
We've had no deployment issues.
What do I think about the stability of the solution?
There have been no issues with the stability.
What do I think about the scalability of the solution?
Scaling it has been fine. We've had no issues with an inability to scale.
How are customer service and technical support?
In our experience, technical support has been good.
Which solution did I use previously and why did I switch?
- QRadar
- RSA enVision
How was the initial setup?
Deployment of any of these products is easy. What becomes a daunting task is the creation of use cases and also ensuring that alerts are accurate.
What about the implementation team?
We used an in-house team with a vendor in-office assistant.
What was our ROI?
Executives don’t see ROI on this solution as the reports are not meant for C-levels.
What other advice do I have?
Make sure you know exactly why you are implementing it and what you are going to monitor. Also, ensure that you have all your use cases way before venturing into buying a solution of this nature.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Assistant Vice President at a financial services firm with 1,001-5,000 employees
Good overall but complex setup and integration needs improvement
Pros and Cons
- "McAfee as a whole is a good solution."
- "It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI."
What is our primary use case?
We are using the solution for log analyzing endpoints and investigating all types of applications, files or network devices login collection.
What is most valuable?
McAfee as a whole is a good solution.
What needs improvement?
When it came to using the solution for a larger organization, we were faced with some troubles attempting to manage the GUI functionality. During some forensic investigations, some of the information was missing from the collected data.
It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI. For Postgre databases, the solution did not collect a lot of information from it. It has some integration problem. Companies, therefore, have to invest twice for collecting logs rather than one SIEM.
For how long have I used the solution?
I have been using the solution for two years.
How was the initial setup?
The initial setup was a bit complex.
What about the implementation team?
The local partner we had was not very experienced in implementing the solution. However, the solution was first implemented in our country.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Manager at a tech services company with 10,001+ employees
It has good technical support, but I can't scale it
Pros and Cons
- "It has performed well and delivered the results that I have been looking for."
- "It has good technical support, which is available around the clock. You can call up anytime and get whatever you want. My queues are resolved."
- "I have to purchase a new box now. Its existing box is not scalable and I can't use it anymore."
What is our primary use case?
It has performed well and delivered the results that I have been looking for.
How has it helped my organization?
It does a good job for us.
What is most valuable?
- Ease of use.
- Quick training period.
What needs improvement?
I can't scale it.
I would like to see AI play a major role going forward.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
I have to purchase a new box now. Its existing box is not scalable and I can't use it anymore.
How is customer service and technical support?
It has good technical support, which is available around the clock. You can call up anytime and get whatever you want. My queues are resolved.
How was the initial setup?
I was not involved in the initial setup, but it was straightforward.
Which other solutions did I evaluate?
We are currently evaluating ArcSight and LogRhythm.
At the time we previously purchased McAfee, I had fewer requirements and it catered to my needs.
What other advice do I have?
Most important criteria when selecting a vendor: support.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Officer at a tech services company with 51-200 employees
It is easy to use and deploy, but it lacks proper support
Pros and Cons
- "It is easy to use and deploy. It comes with user-friendly manuals."
- "McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support. It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better."
What is our primary use case?
We use McAfee ESM for IT operations and a few security-related things.
What is most valuable?
It is easy to use and deploy. It comes with user-friendly manuals.
What needs improvement?
McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support.
It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better.
For how long have I used the solution?
I have been using McAfee ESM for maybe the last six years.
What do I think about the stability of the solution?
It has very good stability.
What do I think about the scalability of the solution?
So far, we haven't tried scaling. Because it is on-premises, it is almost a setup environment. We don't do any major changes on the same site because it is quite critical and gets alerts. We don't want to mess up with our configuration.
How are customer service and technical support?
They take a long time, and the technical person who comes from support doesn't seem to be knowledgeable. When something goes wrong on the hardware or the application side, or we need some technical support in filling up use cases, it takes a long time.
We always struggle to get proper support from their technical support team. It seems that there is only one person who is handling the Middle East technical support, and when we don't get that person, we struggle a lot.
How was the initial setup?
The initial setup was straightforward. There were no complications in its deployment.
What about the implementation team?
Its deployment was done by an engineer in our company.
We are a security team of five members. Whoever a ticket is assigned to handles the cases.
What's my experience with pricing, setup cost, and licensing?
The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it.
What other advice do I have?
We are quite happy with the product and its stability, but the problem is the lack of support, which is one of the major issues that we are facing. I really look forward to them providing proper technical support.
I would rate McAfee ESM a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Splunk Enterprise Security
Microsoft Sentinel
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Fortinet FortiSIEM
Exabeam
USM Anywhere
ManageEngine EventLog Analyzer
ArcSight Enterprise Security Manager (ESM)
SolarWinds Security Event Manager
Trellix Helix
Snare
RSA enVision
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?