it_user374493 - PeerSpot reviewer
Security Consultant, Presale and System Engineer at a tech services company with 501-1,000 employees
Consultant
If you provide it with the Advanced Correlation Engine and Global Threat Intelligence, you can raise your infrastructure to be a complete advanced SOC.

What is most valuable?

Doing Incident analysis in my opinion with ESM is easier than other solutions. There are a lot of ways to build queries and a great filter engine; if you provide ESM with the Advanced Correlation Engine and Global Threat Intelligence you can raise your infrastructure to be a complete advanced SOC.

How has it helped my organization?

I work for a System Integrator.

What needs improvement?

I have almost no complaints with this solution because it's almost a complete solution, but I do hope to have more stability in the next upgrade and to have the interface re-engineered to be HTML5-based rather than Flash-based.

I'd also like some Splunk-like ELM (Log Manager) enterprise functions.

For how long have I used the solution?

I've used it for three years, from versions 9.1 to 9.5

Buyer's Guide
Trellix ESM
April 2024
Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,141 professionals have used our research since 2012.

What was my experience with deployment of the solution?

Yes, sometimes it seems that versions with major upgrades come with some bugs and regressions that affected deployment.

What do I think about the stability of the solution?

Yes, sometimes it seems that versions with major upgrades come with some bugs and regressions that affected stability.

What do I think about the scalability of the solution?

It has scaled to our needs.

How are customer service and support?

Customer Service:

Customer service is very good and very professional.

Technical Support:

Technical support is very good and very professional.

Which solution did I use previously and why did I switch?

I also work with with RSA and McAfee SIEM solutions.

How was the initial setup?

If you buy the all-in-one solution (Virtual or Hardware), the setup takes a couple of hours.

What's my experience with pricing, setup cost, and licensing?

SIEM is not a Log Manager; ESM is meant for people who need advanced SOC functionality and not only to satisfy compliance rules.

Disclosure: My company has a business relationship with this vendor other than being a customer: We're a partner.
PeerSpot user
Assistant Vice President at a financial services firm with 1,001-5,000 employees
Real User
Good overall but complex setup and integration needs improvement
Pros and Cons
  • "McAfee as a whole is a good solution."
  • "It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI."

What is our primary use case?

We are using the solution for log analyzing endpoints and investigating all types of applications, files or network devices login collection.

What is most valuable?

McAfee as a whole is a good solution.

What needs improvement?

When it came to using the solution for a larger organization, we were faced with some troubles attempting to manage the GUI functionality. During some forensic investigations, some of the information was missing from the collected data. 

It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI. For Postgre databases, the solution did not collect a lot of information from it. It has some integration problem. Companies, therefore, have to invest twice for collecting logs rather than one SIEM.

For how long have I used the solution?

I have been using the solution for two years.

How was the initial setup?

The initial setup was a bit complex.

What about the implementation team?

The local partner we had was not very experienced in implementing the solution. However, the solution was first implemented in our country.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Trellix ESM
April 2024
Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,141 professionals have used our research since 2012.
IT Manager at a tech services company with 10,001+ employees
Real User
It has good technical support, but I can't scale it
Pros and Cons
  • "It has performed well and delivered the results that I have been looking for."
  • "It has good technical support, which is available around the clock. You can call up anytime and get whatever you want. My queues are resolved."
  • "I have to purchase a new box now. Its existing box is not scalable and I can't use it anymore."

What is our primary use case?

It has performed well and delivered the results that I have been looking for.

How has it helped my organization?

It does a good job for us.

What is most valuable?

  • Ease of use.
  • Quick training period.

What needs improvement?

I can't scale it.

I would like to see AI play a major role going forward.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is a stable product.

What do I think about the scalability of the solution?

I have to purchase a new box now. Its existing box is not scalable and I can't use it anymore.

How is customer service and technical support?

It has good technical support, which is available around the clock. You can call up anytime and get whatever you want. My queues are resolved.

How was the initial setup?

I was not involved in the initial setup, but it was straightforward.

Which other solutions did I evaluate?

We are currently evaluating ArcSight and LogRhythm.

At the time we previously purchased McAfee, I had fewer requirements and it catered to my needs.

What other advice do I have?

Most important criteria when selecting a vendor: support.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Business System Analyst at a consultancy with 5,001-10,000 employees
Real User
An easy way to protect my privacy if I lose my computer
Pros and Cons
  • "It is easy to use."
  • "I would like to see fingerprint recognition included in the next release of this solution."

What is our primary use case?

My primary use case for this solution is to secure the data on my laptop.

How has it helped my organization?

If I lost my computer somewhere then hopefully the software will protect my data from anyone.

What is most valuable?

The ability to secure my data is the most important feature.

It is easy to use. I just need to enter the username and the password and it protects my data.

What needs improvement?

I would like to see fingerprint recognition included in the next release of this solution.

How are customer service and technical support?

I have not used technical support for the product.

Which solution did I use previously and why did I switch?

My company did use another product previous to this one but I do not know why they switched.

How was the initial setup?

The installation and setup of this solution is straightforward.

What about the implementation team?

I handled the deployment myself.

What other advice do I have?

This is a product that I would recommend to a colleague at another company.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Vice President Cyber Security Practice Head at a tech services company with 1,001-5,000 employees
Real User
Does not integrate well, and scalability needs improvement but it's fairly priced
Pros and Cons
  • "I like the ease of deployment."
  • "I would like to see good analytics in future releases."

What is our primary use case?

We use this solution for correlation, alerting, and log management.

We are integrators.

What is most valuable?

I like the ease of deployment.

What needs improvement?

I would like to see good analytics in future releases.

McAfee has many issues with integration. I am looking for an end-to-end integration such as EDR, and Next-Generation SOC 2.0. 

For how long have I used the solution?

I have been working with McAfee ESM for 20 years.

What do I think about the scalability of the solution?

We are looking for horizontal and verticle expansion. McAfee has issues with scalability. Other ESM solutions, don't have the same issues.

How are customer service and technical support?

We have not contacted technical support in quite some time. We had issues with the parsing.

How was the initial setup?

The deployment is easy, but because it is a hybrid deployment which makes it complex. It is partly in the cloud and partly an on-premises deployment. The device will have to access the cloud and on-premises data.

What about the implementation team?

We have an internal team to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

The pricing is fair.

What other advice do I have?

I would recommend this solution to others who are interested in using it.

I would rate McAfee ESM a five out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Information Security Officer at a tech services company with 51-200 employees
MSP
It is easy to use and deploy, but it lacks proper support
Pros and Cons
  • "It is easy to use and deploy. It comes with user-friendly manuals."
  • "McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support. It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better."

What is our primary use case?

We use McAfee ESM for IT operations and a few security-related things. 

What is most valuable?

It is easy to use and deploy. It comes with user-friendly manuals.

What needs improvement?

McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support.

It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better.

For how long have I used the solution?

I have been using McAfee ESM for maybe the last six years. 

What do I think about the stability of the solution?

It has very good stability.

What do I think about the scalability of the solution?

So far, we haven't tried scaling. Because it is on-premises, it is almost a setup environment. We don't do any major changes on the same site because it is quite critical and gets alerts. We don't want to mess up with our configuration.

How are customer service and technical support?

They take a long time, and the technical person who comes from support doesn't seem to be knowledgeable. When something goes wrong on the hardware or the application side, or we need some technical support in filling up use cases, it takes a long time.

We always struggle to get proper support from their technical support team. It seems that there is only one person who is handling the Middle East technical support, and when we don't get that person, we struggle a lot.

How was the initial setup?

The initial setup was straightforward. There were no complications in its deployment.

What about the implementation team?

Its deployment was done by an engineer in our company. 

We are a security team of five members. Whoever a ticket is assigned to handles the cases.

What's my experience with pricing, setup cost, and licensing?

The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it.

What other advice do I have?

We are quite happy with the product and its stability, but the problem is the lack of support, which is one of the major issues that we are facing. I really look forward to them providing proper technical support.

I would rate McAfee ESM a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Systems-Engineer at a tech services company with 10,001+ employees
Real User
Leaderboard
I like the vendor support from McAfee and the overall architecture looks simple. The version I worked on had a bug in the alarm system.

Valuable Features

This is the first SIEM product that I have used. My impressions so far are that I like the vendor support from McAfee and the overall architecture looks simple.

Improvements to My Organization

I helped a client of ours implement and deploy it.

Room for Improvement

The product documentation is good, but could be better. Also a bug-free version would be nice as the version I worked on had a bug in the alarm system.

Use of Solution

I've used it for five months.

Deployment Issues

We had bug alarm issues during deployment. The bug, I think, was part of the product.

Stability Issues

We had no issues with the stability.

Scalability Issues

We have had no issues scaling it for our needs.

Customer Service and Technical Support

Customer Service:

Customer service is very good.

Technical Support:

Technical support is very good.

Initial Setup

The initial setup was straightforward.

Implementation Team

You will have a better implementation if you get support from the vendor.

Pricing, Setup Cost and Licensing

Overall, it was expensive, as it has split components.

Other Solutions Considered

We have now started using ArcSigh as well. I don't have much experienced with it, but the overall architecture looks similar to McAfee.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user380976 - PeerSpot reviewer
Information Security Analyst at a tech services company with 501-1,000 employees
Consultant
The most valuable feature for us is that it comes with many correlations, reports, and dashboards already available.
Pros and Cons
  • "The most valuable feature for us is that it comes with many correlations, reports, and dashboards already available. It's also very easy to use."
  • "The disk space needed for events is not clear. In all clients, we had at least more than 100GB free that we could not use."

What is most valuable?

The most valuable feature for us is that it comes with many correlations, reports, and dashboards already available. It's also very easy to use.

How has it helped my organization?

It's easy to create reports for compliance and for detecting different kinds of attacks and breaches through correlations. This makes the client devices to be more secure.

What needs improvement?

The disk space needed for events is not clear. In all clients, we had at least more than 100GB free that we could not use.

For how long have I used the solution?

I've used it for two-and-a-half years.

What was my experience with deployment of the solution?

The disk space sizing is very hard and when the version was updated to 9.4 the space needed to store events was cut by half, making it harder to explain to clients who now needed twice as much disk space, with no explanation from the vendor what happened. This was not even in the release notes.

I suggest that you configure the data archive prior to deployment because once the partition is detached, it will be deleted and you can lose a weeks-worth of events. You don't know when it will be deleted because even with a lot of space disk the partition is detached.

What do I think about the stability of the solution?

There have been no issues with the stability.

What do I think about the scalability of the solution?

There have been no issues scaling.

How are customer service and technical support?

Customer Service:

I give customer service a 7 out of 10.

Technical Support:

I give technical support a 7 out of 10.

Which solution did I use previously and why did I switch?

We used HP ArcSight, IBM Q1 Labs, Splunk, and we chose McAfee Enterprise Security Manager because it’s very easy to deploy.

How was the initial setup?

The initial setup is simple and descriptive. It was very straightforward.

What about the implementation team?

We implemented it with our in-house team.

What was our ROI?

The in-house sales team said McAfee has the best ROI on the market.

What's my experience with pricing, setup cost, and licensing?

You should buy the distributed option instead of the all-in-one for environments with more than 1000 end points.

What other advice do I have?

Multiple dashboards already created
More than 200 correlation rules created and available to use on the Correlation Engine
Multiple reports already created, ready to use or you can edit them
Disclosure: My company has a business relationship with this vendor other than being a customer: We're partners.
PeerSpot user
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros sharing their opinions.