IT Security Analyst at Ingenium Group
Real User
A good central viewpoint for issues, but it requires Flash
Pros and Cons
  • "It is a good central viewpoint for issues. These can then be investigated in more detail on the subnet server(s)/endpoints."
  • "Product currently requires Flash."
  • "Update to user interface from version 9 is cosmetic in some aspects, and after a few clicks you are back on the old interface."
  • "We would welcome integrations with some of the new McAfee acquisitions, e.g., behavioural analytics."

What is our primary use case?

  • To gain transparency into potential vulnerabilities within the network. 
  • To monitor problems, e.g., failure to update packages within the back-end security environment.

How has it helped my organization?

It is a good central viewpoint for issues. These can then be investigated in more detail on the subnet server(s)/endpoints.

What is most valuable?

Ability to create own views. Statistical (normalised) views help to highlight inconsistencies, which may need further investigation

What needs improvement?

  • Product currently requires Flash. 
  • Update to user interface from version 9 is cosmetic in some aspects, and after a few clicks you are back on the old interface.
  • Some filters are still very low level "magic numbers", which do not make sense on the high level user interface. 
  • We would welcome integrations with some of the new McAfee acquisitions, e.g., behavioral analytics.
Buyer's Guide
Trellix ESM
April 2024
Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
770,141 professionals have used our research since 2012.

For how long have I used the solution?

Less than one year.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user380976 - PeerSpot reviewer
Information Security Analyst at a tech services company with 501-1,000 employees
Consultant
Through correlation rules, it finds malware that anti-virus and other security solutions do not find.

What is most valuable?

The easy interface is the most valuable feature.

How has it helped my organization?

Through correlation rules, it finds malware that compromised the computer that anti-virus and other security solutions do not find.

What needs improvement?

I had a couple of problems collecting Windows events. The local plugin should be easier to use, because when ESM is collecting through the manager, many performance issues occur.

For how long have I used the solution?

I have been using McAfee for over three years.

What do I think about the stability of the solution?

We did have stability issues, but they were resolved by McAfee support.

What do I think about the scalability of the solution?

We have not had scalability issues.

How are customer service and technical support?

I would give technical support a rating of 8/10.

Which solution did I use previously and why did I switch?

I used different solutions, but for different clients.

How was the initial setup?

This was the easiest initial setup that I have made.

What's my experience with pricing, setup cost, and licensing?

The product is worth the price. There are other cheaper tools in the market, but it is harder to work with them.

Which other solutions did I evaluate?

We looked at HPE ArcSight, Splunk, RSA Analytics, and IBM QRadar.

What other advice do I have?

Stay focused, read the documentation, plan it well, and the project will be a success.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros sharing their opinions.