The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.
Use our online form to submit your review. It's quick and you can post anonymously.
Positive
My company is a customer of Anomali.
I would recommend it to other people.
I would advise making sure you don't pick it without testing other products and have your use cases well thought out and documented before testing, so you know it will solve the problems you're trying to address. Keep an open mind with it and realize that whatever you can dream of, you can probably do with the platform.
Overall, I would rate Anomali an eight out of ten.
I am working with something that is similar to Trellix ESM for event management. It is similar to Trellix Enterprise Security Manager.
Mainly compliance is the primary concern where organizations have to have log retention for more than six months, one year, or six years, depending on the compliance applicable to the organization for the Enterprise Security Manager. And Trellix gives us good reporting.
The strongest part of Trellix ESM is that we get quite good reports, while the weakest point is it doesn't cover almost all the devices, so the customer has to be more dependent on the parsers to be written by the Professional Services team. In the case of other ESM solutions, there are no parsers required, and almost every device is covered within the license, so there is no hidden cost as custom parsers.
Functionality and installation of Trellix ESM has never been a challenge.
We need to improve Trellix ESM by making sure that most of the logging devices available in the global market should be covered, and if there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that.
We can add some new features regarding AI in the future for Trellix ESM, but the maturity will take a longer time.
There are many false positives that happen in an environment during the first couple of months, or around six months, so the system analyst is not able to identify whether the event which has occurred is a true positive or a false positive.
With Trellix ESM, I have been using it from day one when the product was launched in India, which is more than 15 years.
For us, Trellix ESM is quite stable.
Scalability is quite easy with Trellix ESM. All we need to do is add more receivers to it, so it can go to any point.
When discussing Trellix ESM suitability for enterprise, commercial, and government sectors, it is quite good. For small and medium enterprises, we have a solution that is an all-in-one device for the ESM, however, the limitation is that it can take a very small number of EPS count, meaning it doesn't suit medium enterprises, and they will not invest in the enterprise type of solution.
I would rate support for Trellix ESM 10 out of 10 because if we connect with the support in the UK, we get excellent support. However, the problems arise if we connect into the India data centers where there are challenges and people are not well equipped with the support infrastructure required to support for the ESM solution.
Positive
I am familiar with other products from Trellix.
Maintenance of Trellix ESM is quite easy and it's not difficult to maintain.
When discussing Trellix ESM pricing and licensing, if you consider some premium product, the pricing also has to be premium, however, enterprise customers who look for a premium product, alongside the Gartner reporting, Forester reporting, and PeerSpot, they don't look at the pricing.
Regarding AI functionality, I have not seen any integrations in the Trellix ESM product.
I rate Trellix ESM 10 out of 10.