

Trellix ESM and Devo compete in the realm of security information and event management solutions. Based on user reviews, Devo seems to have the upper hand due to its superior features and functionality.
Features: Trellix ESM provides valuable features such as automated threat detection, flexible integration, and strong customer service. Devo offers powerful analytics, real-time threat detection, and advanced capabilities, leading to higher user satisfaction regarding features.
Room for Improvement: Trellix ESM needs a more intuitive system, reduced complexity in setup, and streamlined workflows. Devo could improve by offering more customization options, better documentation, and enhanced user training materials.
Ease of Deployment and Customer Service: Trellix ESM’s deployment is straightforward, supported by strong customer service that eases user adoption. Devo also offers smooth deployment but has slightly less stellar customer service.
Pricing and ROI: Trellix ESM users are generally satisfied with its pricing and ROI, finding it cost-effective. Devo, despite higher costs, delivers a compelling ROI due to its advanced features, justifying the investment for users.
It's rare for me to need them unless it's an issue with licensing, and they are the best in that regard.
I would rate support for Trellix ESM 10 out of 10 because if we connect with the support in the UK, we get excellent support.
Scalability is quite easier with Trellix ESM, because all we need to do is add more receivers to it, so it can go to any point.
Integrations with other sandboxes could be improved to better interpret data using AI and machine learning models.
If there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
The weakest point is it doesn't cover almost all the devices, so the customer has to be more dependent on the parsers to be written by the Professional Services team.
| Product | Market Share (%) |
|---|---|
| Devo | 1.1% |
| Trellix ESM | 1.2% |
| Other | 97.7% |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 6 |
| Large Enterprise | 24 |
Devo is the only cloud-native logging and security analytics platform that releases the full potential of all your data to empower bold, confident action when it matters most. Only the Devo platform delivers the powerful combination of real-time visibility, high-performance analytics, scalability, multitenancy, and low TCO crucial for monitoring and securing business operations as enterprises accelerate their shift to the cloud.
Make your organization more resilient and confident with Trellix Security Operations. Filter out the noise and cut complexity to deliver faster, more effective SecOps. Integrate your existing security tools and connect with over 650 Trellix solutions and third-party products.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.