

Both Trellix ESM and Elastic Security are formidable players in the cybersecurity market. Trellix ESM appears to have the upper hand for comprehensive features and reliable support, while Elastic Security excels in analytics and deployment flexibility.
Features: Trellix ESM is celebrated for its comprehensive threat detection, user-friendly customization options, and reliable network monitoring. Elastic Security stands out with its advanced analytics, real-time monitoring, and seamless integration with existing systems.
Room for Improvement: Trellix ESM could enhance its reporting functionality, reduce system resource consumption, and improve efficiency. Elastic Security needs better documentation, streamlined setup processes, and enhanced support materials.
Ease of Deployment and Customer Service: Trellix ESM deployment is often straightforward with strong customer service, but it can be resource-intensive. Elastic Security offers flexible deployment options but may require more effort to set up due to less comprehensive customer support.
Pricing and ROI: Trellix ESM's pricing is viewed as competitive, offering good ROI through its extensive features despite initial setup costs. Elastic Security is appreciated for its cost-effectiveness, providing significant ROI, particularly valued by businesses leveraging its advanced analytics.
It does not require hefty security budgets and can be deployed for enterprise security effectively.
Providing necessary assistance efficiently.
Most of the time when my team encounters issues, they receive responses within 24 hours.
It's rare for me to need them unless it's an issue with licensing, and they are the best in that regard.
I would rate support for Trellix ESM 10 out of 10 because if we connect with the support in the UK, we get excellent support.
It allows us to think about specific use cases, such as gathering malicious IPs in a single view and analyzing threats based on geolocation.
Scalability is quite easier with Trellix ESM, because all we need to do is add more receivers to it, so it can go to any point.
In terms of stability, I would rate Elastic a solid eight out of ten.
My security testing team continuously reports vulnerabilities, and we have to fix and update the versions frequently.
CrowdStrike and Defender have more established threat intelligence integration due to having a larger client base.
Elastic Security consumes a lot of resources, requiring a substantial deployment setup.
If there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that.
The pricing is reasonable, especially for Small Medium Enterprises (SMEs), making it a viable option for businesses building their security infrastructure.
This is beneficial for SMEs as they do not need extensive budgets for security solutions.
Elastic Security is considered cost-effective, especially at lower EPS levels.
Elastic Security is as flexible and configurable as Microsoft Sentinel.
Elastic Security offers advanced features such as machine learning and integration with ChatGPT.
We require rapid processing speed for alerts and event data, and Elastic Security is very efficient at handling this level of data.
The weakest point is it doesn't cover almost all the devices, so the customer has to be more dependent on the parsers to be written by the Professional Services team.


| Product | Market Share (%) | 
|---|---|
| Elastic Security | 4.9% | 
| Trellix ESM | 1.1% | 
| Other | 94.0% | 


| Company Size | Count | 
|---|---|
| Small Business | 40 | 
| Midsize Enterprise | 11 | 
| Large Enterprise | 14 | 
| Company Size | Count | 
|---|---|
| Small Business | 15 | 
| Midsize Enterprise | 6 | 
| Large Enterprise | 24 | 










Elastic Security combines the features of a security information and event management (SIEM) system with endpoint protection, allowing organizations to detect, investigate, and respond to threats in real time. This unified approach helps reduce complexity and improve the efficiency of security operations.
Additional offerings and benefits:
Finally, Elastic Security benefits from a global community of users who contribute to its threat intelligence, helping to enhance its detection capabilities. This collaborative approach ensures that the solution remains on the cutting edge of cybersecurity, with up-to-date information on the latest threats and vulnerabilities.
Make your organization more resilient and confident with Trellix Security Operations. Filter out the noise and cut complexity to deliver faster, more effective SecOps. Integrate your existing security tools and connect with over 650 Trellix solutions and third-party products.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.