No more typing reviews! Try our Samantha, our new voice AI agent.

Illumio Insights vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Illumio Insights
Ranking in Network Detection and Response (NDR)
19th
Average Rating
9.6
Reviews Sentiment
1.8
Number of Reviews
4
Ranking in other categories
Microsegmentation Software (6th), Cloud Detection and Response (CDR) (11th)
Trellix Network Detection a...
Ranking in Network Detection and Response (NDR)
4th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
53
Ranking in other categories
Advanced Threat Protection (ATP) (6th)
 

Featured Reviews

EM
Manager at OOCL
Micro-segmentation has improved threat visibility and supports ongoing zero-trust monitoring
Deployment of Illumio Insights was not difficult, but the difficulty depends on how micro your design is. For Docker containers, it is not quite suitable for that kind of application traffic. For container architectures, it is not quite designed that way. For normal VMs it might be acceptable, but for container architectures, I cannot be as micro-segmented as I want to be. Illumio Insights is not very well designed for containers, which is one of the drawbacks and weak sides of the product. I use Illumio Insights' real-time analytics for micro-segmentation, and beyond zero-trust monitoring, I also want to do analysis. However, the product coverage is not very broad, so I have to do my own filtering and analysis, and integration with other tools is necessary. The reporting and analysis are not ready out of the product itself. Reporting is another area for improvement in this product and is not very sufficient, so I have to further integrate or do it on my own. Illumio Insights is stable and a mature product. The functionality, such as reporting and analysis, may extend in the roadmap, but it has not in the past. The current functionality is adequate and quite mature, which is how I chose it based on maturity and market share. However, it is not very modern for Kubernetes and containers. If this functionality can extend, that would be a valuable roadmap addition. Streamline integration with Illumio Insights does not help me much since it does not require too much integration with my other operations.
Twinkle Solanki - PeerSpot reviewer
Business development executive at Digitaltrack solution Pvt Ltd
Continuous network insight has improved early threat detection and streamlined investigations
Overall, we have a positive experience with Trellix Network Detection and Response, but like any enterprise security solution, there are areas where it can continue to improve. One area would be user interface and dashboard customization. While the platform provides a lot of valuable information, new users can sometimes face a learning curve when navigating and investigating and creating customized views. More intuitive dashboards would simplify workflows and help analysts access critical information even faster. Another area for improvement is reporting and analytics. The existing reporting capabilities are useful, but more flexibility and customizable reporting options would make it easier to generate executive-level summaries, compliance reports, and operational metrics for different audiences.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the most valuable features is the ability to map traffic and patterns over multiple hyperscalers, not just AWS."
"This solution has contributed to quick detection of risky traffic and offers one-click containment."
"Illumio Insights is stable and a mature product."
"Illumio Insights impressed me with its ease of use, clarity, and potential to significantly improve breach containment strategies."
"Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall."
"There are sandbox capabilities; you can submit malicious files and get great feedback, including if there is malware and what it is doing, and it can give you simulations in different operating systems and applications to provide real insights from the perspective of a real environment."
"The real-time alerts from Trellix Network Detection and Response reduced our average incident detection time from several hours to under thirty minutes, allowing the team to contain threats much faster."
"The scalability has not been a problem. We have deployed the product in very high bandwidth networks. We have never had a problem with the FireEye product causing latency issues within our networks."
"It protects from signature-based attacks and signature-less attacks. The sandboxing technology, invented by FireEye, is very valuable. Our customers go for FireEye because of the sandboxing feature. When there is a threat or any malicious activity with a signature, it can be blocked by IPS. However, attacks that do not have any signatures and are very new can only be blocked by using the sandboxing feature, which is available only in FireEye. So, FireEye has both engines. It has an IPS engine and a sandbox engine, which is the best part. You can get complete network protection by using FireEye."
"Trellix Network Detection and Response definitely helps make investigations faster and more efficient."
"The features that I find most valuable are the MIR (Mandiant Incident Response) for checks on our inbound security."
"The most valuable feature of the solution stems from how it allows users to do the investigation part. Another important part of the product that is valuable is associated with how it gives information to users in the form of a storyline."
 

Cons

"In some of the views, an IP address appears to be a link, but it doesn't open any new windows or display any new information."
"Illumio Insights is not very well designed for containers, which is one of the drawbacks and weak sides of the product."
"There is room for improvement with more AI-based detection to report traffic abnormalities and potential issues."
"It doesn't connect with the cloud, advanced machine learning is not there. A known threat can be coming into the network and we would want the cloud to look up the problem. I would also like to see them develop more file replication and machine learning."
"The product's integration capabilities are an area of concern where improvements are required."
"Without tuning, you may get many false positives."
"It doesn't connect with the cloud, advanced machine learning is not there."
"They can maybe consider supporting some compliance standards. When we are configuring rules and policies, it can guide whether they are compliant with a particular compliance authority. In addition, if I have configured some rules that have not been used, it should give a report saying that these rules have not been used in the last three months or six months so that I disable or delete those rules."
"It would be great if we could create granular reports based on the protocols, types of attacks, regions of attack, etc. Also we would like to easily be able to add exceptions to rules in cases of false positives."
"Stability issues manifested in terms of throughput maximization."
"Customer service and technical support could use some enhancement. On a scale from 1 to 10, it is between six and seven."
 

Pricing and Cost Advice

Information not available
"The pricing is a little high."
"Because of what the FireEye product does, it has significantly decreased our mean time in being able to identify and detect malicious threats. The company that I work with is a very mature organization, and we have seen the meantime to analysis decrease by at least tenfold."
"There are some additional services that I understand the vendor provides, but our approach was to package all of the features that we were looking to use into the product."
"Pricing and licensing are reasonable compared to competitors."
"When I compare this solution to its competitors in the market, I find that it is a little expensive."
"It's an expensive solution."
"The tool is a bit pricey."
"We're partners with Cisco so we get a reasonable price. It's cheaper than Palo Alto in terms of licensing."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Manufacturing Company
16%
Outsourcing Company
12%
Financial Services Firm
12%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business35
Midsize Enterprise11
Large Enterprise23
 

Questions from the Community

What needs improvement with Illumio Insights?
Deployment of Illumio Insights was not difficult, but the difficulty depends on how micro your design is. For Docker containers, it is not quite suitable for that kind of application traffic. For c...
What is your primary use case for Illumio Insights?
Illumio Insights plays its own role in enhancing threat visibility. Illumio Insights performs micro-segmentation according to the traffic, determining whether to trust it, allow it, or block it. Mi...
What is your experience regarding pricing and costs for FireEye Network Security?
My experience with pricing, setup cost, and licensing for Trellix Network Detection and Response is positive, as the setup process was straightforward, licensing was flexible, and the value deliver...
What needs improvement with FireEye Network Security?
Based on my experience with the solution, I do not see any improvements needed for Trellix Network Detection and Response at present; it might be required in the future, but there is no space to im...
What is your primary use case for FireEye Network Security?
Our main use case for Trellix Network Detection and Response is to maintain oversight of our network traffic and catch any threats or unusual activity as early as possible. Trellix Network Detectio...
 

Also Known As

No data available
FireEye Network Security, FireEye
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Information Not Available
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Illumio Insights vs. Trellix Network Detection and Response and other solutions. Updated: July 2026.
909,725 professionals have used our research since 2012.