No more typing reviews! Try our Samantha, our new voice AI agent.

SentinelOne Singularity AI SIEM vs Trellix ESM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SentinelOne Singularity AI ...
Ranking in Security Information and Event Management (SIEM)
14th
Average Rating
8.6
Reviews Sentiment
6.1
Number of Reviews
5
Ranking in other categories
AI Observability (12th)
Trellix ESM
Ranking in Security Information and Event Management (SIEM)
30th
Average Rating
7.4
Reviews Sentiment
7.0
Number of Reviews
38
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of SentinelOne Singularity AI SIEM is 1.4%, up from 0.4% compared to the previous year. The mindshare of Trellix ESM is 1.2%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity AI SIEM1.4%
Trellix ESM1.2%
Other97.4%
Security Information and Event Management (SIEM)
 

Featured Reviews

Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
AI-driven monitoring has improved real-time threat detection but still needs better automation
I could see some workflows, but I am unable to do automated workflows. For example, some repetitive jobs or repetitive tasks I am doing, but I am trying to have less manual intervention on the front. I am raising some issues that should be resolvable. The SentinelOne team has told me that this can be resolved within a couple of months, but they are saying that it is in future for enhancement and it may take some time. So far, the numbers are great. Regarding disadvantages or areas for improvement, I could say that 35 percent of my manual effort can be detected since I implemented it very recently. I could be able to say my current data talks about only 35 percent, and it may improve further, as I am expecting. But I can only comment based on my alerts and events. The adoption rate will be less compared to other products, as this can be a time-taken process because all my data needs to be offloaded and the system needs to understand my existing alerts, logs, and other things. This will take some more time, probably another month. Another area for improvement is that the product is somewhat expensive. Pricing could be improved as well.
MD
Senior Vice President IT at AS IT Consulting Pvt. Ltd.
Offers comprehensive report generation while maintaining ease of integration
We need to improve Trellix ESM by making sure that most of the logging devices available in the global market should be covered, and if there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that. We can add some new features regarding AI in the future for Trellix ESM, but the maturity will take a longer time. There are many false positives that happen in an environment during the first couple of months, or around six months, so the system analyst is not able to identify whether the event which has occurred is a true positive or a false positive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"SentinelOne Singularity AI SIEM's AI-powered analytics does affect our SOC's ability to reduce false positives; that is one of the biggest advantages because the manpower that I have is limited."
"When they face attacks such as ransomware and are dissatisfied with their existing solutions, they switch to SentinelOne Singularity AI SIEM, which is quite good in detecting unknown threats, cleaning the system, and handling ransomware."
"AI-driven capabilities will give me real-time detection and will protect my autonomous AI interruption."
"Overall, I would assess the overall security posture after implementing SentinelOne Singularity AI SIEM as significantly better."
"After using SentinelOne Singularity AI SIEM, it has reduced our incident response time by forty to fifty percent compared to other tools."
"The most valuable feature is the correlation rules."
"On the security side, it reduces the time needed to make changes in case of an attack; if we didn't have the tool, the amount of time would be double or triple, and it helps with productivity and the maturity of our security program."
"Compared to other solutions, the user interface is good."
"The most valuable feature is the capability to correlate different events from different platforms that we feed into it."
"The ability to secure my data is the most important feature."
"You will definitely get a return on your investment if you develop the correct security management metrics and have decent operational procedures in place to take action on events in ESM."
"Customer service is very good."
"McAfee ESM is the perfect SIEM tool, and it provides best results based on data intake and rule based configuration."
 

Cons

"SentinelOne Singularity AI SIEM has some performance and reliability issues that need improvement."
"In AI SIEM, the areas that have room for improvement are the parsers for third-party integrated data or for third-party data sources that are not native integrations, which could be made a bit easier."
"Another area for improvement is that the product is somewhat expensive. Pricing could be improved as well."
"At the moment, I feel the pricing is a little bit on the higher side, but the tool is positioned in a place where risk is very high, and we do not want to take chances, so we are prepared to pay the premium."
"It is quite good, but the only downside is that it is costly."
"There are always multiple bugs in the product. For example, the console page was hanging multiple times. Afterwards, they released multiple upgrades for the same, multiple patches from McAfee."
"The initial setup is difficult and could improve."
"Executives don’t see ROI on this solution as the reports are not meant for C-levels."
"Update to user interface from version 9 is cosmetic in some aspects, and after a few clicks you are back on the old interface."
"The API the product provides still needs to develop some maturity."
"The product documentation is good, but could be better. Also a bug-free version would be nice as the version I worked on had a bug in the alarm system."
"The only drawback is that they don't have any packet capturing or network behavior analysis."
"McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped."
 

Pricing and Cost Advice

Information not available
"The cost is dependent on the customer's environment and requirements."
"Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar."
"We pay for our licensing fees on a yearly basis, and there are no costs in addition to the standard licensing fees."
"You should buy the distributed option instead of the all-in-one for environments with more than 1000 end points."
"The licensing cost is based on EPS."
"The product is slightly expensive."
"The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar."
"When compared to IBM Security QRadar and other similar platforms, the pricing of McAfee ESM is reasonable and comparatively less expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Construction Company
9%
Outsourcing Company
8%
Comms Service Provider
8%
Healthcare Company
8%
Comms Service Provider
16%
Construction Company
11%
Financial Services Firm
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise2
Large Enterprise2
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What needs improvement with SentinelOne Singularity AI SIEM?
I would not say there is anything that could be better in SentinelOne Singularity AI SIEM; I think we have seen something unique in the product. This product has the potential to add more SOC funct...
What is your primary use case for SentinelOne Singularity AI SIEM?
For us, the use case is primarily to analyze security events that are coming in and also events that are kept over a period of time, to track and use it for investigation and maybe analysis, someti...
What advice do you have for others considering SentinelOne Singularity AI SIEM?
I assess the overall security posture of the company after implementation as positive; I see a big impact on that. I would rate this review as an overall eight.
What is your experience regarding pricing and costs for McAfee ESM?
When discussing Trellix ESM pricing and licensing, if you consider some premium product, the pricing also has to be premium, however, enterprise customers who look for a premium product, alongside ...
What needs improvement with McAfee ESM?
Areas of Trellix ESM that could be improved or enhanced include checking on the clients who are still on-prem, especially banks, as most are not moving everything to the cloud due to confidentialit...
What is your primary use case for McAfee ESM?
My customer's usual use case for Trellix ESM involves one client, as most of the users have moved to ESM. Nowadays, they don't use IPS only, since McAfee IPS is standalone; they incorporate firewal...
 

Also Known As

No data available
McAfee ESM, NitroSecurity, McAfee Enterprise Security Manager
 

Overview

 

Sample Customers

Information Not Available
San Francisco Police Credit Union, Wªstenrot Gruppe, Volusion, California Department of Corrections & Rehabilitation, Government of New Brunswick, State of Colorado, Macquarie Telecom, Texas Tech University Health Sciences Center, Cologne Bonn Airport
Find out what your peers are saying about SentinelOne Singularity AI SIEM vs. Trellix ESM and other solutions. Updated: April 2026.
894,738 professionals have used our research since 2012.