We are using the solution for log analyzing endpoints and investigating all types of applications, files or network devices login collection.
Assistant Vice President at a financial services firm with 1,001-5,000 employees
Good overall but complex setup and integration needs improvement
Pros and Cons
- "McAfee as a whole is a good solution."
- "It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI."
What is our primary use case?
What is most valuable?
McAfee as a whole is a good solution.
What needs improvement?
When it came to using the solution for a larger organization, we were faced with some troubles attempting to manage the GUI functionality. During some forensic investigations, some of the information was missing from the collected data.
It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI. For Postgre databases, the solution did not collect a lot of information from it. It has some integration problem. Companies, therefore, have to invest twice for collecting logs rather than one SIEM.
For how long have I used the solution?
I have been using the solution for two years.
Buyer's Guide
Trellix ESM
July 2025

Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
How was the initial setup?
The initial setup was a bit complex.
What about the implementation team?
The local partner we had was not very experienced in implementing the solution. However, the solution was first implemented in our country.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Information Security Officer at a tech services company with 51-200 employees
It is easy to use and deploy, but it lacks proper support
Pros and Cons
- "It is easy to use and deploy. It comes with user-friendly manuals."
- "McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support. It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better."
What is our primary use case?
We use McAfee ESM for IT operations and a few security-related things.
What is most valuable?
It is easy to use and deploy. It comes with user-friendly manuals.
What needs improvement?
McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support.
It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better.
For how long have I used the solution?
I have been using McAfee ESM for maybe the last six years.
What do I think about the stability of the solution?
It has very good stability.
What do I think about the scalability of the solution?
So far, we haven't tried scaling. Because it is on-premises, it is almost a setup environment. We don't do any major changes on the same site because it is quite critical and gets alerts. We don't want to mess up with our configuration.
How are customer service and technical support?
They take a long time, and the technical person who comes from support doesn't seem to be knowledgeable. When something goes wrong on the hardware or the application side, or we need some technical support in filling up use cases, it takes a long time.
We always struggle to get proper support from their technical support team. It seems that there is only one person who is handling the Middle East technical support, and when we don't get that person, we struggle a lot.
How was the initial setup?
The initial setup was straightforward. There were no complications in its deployment.
What about the implementation team?
Its deployment was done by an engineer in our company.
We are a security team of five members. Whoever a ticket is assigned to handles the cases.
What's my experience with pricing, setup cost, and licensing?
The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it.
What other advice do I have?
We are quite happy with the product and its stability, but the problem is the lack of support, which is one of the major issues that we are facing. I really look forward to them providing proper technical support.
I would rate McAfee ESM a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Trellix ESM
July 2025

Learn what your peers think about Trellix ESM. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
865,295 professionals have used our research since 2012.
Information Security Engineer at a financial services firm with 51-200 employees
Good reporting, correlation capability, and user interface
Pros and Cons
- "Compared to other solutions, the user interface is good."
- "The only drawback is that they don't have any packet capturing or network behavior analysis."
What is our primary use case?
We are a service provider and we implement it for our customers, as well as use it internally.
This is a SIEM product that makes up part of our overall security solution.
What is most valuable?
Compared to other solutions, the user interface is good.
The correlations that it discovers are helpful.
The reporting is good.
What needs improvement?
The only drawback is that they don't have any packet capturing or network behavior analysis. Including network behavior analysis in the future would be a good addition.
The speed of technical support can be improved.
For how long have I used the solution?
We have been using McAfee ESM for between five and six years.
What do I think about the stability of the solution?
We have had no issues with stability.
What do I think about the scalability of the solution?
If we want to increase or expand then we just have to add devices, so it should not be a problem.
How are customer service and technical support?
I would say that the technical support is not very prompt, but the end result is good.
Which solution did I use previously and why did I switch?
We also work with Splunk and we have experience with similar solutions such as IBM QRadar.
How was the initial setup?
The initial setup is pretty much straightforward. We haven't had any problem.
What's my experience with pricing, setup cost, and licensing?
The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar.
What other advice do I have?
The suitability of McAfee ESM is based on the requirements. If a customer is specifically looking for log and event analysis, with the correlations, then this solution is a good choice. If instead, they are looking for network behavior analytics then they should consider IBM QRader or something else.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Operations Manager at a aerospace/defense firm with 5,001-10,000 employees
Excellent security features with 100% stability and good scalability capabilities
Pros and Cons
- "The solution is 100% stable. We really have had a great time working with it. It hasn't let us down."
- "The user interface could be more user-friendly."
What is most valuable?
The security can't be compromised. The security features on offer are the most valuable feature and are why it's really worth having as a product like this in our organization.
What needs improvement?
The user interface could be more user-friendly.
Technical support could be improved.
For how long have I used the solution?
I've been using the solution for two or three years.
What do I think about the stability of the solution?
The solution is 100% stable. We really have had a great time working with it. It hasn't let us down.
What do I think about the scalability of the solution?
We've been satisfied with the level of scalability the solution offers us.
How are customer service and technical support?
We've had some issues in the past and have had their Pakistani representative here. We've also communicated with foreign branches of technical support. The solution offers okay assistance. It's not a mature solution like Fortinet or Watchguard, but it's still providing okay service. I'd say the help we've received is largely mixed. It's been 50/50 in terms of resolving our issues.
What's my experience with pricing, setup cost, and licensing?
It's a fairly low-cost solution, so the pricing is pretty good.
What other advice do I have?
I'd rate the solution eight out of ten. If it was more user-friendly, I'd mark it higher. Right now, technical people working on the solution don't understand what it is are trying to communicate in its tabs. As a company, you need to have a certified or experienced McAfee engineer there or on staff to guide you.
I'd recommend the product, however. It's a nice, robust product.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Consultant at a computer software company with 51-200 employees
Helpful dashboards for log monitoring, and integrates well with other technologies
Pros and Cons
- "This solution integrates easily and very well with other technologies."
- "We cannot add new data sources to the most recent version."
What is our primary use case?
We use this solution to provide managed security services. We use loggers at the client site to generate logs for monitoring their devices. We handle the monitoring, administration, and troubleshooting of their endpoints.
For some customers, we manage everything, while for other customers we only monitor their critical devices.
We are using an on-premises deployment model.
How has it helped my organization?
This solution helps us to provide services for our clients and integrates well with their other technologies.
What is most valuable?
The most valuable features of this solution are the logging and the dashboards.
This solution integrates easily and very well with other technologies. We are creating custom connectors for some of the technologies that our customers are using.
What needs improvement?
We are having trouble migrating our data sources from version 10 to version 11.2. We cannot add new data sources to the most recent version.
I would like to see the Active Response function enhanced.
For how long have I used the solution?
I have been using this solution for about eighteen months.
What do I think about the stability of the solution?
The stability of this solution is good. So far, we have not faced much downtime. The issues that we are currently experiencing, moving versions, did not happen the last time we upgraded. This is really the first trouble that we have had.
What do I think about the scalability of the solution?
This solution is very scalable.
We have four or five customers that we are performing monitoring for. Their user-base varies, with some having fifty users and some having more than one thousand users.
We do plan to increase our usage and have had meetings with McAfee as a partner. We would be offering this solution exclusively to our clients.
How are customer service and technical support?
Technical support, as well as their online knowledge base, has helped us a lot. However, our current issue with respect to not being able to add new data sources was reported two weeks ago and it has not yet been resolved.
I think that technical support can be improved in terms of providing quicker resolutions to problems.
Which solution did I use previously and why did I switch?
We did not previously offer a different solution to our customers. We are currently onboarding Splunk to work concurrently with this solution, but it depends on the customer. Splunk is a little bit expensive.
How was the initial setup?
The initial setup of this solution is easy. There is no problem with it.
Our deployment took about one week. It involved upgrading to the new version and adding the data sources. Integration of the new devices was not complex.
Two people are required for the deployment, with one being from our side and one from the client's side.
What about the implementation team?
We hired consultants to assist with our deployment. We have had a good experience with them and they are still supporting us to deal with any issues or errors.
What's my experience with pricing, setup cost, and licensing?
The cost is dependent on the customer's environment and requirements.
Which other solutions did I evaluate?
We have experience using ArcSight, but it is very difficult when it comes to creating the connector to integrate with different technologies.
We spend time evaluating each customer's business model and offer them the appropriate solution.
What other advice do I have?
From my perspective, for anyone with a small or medium-sized business, this is the best solution. It is easy to deploy and it is less, from a cost point of view, than others.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
IT Consultant and Project Manager at a government with 1-10 employees
Out-of-the-box rules are helpful in monitoring our hybrid-cloud environment
Pros and Cons
- "We are now able to completely monitor our environment so we can review what is there, which is a big win for us."
- "I would like to see improvements to the user interface."
What is our primary use case?
We use this solution to monitor everything in our hybrid-cloud environment. This includes IoT devices and a couple of data centers.
How has it helped my organization?
We are now able to completely monitor our environment so we can review what is there, which is a big win for us. This solution helps with the maturity of our environment.
Using the out-of-the-box rules has made our work more relaxing.
What is most valuable?
There are more than two hundred out-of-the-box rules.
We have been using the advanced correlation agent.
What needs improvement?
Technical support for this product could be improved.
I would like to see improvements to the user interface.
It would be helpful to have a diagram in the interface that shows the actions.
For how long have I used the solution?
We have been using this solution for two years.
What do I think about the stability of the solution?
This is a very stable solution, although there are some bugs in the GUI.
What do I think about the scalability of the solution?
This solution is very scalable from my perspective. We have around twenty-five users. We have level one users, which are operation analysts. We also have level two users, who take care of daily operations. Level two includes, for example, handling the rules on the creation of users. Everything is segregated. We also have a second engineer.
How are customer service and technical support?
We have had issues where we had to contact technical support. While they answered ok, the timing may have been a little slow.
Which solution did I use previously and why did I switch?
We used another solution prior to this one.
How was the initial setup?
The initial setup of this solution was very clear. We followed the instructions on the web page, and there were no problems. The deployment was really quick and completed within a couple of hours.
What about the implementation team?
We performed the implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
We pay for our licensing fees on a yearly basis, and there are no costs in addition to the standard licensing fees.
Which other solutions did I evaluate?
We evaluated several other options before choosing this one, including Elasticsearch.
What other advice do I have?
I recommend trying this product. This is a quality solution at a fair price.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Business System Analyst at a consultancy with 5,001-10,000 employees
An easy way to protect my privacy if I lose my computer
Pros and Cons
- "It is easy to use."
- "I would like to see fingerprint recognition included in the next release of this solution."
What is our primary use case?
My primary use case for this solution is to secure the data on my laptop.
How has it helped my organization?
If I lost my computer somewhere then hopefully the software will protect my data from anyone.
What is most valuable?
The ability to secure my data is the most important feature.
It is easy to use. I just need to enter the username and the password and it protects my data.
What needs improvement?
I would like to see fingerprint recognition included in the next release of this solution.
How are customer service and technical support?
I have not used technical support for the product.
Which solution did I use previously and why did I switch?
My company did use another product previous to this one but I do not know why they switched.
How was the initial setup?
The installation and setup of this solution is straightforward.
What about the implementation team?
I handled the deployment myself.
What other advice do I have?
This is a product that I would recommend to a colleague at another company.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO at Inteligencia
Quarantines suspect files without stopping everything else
Pros and Cons
- "The most valuable feature is that if the scanning does find something, it quarantines it. Then you can decide what you are going to do with it."
- "The only issue I have with McAfee is the amount of computer resources that it takes... it's definitely impacting some of the other applications that are running on a computer at the same time."
What is most valuable?
The most valuable feature is that if the scanning does find something, it quarantines it. Then you can decide what you are going to do with it. It doesn't just stop everything but actually tells you there's a quarantine, that these files are in quarantine. You have to deal with them. That's good.
If you don't keep up with updates, they pop up until you actually do something. That's a good thing because we want protection.
What needs improvement?
There are a lot of things that could be part of future editions. One would be to speed up the scanning of email. As emails come in, it takes a lot of time to scan through them, whether you're on your computer or on your phone. If it were a little quicker doing that, that would be helpful. That's not a new feature but speed always counts.
The only issue I have with McAfee is the amount of computer resources that it takes. When you're running the program it really is heavy on the computer resources. It only impacts staff productivity when it's running the updates. However, it's definitely impacting some of the other applications that are running on a computer at the same time.
What do I think about the stability of the solution?
McAfee has been around for so long. It's a stable product. They've worked out a lot of glitches, a lot of bugs. There are always new bugs introduced with any product, but it's a stable product.
What do I think about the scalability of the solution?
They do pretty well with scalability because McAfee has so many different solutions. There's a personal edition, then you have a small business edition, and there's an enterprise edition. It can be scaled, and I think they've done a good job.
How was the initial setup?
The setup is pretty good. The only problem is when you're trying to remove a certain version It takes a long time because McAfee keeps a lot of files in the source, on the computer, so you really have to make sure that you delete everything when you're removing the software. When you install a different version of McAfee you need to make sure that you grab all the files and clean the computer out.
What other advice do I have?
Using it, I haven't noticed any difference in the mean time it takes us to detect and respond to threats.
We've been happy with it so far. McAfee is a company whose products we've used quite a bit in the last 20 years so I'm familiar with them. McAfee is a very strong company; it's used around the world.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.

Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2025
Product Categories
Security Information and Event Management (SIEM)Popular Comparisons
Microsoft Sentinel
Splunk Enterprise Security
IBM Security QRadar
Elastic Security
LogRhythm SIEM
Fortinet FortiSIEM
Securonix Next-Gen SIEM
Exabeam
Stellar Cyber Open XDR
ManageEngine EventLog Analyzer
OpenText Enterprise Security Manager
Trellix Helix Connect
SolarWinds Security Event Manager
Snare
Graylog Security
Buyer's Guide
Download our free Trellix ESM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?
- RSA-EMC vs. other SIEM products?