No more typing reviews! Try our Samantha, our new voice AI agent.

Coralogix vs Trellix ESM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Coralogix
Ranking in Security Information and Event Management (SIEM)
12th
Average Rating
8.4
Reviews Sentiment
6.3
Number of Reviews
20
Ranking in other categories
Application Performance Monitoring (APM) and Observability (14th), Log Management (11th), API Management (11th), Streaming Analytics (13th), Anomaly Detection Tools (2nd), AI Observability (8th)
Trellix ESM
Ranking in Security Information and Event Management (SIEM)
30th
Average Rating
7.4
Reviews Sentiment
7.0
Number of Reviews
38
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Coralogix is 1.1%, up from 0.3% compared to the previous year. The mindshare of Trellix ESM is 1.2%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Coralogix1.1%
Trellix ESM1.2%
Other97.7%
Security Information and Event Management (SIEM)
 

Featured Reviews

Naveenkumar Lakshman - PeerSpot reviewer
Presales Engineer at Crayon AS
Centralized monitoring has improved real-time issue tracking and reduced root cause analysis time
One of the best features that Coralogix offers is that it is integration friendly. I can seamlessly work with different cloud providers including AWS, Azure, and GCP. I can monitor Kubernetes or Docker platforms as well, and I can integrate with the DevOps chain including Jenkins and all infrastructure code, Terraform, or Ansible. Coralogix has positively impacted my organization by providing a centralized console to monitor the dashboard, giving me rich flexibility to see different sorts of data that is spread across the logs, metrics, or traces, which are the typical pillars of the observability tool. I have the interface where I can use the drag-and-drop feature, and I can create different types of charts. Mainly, I have the line charts and time series ones that I generally use in many use cases, gauges, tables, pie charts, or markdown widgets. These are the ones generically available, and I can switch between the visualization types. I am getting the underlying query in that and can import and export dashboards built upon the JSON format. I can have my own APIs integrated with my dashboards as well, such as with Terraform, which is useful for scaling across my environments. Regarding root cause analysis, mainly what I can do is correlate across all of the layers because the main logs that I work on are storage-related, including CIFS, NFS, SAN traffic, and the metrics including storage, throughput, or VM resource usage. Being able to view logs, metrics, or traces available, I get all of these in one place, and I can do root cause analysis much quicker.
MD
Senior Vice President IT at AS IT Consulting Pvt. Ltd.
Offers comprehensive report generation while maintaining ease of integration
We need to improve Trellix ESM by making sure that most of the logging devices available in the global market should be covered, and if there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that. We can add some new features regarding AI in the future for Trellix ESM, but the maturity will take a longer time. There are many false positives that happen in an environment during the first couple of months, or around six months, so the system analyst is not able to identify whether the event which has occurred is a true positive or a false positive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For now, we have not experienced any stability issues."
"I have worked on multiple logging systems, and I would say Coralogix was the best among those."
"The solution offers very good convenience filtering."
"In my experience, the best feature Coralogix offers is that the dashboard is pretty good."
"The initial setup is straightforward."
"It's been absolutely brilliant, I would say."
"In my opinion, the best feature of Coralogix is that it's convenient to look at errors."
"Numerous data monitoring tools are available, but Coralogix somehow fine-tunes our policies and effectively supports our teams."
"McAfee ESM is the perfect SIEM tool, and it provides best results based on data intake and rule based configuration."
"It enables us to detect malicious threats, issues, or vulnerabilities in our network."
"The most valuable feature is the correlation rules."
"It is easy to use and deploy. It comes with user-friendly manuals."
"It is a good central viewpoint for issues, which can then be investigated in more detail on the subnet servers and endpoints."
"Trellix ESM utilizes fewer human resources and improves security and visibility."
"It enables us to detect malicious threats, issues, or vulnerabilities in our network."
"It is user-friendly. The notification part of McAfee ESM is very easy."
 

Cons

"Coralogix's dashboard and search capabilities do not help me in any particular way."
"The documentation of the tool could be improved"
"Maybe they could make it more user-friendly."
"Coralogix should have some AI capabilities to auto-detect anomalies and provide suggestions. The increasing volume of data and the resulting bandwidth charges are concerns."
"From my experience, Coralogix has horrible Terraform providers."
"The customizable dashboards haven't really helped with my company's efficiency at all, and I think there's room for improvement."
"The features we were missing in the past were related to the way we see our metrics and aggregate our data."
"In terms of documentation, I think there can be more user-friendly documentation that stresses more on day-to-day issues."
"The support from McAfee ESM could improve. They could improve the speed."
"There's no software support from McAfee."
"I had a couple of problems collecting Windows events."
"The disk space needed for events is not clear."
"The API the product provides still needs to develop some maturity."
"Tech support is required each time there is a system update of the solution."
"Cloud integration has room for improvement because they're not full-fledged to integrate with the cloud solutions that come. They use different integration platforms to bring in data, and that needs to be improved."
"Update to user interface from version 9 is cosmetic in some aspects, and after a few clicks you are back on the old interface."
 

Pricing and Cost Advice

"We are paying roughly $5,000 a month."
"The platform has a reasonable cost. I rate the pricing a three out of ten."
"Currently, we are at a very minimal cost, which is around $400 per month since we have reduced our usage. Initially, we were at $900 per month."
"The cost of the solution is per volume of data ingested."
"When compared to IBM Security QRadar and other similar platforms, the pricing of McAfee ESM is reasonable and comparatively less expensive."
"You should buy the distributed option instead of the all-in-one for environments with more than 1000 end points."
"The product is slightly expensive."
"The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it."
"The price of McAfee ESM is higher than some of the other solutions. There are additional features that can be added at an additional fee."
"We pay for our licensing fees on a yearly basis, and there are no costs in addition to the standard licensing fees."
"Regarding pricing, Trellix ESM is not that expensive. It's less than half the cost of IBM QRadar."
"The licensing cost is based on EPS."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
893,164 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Manufacturing Company
8%
Computer Software Company
8%
Comms Service Provider
8%
Comms Service Provider
16%
Construction Company
11%
Financial Services Firm
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise7
Large Enterprise9
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise6
Large Enterprise24
 

Questions from the Community

What is your experience regarding pricing and costs for Coralogix?
My experience with pricing, setup cost, and licensing has been transparent since I am only the engineer using it.
What needs improvement with Coralogix?
Coralogix has many features, but we usually use only these two, and the syntax has not been so straightforward. It was a bit difficult to write specific queries, so I have templates of specific que...
What is your primary use case for Coralogix?
My main use case with Coralogix has been to troubleshoot, narrow down the problem, understand the logs, and identify errors. For troubleshooting or analyzing logs, we usually employ two methods. Th...
What is your experience regarding pricing and costs for McAfee ESM?
When discussing Trellix ESM pricing and licensing, if you consider some premium product, the pricing also has to be premium, however, enterprise customers who look for a premium product, alongside ...
What needs improvement with McAfee ESM?
Areas of Trellix ESM that could be improved or enhanced include checking on the clients who are still on-prem, especially banks, as most are not moving everything to the cloud due to confidentialit...
What is your primary use case for McAfee ESM?
My customer's usual use case for Trellix ESM involves one client, as most of the users have moved to ESM. Nowadays, they don't use IPS only, since McAfee IPS is standalone; they incorporate firewal...
 

Also Known As

No data available
McAfee ESM, NitroSecurity, McAfee Enterprise Security Manager
 

Overview

 

Sample Customers

Payoneer, AGS, Monday.com, Capgemini
San Francisco Police Credit Union, Wªstenrot Gruppe, Volusion, California Department of Corrections & Rehabilitation, Government of New Brunswick, State of Colorado, Macquarie Telecom, Texas Tech University Health Sciences Center, Cologne Bonn Airport
Find out what your peers are saying about Coralogix vs. Trellix ESM and other solutions. Updated: April 2026.
893,164 professionals have used our research since 2012.