

Trellix ESM and Fortinet FortiSIEM are prominent players in the SIEM market. Based on user reviews, Fortinet FortiSIEM appears to have the upper hand in features, though Trellix ESM offers stronger support and pricing advantages.
Features: Users praise Trellix ESM for its robust analytics, adaptability to diverse IT environments, and efficient threat detection. Fortinet FortiSIEM is noted for comprehensive incident management features, seamless integration capabilities, and advanced correlation engine. Fortinet FortiSIEM's extensive feature set gives it an edge in this category.
Room for Improvement: Trellix ESM users highlight needs for enhanced reporting, more intuitive configuration options, and improved UI experience. Fortinet FortiSIEM feedback points to complexity in setup, a steeper learning curve, and occasional performance lags. Trellix ESM needs user-friendliness enhancements, while Fortinet FortiSIEM requires simplification in deployment.
Ease of Deployment and Customer Service: Trellix ESM is favored for its quicker deployment times and responsive customer support. Fortinet FortiSIEM, while powerful, has a lengthier and more complex setup process but compensates with detailed documentation and training resources. Trellix ESM stands out for better deployment ease and customer service.
Pricing and ROI: Trellix ESM is often seen as more cost-effective with favorable ROI, thanks to lower setup costs and ongoing expenses. Fortinet FortiSIEM, although pricier, justifies its cost through extensive features and longer-term ROI benefits. Users generally find Trellix ESM more budget-friendly, whereas Fortinet FortiSIEM aligns with organizations seeking comprehensive feature sets despite higher costs.
There is a knowledgeable, though small, team of support engineers around the world.
Local tech support is available, however, for more critical or technical issues, we depend on the OEM directly, especially when it comes to on-prem solutions.
They take some time to respond because they need logs and investigations, which delays the response time.
I would rate support for Trellix ESM 10 out of 10 because if we connect with the support in the UK, we get excellent support.
It's rare for me to need them unless it's an issue with licensing, and they are the best in that regard.
Fortinet FortiSIEM is highly scalable.
At any point in time, when network devices increase or there is a change in the infrastructure, we can add more workers and collectors to expand our infrastructure setup.
Fortinet FortiSIEM is easy to scale.
Scalability is quite easier with Trellix ESM, because all we need to do is add more receivers to it, so it can go to any point.
It stabilizes itself in an appropriate time, so its uptime is good.
Some stability issues occur, but Fortinet's technical support team provides assistance.
These issues may cause unusual errors and user interface issues.
Fortinet FortiSIEM should broaden its remediation part to include more features for incident management.
Enhancing the completeness of its APIs could aid in better external integrations.
Recently, they revised it to a subscription-based, all-inclusive license.
If there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that.
Windows agent licenses cost around 3,000 Rupees per device per year.
Setting it up for oneself as an enterprise-licensed product can be quite expensive.
The revised model is subscription-based and more flexible.
It provides extensive logging and record-keeping for internal networks, cloud applications, and services as well as perimeter physical network security.
I find the real-time monitoring and correlation capabilities effective for security alerts.
In case of other ESM solutions, there are no parsers required, and almost every device is covered within the license, so there is no hidden cost as custom parsers.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiSIEM | 2.3% |
| Trellix ESM | 1.2% |
| Other | 96.5% |
| Company Size | Count |
|---|---|
| Small Business | 34 |
| Midsize Enterprise | 22 |
| Large Enterprise | 24 |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 6 |
| Large Enterprise | 24 |
Fortinet FortiSIEM offers robust features like automation, real-time monitoring, and scalable log correlation. It integrates SOC and NOC, enhancing security by seamlessly managing data. A preferred choice for threat management, its comprehensive reports and competitive pricing add value.
Fortinet FortiSIEM serves as a comprehensive platform for security monitoring, threat detection, and incident management. It streamlines operations by integrating seamlessly with Fortinet and third-party tools, offering dynamic service discovery and user-friendly analytics. Leveraging its stable infrastructure, organizations conduct log analysis and behavioral monitoring across networks and applications. It supports compliance reporting and enhances security environments through integration with firewalls and security devices. Its cloud and on-premise options cater to regulatory and operational needs, while multitenant capabilities enable managed security service providers to extend robust security services. Users have highlighted areas for improvement in API integration, data retrieval speed, resource consumption, automation, and reporting flexibility.
What are the key features of Fortinet FortiSIEM?In healthcare, Fortinet FortiSIEM ensures compliance and secure health data management. Financial institutions utilize it for real-time monitoring and fraud detection, while educational sectors deploy for network security and data integrity. Service providers leverage its multitenant features for expansive client management.
Trellix ESM is an innovative tool designed to enhance security management through its seamless integration, user-friendly deployment, customizable dashboards, and robust threat detection capabilities.
Trellix ESM is essential for comprehensive security management, ensuring effective threat detection and analysis. It integrates seamlessly with third-party systems and provides advanced correlation and security visualization. Capable of managing logs and monitoring network traffic, it enhances security across diverse environments, making it indispensable for security operations. Despite needing improved SaaS integration, API documentation, and addressing stability issues, it remains crucial for user-friendly deployment and incident analysis. Its benefits are complemented by comprehensive reporting and real-time malware protection.
What Are Trellix ESM's Most Important Features?In diverse industries, Trellix ESM is deployed for central log management and security operations, monitoring servers, virtual machines, and hybrid-cloud environments. Companies use it for managed security services and threat detection, analyzing logs and securing data. It finds great use in monitoring network vulnerabilities and event correlation, enabling service providers and MSSPs to effectively manage endpoints and hybrid-cloud setups as well as gather logs from servers and firewalls, offering abundant transparency into security threats and network activities.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.