

Trellix ESM and Sentinel are two competing security management solutions. Sentinel appears more favorable due to its feature depth and utility, though Trellix ESM offers valuable support and cost efficiency.
Features: Trellix ESM is praised for its comprehensive monitoring capabilities, detailed alert system, and cost value. Sentinel is noted for its intuitive dashboard, advanced threat detection, and threat intelligence.
Room for Improvement: Trellix ESM needs better integration options, enhanced analytics, and reduced setup time. Sentinel requires more customization features, frequent updates, and can be pricey.
Ease of Deployment and Customer Service: Trellix ESM requires longer setup but offers strong customer service. Sentinel has quicker deployment with satisfactory support. While Sentinel deploys faster, Trellix ESM's customer service remains a strength.
Pricing and ROI: Trellix ESM is cost-effective and offers significant ROI despite higher initial setup costs. Sentinel, though pricier, provides superior features and beneficial ROI that justify the expense for many users.
It's rare for me to need them unless it's an issue with licensing, and they are the best in that regard.
I would rate support for Trellix ESM 10 out of 10 because if we connect with the support in the UK, we get excellent support.
Scalability is quite easier with Trellix ESM, because all we need to do is add more receivers to it, so it can go to any point.
Price is always a consideration, so the price would be nice if it were lower.
If there is any device which is not covered, there should not be any additional charges for writing the custom parsers on that.
They nearly always bill it in dollars, so if it can be billed in our currency, that would be helpful and fixed in our currency.
Sentinel's best features include that it's a very easy product to use.
In case of other ESM solutions, there are no parsers required, and almost every device is covered within the license, so there is no hidden cost as custom parsers.
| Product | Mindshare (%) |
|---|---|
| Sentinel | 2.7% |
| Trellix ESM | 1.2% |
| Other | 96.1% |

| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 6 |
| Large Enterprise | 24 |
Sentinel is a robust platform offering seamless native integration, enhanced security through transactional data, and a user-friendly interface reminiscent of Microsoft Windows. Its capabilities in threat detection, monitoring, and business intelligence integration make it an attractive choice for organizations.
Sentinel simplifies security management with its advanced features, including the Kusto Query Language and automation abilities that reduce the complexity of coding tasks. The platform's correlation engine allows for efficient rule generation, while its threat visibility and intelligence features offer preparation against risks. Advanced hunting queries, anomaly dashboards, and scalability options enhance its utility. Users appreciate its seamless connections with Microsoft tools and ability to improve threat detection through cloud and business intelligence integration. However, enhancements could improve documentation on security aspects, simplify dashboards, and optimize drag-and-drop features. There are suggestions for better device integration, a shift to web interfaces, and improved customization options, although some users face challenges with Unix scripting.
What are the most important features of Sentinel?Sentinel finds application across sectors for logging, security event monitoring, and integration with tools like Microsoft Defender for Endpoint. Users from industries such as government and academic institutions leverage its advanced SQL query support for customized responses, enhancing security measures with AI capabilities in diverse environments.
Trellix ESM is an innovative tool designed to enhance security management through its seamless integration, user-friendly deployment, customizable dashboards, and robust threat detection capabilities.
Trellix ESM is essential for comprehensive security management, ensuring effective threat detection and analysis. It integrates seamlessly with third-party systems and provides advanced correlation and security visualization. Capable of managing logs and monitoring network traffic, it enhances security across diverse environments, making it indispensable for security operations. Despite needing improved SaaS integration, API documentation, and addressing stability issues, it remains crucial for user-friendly deployment and incident analysis. Its benefits are complemented by comprehensive reporting and real-time malware protection.
What Are Trellix ESM's Most Important Features?In diverse industries, Trellix ESM is deployed for central log management and security operations, monitoring servers, virtual machines, and hybrid-cloud environments. Companies use it for managed security services and threat detection, analyzing logs and securing data. It finds great use in monitoring network vulnerabilities and event correlation, enabling service providers and MSSPs to effectively manage endpoints and hybrid-cloud setups as well as gather logs from servers and firewalls, offering abundant transparency into security threats and network activities.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.