We use this solution for correlation, alerting, and log management.
We are integrators.
We use this solution for correlation, alerting, and log management.
We are integrators.
I like the ease of deployment.
I would like to see good analytics in future releases.
McAfee has many issues with integration. I am looking for an end-to-end integration such as EDR, and Next-Generation SOC 2.0.
I have been working with McAfee ESM for 20 years.
We are looking for horizontal and verticle expansion. McAfee has issues with scalability. Other ESM solutions, don't have the same issues.
We have not contacted technical support in quite some time. We had issues with the parsing.
The deployment is easy, but because it is a hybrid deployment which makes it complex. It is partly in the cloud and partly an on-premises deployment. The device will have to access the cloud and on-premises data.
We have an internal team to maintain this solution.
The pricing is fair.
I would recommend this solution to others who are interested in using it.
I would rate McAfee ESM a five out of ten.
We are using this solution primarily for SIEM logs.
The ease of use is the most valuable feature. Over the years I have always been using this solution and have become comfortable with it.
I have been using this solution for approximately six years.
The stability of this solution has been good.
We have never had an issue with the scalability of this solution.
The technical support could improve from McAfee.
The initial setup is difficult and could improve.
We have four engineers that do the maintenance for this solution.
My advice to those wanting to implement this solution is to do a lot of training. I think every solution is complex until you are trained in it. It is best to have some sort of previous training before you start using it.
I rate McAfee ESM a five out of ten.
We use McAfee ESM for log storage and audit purposes. Security is the base reason, and we do build content for them.
The most valuable feature in ESM is its search and reporting feature. It's really nice.
Cloud integration has room for improvement because they're not full-fledged to integrate with the cloud solutions that come. They use different integration platforms to bring in data, and that needs to be improved.
In general, every SIEM product has that sort of glitch, some partial development. It's like the enrichment of logging level understanding for a SIEM. More enrichment leads to more understanding and use case improvement. That's the gap there, and you will have technical issues already there with all of the products. They keep on fixing that. It's not a problem. They are fast on that point.
I would like to have some sort of automation module and some sort of SOAR module in the next release.
I have used McAfee ESM over the last 12 months.
Stability is good. I can say that because of the way their reporting is running right now. The reporting, dashboard, or their use cases are running in the field of security in the scope of data centers. In the scope of data centers, they're very stable. There isn't a problem with that.
Scalability is good. You can increase their EPS module as EPS is about events per second. The cost goes to the customer if it wants to charge them. It's very scalable. At any point in time, you can scale it up, and you can scale it down. That's not a problem.
The tech support is great. The engineering team helped us well at one point, and they're very good.
The initial setup is straightforward. SIEM isn't a single module component. They have different modules, like the receiver and the console, and the two modules switch. Right now, we have a complex module, and it's compatible. It's not a worry to implement it.
When it comes to infrastructure deployment, it won't take more than two weeks. The first stage would be procuring the software. If you want to deploy it in your own mediums, or if you want to bring in your own box, it could take a few more days. But once the software and the license are there in your hands, it doesn't take more than a week to get it implemented.
The price is good. It's moderate. We follow a pay-as-you-go model. There are different models available, and they can also be monthly. You can choose monthly or yearly. It's very flexible. If our existing customers exceed the current plan, you can just call McAfee and get it extended.
I would tell potential customers that ESM has a feature called all in one box. If a customer is full-fledged on an in-house data center model and has extensive products running on Windows, Linux, and Cisco and it's all sitting on-premises, this is a great option to work with all of them. They have a good set of use cases, reports, and dashboards prebuilt.
Right now, people are migrating to different solutions, and security generation is growing very vast, and it's going a step ahead. Everything is coming to the cloud. Everything is fast, and everything is a hybrid network. Because of COVID, everyone is working from home, everyone is accessing data with their own internet line, and everyone is outside the network.
McAfee will fall back a little in this scenario because the cloud integrations aren't extensively available. In this data center, most of the customers will fall back from ESM. They will come and withdraw their existing accounts, and they might move to different SIEM solutions. This is how it could be in the future. If the existing integrations come with the upgrade and if they're able to upgrade, then they might stick back with ESM.
On a scale from one to ten, I would give McAfee ESM a six.
We use it for malware detection and authentication or login failures.
It hasn't been helpful. McAfee is not investing much in this solution to improve it. It cannot cope with the advanced feature that we require, and that's the reason why we are migrating to a new solution.
It is user-friendly. The notification part of McAfee ESM is very easy.
It is not a very advanced solution, and it is for very generic use cases. It cannot cope with the advanced requirements that we're going to have. For example, for multiple authentication failures, it is still based on Windows events for detecting multiple login failures, whereas other companies are going beyond and working on implementing two-factor authentication. It is time to correlate the two-factor authentication results with authentification failures, which is not happening with McAfee ESM.
The performance of the tool should be improved because it is very slow. The data display on the console is very slow in McAfee ESM. Its data storage is still old-fashioned, and it should be improved and upgraded to the latest versions. They have to come up with some new ideas to match what other leaders in the same domain are doing. For example, in Splunk, when you search for information for the last 60 days or five months, it quickly shows the information, but that is not the case with McAfee. The results should be quicker and faster on the console.
They should integrate some additional features such as User Behavior Analytics (UBA) and automation. The threat intelligence part should also be improved on McAfee.
I have been using this solution for more than six years.
Sometimes, they have been helpful, and sometimes, they drag their feet, and it takes days to fix an issue.
I have worked on Splunk.
It is easy to implement and not complex. It can be done in a week if the information is ready. Its integration, however, can take a long time depending on the requirements.
McAfee is the right choice for a low-budget solution.
It is suitable for a medium-sized company but not for a big company. A medium-sized company that has less than a thousand data sources and doesn't need to correlate different use cases with different scenarios can go for McAfee because it is user-friendly and doesn't require many skills. McAfee will also be the right choice for a low-budget solution.
We are almost done with using this solution, and we are not going to use McAfee going forward. McAfee ESM is not able to cope with the advanced features. An army cannot do anything without good weapons in hand, and that's the issue with McAfee. They do not have good weapons to investigate.
McAfee ESM is no longer a leader in the Gartner Magic Quadrant. They should improve its performance and invest more in new features. After that, they will come back to the top position.
I would rate McAfee ESM a five out of ten.
We implement it in our hospital applications.
It has been very helpful to our company. It enables us to detect malicious threats, issues, or vulnerabilities in our network.
We acquired the IBM product because McAfee is slightly confusing to use, and it's broader.
I have used McAfee ESM for three years.
We are using Version 11.
It's scalable, and we can implement our network use cases.
We have five users in our organization.
The technical support is fast and they have been helpful in resolving our issues.
Previously, I did not use another solution. McAfee ESM is the only solution I know.
I was not a part of the installation. It was installed before I joined the company.
We had help from the McAfee teams in Singapore and India. We also had some help from Trend Micro and one colleague from our company.
We renew our license annually.
We have just acquired IBM QRadar. It is still in the implementation process. We have not used it.
Last January, our Adobe has come to its end of life, and we can not use it anymore.
I can recommend this solution.
I would rate McAfee ESM a seven out of ten.
I work with an integration company and implement tools such as McAfee ESM.
We are an MSSP for a lot of clients. We gather their logs, correlate them, create rules, and assume the role of their SOC. We have skilled operators 24/7 who take care of these clients.
The most valuable feature is the correlation rules.
This product is easy to use.
There should be support for multitenancy in the product. Because they don't have it, I think it is the biggest improvement that the vendor could make.
I have been working with McAfee ESM for approximately eight years.
This is a very scalable product.
In the on-premises deployment, we have large enterprise clients. For cloud-based deployment, our clients are small to medium-sized companies.
Although I am satisified with the technical support, there is room for improvement. The support is not as good as it could be because McAfee has moved so many times.
The initial setup is straightforward and easy to do. The deployment is very fast.
In summary, this is a good product. We have all of the functionality but it needs support for multitenancy and better support.
I would rate this solution an eight out of ten.
We are using the solution for log analyzing endpoints and investigating all types of applications, files or network devices login collection.
McAfee as a whole is a good solution.
When it came to using the solution for a larger organization, we were faced with some troubles attempting to manage the GUI functionality. During some forensic investigations, some of the information was missing from the collected data.
It cannot integrate with our Next-Generation Firewall and few applications such as Cisco ACI. For Postgre databases, the solution did not collect a lot of information from it. It has some integration problem. Companies, therefore, have to invest twice for collecting logs rather than one SIEM.
I have been using the solution for two years.
The initial setup was a bit complex.
The local partner we had was not very experienced in implementing the solution. However, the solution was first implemented in our country.
We use McAfee ESM for IT operations and a few security-related things.
It is easy to use and deploy. It comes with user-friendly manuals.
McAfee is no more providing security updates on this product, and the enhancements to this product seem to have stopped. Moreover, we don't get proper support, and we struggle to get its support.
It would be good if they can add some AI engine and out of the box use cases because it is currently limited to the same scenario and the same setup. I have done a POC for Securonix, LogRhythm. These products are much more ahead as compared to McAfee ESM. They have included multiple modules in the same solution. Correlation is very easy. If McAfee ESM can improve, especially in such implementations, then I believe it would be much better.
I have been using McAfee ESM for maybe the last six years.
It has very good stability.
So far, we haven't tried scaling. Because it is on-premises, it is almost a setup environment. We don't do any major changes on the same site because it is quite critical and gets alerts. We don't want to mess up with our configuration.
They take a long time, and the technical person who comes from support doesn't seem to be knowledgeable. When something goes wrong on the hardware or the application side, or we need some technical support in filling up use cases, it takes a long time.
We always struggle to get proper support from their technical support team. It seems that there is only one person who is handling the Middle East technical support, and when we don't get that person, we struggle a lot.
The initial setup was straightforward. There were no complications in its deployment.
Its deployment was done by an engineer in our company.
We are a security team of five members. Whoever a ticket is assigned to handles the cases.
The cost is all included. The finance department handles the financial part, and we mostly don't get involved in it.
We are quite happy with the product and its stability, but the problem is the lack of support, which is one of the major issues that we are facing. I really look forward to them providing proper technical support.
I would rate McAfee ESM a seven out of ten.
We are a service provider and we implement it for our customers, as well as use it internally.
This is a SIEM product that makes up part of our overall security solution.
Compared to other solutions, the user interface is good.
The correlations that it discovers are helpful.
The reporting is good.
The only drawback is that they don't have any packet capturing or network behavior analysis. Including network behavior analysis in the future would be a good addition.
The speed of technical support can be improved.
We have been using McAfee ESM for between five and six years.
We have had no issues with stability.
If we want to increase or expand then we just have to add devices, so it should not be a problem.
I would say that the technical support is not very prompt, but the end result is good.
We also work with Splunk and we have experience with similar solutions such as IBM QRadar.
The initial setup is pretty much straightforward. We haven't had any problem.
The pricing is good, and they are competitive compared to providers such as RSA and IBM QRadar.
The suitability of McAfee ESM is based on the requirements. If a customer is specifically looking for log and event analysis, with the correlations, then this solution is a good choice. If instead, they are looking for network behavior analytics then they should consider IBM QRader or something else.
I would rate this solution an eight out of ten.
The security can't be compromised. The security features on offer are the most valuable feature and are why it's really worth having as a product like this in our organization.
The user interface could be more user-friendly.
Technical support could be improved.
I've been using the solution for two or three years.
The solution is 100% stable. We really have had a great time working with it. It hasn't let us down.
We've been satisfied with the level of scalability the solution offers us.
We've had some issues in the past and have had their Pakistani representative here. We've also communicated with foreign branches of technical support. The solution offers okay assistance. It's not a mature solution like Fortinet or Watchguard, but it's still providing okay service. I'd say the help we've received is largely mixed. It's been 50/50 in terms of resolving our issues.
It's a fairly low-cost solution, so the pricing is pretty good.
I'd rate the solution eight out of ten. If it was more user-friendly, I'd mark it higher. Right now, technical people working on the solution don't understand what it is are trying to communicate in its tabs. As a company, you need to have a certified or experienced McAfee engineer there or on staff to guide you.
I'd recommend the product, however. It's a nice, robust product.
