McAfee Enterprise Security Manager

McAfee Enterprise Security Manager

McAfee Enterprise Security Manager

Overview

Recent Reviews

Manage you events

10 out of 10
May 29, 2019
McAfee Enterprise Security Manager is a powerful SIEM that offers us the comfort of being in compliance with international standards in …
Continue reading

Best SIEM

10 out of 10
May 23, 2019
McAfee Enterprise Security Manager is easy to use and to maintain, with great results. We use this SIEM because it offers threat …
Continue reading

McAfee ESM, a cautionary tale

5 out of 10
December 07, 2018
McAfee Enterprise Security Manager (previously called Nitro) is used as an enterprise SIEM across multiple sites and domains. It collects …
Continue reading

Popular Features

View all 13 features

Custom dashboards and workspaces (16)

9.4
94%

Centralized event and log data collection (9)

8.9
89%

Event and log normalization/management (16)

8.0
80%

Correlation (9)

7.0
70%

Reviewer Pros & Cons

View all pros & cons

Video Reviews

Leaving a video review helps other professionals like you evaluate products. Be the first one in your network to record a review of McAfee Enterprise Security Manager, and make your voice heard!

Pricing

View all pricing
N/A
Unavailable

What is McAfee Enterprise Security Manager?

McAfee Enterprise Security Manager is security information and event management (SIEM) software, from McAfee / Intel Security.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting / Integration Services

Would you like us to let the vendor know that you want pricing?

12 people want pricing too

Alternatives Pricing

What is Microsoft Sentinel?

Microsoft Sentinel (formerly Azure Sentinel) is designed as a birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make threat detection and response smarter and faster with artificial intelligence (AI). Eliminate…

What is IBM Security QRadar?

IBM Security QRadar is security information and event management (SIEM) Software.

Features Scorecard

Security Information and Event Management (SIEM)

8.7
87%

Product Details

What is McAfee Enterprise Security Manager?

McAfee Enterprise Security Manager is security information and event management (SIEM) software, from McAfee / Intel Security.

McAfee Enterprise Security Manager Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Comparisons

View all alternatives

Frequently Asked Questions

What is McAfee Enterprise Security Manager?

McAfee Enterprise Security Manager is security information and event management (SIEM) software, from McAfee / Intel Security.

What is McAfee Enterprise Security Manager's best feature?

Reviewers rate Integration with Identity and Access Management Tools highest, with a score of 9.5.

Who uses McAfee Enterprise Security Manager?

The most common users of McAfee Enterprise Security Manager are from Mid-sized Companies (51-1,000 employees) and the Computer & Network Security industry.

Reviews and Ratings

 (34)

Ratings

Reviews

(1-9 of 9)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is used by our entire office staff. With the help of McAfee Enterprise Security Manager, we have been able to prevent - as well as identify - security threats to our organization. Every computer in our office has McAfee Enterprise Security Manager installed and I believe our office is truly safer as a result.
  • Runs on Startup
  • User-Friendly
  • Identifies Threats
  • Customer Outreach
  • IT Support
  • Overall Aesthetic
I believe that McAfee Enterprise Security Manager is best-suited for anyone in an office setting with a computer containing sensitive information. McAfee Enterprise Security Manager is constantly working to make sure that your device is free from an threats. Our field workers, however, probably wouldn't have a need for McAfee Enterprise Security Manager. They do not use computers for work and have no sensitive information stored in a work-related cloud.
Fernanda Ministerio | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is being managed by the company's infrastructure area to improve information security processes in monitoring, investigating and minimizing problems and threats to our cloud services and systems. We use it mainly to monitor the performance of systems and applications, databases and critical network processes. The objective is to perform data analysis for patterns that may indicate a threat. This intelligence process determines priorities and alerts that reveal possible threats as early as possible.
  • Allows data analysis for patterns that may indicate a threat
  • Real-time activity visibility
  • Gives technology support intelligence by creating prioritized alerts that reveal potential threats before they happen
  • Problem reporting is integrated and simplifies analysis and compliance operations
  • Reports can be difficult to analyze
  • There is little training for technology teams to master the key features of the tools
  • Our team may have problems locating errors in our country's bases
  • Reports can be difficult to customize and adapt
It is an important tool for large companies that have their cloud infrastructure. It is very interesting for organizations that need to monitor and analyze data from a heterogeneous infrastructure. It allows you to store billions of events and flows with quick access to long-term event data storage, but this infrastructure has a processing cost.
Score 7 out of 10
Vetted Review
Verified User
Review Source
We deploy and sell the McAfee ESM (the SIEM solution) to our clients. We had it deployed in several kinds of companies, from small companies to large organizations. From private sector to public sector. McAfee is used to monitor the events (logs) of the clients and correlate them to generate alerts regarding security threats.
  • Good parsing capability
  • Enables integrations
  • The user interface is not the best, it is still based on Flash player (but they have plans to migrate to HTML5).
  • While the "user" interface is pretty straight forward, the management interface is fairly complicated.
McAfee is a good solution if you're in a medium/large company and if you're looking for a solution that can be customized and expanded. I also recommend if you have the most common log sources on your environment, since McAfee supports the major log sources (but lack a lot of small vendors).
In my opinion, I wouldn't recommend McAfee for small companies, since it's not that easy to manage and maintain.
Dealing with the McAfee support is a lottery. Sometimes you reach them and it's a really experienced engineer, but sometimes it's a person with no clue on the tool. We had few cases where our internal engineers knew more about the tool than the McAfee support. However, sometimes we get hold of some really good engineers that know the tool from inside out.
Brandon Macapelit, CISA | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is used in our company as the overall security information and event management system. It manages the whole network security inside our organization. Together with other McAfee services, it proactively monitors the behavior of all activities within the network and would prompt the security team whenever there seems to malicious things happening within the corporate network and connected devices.
  • Updated and current incident libraries.
  • It monitors the entire enterprise network proactively.
  • Its monitoring activities do not impact the network.
  • Widen more its integration capabilities, such as integration to some cloud platforms.
McAfee Enterprise Security Manager can be well suited to any type of business or architecture of enterprise IT infrastructure and network since it can be tailored fit to your organization needs. Just make sure that during the engagement with the vendor, you need to be clear with what systems you have, as McAfee tends to have some limitations on integrating with other systems, especially with some cloud platform wherein we needed to acquire other SIEM because McAfee isn't compatible with the function we need from it in our cloud system.
McAfee Enterprise Security Manager overall is a great tool. It is effective in today's setting, wherein lots of potential threats are lurking. Its operations within the network are seamless. Users won't even notice that a SIEM is working in the background. But in today's trend, most of the businesses is heading towards the migration to cloud, which McAfee should improve its integration with.
May 29, 2019

Manage you events

Score 10 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is a powerful SIEM that offers us the comfort of being in compliance with international standards in the domain of information security and helps us to assure security. Correlation of different events from different platforms is very useful and necessary. The integration with another software from McAfee is also very good (EPO, DLP).
  • Integration with other software
  • Log sources integration
  • Very user friendly interface
  • Real-time monitoring
  • Pre-defined reports
  • The system requirements are quite demanding
  • No other tool issue or operational issue was identified
Collect valuable data from hundreds of types of devices. Events correlation and offenses work very well. Notification in case of an incident also works perfectly. The configuration is easy to customize. With the Content Packs (plugins) the system is flexible for new questions or new situations. Helps in improving visibility of threat actors and helps in further prevention.
May 23, 2019

Best SIEM

Score 10 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is easy to use and to maintain, with great results. We use this SIEM because it offers threat intelligence correlation, analytics, profiling, security alerts, data presentation and compliance. Good integration with log sources, inclusive with other McAfee tools. It is easy to monitor security events and identify incidents and cyber attacks.
  • Identify brute force attaks
  • Anomalous traffic detection
  • Faster ingestion and query performance
  • Can collect large volumes of events
  • Operating in all bowsers
  • Documentation detailation
  • Simplify the process of creation core relation rules
The solution offers a lot of features. Great threat categorization and classification. Collect very quick a large volumes of events. Working in cluster is very useful. Data source onboarding reduces the time required to configure new data sources. Support includes professional services and training. Good performance and redundancy. High level of security.
Score 5 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager (previously called Nitro) is used as an enterprise SIEM across multiple sites and domains. It collects system logs and system events for correlation and alerting. It's a hub for security operations.
  • McAfee Enterprise Security Manager has a large library of pre-made correlations that reduces the amount of work needed to make it functional.
  • This is a core McAfee product that is still getting support.
  • It has a substantial amount of compatibility and integration with other products.
  • The migration off of Flash has been painful. The new interface is very difficult to work with. Even support tends to fall back to the Flash version.
  • The GUI is not intuitive under any version. Finding settings takes a significant amount of learning.
  • While the product is supported, the transitions from various directions have left the future of the product in question. It used to be the interface for IDS, but the new IDS is stand alone.
  • The way McAfee has dropped products with no warning in the past makes us skeptical of trusting any stated roadmap.
I would make a cautionary recommendation. If you're heavily invested in a McAfee product line, the McAfee Enterprise Security Manager is a natural fit and you probably already understand the risk of working with them. If you are greenfield looking for a SIEM, I would advise documenting your use cases very well, because you may find yourself doing a new implementation down the road.
Score 8 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager is used not only for its log collection capabilities but also for its advanced threat intelligence. We are using the product as part of moving into Intel's complete suite of products, where appliance integration will bring a commonality to our incident capabilities and help with faster response times and visibility.
  • Advanced Threat intelligence gives us the ability to prioritise alerts quickly and efficiently.
  • SIEM log collection allows us to integrate our other Intel products to a centralised point.
  • Physical appliances is one of the areas we have moved away from, so the ability for ESM to be available as a VDI was key.
  • If there is a requirement to integrate into other vendor products i.e. (log sharing) then this was very cumbersome.
  • Integration of vulnerability scanning that is available in other vendor products would be a good addition.
  • When integrating all of Intel's products a third party consultancy is usually required, where other vendor products can be configured without this additional cost.

McAfee Enterprise Security Manager is well placed when the environment has other Intel products. We operate McAfee Move and the two products work extremely well together. The anti-virus product can be very cumbersome if used with another SIEM solution when log collecting.

We have other areas where intel solutions are not in use and in these circumstances we used another well-known SIEM solution that had an easier implementation phase than Intel's and where remote access was challenging.

Alex Waitkus, CISSP-ISSAP, OSCP | TrustRadius Reviewer
Score 7 out of 10
Vetted Review
Verified User
Review Source
McAfee Enterprise Security Manager was used to deploy full disk encryption to sensitive end points, manage the HIPS, and end point security across the enterprise of 5000 + endpoints.
  • It is a great central management tool with great reports and dashboards.
  • It can easily show devices out of compliance.
  • ESM is easy to manage and maintain.
  • Some tools it manages lack features.
  • ESM can have some issues with upgrading.
  • MFA support is needed.
It is great for deploying and managing enterprise endpoint protection; McAfee Antivirus is still not a leader.