McAfee Advanced Correlation Engine

Detect threats based on what you value

Free Trial

Sophisticated, dedicated threat detection based on risk and real-time data

Deploy McAfee Advanced Correlation Engine with McAfee Enterprise Security Manager to identify and score threat events in real time, using both rule- and risk-based logic.

Real-time tracking and alerting

Receive notifications if specific users, groups, applications, servers, or subnets are threatened.

Performance where you need it

Get the processing power required to support rich event correlation across your entire enterprise by leveraging a data engine that scales to accommodate even the largest networks.

Simplified deployment

Streamline event correlation and startup. McAfee Advanced Correlation Engine does not require rule updates or signature tuning.

Historical threat analysis

Use audit trails and historical replays to support forensics, compliance, and rule tuning. Keep a complete audit trail of risk scores to analyze threat conditions over time.

Find threats that defy rules-based detection

Real-time and historical threat detection

Get zero-day threat detection. Analyze events for immediate threat and risk detection to determine if your organization was exposed to a specific attack.

Rule-based event correlation

Correlate all logs, events, and network flows together—along with contextual information such as identity, roles, vulnerabilities, and more—to detect patterns indicative of a larger threat.

Risk score correlation without rules

In rule-less correlation systems, detection signatures are replaced with a simple, one-time configuration, providing real-time threat detection.

McAfee Connect

Maximize the value of your McAfee Enterprise Security Manager with pre-built content packs to streamline security monitoring, threat management, and incident response.

Learn More

System requirements

McAfee Advanced Correlation Engine can be deployed as a physical or virtual appliance. Specific McAfee Advanced Correlation Engine models require McAfee Enterprise Security Manager (ESM). McAfee SIEM appliance specifications and descriptions are provided for information only, subject to change without notice, and provided without warranty of any kind, expressed, or implied.

Model Number Deployment Local Storage1 CPU Cores System Requirements
ACE-VM AWS, Azure, HyperV, ESX, KVM, XEN Minimum 250 GB2 8 8 Processor Cores, 32 GB RAM
ACE-VM-4-CORE-ADDON AWS, Azure, HyperV, ESX, KVM, XEN See footnote 2 See footnote 3 Per 4 Core Add-on, 32 GB RAM

Model Number Appliance Size Local Storage1 CPU Cores System Requirements
ACE-2650 2U 12 TB 18 Requires ESM
ACE-4700 2U 5.6 TB SSD 28 Requires ESM

1Usable event and flow data storage capacity will vary by customer event types, event rates, software version, and other factors.
2It’s recommended that VMs have dedicated SSD storage to reach higher ingestion and query performance.
3Option to expand ACE-VM in 4-core increments up to 32-core maximum.

Need additional technical resources? Visit the McAfee Expert Center >

Learn more about McAfee Advanced Correlation Engine

Data Sheet

McAfee Advanced Correlation Engine

McAfee Advanced Correlation Engine identifies and scores threat events in real time using both rule- and risk-based logic.

Read Data Sheet >
White Paper

Sustainable Security Operations

Discover how to successfully adopt sustainable security operations with optimized processes and tools to compress decision-making and quickly detect, contain, and remediate attacks.

Read White Paper >

This remains the top SIEM available.
Read Product Review > SC Magazine

Have Additional Questions?

We’re here to help. Contact us to learn about implementation, pricing, technical specifications, and more.

Contact Us

Register for a Free Trial

Get started now. Test drive McAfee Advanced Correlation Engine in your environment.

Free Trial