IBM Resilient is valued for its simplicity and integration with IBM QRadar, offering flexibility and a user-friendly interface. It excels in incident response monitoring with robust security features. Users appreciate its comprehensive stack, mature architecture, and scalability. Dynamic playbooks, rapid action, and effective user behavior analytics enhance its appeal. Its incident response capabilities, threat intelligence, and container options are highly beneficial. Integration with IBM SIM and effective user blocking during attacks are key highlights.
- "The integration with IBM SIM and the ability to block users during brute force attacks are particularly effective."
- "It is a stable solution...It is a scalable solution."
- "The initial setup of IBM Resilient is not that complex since my company already has a support license that we use internally. In general, the product's deployment phase is not that complex."
IBM Resilient requires enhanced integration with third-party tools and improved pricing and technical support. Users report complexity in initial setup and configuration, frequent compatibility issues, and limitations in device integration. More built-in automation and AI features would benefit users. The need for better documentation and user guidance, especially on custom playbooks and licensing, is evident. The lack of flexibility and challenges with data format handling suggest more development and research are necessary.
- "Integration with some devices, including Cisco PowerPower and certain antivirus products, has limitations."
- "The response time of the support is an area of concern where improvements are required."
- "There are shortcomings with IBM Resilient's technical support team that can be considered for improvement in the future."