Try our new research platform with insights from 80,000+ expert users

Citrix Analytics for Security [EOL] vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Citrix Analytics for Securi...
Average Rating
8.0
Number of Reviews
2
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Average Rating
8.0
Number of Reviews
204
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (19th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (14th)
 

Featured Reviews

Federico_Villanueva - PeerSpot reviewer
Jun 22, 2023
Helped the organization to provide high-security access to applications and performs well
The solution is used for platform security.  It has helped the organization to provide high-security access to applications and performs well. Auto-finance provides a set of features that we would like to get benefits from. The solution is easy to handle.  The remote access features need…
Muzzamil Hussain - PeerSpot reviewer
Aug 1, 2024
Is easy to integrate and doesn't require maintenance
One major drawback we are facing is in the area of IBM Security QRadar integration with flat file databases. IBM Security QRadar does not support flat file database integration. We are currently facing an issue with respect to the database, which you normally call a NoSQL database. There is no direct integration mechanism available with IBM Security QRadar. We have to approach IBM and generate a ticket so that they can develop a custom method for the integration. In database integration, we are facing issues with IBM Security QRadar. The solution does not support the integration of flat file databases. Certain organizations have flat file databases. IBM does not support direct integration with some databases. We had to create a plug, and we requested IBM to develop a parser, but it is taking IBM a couple of months to develop it. I think a flat-file database should be supported directly instead of developing a parser plugin. There should be a more refined threat intelligence platform, and cross-integration should be possible with locally available threat intelligence platforms.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is easy to handle."
"Very good scalability."
"The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
"The solution is easy to use, manage, and review all incidents."
"It has a good integration with the artificial intelligence engine of Watson."
"It can analyze event logs, event security, and give a good consult."
"The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well."
"It saves a lot of time. We integrate the customer's firewall with all their networking devices."
"The interface is good."
"In terms of the most valuable features, the log collections and log processing mechanisms are good. They have good dashboards."
 

Cons

"Lacks recording features."
"The remote access features need improvement."
"The user interface is a bit clunky, a bit hard to find what you need."
"The solution could improve by having more out-of-the-box use cases."
"SOAR is what is expected the most from QRadar. They have something called SOAR Resilient, and it would be great if that gets induced in SIEM. IBM QRadar (as well as McAfee ESM) should have analytics platform integration. Currently, SIEMs don't have full-fledged integration with analytics where we are able to dump our data in SIEM, and the same data can be called from different analytics applications. We should be able to bring this data to a platform like Hadoop for big data and run the analytics there. Currently, people are seeing the past data and taking some actions in the present, but when it comes to analytics, there should be futuristic data where you can predict something out of your present and past data. Apart from that, I would like to see a full-fledged ITSM tool in QRadar. It sometimes has some technical issues that need to be checked. It requires a dedicated QRadar engineer to completely manage it. It has different module sets, such as event collector and event processor, and some technical glitches come in between. It takes the log but doesn't exactly process it in the way we want."
"There was some complexity in the initial setup due to bandwidth issues."
"The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."
"There should be more opportunity for community kind of distribution where, for example, if there was a zero-day threat targeting companies."
"QVM is another instance where they need to revise the vulnerability scoring and the proper remediation details."
"Ideally we would like a mobile version so that any alert that comes in will notify us in a mobile app, or by using SMS integration."
 

Pricing and Cost Advice

"The solution is fairly priced. There are no additional costs involved, one only needs to pay the licensing cost."
"It could be cheaper, but the value itself is far more important for us than the price. Typically, our clients have yearly subscriptions."
"When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products."
"They can give us some scalability and flexibility on pricing. If its pricing can be reduced, it would help a lot of customers in bringing in a new SIEM environment and grow business in the market. If I start a license today and take around 10,000 EPS, and after a month, there is an increase in the number of clients on my platform, I can increase the number of licenses. I can add 5,000 EPS on a yearly basis."
"A good approach would be to begin with an On Cloud subscription, then later on do a more exact sizing."
"The pricing needs to be such that they are more competitive with other vendors."
"I feel that the price is reasonable but compared to other products that are on the market, such as an offering by Microsoft, it is more expensive."
"The solution's pricing is based on the EPS model."
"It is cheaper than ArcSight."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
814,485 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
No data available
Educational Organization
22%
Computer Software Company
15%
Financial Services Firm
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Citrix Analytics?
The solution is fairly priced. There are no additional costs involved, one only needs to pay the licensing cost.
What needs improvement with Citrix Analytics?
The remote access features need improvement.
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

Citrix Analytics for Performance
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

Scripps Health, Sydney University, Element Six, Lindex, SAS
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about IBM, Rapid7, Exabeam and others in User Entity Behavior Analytics (UEBA). Updated: October 2024.
814,485 professionals have used our research since 2012.