It has improved our ability to research and detect anomalous behavior and activity within our network. It has really helped us in our ability to research active threats. We saw the threats when we implemented it, and we saw that we had all kinds of deficiencies in our network infrastructure that we were unaware of previously.
IT Director at MyEyeDr.
It summarizes all the other security products.
How has it helped my organization?
What is most valuable?
It has the ability to summarize all the other security products and give us a one-stop-shop dashboard.
IBM has added a new UBA (User Behavior Analytics) app to QRadar that uses the cognitive abilities of Watson to detect and prioritize user activity and risks on the network. It analyzes log activity already recorded so it can begin providing insights quickly after installation.
What needs improvement?
I'm anxious to see the Watson integration. We just finished an upgrade of our appliance so that we can be eligible to do the Watson integration. I'm anxious to see how that works.
What do I think about the stability of the solution?
It works well. We've been using it for a year now. It's helped us greatly to cut down on the time it takes to research a problem or to actually find the problem.
Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the scalability of the solution?
In terms of scalability, so far, so good. What we've purchased so far is well with the infrastructure that we have. I know there are options to buy additional components should I need them.
How are customer service and support?
We use a business partner for implementation and support. They are always involved with it. They are not IBM.
Which solution did I use previously and why did I switch?
We weren't previously using a different solution. As security becomes more and more important, we added different security components from IBM, with QRadar being the last one. We needed some way to see all the data, all the information, and get it together in one single source of truth.
How was the initial setup?
I was involved as far as picking and approving the solution. I was not involved in the installation.
What other advice do I have?
We try to do everything all at once.
Find the right partner to help you do the implementation.
When picking a vendor, we look for the support, the ease of the installation, and the future of the product.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Cyber Security at a insurance company with 10,001+ employees
The ability to correlate large amounts of data into rules that provide real-time alerting is valuable.
What is most valuable?
The ability to correlate large amounts of data into rules that provide real-time alerting is the most valuable feature.
How has it helped my organization?
It has provided us with quicker mitigation to threats. We used to do everything manually, so it automated a lot of workflows that in the past, we weren't able to do from an automation perspective.
What needs improvement?
We are still two versions behind, so I don't know specifically what could be improved. I've told all the executives and staff we met at a recent IBM conference that integration with other solutions is important so that we don't have to do a bunch of different things to consider.
What do I think about the stability of the solution?
We are the largest user of QRadar, so the stability is average. There are several vulnerabilities that IBM is working with us on. They don't have a test environment big enough to imitate the stress we put on it. Stability is probably OK for the normal customers, but we break everybody's apps just because of our size.
What do I think about the scalability of the solution?
There are some vulnerabilities that may be further exasperated at our size, so they are trying to fix some of those issues and bring stability, but it's really product issues that don't scale right now.
Which solution did I use previously and why did I switch?
It was functionality which drove us to change. QRadar had better functionality than what we were getting out of the previous solution. Scale was probably also a factor at that time. It was right after IBM bought Q1 Labs, so it was an industry leader along with some others. We did an evaluation and QRadar came out on top.
How was the initial setup?
Initial setup was pretty straightforward. It's a complex solution, but it was straightforward for a large environment.
Which other solutions did I evaluate?
The two big options we evaluated would be IBM and HP. What we understood was that QRadar would be a more simplistic implementation, taking up less time.
What other advice do I have?
Make sure you really understand all the requirements before you implement. I think the group that did this implementation didn't necessarily understand fully what we were going to use it for, so it was maybe designed for smaller things. So, you should really understand the requirements prior to stepping into it.
If QRadar is going to be a central sort of hub for IBM's security solutions, make sure that the other tools integrate very easily into it. That would probably be the biggest task.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Security Consultant at a tech services company with 11-50 employees
Some of the valuable features are vulnerability management, cognitive security, and risk management.
What is most valuable?
The SIEM features are what sell this product. Lately, it has been heavily expanded with others. For example vulnerability management, risk management, incident forensics, cognitive security, and user behavior analytics.
Basic SIEM features include log management, reporting, and correlations and alerting. All SIEM products started with those.
Modern SIEM solutions are expanded with additional components that i mentioned.
So today, you will rarely see RFP for only SIEM. It will usually include other requirements. To answer this, vendors started adding additional valuable features.
Lately, Qradar also opened their APIs to the development community, in order to confront Splunk, and that resulted in a large number of additional functionalities in the form of add-ons (Qradar apps).
How has it helped my organization?
We are an IBM business partner. In short, this tool helps our clients have visibility into the IT infrastructure, events, and network traffic.
What needs improvement?
Dashboards!!! Dashboards are one of the most frequent complaints I receive from customers. Customers are complaining about the limited set of graphs and the inability to change colors. Although this might seem trivial, a large number of the same complaints probably mean something.
A lot of bugs are reported for dashboard items. Also, I personally have found that it does not work as indicated by the documentation. The same methodology is used to produce different results for similar searches. Also, customers would like to see near real-time data on the dashboard, which is very hard to achieve according to the mentioned problems.
For how long have I used the solution?
I have been using this since 2011, even before the IBM acquisition.
What do I think about the stability of the solution?
We have not had stability issues.
What do I think about the scalability of the solution?
High availability deployments have serious upgrade issues.
How are customer service and technical support?
Support is great, but sometimes they are a little slow.
Which solution did I use previously and why did I switch?
We did not have any previous solution. We have used only QRadar for the last six years. Even at that time, it was leader in Gartner and so it remained. It is very user friendly.
How was the initial setup?
The initial setup was very easy. Integrating the infrastructure configuration is the biggest problem for any SIEM project.
What's my experience with pricing, setup cost, and licensing?
Licensing was simplified two months ago. I don’t have insight into pricing. But as with any software, the price can probably change depending on your negotiation skills :)
Which other solutions did I evaluate?
We didn’t evaluate other solutions. However, in my career, I saw Splunk, RSA, ArcSight, and AlienVault.
What other advice do I have?
If you are a security officer who wants to protect his job, go for Splunk :) If you are a customer who wants to have an easy tool and save time and resources, definitely go for QRadar.
Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a business partner.
Security Manager at a pharma/biotech company with 1,001-5,000 employees
The search capability and data consolidation are some of the key features. I want to see a three-dimensional perspective of the data.
What is most valuable?
The search capability (I've used other solutions) and data consolidation are some of the key features.
How has it helped my organization?
For this organization, it was the first log management solution. So, it definitely gave us the ability to search through the data when we had events. We could search based on the identity of the person, or the machine, or the IP address. We could do a lot of different searches. We could also do payload searches, and depending on how much capacity you have, you can do quite a lot with it.
What needs improvement?
I want to see a three-dimensional perspective of the data. I don't want to see just an event perspective of the data. I want to be able to identify a user, and within clicks, know all the activity of that user. I don't want to see it in events. I want to see it in relevant information.
There needs a little bit more investment into enhancing the user interface. That is the main thing; making it represent an actual incident response state-of-mind, similar to how you would troubleshoot an incident. That is the main issue. It was a major position by IBM when they bought it. But we see a lot of things being done around the Cognitive side, around the Watson side. But what we're not seeing the growth in, is the actual tools interface and usability. And that's what we wanted to see. We wanted to be able to see seamless identification of log sources, seamless categorization and normalizing of log sources, seamless alerts. In all those things, for the solution to mature, it has to be able to take data and make sense of it by itself, without a lot of input. And those are the areas that they can really improve it.
What do I think about the stability of the solution?
It's been stable. Stability hasn't been a problem, as long as you have enough capacity. It's all about sizing it right for the size of your environment. We do drop packets every day. So depending on how our log volume increases or reduces, you see the impact on the packets being dropped.
How are customer service and technical support?
We've used technical support and it hasn't been great. It didn't seem like we could get the answers we needed without having to use professional services. For a solution like this, little things like how to tune it, how to upgrade it; there are things that as a customer we don't feel the need to use professional services for. We want to be able to just find a document on how to upgrade, and that has been difficult to find.
Which solution did I use previously and why did I switch?
We didn't have a previous solution. We kind of inherited it as part of another acquisition from IBM, and then we scaled it up to meet our capacity.
How was the initial setup?
We got the basic functionality working, which is not difficult. It's getting the full value out of the solution, which is harder.
What other advice do I have?
From an analytics perspective, it's a good tool. But you have to have the resources to own it. It's not only about buying it. It's not only about capacity, but somebody has to care and feed it. It's not one of those things that you can put it in, walk away and just consume the data. If you don't take care of it and feed it, you won't get what you need out of it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Student at Baku Higher Oil School
Scalable, easy to use, and has a visualization feature that shows spikes in the system
Pros and Cons
- "The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log."
- "IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others."
What is our primary use case?
We are using IBM QRadar for log reviews, particularly logs that come and go from the IPS, firewall, etc.
We have different dashboards for different technologies such as our firewall, IPS, and domains for our main website, so we use IBM QRadar to observe the logs from our website, and we try to make internal and external connections for better domain security.
What is most valuable?
The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log.
What needs improvement?
IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others.
There isn't any additional feature I'd like added to IBM QRadar at this point because it's sufficient for visualizing the logs.
For how long have I used the solution?
I've been with the company for one and a half months, and I've been using IBM QRadar almost daily, but the solution was deployed five or six months ago.
What do I think about the stability of the solution?
IBM QRadar is a stable solution.
What do I think about the scalability of the solution?
IBM QRadar is a scalable solution. My company currently has seven to eight different accounts on IBM QRadar, so it's a scalable technology. It has no problems with scalability.
How are customer service and support?
I didn't have any problems with IBM QRadar, so I never contacted the technical support team.
Which solution did I use previously and why did I switch?
I'm assuming that the main reason my company chose IBM QRadar is that IBM is one of the biggest tech companies in the world, so IBM products would be more secure and more reliable than other solutions.
How was the initial setup?
As I didn't set up or deploy IBM QRadar, I have no information on whether it was easy or complex to set up.
What's my experience with pricing, setup cost, and licensing?
I have no information about the licensing costs of IBM QRadar, and whether or not it requires a license.
What other advice do I have?
I'm an intern at one of the biggest telecommunication companies, and my company uses IBM QRadar.
My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use. The solution also has many dashboards, and you don't have to write any code or write different scripts to get the information you need. You can do it from the UI of IBM QRadar. The only room for improvement in the solution is that it doesn't support newer technologies, and it's late when it comes to updates.
I'm rating IBM QRadar nine out of ten because my experience with it has been excellent. The only downside to it is that IBM is late with adding new features or supporting new technologies compared to its competitors.
My company is an IBM QRadar customer.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IM Operations Manager at a tech services company with 1,001-5,000 employees
Simplified event quantity, scalable, but source data reports needed
Pros and Cons
- "IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through."
- "IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features."
What is most valuable?
IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through.
What needs improvement?
IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features.
For how long have I used the solution?
I have been using IBM QRadar for approximately 10 years.
What do I think about the stability of the solution?
The stability of IBM Qradar is good.
What do I think about the scalability of the solution?
IBM Qradar is a scalable solution.
How are customer service and support?
The technical support from IBM Qradar could improve.
I rate the support from IBM Qradar a two out of ten.
How was the initial setup?
The initial setup of IBM Qradar is difficult, you need to know what you are doing to be able to complete the task. It is not easy.
We used three to four specialists to do the implementation depending on how many integration levels you're going to have. If you're managing the flows and going to be managing applications, logical access, patch management, vulnerability management then it can take more time and more people. It depends on the scale that you want to integrate.
IBM Qradar doesn't come ready for plug and play, for your APIs, integration, and all the other elements you will need a person that knows how to do the IBM QRadar setup. From that perspective, you need to make sure that integration points to the license keys, for validation, and that can be a different challenge if it doesn't work.
What other advice do I have?
My advice to others is they have to have IBM Qradar set for purpose and it depends on the role that you see your SIEM solution playing in the company. If you're offering it as a service to other companies, or you're an IT service provider or security solution provider, then yes, you probably need an enterprise base that is scalable but not with smaller enterprises.
I do think the IoT component of IBM Qradar is lacking. IBM tried and IoT is not specifically aimed at only cameras or what I call physical access points, integration into what I call scale technology. They are areas that would depend on each business to map out what the requirements are. This is not a McAfee endpoint or a Symantec endpoint device that gives you an alert.
There is more competition and innovative application development in this area we've seen in the last few years.
I rate IBM Qradar a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Head Of Sales at Cascade Solutions Inc
Modular product that sets up a clear roadmap
Pros and Cons
- "Flexible and valuable product that is modular, so you can easily set up a roadmap for your clients."
- "Each module requires a separate license and a separate cost."
What is most valuable?
From a sales perspective, IBM QRadar is very competitive when it comes to prices. It's a flexible and valuable product. It has a good edge in the region and good references as well. You can easily capitalize and upsell on whatever you sold previously. It's a modular product, so you can set up a roadmap and plan for your customers. This is one of the main advantages of QRadar.
What needs improvement?
Right now, there are a lot of solutions in the market that consider themselves next-gen SIEM solutions, like AzureVM. IBM QRadar can be revised considering the competition, market segment, references, and the maintenance of the landscape.
Some modules can be shared as embedded within the same solution because this would be a compelling edge versus others. When it comes to other products, like LogRhythm for example, they can consider the SOAR and the threat Intel embedded with the SIEM Solution licenses. However, when it comes to IBM, they consider each module as a separate license with a separate cost. So it doesn't make sense to compete if the customer isn't convinced with IBM, because you'd have tough competition when it comes to financials.
For how long have I used the solution?
I have been using QRadar for more than five to six years.
What do I think about the stability of the solution?
IBM QRadar is a stable product.
What other advice do I have?
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
AVP - Cyber Secuirty at Cloud4C Services
A stable solution which allows a single system to be onboarded for all 200 existing customers for monitoring purposes.
Pros and Cons
- "No doubt about it, the solution is extremely stable."
- "The implementation of the solution's technology needs to be simplified."
What is our primary use case?
We are using the current version.
What is most valuable?
The solution supports MSSP models, which most service providers have. This means that a single system can be onboarded for all 200 existing customers for monitoring purposes.
What needs improvement?
The implementation of the solution's technology needs to be simplified. It is overly complex.
The integration also must be simplified.
The licensing is also overly complex, as there is a need to buy the work load performance monitoring separately. These are the different modules we need to buy.
IBM does not provide a combined, combo suitor solution which the customer can easily look at. The multiple functionalities are segmented and do not allow for an idea which is complete. It makes it difficult for us to do a realistic comparison with other products. I hope that others follow suit.
For how long have I used the solution?
We have been using IBM QRadar for almost eight-and-a-half years.
What do I think about the stability of the solution?
No doubt about it, the solution is extremely stable.
What do I think about the scalability of the solution?
The solution needs to be redesigned to allow for scalability or for extending it to the existing one. There is a need to do long-term planning and migration from an existing to a new one and this cannot be easily accomplished. Storage cannot be added to the installation. One must completely migrate to the new storage to add additional terabytes.
As such, the solution is not quite scalable. The scalability exists, but it requires migration.
How are customer service and technical support?
We are very happy with the technical support.
How was the initial setup?
The initial setup was extremely complex.
What about the implementation team?
We made use of an integrator.
What other advice do I have?
We have nearly two hundred customers making use of the solution.
We have direct contact with Ingram Micro or have a service partner relationship with it, but work directly with IBM as our ISP.
We are a managed security service provider and wholesale customer of IBM QRadar
We buy a bulk license from IBM QRadar and host around 200 plus customers in a single integration so that all the customer events will be integrated in one solution. We are not integrators and do not resell their services.
As such, we don't buy the license or sell the tools to others. We will buy a license, inclusive of the services, host it with our private cloud and provide services to the end clients.
Our customer base of IBM users is limited. When it comes to a security operations center team, IBM will be looked to for providing security monitoring on an ongoing basis. We must see that it is working as it should be.
I would recommend this solution to others.
I rate IBM QRadar as an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
USM Anywhere
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
My QRadar Interview at IBM InterConnect 2017