The product provides a very defined solution. It provides a complete platform for ingesting the log, doing the correlations and handling the runtime.
Vice President at a financial services firm with 10,001+ employees
Provides a complete platform for log ingestion, correlations and runtime
Pros and Cons
- "The product provides a complete platform for ingesting the log, doing the correlations and handling the runtime."
- "The solution should enhance its capabilities of UEBA and AI/ML tech modeling."
What is most valuable?
What needs improvement?
The solution should enhance its capabilities of UEBA and AI/ML tech modeling.
For how long have I used the solution?
I have been using IBM QRadar for approximately four years.
What do I think about the stability of the solution?
IBM QRadar is a very stable product.
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The product is very scalable and this can be done to a number of endpoints and towers. However, this is not very feasible, as it depends on the available in-house infrastructure.
How are customer service and support?
Technical support is very helpful. They are very knowledgeable. While the geographic location can sometimes pose a challenge, my overall experience with the technical support team has been very positive.
How was the initial setup?
The complexity of the initial setup is intermediate. It is neither straightforward nor complex but somewhere in the middle. A person with experience working in a security operation center and who is experienced with correlation rules and use cases can directly configure into the solution.
What other advice do I have?
Someone considering implementing IBM QRadar should possess a good knowledge of his own infrastructure. He should have all the documents in place. While IBM provides very good implementation support, a complete inventory and technology detail is required, in respect of how the application is flowing, how the infrastructure is connected, and the version and inventory relationship.
I rate IBM QRadar as an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Manager at a tech services company with 1,001-5,000 employees
Easy to set up but support is lacking
Pros and Cons
- "The initial setup of QRadar is not complex because we have done it before and we are used to the development. It is getting easier all the time."
- "The solution is highly used here in Pakistan and in many sectors, they could improve it by having more SIEM connectors."
What is our primary use case?
There are many use cases for this solution. One example is we are using this solution to monitor user site access to band sites.
What needs improvement?
The solution is highly used here in Pakistan and in many sectors, they could improve it by having more SIEM connectors.
For how long have I used the solution?
I have been using this solution for approximately four years.
What do I think about the stability of the solution?
The stability is good until you upgrade to a new version. You have to properly shut down services when you are doing some maintenance activities every three to four months. There might be some problems that you do not expect. We have had some complaints from users regarding operation.
How are customer service and technical support?
We have had bad experiences with support from IBM. We are not satisfied with the support and they have made me very angry. My customers have had similar experiences.
How was the initial setup?
The initial setup of QRadar is not complex because we have done it before and we are used to the development. It is getting easier all the time.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk.
Which other solutions did I evaluate?
I am evaluating Splunk.
What other advice do I have?
Here in Pakistan, this solution has already saturated the financial market.
I rate IBM QRadar a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
CTO at IT Specialist LLC
Free of charge and fully integrated with QRadar SIEM
Pros and Cons
- "The feature that I find the most useful is that IBM QRadar User Behavior Analytics is free of charge. It's a fully free product that can be installed on top of IBM QRadar SIEM."
- "The user interface and configurability of IBM QRadar User Behavior Analytics can be improved. It has a lot of pre-configured settings and not many things can be changed. It also needs more integrations. Currently, User Behavior Analytics is integrated only with IBM QRadar. It could have deeper integrations. It can also have more complicated scoring models. Currently, it has a very simple linear scoring model for users."
What is our primary use case?
User Behavior Analytics is a part of IBM QRadar. It's a kind of application that can be installed over IBM QRadar SIEM. The primary use case is to detect user behavior anomalies, and through these anomalies, detect and better understand different threats and attacks.
What is most valuable?
The feature that I find the most useful is that IBM QRadar User Behavior Analytics is free of charge. It's a fully free product that can be installed on top of IBM QRadar SIEM.
What needs improvement?
The user interface and configurability of IBM QRadar User Behavior Analytics can be improved. It has a lot of pre-configured settings and not many things can be changed.
It also needs more integrations. Currently, User Behavior Analytics is integrated only with IBM QRadar. It could have deeper integrations.
It can also have more complicated scoring models. Currently, it has a very simple linear scoring model for users.
For how long have I used the solution?
I have been using this solution for about two years. We implement this solution as well as do demonstrations. We are also using it.
What do I think about the stability of the solution?
It's quite stable.
What do I think about the scalability of the solution?
It could be quite scalable, but it is not so easy to use when you have a lot of users. Because of the user interface shortcomings, it's not so useful when you have thousands of users.
How are customer service and technical support?
The second line of support is quite inexperienced in User Behavior Analytics, and they rarely are able to help. We had several serious issues with this product, which made it impossible to use for a customer. We had to spend a lot of time in finding the right person to help us in resolving the issues.
How was the initial setup?
The initial setup is really straightforward. IBM QRadar User Behavior Analytics is very easy to deploy. Usually, if someone has already installed QRadar SIEM, then deploying User Behavior Analytics takes two to three hours.
What's my experience with pricing, setup cost, and licensing?
It's free of charge.
What other advice do I have?
I like IBM QRadar User Behavior Analytics. I would rate it an eight of ten. It still needs a lot of improvement, but its main advantage is that it's fully integrated with a SIEM system, and it's free of charge.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Useful searching capability for multiple, correlated logs
Pros and Cons
- "This solution has allowed us to correlate logs from multiple sources."
- "We would like to see better instrumentation for debugging changes in the log flow."
What is our primary use case?
We use this solution for log correlation and alerting.
How has it helped my organization?
This solution has allowed us to correlate logs from multiple sources.
What is most valuable?
The searching capability is good.
What needs improvement?
We would like to see better instrumentation for debugging changes in the log flow.
For how long have I used the solution?
We have been using this solution for four years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security and Business Development Manager at a computer software company with 51-200 employees
Enables us to ensure that the data being transferred from one company to another is done securely but it needs better cloud security
Pros and Cons
- "The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two."
- "Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them."
What is our primary use case?
Our primary use case is for the security. We use it to make sure that the data that is being transferred from one company to the other is being done securely.
How has it helped my organization?
The security has improved my organization.
What is most valuable?
The securing of data is the most important feature because nowadays as cloud has come in, it is especially challenging to secure. We are actually planning for Palo Alto to be a better option because IBM needs better security for their cloud.
What needs improvement?
If IBM provides me with a better service or better options than Palo Alto, I would remain with IBM. As for my knowledge, I recently evaluated Palo Alto that has better security features, especially for a client's email.
Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them.
If IBM could give us a complete package of on-cloud solutions, firewall, antivirus, and also mobile security, that would make it a lot better. Nowadays people are using mobile and tablets, rather than laptops or computers.
We get updates from IBM directly but then the users have to update. There are challenges where sometimes if we update the client's system, it takes a lot of time to update.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
Stability is very good. It's better than it used to be.
What do I think about the scalability of the solution?
Scalability is very good.
Everyone has used this solution for security purposes. We use it daily.
How are customer service and technical support?
The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two.
How was the initial setup?
The initial setup is fine. The moment we send the packets for an update it's easy but then there are challenges for the users. We have actually changed the hardware, so it got updated. We have to check if the problems are due to the hardware or due to the software.
The initial setup normally will take a day. it depends on the number of users. We have 300 users on the system which took around ten days.
We require five to ten staff members for deployment and maintenance.
Which other solutions did I evaluate?
Before we went with IBM, we didn't look at other solutions but recently I looked into switching to Palo Alto and also evaluated Fortinet.
What other advice do I have?
I would advise someone considering this solution to evaluate several solutions, compare them, and if there is an option for customization check with the solution provider, and then go for it.
I would rate it a seven out of ten. It's a good solution, we've used it for a long time, but then there are a few issues with security.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Application Infrastructure innovation at a financial services firm with 1,001-5,000 employees
Using it through IBM's Managed Security Services, they keep us alerted of what events are hitting, and adapting for it. I'd like to see tighter integration with other IBM products.
What is most valuable?
What is valuable is that we're using it through IBM's MSS services, and that they're doing a really good job of keeping us alerted of what events are hitting, and adapting for it.
How has it helped my organization?
It benefits us from a standpoint that we're very immature in our review of how security should be approached, and it's really helped us move up to modern awareness of what's going on on the internet.
What needs improvement?
I'd like to see, and they're getting there, is more integration; tighter integration with some of the other IBM Security products. They're moving a lot tighter to BigFix. BigFix has a lot of power in it, and MaaS360 also has a lot of power in it. I'd like to see those more tightly integrated.
What do I think about the stability of the solution?
We have not had any stability or scalability issues. We're a little concerned about the latest version and the fact that it cannot be upgraded, that it requires a clean install.
How are customer service and technical support?
We have not really used technical support, because it's a managed service, so we call the SOC and they help us. They are very helpful.
Which solution did I use previously and why did I switch?
We just really sold our CIO and CTO on the fact that we need to do better than we are, where we're at today. We had a lot of virus challenges, like most companies, and malware, so we had to figure out how to reduce that.
How was the initial setup?
I was involved in the initial setup. Well, IBM did it, since it was a managed service. It was pretty straightforward.
Which other solutions did I evaluate?
We looked at numerous other players. We chose IBM because it has a lot of power, and you can grow it as much as and however you want it to.
When I am looking for a vendor, I don't look for a VAR, I look for a partner.
What other advice do I have?
If you're going to implement it, implement it using managed services, because it's too complex of a product to try to do yourself.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Engineer (Cybersecurity) at Omgea Exim Ltd
A scalable solution with great event and flow collectors
Pros and Cons
- "The event collector, flow collector, PCAP and SOAR are valuable."
- "The solution is expensive compared to other products."
What is most valuable?
The event collector, flow collector, PCAP and SOAR are valuable.
What needs improvement?
Whenever we connect the span port, its device and health status increase the capacity level. So I suggest the mitigation of that part for IBM. Otherwise, it's a good product. We also continuously have issues with technical support because they do not have a prompt response time.
For how long have I used the solution?
We have been using IBM QRadar for the last five years.
What do I think about the stability of the solution?
I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the scalability an eight out of ten. We deploy to many customers and have completed many POCs. We have a four-person team.
How are customer service and support?
The technical support is good, but they are not prompt. I rate them a five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate the initial setup a ten out of ten. It is deployed on-premises and takes about two to three days to deploy the full environment readiness. But the device integration, rules screening and log onboarding take too long, about three to four months. The deployment was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive compared to other products, and I rate the pricing a five out of ten.
What other advice do I have?
I rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner/Reseller
Assistant Engineer at Harel Mallac Technologies Ltd
Simple to manage, reliable, and straightforward installation
Pros and Cons
- "The solution is easy to use, manage, and review all incidents."
- "If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."
What is our primary use case?
I use IBM QRadar for user behavior analytics, and mostly incident handling.
What is most valuable?
The solution is easy to use, manage, and review all incidents.
What needs improvement?
If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage.
For how long have I used the solution?
I have been using IBM QRadar for approximately four years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
We have approximately three customers and the total users that are using it would be approximately 200.
How was the initial setup?
The initial installation was straightforward, we were able to have it running in half a day.
What about the implementation team?
I do the implementation and maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option.
What other advice do I have?
I would recommend this solution to others.
I rate IBM QRadar a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?