What is valuable is that we're using it through IBM's MSS services, and that they're doing a really good job of keeping us alerted of what events are hitting, and adapting for it.
Application Infrastructure innovation at a financial services firm with 1,001-5,000 employees
Using it through IBM's Managed Security Services, they keep us alerted of what events are hitting, and adapting for it. I'd like to see tighter integration with other IBM products.
What is most valuable?
How has it helped my organization?
It benefits us from a standpoint that we're very immature in our review of how security should be approached, and it's really helped us move up to modern awareness of what's going on on the internet.
What needs improvement?
I'd like to see, and they're getting there, is more integration; tighter integration with some of the other IBM Security products. They're moving a lot tighter to BigFix. BigFix has a lot of power in it, and MaaS360 also has a lot of power in it. I'd like to see those more tightly integrated.
What do I think about the stability of the solution?
We have not had any stability or scalability issues. We're a little concerned about the latest version and the fact that it cannot be upgraded, that it requires a clean install.
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
How are customer service and support?
We have not really used technical support, because it's a managed service, so we call the SOC and they help us. They are very helpful.
Which solution did I use previously and why did I switch?
We just really sold our CIO and CTO on the fact that we need to do better than we are, where we're at today. We had a lot of virus challenges, like most companies, and malware, so we had to figure out how to reduce that.
How was the initial setup?
I was involved in the initial setup. Well, IBM did it, since it was a managed service. It was pretty straightforward.
Which other solutions did I evaluate?
We looked at numerous other players. We chose IBM because it has a lot of power, and you can grow it as much as and however you want it to.
When I am looking for a vendor, I don't look for a VAR, I look for a partner.
What other advice do I have?
If you're going to implement it, implement it using managed services, because it's too complex of a product to try to do yourself.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Engineer (Cybersecurity) at Omgea Exim Ltd
A scalable solution with great event and flow collectors
Pros and Cons
- "The event collector, flow collector, PCAP and SOAR are valuable."
- "The solution is expensive compared to other products."
What is most valuable?
The event collector, flow collector, PCAP and SOAR are valuable.
What needs improvement?
Whenever we connect the span port, its device and health status increase the capacity level. So I suggest the mitigation of that part for IBM. Otherwise, it's a good product. We also continuously have issues with technical support because they do not have a prompt response time.
For how long have I used the solution?
We have been using IBM QRadar for the last five years.
What do I think about the stability of the solution?
I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the scalability an eight out of ten. We deploy to many customers and have completed many POCs. We have a four-person team.
How are customer service and support?
The technical support is good, but they are not prompt. I rate them a five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate the initial setup a ten out of ten. It is deployed on-premises and takes about two to three days to deploy the full environment readiness. But the device integration, rules screening and log onboarding take too long, about three to four months. The deployment was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive compared to other products, and I rate the pricing a five out of ten.
What other advice do I have?
I rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner/Reseller
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Assistant Engineer at Harel Mallac Technologies Ltd
Simple to manage, reliable, and straightforward installation
Pros and Cons
- "The solution is easy to use, manage, and review all incidents."
- "If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."
What is our primary use case?
I use IBM QRadar for user behavior analytics, and mostly incident handling.
What is most valuable?
The solution is easy to use, manage, and review all incidents.
What needs improvement?
If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage.
For how long have I used the solution?
I have been using IBM QRadar for approximately four years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
We have approximately three customers and the total users that are using it would be approximately 200.
How was the initial setup?
The initial installation was straightforward, we were able to have it running in half a day.
What about the implementation team?
I do the implementation and maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option.
What other advice do I have?
I would recommend this solution to others.
I rate IBM QRadar a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Solution Security Architect at PT. Sinergy Informasi Pratama
Provides great analysis of event logs, event security; easily manageable with one monitor
Pros and Cons
- "It can analyze event logs, event security, and give a good consult."
- "Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."
What is our primary use case?
This is a solution you use when you have many security products that you want to manage in one monitor, one analytic. We are partners with IBM and provide implementation services to our customers. I'm a solution security architect.
What is most valuable?
The most valuable feature is that it can analyze event logs, event security, and give a good consult. When you have SIEM, you can easily manage with one single monitor. QRadar can do a lot of analyses of every security product and will let us know what needs to be done to the log. Sometimes we need security orchestration automated response to support the SOC team.
What needs improvement?
The concern with QRadar is that there are so many features in the dashboard, too many menus that require going to two or three sub-monitors to enter the QRadar. The user interface is good but there are so many features that can be confusing for the administrator. It could be simplified.
For how long have I used the solution?
I've been using this solution for a year.
What do I think about the stability of the solution?
I think that QRadar is stable, but I've never worked with other solutions in this area and I have nothing to compare it to. It has dedicated machines and offers great performance.
What do I think about the scalability of the solution?
The scalability is easy but it comes at a high price.
How are customer service and support?
IBM in Indonesia provides great support.
How was the initial setup?
The initial setup is complex if the data set is large. It really depends on that. We provide maintenance services to our clients so that if they have any trouble, we assist with troubleshooting.
What's my experience with pricing, setup cost, and licensing?
SIEM is quite a pricey solution so we only offer it to enterprise companies that can pay the fees. For smaller companies, it's an extremely expensive product.
What other advice do I have?
I recommend this solution because I think they provide great support from the sales and technical perspective.
I rate the solution nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cybersecurity Engineer Consultant at a tech services company with 501-1,000 employees
Its correlation and the parsing features result in good scalability and performance
Pros and Cons
- "The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
- "The weak signal detection with QRadar needs improvement. You can detect what you know, but what is unknown to the rule engine can't be detected."
What is our primary use case?
My use case is the deployment of an X-Force successful connection with a botnet and malware website. An X-Force feed is free with QRadar.
I have been using the product for three years now. I used it for six month at an internship to PoC some different SIEM and for two and a half years as an administrator. Now, I am using it as an architect.
How has it helped my organization?
Previously, we had to do a lot of debugging when we wanted to change our firewall policy to find out which rule was blocking things, etc. With Qradar, when you integrate the logs of the firewall, you have with two clicks, the info in real-time.
What is most valuable?
The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance.
What needs improvement?
The weak signal detection with QRadar needs improvement. You can detect what you know, but what is unknown to the rule engine can't be detected, similar to a base rule of SIEM.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
Sometimes, but not from the system itself, but from the amount of logs it has received.
What do I think about the scalability of the solution?
Not at all.
How are customer service and technical support?
Technical support is good when they using WebEx. By portal, they are slow and inefficient.
Which solution did I use previously and why did I switch?
My service since the beginning has been to only sell and manage QRadar.
How was the initial setup?
It is very easy to deploy. It is not a user-friendly way to deploy, but for IT guys who have the skills of Linux servers, etc., it is easy.
What's my experience with pricing, setup cost, and licensing?
Think what you will integrate into QRadar. It is a SIEM. You need to send it logs, but not everything.
Pricing (based on EPS) will be more accurate.
Which other solutions did I evaluate?
I had the chance to test some other products, and there is a lot of them on the market. However, when you have to deploy and manage it, not just demo it, it is a total different story.
QRadar is not perfect, but I have had the chance to manage ArcSight, Sumo Logic, Unomaly, and RSA for some specific features, and comparatively, QRadar is good
What other advice do I have?
Think scalability and make sure your product can be integrate into QRadar.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Network and Security Technical Team Leader at a wholesaler/distributor with 201-500 employees
A good integration with the artificial intelligence engine of Watson
Pros and Cons
- "It does good correlation for events. It does good general analysis, and it has good apps as well."
- "It has a good integration with the artificial intelligence engine of Watson."
- "IBM needs to invest more into the collaboration with other vendors."
- "The implementation and configuration are not easy."
What is our primary use case?
We work with it in the banking sector. We had torrent limitations and big banks could join them. It has performed well. However, the limitation is not easy, so the product is not easy.
You cannot get the real value of the product unless you combine it with the other products from IBM, like BigFix, the full integration of Vulnerability Management, and so on.
How has it helped my organization?
The product is great. It does good correlation for events. It does good general analysis, and it has good apps as well.
What is most valuable?
- The artificial intelligence ease of integration; it has a good integration with the artificial intelligence engine of Watson.
- There is good collaboration between IBM Cloud and all IBM customers.
What needs improvement?
The implementation and configuration are not easy.
We would like to see user behavior analysis in the next release. IBM claims they have this feature, but I do not see it as mature as in Splunk.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability of the solution is great.
What do I think about the scalability of the solution?
Technically, there are no scalability issues.
How is customer service and technical support?
Support is good. The technical engineers seem they know what they are doing. Though, the escalation response is bad. An escalation takes time, because the response time is not as fast as it should be.
How was the initial setup?
The implementation is complex.
What's my experience with pricing, setup cost, and licensing?
It is expensive. It is not a product that I can provide for SMBs. It is a program that I can only provide for really large enterprises.
Also, the maintenance costs are high.
What other advice do I have?
IBM needs to invest more into the collaboration with other vendors.
If you want to go to IBM, do not just go for QRadar. You need QRadar and all the products that surround QRadar, especially BigFix, because the product is ten times stronger with it.
Most important criteria when selecting a vendor:
- The technical features of the solution.
- The people in my region at the vendor.
- The perspective of the project manager on the customer side.
- Data involved and time of the implementation.
- The needs of the customer.
- The cost of the project.
- Training involved.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Cyber Security Advisor / CISO / Healthcare Security Pro at OMC SYSTEMS LLC
The dashboards give us an overview of traffic flow and pinpoint configuration issues.
Valuable Features
I find that the dashboards are the most helpful to get an overview of traffic flow and issues.
Improvements to My Organization
We find that reviewing Q1 Radar is very helpful to pinpoint configuration issues, as well as go back and find traffic flows from comprimised hosts.
Deployment Issues
No.
Stability Issues
None.
Scalability Issues
N/A
Customer Service and Technical Support
Customer Service:
N/A
Technical Support:N/A
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solutions Architect at a tech services company with 51-200 employees
Excellent visibility, good notifications, and helpful support
Pros and Cons
- "The visibility it gives you into your infrastructure has been great."
- "The AI engine could be smarter."
What is our primary use case?
We are using it for visibility and compliance.
What is most valuable?
The visibility it gives you into your infrastructure has been great.
The notifications it provides offer valuable information when something is happening in your blind spot.
What needs improvement?
The AI engine could be smarter.
It is a bit expensive.
For how long have I used the solution?
I've used the solution for about three years.
What do I think about the stability of the solution?
The solution is stable. I'd rate it five out of five. It's very reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution scales well, and it's easy to do. I'd rate it five out of five in terms of the ease of scalability.
We have a lot of users on the solution currently. We have customers on the product as well. There are likely more than 500 users inside and outside the organization.
How are customer service and support?
Support has been helpful and responsive. There may sometimes be a delay. However, they do get you the information you need.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've only ever used IBM.
How was the initial setup?
The setup is a bit complex. I'd rate it two out of five in terms of ease of deployment. It took us a week to get everything up and running.
We had two engineers working on deployment and maintenance.
What about the implementation team?
We handled the solution in-house. We did not need outside assistance.
What was our ROI?
We've seen a good ROI. I'd give it a five out of five.
What's my experience with pricing, setup cost, and licensing?
It's a bit pricey as a product. I'd rate it a two out of five, with five being the most affordable. It depends on what you buy; the longer you use it, the better the cost. It's an all-inclusive license. You don't need to pay for extra features.
Which other solutions did I evaluate?
We did look at a few other options.
What other advice do I have?
We use the solution inside our organization. Our clients use it too. We are a premium partner in our region.
We're using the latest version of the solution.
I'd rate the solution nine out of ten. It really provides good visibility.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Premium Partners
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Splunk Enterprise Security
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Cortex XSIAM
USM Anywhere
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?