We are a reseller of this solution. We have numerous uses cases all dependant on the needs of our customers.
Cyber Security Specialist at AEC
Alerts and correlates the aggregate events or offenses we receive through all the applications we use
Pros and Cons
- "IBM QRadar has improved my organization by introducing many functions. It collects logs from all of our systems in the organization and has functioned very well. It alerts and correlates the aggregate events or offenses we receive through all the applications we use."
- "There is one problem with QRadar in regards to the add-on apps. The apps can be frustrating. For example, when I add a big app like one of the add-ons for resiliency, add-on applications for QRadar, these applications require different hardware to implement and to deploy. The resiliency connector because there's a considerable amount of data scanning, operates for these apps correctly."
What is our primary use case?
How has it helped my organization?
IBM QRadar has improved my organization by introducing many functions. It collects logs from all of our systems in the organization and has functioned very well. It alerts and correlates the aggregate events or offenses we receive through all the applications we use.
With other solutions, you collect the logs from different sources but you still have to finetune it, and you still have to match them a lot of the time to figure out the correct association to sort out the false positives. QRadar is much easier to use and detect false positives. It can do it by itself, and it allows you to finetune the filtering and check the false positives. There is some backend that protects but it's the best among all in the market.
What needs improvement?
There is one problem with QRadar in regards to the add-on apps. The apps can be frustrating. For example, when I add a big app like one of the add-ons for resiliency, add-on applications for QRadar, these applications require different hardware to implement and to deploy. The resiliency connector because there's a considerable amount of data scanning, operates for these apps correctly.
Acquiring these add-on apps for QRadar is very expensive. This is one of the difficulties that we are facing with the QRadar.
For how long have I used the solution?
More than five years.
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and support?
Technical support hasn't been bad, but sometimes it's inadequate, sometimes it is good. It depends on the case. We've had bad experiences in the past because we didn't get onsite support when we needed it.
They do have onsite support but only for third-party partners working directly with IBM. And sometimes the support is too slow.
Which solution did I use previously and why did I switch?
I've used Alien Vault, McAfee, and Splunk.
How was the initial setup?
The initial set up was a bit hectic the first time because, it's not about the QRadar application itself, it's about defining or configuring the data sources or the traffic sources to QRadar. We are going to use a small file through literally all of the traffic sources. We found it was difficult to merge with QRadar due to different IPs, different sources delaying the process and just technical issues. It's not an issue with the QRadar solution itself.
What about the implementation team?
We implemented through a vendor. I am one of the integrators.
Our requirements are dependent on the size of the deployment and maintenance case, depending on how large of an enterprise solution we are speaking about. The size of the architecture, or for example if the architecture is all in one including the processor, including the QNI and the connector all with one box. A deployment of this type would only require one guy for it if the architecting dissipating these items comes from the all in one box.
What's my experience with pricing, setup cost, and licensing?
The licensing is every year.
There are additional costs, such as the cost associated with the different hardware required for implementation and deployment. Along with the add-on apps, these are all additional costs, and they require licensing as well.
What other advice do I have?
The solution functions very well. It is amazing but there are some bugs with it. The unknown bugs can just come up with the adaptor with the data stored in Qradar.
On a scale from one to 10, ten being the best, I would rate this product an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Market Enabling Solutions at Raksha Technologies Pvt Ltd
In one single pane of glass, we can see all the issues. Though, the architecture could be improved.
Pros and Cons
- "On the back-end, Watson helps me figure out an exact problem, sometimes giving me the result."
- "It saves a lot of time. We integrate the customer's firewall with all their networking devices."
- "This console gives you the entire view, which makes life easier and allows you to take precautionary measures."
- "The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging."
What is our primary use case?
Its primary use case is for people who want to manage all of their logs with analytics and correlate that between different security devices whose logs are related.
This solution is performing well.
How has it helped my organization?
It saves a lot of time. We integrate the customer's firewall with all their networking devices. If there is an issue, it helps us do the proactive work before it becomes a bigger issue. We are able to pinpoint issues and solve them.
Additionally, it is very easy to figure out. In one dashboard, we can see all the issues. There is no need to login to every device. In one single pane of glass, we can see everything.
What is most valuable?
Watson, which is an artificial intelligence, is the most valuable feature. On the back-end, Watson helps me figure out an exact problem, sometimes giving me the result. I never would have imagined this before.
What needs improvement?
The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
It is a combination of multiple factors. The issues is from the customer side, not from QRadar. If you are able to get the right details from the customer, this solution is scalable.
How are customer service and technical support?
I am not involved with technical support because I am in pre-sales.
Which solution did I use previously and why did I switch?
Factors in switching were the console view, as well as Watson. IBM Watson makes a huge difference on the product side.
What's my experience with pricing, setup cost, and licensing?
I do not have control over pricing, though I do help customers with their sizing.
Which other solutions did I evaluate?
I select the vendor based on the customer's requirements. On the customer side, pricing is very important. They also consider the support to be an important factor.
My present organization does mostly IBM business. We have a very good rapport with the IBM team. We have won a lot of cases against competitors. We get trained frequently, so if there is an update, then we are prepared.
We are able to see the rapid growth of IBM through QRadar compared to the other SIEM tools.
What other advice do I have?
I would rate it a seven out of 10. I have had some challenges integrating this solution.
Each organization is looking for security. If you have a SIEM tool, you can integrate it with all of your security devices, and get all your security logs. This console gives you the entire view, which makes life easier and allows you to take precautionary measures.
People who handle only four or five security devices spread across the globe should go with this SIEM tool.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
It has a logical, user-friendly GUI
Pros and Cons
- "IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot."
- "It has a logical, user-friendly GUI."
- "Dashboards and reports could provide better visualization of SIEM activity."
What is our primary use case?
We used QRadar SIEM over Juniper Secure Analytics platform.
The company profile is telecom. The infrastructure has a large geographical spread.
How has it helped my organization?
IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot.
What is most valuable?
- It has a logical, user-friendly GUI.
- Very easy to drill down in offenses and get to the bottom of raw data.
What needs improvement?
Dashboards and reports could provide better visualization of SIEM activity.
An executive or CISO dashboard would be nice to have by default.
For how long have I used the solution?
Three to five years.
What other advice do I have?
The tool gets better value in the hands of an experienced security analyst.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Vice President & Country Head at Inspira Enterprise
Excellent risk rating but could keep data longer
Pros and Cons
- "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
- "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."
What is most valuable?
QRadar UBA's most valuable feature is the risk rating of users depending on their behavior.
What needs improvement?
QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month. In the next release, I would like to be able to do a historical search of user scores.
For how long have I used the solution?
I've been using QRadar UBA for two and a half years.
What do I think about the stability of the solution?
QRadar UBA is quite stable.
Which other solutions did I evaluate?
QRadar UBA's price is a little more than street price and could be reduced.
What other advice do I have?
I would rate QRadar UBA seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Country Manager at Magarah
Beneficial portfolio, reliable, and integrates well
Pros and Cons
- "IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration."
- "The solution could improve by having more out-of-the-box use cases."
What is our primary use case?
IBM QRadar User Behavior Analytics has a dedicated application for user behavior analytics and must be installed separately on an application server. It is valuable if you created the setup for the use cases. It needs additional customization to have a good value. You will have to point the solution to the suitable data sources that will feed the user analytics in a good manner. You will have good user behavior analytics, based on the created use cases.
What is most valuable?
IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration.
What needs improvement?
The solution could improve by having more out-of-the-box use cases.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for approximately two years.
What do I think about the stability of the solution?
IBM QRadar User Behavior Analytics is stable.
What do I think about the scalability of the solution?
I have found IBM QRadar User Behavior Analytics to be scalable.
We have approximately 15 clients using this solution.
How are customer service and support?
The support is satisfactory.
How was the initial setup?
The implementation was not easy and was not difficult, it was in the middle.
The full implementation can take approximately two to three months.
What about the implementation team?
We have three people that are supporting IBM QRadar User Behavior Analytics.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required for this solution.
What other advice do I have?
I rate IBM QRadar User Behavior Analytics an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Sr. Information Security Analyst at a insurance company with 51-200 employees
Robust monitoring that is scalable and includes the SOC service
Pros and Cons
- "The best part of this solution is having a third-party SOC."
- "The user interface is a bit difficult to get used to."
What is our primary use case?
The primary use case of this solution is for monitoring the network.
What is most valuable?
Part of the SaaS offering is the SOC service. The best part of this solution is having a third-party SOC.
It's a robust solution.
What needs improvement?
The user interface is a bit difficult to get used to. Once you do, it's not difficult.
For how long have I used the solution?
I have been working with QRadar for two years.
We are working with the latest version.
What do I think about the stability of the solution?
The stability is excellent.
What do I think about the scalability of the solution?
It's scalable. Everything is done through our third-party vendor.
We have four other people in my group that have access to it, and we have six people who use it.
How was the initial setup?
The third-party vendor manages the system
What about the implementation team?
We had a third party vendor to complete the installation, so it wasn't bad.
Which other solutions did I evaluate?
We evaluated all of the Gartner top quadrants.
What other advice do I have?
I would recommend having a third-party vendor.
There are a lot of alerts and a lot of tuning that has to be done. Every time we add new rules to it, an alert goes up. Having the SOC to go through it all first is very beneficial.
For what we do, I would rate IBM QRadar a ten out of ten. We are satisfied with it.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
A solution with a powerful and easy-to-use GUI and good technical support
Pros and Cons
- "It has a powerful GUI where you can put together your use cases, and don't have to write your own scripts."
- "While the interface is easy to use, it could be a little more responsive."
What is our primary use case?
The first thing that we implemented for user behavior was to find out whether somebody is logging in at odd hours. It studies user behavior.
What is most valuable?
My favorite thing is that it comes with good usability.
It has a powerful GUI where you can put together your use cases, and don't have to write your own scripts.
What needs improvement?
The price of this solution is a little bit expensive, so if it were cheaper then it would help.
While the interface is easy to use, it could be a little more responsive. It can be a bit sluggish at times.
For how long have I used the solution?
I have been using IBM QRadar for about a year.
What do I think about the stability of the solution?
We have not experienced any issues with stability.
What do I think about the scalability of the solution?
Scalability has not been a problem, although our environment is not very big. Perhaps at a later stage and with a bigger environment, we might have issues.
How are customer service and technical support?
I have been in contact with technical support on one or two occasions. The experience was good and we are satisfied.
Which solution did I use previously and why did I switch?
I also have experience using Splunk.
How was the initial setup?
The initial setup is really straightforward. It's a bonus point of this solution.
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Cybersecurity Practice Lead at a tech services company with 201-500 employees
Enables us to handle the most critical attacks and integrates well with other solutions
Pros and Cons
- "One of the most valuable features is its ability to integrate with other solutions. IBM has a lot of solutions and we have managed to make it work with IBM BigFix and MaaS360, and even Microsoft."
- "In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting."
What is our primary use case?
We are using it for SIEM, for Security Information and Event Management. We're gathering the logs and doing analytics on how we are going to react to security incidents.
How has it helped my organization?
With QRadar we managed to focus on the more critical incidents that we have experienced. As a result, we have managed to decrease the most critical incidents, most critical attacks. Now we're focusing on the ones that are not too heavy, not too critical. As of the moment, we are more secure than before.
What is most valuable?
One of the most valuable features is its ability to integrate with other solutions. In our current setup, we need a holistic view of our network to provide better service. Therefore, integration with our security tools and infrastructure is a must. We managed to get our NGFW, Endpoint Security, network servers, compliance tools and others to integrate with QRadar which enables our team to better understand what is happening in our network and respond accordingly.
What needs improvement?
The first area for improvement is the cost. It's a little bit too expensive for us.
Also, initially it was difficult to understand or to grasp, but once you get the hang of it is easier to understand and to analyze. So the main problems are its cost, the maintenance cost, and the fact that it takes some time to learn how to use it.
In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It's very robust. If it fails it does not really harm the network. It just gathers information and that's the important part. It has not failed, it's been working since day one so there is no problem. As long as the server that you install it on is working fine, it's very reliable. It's very stable.
What do I think about the scalability of the solution?
It's also scalable yes. You can adjust the number of devices it communicates with so there is no problem with scalability.
How are customer service and technical support?
I have not yet contacted technical support. I have not encountered any problems. So far, we have had no need for them. We have just fixed things ourselves.
Which solution did I use previously and why did I switch?
We did not use any solutions before QRadar.
How was the initial setup?
It's straightforward. We just had to connect it to our servers, to our security solutions, and that was it. Everything was already communicating.
We are just a small company, so the deployment did not take that long, about a month to a month-and-a-half. It didn't involve too much downtime since we're just monitoring a few servers and a couple of security tools.
What about the implementation team?
We are directly in touch with IBM and we have an IBM security specialist. He usually gives us pointers and he's the one who also gave us a little bit of training and knowledge transfer.
What's my experience with pricing, setup cost, and licensing?
It's too expensive. The licensing is also a little bit difficult to understand because you have to license it per event and per number of flows. So you have to understand the difference between a flow and an event, and then you have to forward that to the resellers, the distributors, and to IBM. That part took a long time for us. Now we're adjusted to the process.
Which other solutions did I evaluate?
We did evaluate some, like LogRhythm. We found that LogRhythm was more difficult to understand because it was a little bit too static. I believe they have already improved but, as of the moment, we are still happy with QRadar.
What other advice do I have?
My advice is to take your time. It depends on your network, on what you want to gather information from. Make sure that the networking and the cybersecurity teams are working towards a common goal. The solution is very much worth it. You can gather all the information that you need as long as you know first what you need.
This solution is mainly for the Security Operations Center, so there are just three or four users. But it's one of the key tools for us to identify threats and attacks. The users are security operations analysts and threat hunters.
In our case, deployment and maintenance requires just a few people. They are the network administrators and our cybersecurity engineers.
At the moment we have no plans to increase usage. If the company grows, usage should grow as well. The company is growing but, as of the moment, we are planning for expansion. That's why the solutions that we carry are already built for expansion for the next three to five years.
I would rate QRadar at eight out of ten. It's not perfect and the big issues would be the price and it that it takes some time to understand it. But so far, it's one of the best solutions out there.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?