Try our new research platform with insights from 80,000+ expert users
Enterprise Architect, CISSP at a tech services company with 1,001-5,000 employees
Real User
A solution with a powerful and easy-to-use GUI and good technical support
Pros and Cons
  • "It has a powerful GUI where you can put together your use cases, and don't have to write your own scripts."
  • "While the interface is easy to use, it could be a little more responsive."

What is our primary use case?

The first thing that we implemented for user behavior was to find out whether somebody is logging in at odd hours. It studies user behavior.

What is most valuable?

My favorite thing is that it comes with good usability.

It has a powerful GUI where you can put together your use cases, and don't have to write your own scripts.

What needs improvement?

The price of this solution is a little bit expensive, so if it were cheaper then it would help.

While the interface is easy to use, it could be a little more responsive. It can be a bit sluggish at times.

For how long have I used the solution?

I have been using IBM QRadar for about a year.

Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have not experienced any issues with stability.

What do I think about the scalability of the solution?

Scalability has not been a problem, although our environment is not very big. Perhaps at a later stage and with a bigger environment, we might have issues.

How are customer service and support?

I have been in contact with technical support on one or two occasions. The experience was good and we are satisfied.

Which solution did I use previously and why did I switch?

I also have experience using Splunk.

How was the initial setup?

The initial setup is really straightforward. It's a bonus point of this solution.

What other advice do I have?

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Solution Manager at ZZTL
Reseller
Has a good feature set and good stability
Pros and Cons
  • "Most of the features are good. It is an excellent solution."
  • "IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer."

What is most valuable?

Most of the features are good. It is an excellent solution. 

What needs improvement?

Some of the features should be more cooperative but other than that, everything is okay.

For how long have I used the solution?

I have been using IBM QRadar User Behavior Analytics for a year. 

What do I think about the stability of the solution?

It is very stable. 

What do I think about the scalability of the solution?

It is also scalable. 

How are customer service and technical support?

Our team handles its own support. We are capable of doing our own technical support but we also have IBM to get their help as well.

How was the initial setup?

The initial setup is not straightforward but of medium complexity. It's not simple but not so complex. It usually takes two to three weeks to deploy. 

What's my experience with pricing, setup cost, and licensing?

The price is very high. Some of our customers cannot afford it. 

What other advice do I have?

IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer.

I would rate it an eight out of ten. They should reduce the pricing. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Director, Cybersecurity at a media company with 51-200 employees
User
It has a logical, user-friendly GUI
Pros and Cons
  • "IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot."
  • "It has a logical, user-friendly GUI."
  • "Dashboards and reports could provide better visualization of SIEM activity."

What is our primary use case?

We used QRadar SIEM over Juniper Secure Analytics platform. 

The company profile is telecom. The infrastructure has a large geographical spread.

How has it helped my organization?

IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot.

What is most valuable?

  • It has a logical, user-friendly GUI. 
  • Very easy to drill down in offenses and get to the bottom of raw data.

What needs improvement?

Dashboards and reports could provide better visualization of SIEM activity. 

An executive or CISO dashboard would be nice to have by default.

For how long have I used the solution?

Three to five years.

What other advice do I have?

The tool gets better value in the hands of an experienced security analyst. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user393954 - PeerSpot reviewer
Application Infrastructure innovation at a financial services firm with 1,001-5,000 employees
Vendor
Using it through IBM's Managed Security Services, they keep us alerted of what events are hitting, and adapting for it. I'd like to see tighter integration with other IBM products.

What is most valuable?

What is valuable is that we're using it through IBM's MSS services, and that they're doing a really good job of keeping us alerted of what events are hitting, and adapting for it.

How has it helped my organization?

It benefits us from a standpoint that we're very immature in our review of how security should be approached, and it's really helped us move up to modern awareness of what's going on on the internet.

What needs improvement?

I'd like to see, and they're getting there, is more integration; tighter integration with some of the other IBM Security products. They're moving a lot tighter to BigFix. BigFix has a lot of power in it, and MaaS360 also has a lot of power in it. I'd like to see those more tightly integrated.

What do I think about the stability of the solution?

We have not had any stability or scalability issues. We're a little concerned about the latest version and the fact that it cannot be upgraded, that it requires a clean install.

How are customer service and technical support?

We have not really used technical support, because it's a managed service, so we call the SOC and they help us. They are very helpful.

Which solution did I use previously and why did I switch?

We just really sold our CIO and CTO on the fact that we need to do better than we are, where we're at today. We had a lot of virus challenges, like most companies, and malware, so we had to figure out how to reduce that.

How was the initial setup?

I was involved in the initial setup. Well, IBM did it, since it was a managed service. It was pretty straightforward.

Which other solutions did I evaluate?

We looked at numerous other players. We chose IBM because it has a lot of power, and you can grow it as much as and however you want it to.

When I am looking for a vendor, I don't look for a VAR, I look for a partner.

What other advice do I have?

If you're going to implement it, implement it using managed services, because it's too complex of a product to try to do yourself.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Cyber Security Advisor / CISO / Healthcare Security Pro at OMC SYSTEMS LLC
Vendor
The dashboards give us an overview of traffic flow and pinpoint configuration issues.

Valuable Features

I find that the dashboards are the most helpful to get an overview of traffic flow and issues.

Improvements to My Organization

We find that reviewing Q1 Radar is very helpful to pinpoint configuration issues, as well as go back and find traffic flows from comprimised hosts.

Deployment Issues

No.

Stability Issues

None.

Scalability Issues

N/A

Customer Service and Technical Support

Customer Service:

N/A

Technical Support:

N/A

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Vice President & Country Head at Inspira Enterprise
Real User
Excellent risk rating but could keep data longer
Pros and Cons
  • "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
  • "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."

What is most valuable?

QRadar UBA's most valuable feature is the risk rating of users depending on their behavior.

What needs improvement?

QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month. In the next release, I would like to be able to do a historical search of user scores.

For how long have I used the solution?

I've been using QRadar UBA for two and a half years.

What do I think about the stability of the solution?

QRadar UBA is quite stable.

Which other solutions did I evaluate?

QRadar UBA's price is a little more than street price and could be reduced.

What other advice do I have?

I would rate QRadar UBA seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Muhammad Ali Aziz - PeerSpot reviewer
Senior Manager Cyber Security Services & Solutions at Trillium
Vendor
Top 10
A User Behavior Analytics (UBA) solution with useful out-of-the-box rules and use cases, but functionality should be more integrated
Pros and Cons
  • "I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot."
  • "IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."

What is most valuable?

I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot.

What needs improvement?

IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on. 

For how long have I used the solution?

We have been using IBM QRadar User Behavior Analytics for about four years.

What do I think about the stability of the solution?

Stability is good, but the investigation system should be better.

What do I think about the scalability of the solution?

IBM QRadar User Behavior Analytics is scalable. You have the EPS and closed license. I think scalability is not an issue because it is available on both the hardware and the software. You can install the software plans if you want, and there is also a hardware plan.

How are customer service and support?

Their technical support is good. I have not faced any issues before, and the technical support is good.

What other advice do I have?

I will recommend this solution to potential users.

On a scale from one to ten, I would give IBM QRadar User Behavior Analytics a seven. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1421823 - PeerSpot reviewer
Deputy General Manager at a comms service provider with 5,001-10,000 employees
Real User
Correlation done well, fair pricing, and knowledgeable technical team
Pros and Cons
  • "When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed."
  • "I have noticed the interface has room for improvement."

What is most valuable?

We are looking for the entire QRadar spectrum but it has many products. QRadar is a kind of program, we are looking for system modelling, point modelling, network side modelling similar to QRadar network inside, and the capability to correlate between the network and endpoint. Most of the SIEM's have to rely on when it comes to network side third party or separate network traffic analysis. When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed.

What needs improvement?

Since we have not used the solution very long my information is limited when it comes to improvements. I have noticed the interface has room for improvement.

For how long have I used the solution?

I have been using the solution for two years. However, my company has not deployed the solution yet and we are in the early stages of testng.

How are customer service and technical support?

The solution has a good technical team.

How was the initial setup?

The installation is complex. There is some overloading that happens, this could be simplified and made easier by allowing all key features on the first level dashboard to be viewed.

What's my experience with pricing, setup cost, and licensing?

When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products. Even though the price can be a little high sometimes there product is number one. They have a wide range of products.

Which other solutions did I evaluate?

We have compared Securonix and many other solutions to this one.

What other advice do I have?

I rate IBM QRadar a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.