We are using it for SIEM, for Security Information and Event Management. We're gathering the logs and doing analytics on how we are going to react to security incidents.
Cybersecurity Practice Lead at a tech services company with 201-500 employees
Enables us to handle the most critical attacks and integrates well with other solutions
Pros and Cons
- "One of the most valuable features is its ability to integrate with other solutions. IBM has a lot of solutions and we have managed to make it work with IBM BigFix and MaaS360, and even Microsoft."
- "In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting."
What is our primary use case?
How has it helped my organization?
With QRadar we managed to focus on the more critical incidents that we have experienced. As a result, we have managed to decrease the most critical incidents, most critical attacks. Now we're focusing on the ones that are not too heavy, not too critical. As of the moment, we are more secure than before.
What is most valuable?
One of the most valuable features is its ability to integrate with other solutions. In our current setup, we need a holistic view of our network to provide better service. Therefore, integration with our security tools and infrastructure is a must. We managed to get our NGFW, Endpoint Security, network servers, compliance tools and others to integrate with QRadar which enables our team to better understand what is happening in our network and respond accordingly.
What needs improvement?
The first area for improvement is the cost. It's a little bit too expensive for us.
Also, initially it was difficult to understand or to grasp, but once you get the hang of it is easier to understand and to analyze. So the main problems are its cost, the maintenance cost, and the fact that it takes some time to learn how to use it.
In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting.
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,636 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It's very robust. If it fails it does not really harm the network. It just gathers information and that's the important part. It has not failed, it's been working since day one so there is no problem. As long as the server that you install it on is working fine, it's very reliable. It's very stable.
What do I think about the scalability of the solution?
It's also scalable yes. You can adjust the number of devices it communicates with so there is no problem with scalability.
How are customer service and support?
I have not yet contacted technical support. I have not encountered any problems. So far, we have had no need for them. We have just fixed things ourselves.
Which solution did I use previously and why did I switch?
We did not use any solutions before QRadar.
How was the initial setup?
It's straightforward. We just had to connect it to our servers, to our security solutions, and that was it. Everything was already communicating.
We are just a small company, so the deployment did not take that long, about a month to a month-and-a-half. It didn't involve too much downtime since we're just monitoring a few servers and a couple of security tools.
What about the implementation team?
We are directly in touch with IBM and we have an IBM security specialist. He usually gives us pointers and he's the one who also gave us a little bit of training and knowledge transfer.
What's my experience with pricing, setup cost, and licensing?
It's too expensive. The licensing is also a little bit difficult to understand because you have to license it per event and per number of flows. So you have to understand the difference between a flow and an event, and then you have to forward that to the resellers, the distributors, and to IBM. That part took a long time for us. Now we're adjusted to the process.
Which other solutions did I evaluate?
We did evaluate some, like LogRhythm. We found that LogRhythm was more difficult to understand because it was a little bit too static. I believe they have already improved but, as of the moment, we are still happy with QRadar.
What other advice do I have?
My advice is to take your time. It depends on your network, on what you want to gather information from. Make sure that the networking and the cybersecurity teams are working towards a common goal. The solution is very much worth it. You can gather all the information that you need as long as you know first what you need.
This solution is mainly for the Security Operations Center, so there are just three or four users. But it's one of the key tools for us to identify threats and attacks. The users are security operations analysts and threat hunters.
In our case, deployment and maintenance requires just a few people. They are the network administrators and our cybersecurity engineers.
At the moment we have no plans to increase usage. If the company grows, usage should grow as well. The company is growing but, as of the moment, we are planning for expansion. That's why the solutions that we carry are already built for expansion for the next three to five years.
I would rate QRadar at eight out of ten. It's not perfect and the big issues would be the price and it that it takes some time to understand it. But so far, it's one of the best solutions out there.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
Senior Cybersecurity Consultant at CIA Botswana
Enables our clients to detect threats and vulnerabilities in real time
Pros and Cons
- "Most of our clients are interested in automation. The automation part is good because they are able to detect threats and vulnerabilities in real time. It's very fast."
- "The API integration for AD is a problem when it comes to vulnerability management. If you want to incorporate multiple factor authentication it becomes a problem with the AD. It doesn't integrate well. That needs to be improved."
What is our primary use case?
Our primary use case if for security analytics. We do investigation and security analytics, so we collect events and after collecting events we give positive security analytics to clients.
How has it helped my organization?
Most of our clients are interested in automation. The automation part is good because they are able to detect threats and vulnerabilities in real time. It's very fast.
What is most valuable?
The vulnerability management aspect is the most valuable feature. IBM QRadar is the only SIEM solution with integrated vulnerability management. That's why most clients are flocking to it. API integration is very easy.
What needs improvement?
The API integration for AD is a problem when it comes to vulnerability management. If you want to incorporate multiple factor authentication it becomes a problem with the AD. It doesn't integrate well. That needs to be improved.
The configuration steps are not easy to follow compared to NetWitness.
What do I think about the scalability of the solution?
Scalability is good. I have plans to increase usage it just depends on the contracts. If I get more contracts I get more people. Most clients want to manage security and so they would want to outsource their expertise. If they outsource their expertise that means I have to recruit more people.
How are customer service and technical support?
Their technical support is pretty good.
How was the initial setup?
The initial setup was easy. It usually takes around three months or so. In terms of the implementation strategy, once we get the correct events sorted, the strategy is to connect enough events sources so that they give you an efficient solution.
We require five to ten people for setup and maintenance.
What about the implementation team?
I'm the consultant so we do the implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
The licensing depends on the customer. The pricing is good.
What other advice do I have?
I would rate it an eight out of ten. Not a ten because the configuration part of it should be easier. They tried to integrate everything together to be all in one, but it's not easy to configure.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,636 professionals have used our research since 2012.
Cyber Security Engineer
The most valuable feature is the ability to get the logs and analyze them.
What is most valuable?
The most valuable feature is the ability to get the logs and analyze them. These logs help us in terms of analyzing and actually using Watson on them. It's a pretty great tool for intelligence. I think it is really a great product.
How has it helped my organization?
To be able to get the logs and analyze them has improved the way my organization functions. You can see where the source destination is coming from. You can actually see the data and pause the dashboard. It actually helps you to analyze the data the way you are supposed to. Nobody else is doing that right now.
What needs improvement?
I don't have any problems with the solution right now. As I play with the tools, then I will actually come up with different ideas.
I was able to help out with IBM Guardium version 10. I was helping out with a couple of developers who actually developed the application itself.
I want to see more integration between QRadar and other applications like BigFix and a couple of other tools and applications out there. There are a lot of applications out there. QRadar security intelligence might be one of the best right now.
What do I think about the stability of the solution?
There were no stability issues with QRadar. We've had a couple of stability issues with all the applications that I run. I don't want to mention names.
How is customer service and technical support?
I’ve used technical support, and they were OK. I used to work for IBM.
How was the initial setup?
I was involved in the initial setup. It was straightforward and not complex.
Which other solutions did I evaluate?
I work as security engineer for the Department of Justice. We test hundreds of applications. I actually see which ones work best for the infrastructure.
What other advice do I have?
I would suggest QRadar. The security intelligence is one of the best right now.
When looking for a vendor, I want to be able to win them. I want them to accept the fact that I’m looking for a product for what I am doing and I have a couple of requirements.
From there, I can actually tell them what they need to do, or what I need to do, in the environment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a government with 10,001+ employees
For vulnerabilities, you see a popup on the screen. We do not have to look for it. It is pushed to us.
What is most valuable?
It's easy for us to see what's happening in the environment. It's very good to see the logs and the analytic stuff.
How has it helped my organization?
We can see the vulnerabilities much easier with the product. You see a popup on the screen. We do not have to look for it. It is pushed to us.
What needs improvement?
It is very expensive; very expensive.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
I think it is scalable.
How is customer service and technical support?
We have used technical support. They are very good and very nice.
Which other solutions did I evaluate?
We didn't evaluate any alternatives. We have yearly talks with the IBM consulting team. We look at the trends.
What other advice do I have?
When choosing a vendor, we look for a stable and trustworthy company. I think QRadar is the best solution you can get.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Group CIO at a tech services company with 501-1,000 employees
Provides visibility in terms of the threat surface and proactively looks at mitigation measurements.
How has it helped my organization?
It gives us more visibility in terms of the threat surface and to proactively look at mitigation measurements, in terms of managing our risks. As our side business is increasing, it gives us a better way to handle of things.
What is most valuable?
We are using this SIEM solution, which is pretty good in terms of detecting threats and managing the intelligence for us.
What needs improvement?
In the next release, I obviously would want to see more integration to the cloud-based services such as Microsoft Azure and the other line of business applications, so that we have a comprehensive view on a hybrid cloud stack.
What do I think about the stability of the solution?
The stability of this product is pretty good. It's helping us a lot and they keep on adding new features. Thus, as a platform, it's quite stable.
What do I think about the scalability of the solution?
Scalability is good because it is a cloud-based offering and a managed services offering solution. The scalability is left for IBM to manage, so it's not a headache for us to manage.
How is customer service and technical support?
We have used the technical support on and off. Since it's on a 24/7 SLA, it gets managed well. It is pretty good. On a scale of 1-10, I would give it an eight.
How was the initial setup?
The setup was a bit complex. But as a project team, we pulled it through. It was complex because you need to understand the product and they need to understand our business requirements, as all of this is in the setup. So, it's not a straightforward payoff by just putting us off way there.
Which other solutions did I evaluate?
The SIEM solutions list we looked from included IBM, Cisco and Check Point.
The most important criteria while selecting a vendor are that it is a future-proof and tabulating solution. Also, the other factors involved are being a global leader and getting us up there as well.
The primary reason as to why we chose IBM is because we had a significant local presence. Also, QRadar's portfolio and its features on the Gartner's website were pretty much at the top end, i.e., as a leader in the leadership aspect.
What other advice do I have?
This is quite an established solution so, I will have no hesitations in recommending it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at a tech services company with 11-50 employees
It can collect different types of security feeds and correlate them in real-time with your logs.
What is most valuable?
The most valuable features are:
- Auto update: QRadar will download new logs from the database on the supported security device, so that it will automatically normalize the new log format and you will not need to rewrite all your rules/offenses again.
- X-Force/TAXII feed: QRadar can collect different types of security feeds and correlate them in real-time with your logs.
- Search engine: QRadar is like Excel, i.e., you can add rows and filter like your daily office work, without writing any scripts. So level 1 support also can handle this type of jobs.
How has it helped my organization?
You will learn something that you don't know on the user/machine behaviour.
What needs improvement?
The dashboards and reports may need to improve. We need to export the CSV results to create a report by Excel.
For how long have I used the solution?
I have used this solution for three years.
What do I think about the stability of the solution?
It will slow down, when there are too many people doing a search at the same time, but that depends on your hardware and design.
What do I think about the scalability of the solution?
I did not encounter any scalability issues.
How is customer service and technical support?
You may need to allow remote support for them to help you, for troubleshooting the issues.
How was the initial setup?
The setup is complex, i.e., for the first setup. SIEM is not easy so as to enable logs without any performance issues and the deployment advisor is the key for the project.
What's my experience with pricing, setup cost, and licensing?
You only need to worry about the number of events per second and the number of flows per minute. Storage size is not an issue with QRadar.
Which other solutions did I evaluate?
We did evaluate other options. I think Splunk is the second-best option.
What other advice do I have?
If you have an experienced group of security members, then you may not at all need the advisor for the product. If not, then you will have to find the path to build your team, so as to become more knowledgeable.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are business partners.
Information Security Consultant at a tech services company with 51-200 employees
Although it provides incident management of the alerts it produces, this could be improved to allow more restrictions
What is most valuable?
IBM Security QRadar has many valuable features. One of the most valuable features of IBM Security QRadar is the ease of extracting information from raw logs/events, whether the log source sending the events is supported by IBM or not (for example, a custom in-house application) and use this information in creating searches, correlation rules, reports, and dashboards. Another feature is scalability; scaling up a deployment to support more events per second is made simple just by “linking” new appliances to the main deployment through configuration steps that only take minutes to complete. I do not know if I can call this a feature, but a “general” feature of QRadar is that it does not require highly technically skilled personnel to administer. The dashboards and configurations through the web UI are easy to read, understand, and change.
What needs improvement?
Although QRadar provides incident management of the alerts it produces, this area could use a little improvement to allow more restrictions on who can close alerts and easily updating alerts with and reading text templates.
For how long have I used the solution?
I have used IBM Security QRadar for nearly two years now. I use it as a user in my organization’s Managed Security Services division where we monitor clients’ environments. I also work with it as an implementer to deploy and customize it for clients.
What was my experience with deployment of the solution?
Any deployment will have issues. The issues that I encounter with deploying QRadar are raised with IBM Support and are usually solved quickly through applying patches or changing individual files to fix the web GUI issue.
What do I think about the stability of the solution?
The causes of stability issues are usually not QRadar, but of misconfigured devices/log sources (for example, sending debug events to QRadar that results in millions of events in a short period of time). However, if a deployment is done correctly, QRadar stays stable.
What do I think about the scalability of the solution?
No, I did not face issues with scalability. One of the great features of QRadar is the ease of scalability. A license upgrade is simply done by purchasing it and applying it through the GUI which only takes minutes to. If an organization wants a larger expansion, all that it has to do is to buy the required hardware with QRadar installed, and “link” it to the main deployment through steps that also take minutes. This new hardware will provide the extra events per second or flows per minute capabilities required for the expansion.
How are customer service and technical support?
IBM provides support in various regions in the world. The level of technical support is good. Once a support ticket is open, the support team tries to fix it directly or passes it on to higher levels, and will involve the QRadar development team if required.
Which solution did I use previously and why did I switch?
No, I did not use a separate solution, although I have read and heard about different solutions from the various clients I have met with. Clients switch to using QRadar because they say that maintaining and administering other solutions becomes a hassle and requires trained personnel. Another reason clients switch to using QRadar because of cost.
How was the initial setup?
The initial setup of QRadar is straightforward. From the installation perspective, IBM provides one ISO file that can be used to install any of the QRadar components, with the activation key deciding which components to install. From the deployment perspective, QRadar has the ability to automatically detect many log sources sending logs. The out-of-the-box dashboards, searches, reports, and correlation rules allows QRadar to start displaying intelligence and insight on devices, network statistics, authentication, and many more, and to start alerting on offenses and policy violations automatically. Coupling this with the automatically detected log sources, a demonstration of QRadar can only take a few hours from the installation, to automatically detecting a log source such as firewall logs, to getting alerts on excessive firewall denies, port scans, etc.
What other advice do I have?
The advice I would give to others is to work with the implementation team to properly fine tune the out-of-the-box “building block rules” and to enter their network hierarchy in QRadar in order for it to give best results and reduce false positive alerts.
Disclosure: My company has a business relationship with this vendor other than being a customer: We're a value added services security company that is a distributor of Q1-Labs QRadar (now IBM).
Information Security Leader at a computer software company with 1,001-5,000 employees
Manage and review incidents easily
Pros and Cons
- "The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents."
- "The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."
What is our primary use case?
We use IBM QRadar for user behavior analytics and incident handling.
What is most valuable?
The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents.
What needs improvement?
The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity.
For how long have I used the solution?
I have been using IBM QRadar for four years.
What do I think about the scalability of the solution?
We have three customers using it and these customers have 100 to 300 users.
How are customer service and support?
Getting support sometimes takes time.
How was the initial setup?
The initial setup was quite straightforward.
We had the complete deployment and it was up and running in half a day.
What about the implementation team?
You can implement it by yourself.
What other advice do I have?
I would recommend IBM QRadar to other people who want to start using it.
On a scale of one to ten, I would give QRadar a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Splunk Enterprise Security
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Securonix Next-Gen SIEM
Cortex XSIAM
USM Anywhere
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
I am taking IBM Security Qradar exam c2150-400 early Aug 2015.