Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Security Analyst at a security firm with 11-50 employees
Real User
With more than 120 extensions, it can improve your event analysis
Pros and Cons
  • "There are more than 120 extensions in QRadar, which are easy to install and configure. These can improve your analysis of events."
  • "It comes with many rules disabled. You can tune them and modify them according to your enterprise needs and avoid false positives."
  • "QRadar log integration of various applications can be a tough job at times. There may be occasions when you will not find any QRadar guide on adding logs of a particular application. Even if you come across one, adding a log process is not an easy one."

What is our primary use case?

SIEM solutions must be business driven. Utilizing a SIEM solution depends on your enterprise goals, from meeting compliance requirements to implementing security controls and identifying the absence of controls. A SIEM solution can also be used to improve your business and increase your sales. With QRadar, you can do all these, even if you are not a security expert. It comes with a set of default rules which makes your life easier, from ransomware attacks to DDoS attacks. Everything can be detected if your logs are properly integrated into QRadar

It gets better with extensions and other rules you install from the IBM Security App Exchange, where you can detect malicious website access (with the intent of ransomware), P2P activity, or someone spamming everything. You can be notified, then you can run scripts to make QRadar take an action. 

I am a security analyst working with QRadar.

How has it helped my organization?

It is always evolving with new patches, new UX/UI (such as 7.3), new rules, and new extensions. It lets you evolve your company accordingly.

The usage of QRadar or any SIEM solution depends on the company goals, but with QRadar, the user interface, the dashboards, reports, installing extensions, and playing with the rules are easier. 

QRadar has helped our company a lot in evolving our security policy and taking care of weak controls. QRadar helped us in the blacklisting and whitelisting of applications. It helped us identify our security threats, and improve our firewalls. With the QRadar Vulnerability Manager, it helped us take care of vulnerable assets. 

What is most valuable?

  • Its default set of rules: It comes with many rules disabled. You can tune them and modify them according to your enterprise needs and avoid false positives.
  • The extension management: There are more than 120 extensions in QRadar, which are easy to install and configure. These can improve your analysis of events. 
  • UBA 2.7: It can help you detect insider threats. 

What needs improvement?

QRadar log integration of various applications can be a tough job at times. There may be occasions when you will not find any QRadar guide on adding logs of a particular application. Even if you come across one, adding a log process is not an easy one. Plus, it is also vulnerable because the ports used to integrate those log sources with QRadar are well-known and most of them are vulnerable ones. 

Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.

For how long have I used the solution?

Three to five years.

What do I think about the scalability of the solution?

QRadar is easily scalable in many ways: vertical and horizontal.

  • Horizontal: You can increase the QRadar processing power with QRadar App Node and Data Node.
  • Vertical: You can always implement multiple QRadars: Event collectors and flow, collectors, and then you can route your offenses, such events and flows from one QRadar to the next one.

How are customer service and support?

Buying anything, an enterprise must look for troubleshooting and fixing its issues using its support. With QRadar, all those things are easily available and just a click away on the Internet. From IBM Fixlet to dW Answers, you can do a lot.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Tom WEIZEORICK - PeerSpot reviewer
Tom WEIZEORICKSecurity Brand Channel Account Manager at a tech company with 10,001+ employees
Real User

As an IBMer, I'm always glad to hear about customers experiences with our solutions. Its rewarding to know that we have done a great job of delivering on our promises. Thanks for the positive feedback.

it_user632760 - PeerSpot reviewer
Lead Developer
Real User
Based on the analysis, we can easily identify from where the threat is originating.

What is most valuable?

The most valuable features of this solution are analyzing who is saying what and in case of a threat, we can easily identify from where the threat is originating, based on the analysis.

How has it helped my organization?

We have implemented this QRadar solution to identify the data, whether it is being used at various parties including our trading partners, i.e., both the internal as well as external partners. Thus, by using this product, we can also come to the conclusion as to how the data is being applied best and we can decide what to link, i.e., if we need any infrastructure improvements and so on.

What do I think about the stability of the solution?

I am not currently responsible for this product. However, I did not hear any complaints from the other people in terms of its stability.

What do I think about the scalability of the solution?

We are not directly managing this product. I am from the integration team and the QRadar solution is mostly used by our information security.

Which solution did I use previously and why did I switch?

Initially, we were using another IBM product. With QRadar, we are getting better outputs such as the reports and other outputs.

The reason why we chose IBM is because we are using so many products from IBM today.

In general, the most important criteria that we look for while selecting a vendor are that there should be other proven solutions offered by the vendor and they need to be a type of investigator since we belong to a specific healthcare industry. So, we are very careful when we are choosing a vendor.

How was the initial setup?

We were involved in the setup in terms of sending the information back and forth to QRadar. Other than that, I did not take part in the installation.

What other advice do I have?

Definitely invest in the QRadar solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
it_user643884 - PeerSpot reviewer
Senior System Administrator at a tech services company with 11-50 employees
Consultant
Offers device auto-discovery, along with rules and reports already created.

How has it helped my organization?

I have implemented QRadar in a big airline company, where they needed to get all their security information in one place. It helped in reducing the amount of time that was needed to evaluate the risk of every event. Configuring the alerts has never been easier; you just search for the event you think you need and start creating the rules that way. It is really straightforward and you don't need much IT knowledge for it. Of course, your experience with the product and a generalist view of the infrastructure, business and IT are strongly recommended, when using a tool similar to this.

What is most valuable?

In my understanding, the best features are:

  • DSMs (Device Support Modules),
  • Device auto-discovery, and
  • Hundreds of rules and reports already created for you to mix up.

These features are keeping QRadar on top in Gartner. You can have it running in a few hours, then start collecting your logs and events in no time.

What do I think about the stability of the solution?

We never experienced any stability issues. The only problem that I had was related to the hardware and the high availability worked as expected.

Something to take into account is the IBM support; they really know their business and how to fix problems. I had the opportunity to talk with L2 Managers in the US, who told me that IBM is investing in research, documentation and training for all the people working with it. This is a very interesting thing to have in mind, when choosing this platform.

What do I think about the scalability of the solution?

We never experienced any scalability issues. If you correctly estimate the amount of EPS (the license variable), then scalability is not a problem. They can run in a really big environment (100,000 EPS tested in production) and all the infrastructure will work as a charm.

How are customer service and technical support?

The technical support is excellent. As I've mentioned, they know their business and have a really good team behind them.

Which solution did I use previously and why did I switch?

I had the opportunity to use other SIEM solutions, but no one can provide what QRadar does, i.e., in terms of its simplicity, support or integration.

How was the initial setup?

The setup was really straightforward. You simply need to put your ISO image in the hypervisor, follow the on-screen instructions and you have it running in one hour.

What's my experience with pricing, setup cost, and licensing?

The pricing and licensing policies are really competitive. These solutions are not for a really small business, but having just one license variable is really good. You simple tell the partner or sales representative the number of EPS you want to receive in your appliance and that's it. Other solutions have a 'correlation' license, which is more like a trap than anything else.

Which other solutions did I evaluate?

I have tested Splunk and used a little bit of NitroSecurity (McAfee). I have also seen a little bit of HPE ArcSight.

What other advice do I have?

You should ask the sales representative to give you the Excel sheet to calculate EPS. Keep in mind that the firewalls, proxies and networking devices such as those will consume lots of EPS, but they do provide really nice information and insight from your network.

On Gartner, this is one of the top 10 SIEM solutions in the market. It is robust and IBM is investing a lot of money to get it running even better than it is running right now. You feel secured when you use it.

This solution is being implemented around the world and every day, a new feature or add-on is created for it.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are business partners and have a really good relationship with IBM.
PeerSpot user
Ahmed Hossam - PeerSpot reviewer
SOC Analyst Tier 2 at IP Protocol INC
Real User
An AI-powered incident and risk analysis, triage and response tool with a user-friendly graphical interface
Pros and Cons
  • "I like the graphical interface. It's so good and easy."
  • "Integration could be better. They should make it easy to integrate with other solutions."

What is our primary use case?

First, I used the manual to learn, then I tried to merge it with my company's needs, and there weren't any problems.

What is most valuable?

I like the graphical interface. It's so good and easy.

What needs improvement?

Integration could be better. They should make it easy to integrate with other solutions. 

For how long have I used the solution?

I have been using IBM QRadar Advisor with Watson for three or four years.

What do I think about the stability of the solution?

IBM QRadar Advisor with Watson is a stable solution.

What do I think about the scalability of the solution?

I think IBM QRadar Advisor with Watson is scalable.

How are customer service and support?

We didn't use technical support as the community was very helpful.

How was the initial setup?

The initial setup was difficult the first time, but it got easier after that.

What's my experience with pricing, setup cost, and licensing?

I think my company pays for the license yearly.

What other advice do I have?

I would advise potential users to read the manual or the workbook before going forward with the deployment. Try to match the requirements with the company's needs to avoid facing issues in the future. But if you get stuck, you can always ask the community for help.

On a scale from one to ten, I would give IBM QRadar Advisor with Watson a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
PeerSpot user
Cybersecurity Architecture and Technology Lead at Appxone
Consultant
Can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent.
Pros and Cons
  • "Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure."
  • "AI is superb but need improvements."

What is our primary use case?

Find the malicious activity via filter, don't rely on the rules which trigger the offenses and fix the suspicious activities.

How has it helped my organization?

Gaining application visibility and anomaly detection helping IT personnel to quickly identify meaningful deviations. For example, QRadar SIEM can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent with historical, moving-average profiles and seasonal usage patterns.

What is most valuable?

Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure, helping organizations detect and remediate threats often missed by other security solutions. These threats can include inappropriate use of applications; insider fraud; and advanced, “low and slow” threats easily lost in the “noise” of millions of events..

What needs improvement?

Artificial Intelligence is superb, QRadar correlate the events smartly and remove the same events but need improvements.

For how long have I used the solution?

One to three years...

What do I think about the stability of the solution?

No issues.

How are customer service and technical support?

Very good

Which solution did I use previously and why did I switch?

Mcafee, switched due to the bad correlation of data.

How was the initial setup?

It was straightforward

Which other solutions did I evaluate?

Splunk and Logrhythm..

What other advice do I have?

QRadar also supports UBA which is a fantastic feature to detect user's malicious activities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Shaikh Jamal Uddin - PeerSpot reviewer
Shaikh Jamal UddinCybersecurity Architecture and Technology Lead at Appxone
Consultant

you need more time and knowledge to completely understand about QRadar SIEM.

Technical Consultant at activedge
Consultant
Enchances Security Through Vulnerability Management and Increased Visibility
Pros and Cons
  • "The most valuable features would have to be the products' ability to customize vulnerability management settings."
  • "There could be improvements made to the UI, the user interface. Though the newer version, 7.3.2, might already have this improvement in place."

What is our primary use case?

I'm the technical consultant here at ActivEdge Technologies. Our primary use case for this solution is for Security Intelligence and Event Monitoring (SIEM) p. We provide protection services models for an organization's networks through a sophisticated technology which permits a proactive security posture. We have a business relationship with IBM QRadar as well as being a partner. We are a partner and we also use this feature. It's an integrated solution. We design it to be compatible with our client's network devices to maintain real-time monitoring through a centralized console. Our clients rely on us to create value.

How has it helped my organization?

QRadar has significantly improved our security. It has reduced threats considerably. The solution provides increased visibility along with actionable intelligence. We are looking into implementing it to proactively take steps to prevent or reduce the attacks.

What is most valuable?

The most valuable features would have to be the products' ability to customize vulnerability management settings and the ability to customize integration functions.

What needs improvement?

I can't see any need for service improvements because I feel it's easy to use and very functional as it is. There could be improvements made to the UI, the user interface. Though the newer version, 7.3.2, might already have this improvement in place.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's very stable. We never need much help with that.

What do I think about the scalability of the solution?

The solution is very scalable; it's designed to be, it's distributed architecture. It's entirely scalable.

Currently, there are five domain users working with this solution. We don't have visibility on our end user count due to the fact that end users don't need to log on to the application.

Our maintenance needs require just one experienced QRadar analyst to moderate.

How are customer service and technical support?

Technical support has proven to be very helpful.

How was the initial setup?

The initial setup wasn't straightforward. The setup is situation specific.

The deployment for us took about 3 months.

What about the implementation team?

Implementation was done in-house.

What was our ROI?


What other advice do I have?

I think this product adds significant value to organizations seeking a scalable, security integration tool. It does a great job of identifying, classifying, prioritizing, remediating, and mitigating software vulnerabilities. It's a good solution

On a scale of 1 - 10, 10 being the best, I give this product a rating of 9.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Server Security Engineer
Real User
Has great scalablity, if you use APS 25 GPS license you can change to 3000 EPS anytime
Pros and Cons
  • "IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
  • "I think QRadar is very complex. It's a distributed system and IBM QRadar has an all-in-one solution which is not like that distributed solution but it's a good product. IBM needs to consider the user interface because if we compare it with AlienVault, the AlienVault user interface is fantastic but the IBM QRadar user interface is very complex. They should focus on how to make it easier for the client."

What is our primary use case?

Our primary use case of this solution is to identify threats. 

How has it helped my organization?

We do R&D for IBM QRadar and we are also a cybersecurity solution based company. We provide solutions for our clients like banking, government agencies, and other non-government organizations. Our clients test in our labs and we try to understand how a product works and how a product will help our clients. I have more than three years experience with AlienVault and I use AlienVault a lot and I have already deployed it in a few banks. I am now trying to understand how IBM QRadar works and what the difference between IBM QRadar and AlienVault is. 

What is most valuable?

This solution has many valuable features but I especially like the Log Manager feature.

What needs improvement?

I think QRadar is very complex. It's a distributed system and IBM QRadar has an all-in-one solution which is not like that distributed solution but it's a good product. IBM needs to consider the user interface because if we compare it with AlienVault, the AlienVault user interface is fantastic but the IBM QRadar user interface is very complex. They should focus on how to make it easier for the client.

IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

IBM QRadar is stable and scalable. 

What do I think about the scalability of the solution?

Scalability is good. If you use APS 25 GPS license you can change to 3000 EPS anytime. Also, you can integrate a distributed solution with the all-in-one deployment. If you have a very small organization, you don't need model 5000 EPS license so you can deploy all-in-one and then one day if your organization grows bigger, you can deploy a distributed system.

How are customer service and technical support?

We have our own system and network experts, forensic experts, and database expert so until now, we haven't had any issues that required us to contact their support. 

How was the initial setup?

The initial setup was complex. When it comes to the deployment, you can get it done in a day but if you want to fine-tune it can take a very long time. This isn't only for QRadar, but this applies to most solutions. 

It takes two or three people to deploy this product but if you want to do custom configuration then you need each and every part's expert. You need a network expert, forensic expert, and system expert. If you want an advanced system configuration you need many more people. If you only want to integrate this solution in your organization then two or three people is more than enough for the deployment.

What about the implementation team?

We deploy it for our clients.

What's my experience with pricing, setup cost, and licensing?

Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you.

What other advice do I have?

I would rate it an eight out of ten. Not a ten because of the complex interface. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Member at CIFAL Argentina
Real User
The scalability is awesome, because QRadar includes other solutions in the same console
Pros and Cons
  • "The scalability is awesome, because QRadar includes other solutions in the same console."
  • "The user interface needs improvement."

How has it helped my organization?

QRadar improved risk assessment and vulnerability, plus reduced staff.

What is most valuable?

The threat protection integration with other vendors.

What needs improvement?

The user interface needs improvement.

Network Breach

We have not suffered a network breach.

Events per Day

Our deployment collects nearly a 100 events a day. We often wield a backlog.

What do I think about the stability of the solution?

Stability is great.

What do I think about the scalability of the solution?

The scalability is awesome, because QRadar includes other solutions in the same console.

How is customer service and technical support?

I have not used technical support.

How was the initial setup?

I was not involved in the initial setup.

Which other solutions did I evaluate?

We evaluated Check Point, but went with IBM because of price.

What other advice do I have?

Most important criteria when selecting a vendor: Our customers need a cross of different units which make up a better solution for them.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.