Try our new research platform with insights from 80,000+ expert users
PeerSpot user
Cybersecurity Architecture and Technology Lead at Appxone
Consultant
Top 20
Can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent.
Pros and Cons
  • "Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure."
  • "AI is superb but need improvements."

What is our primary use case?

Find the malicious activity via filter, don't rely on the rules which trigger the offenses and fix the suspicious activities.

How has it helped my organization?

Gaining application visibility and anomaly detection helping IT personnel to quickly identify meaningful deviations. For example, QRadar SIEM can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent with historical, moving-average profiles and seasonal usage patterns.

What is most valuable?

Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure, helping organizations detect and remediate threats often missed by other security solutions. These threats can include inappropriate use of applications; insider fraud; and advanced, “low and slow” threats easily lost in the “noise” of millions of events..

What needs improvement?

Artificial Intelligence is superb, QRadar correlate the events smartly and remove the same events but need improvements.

Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.

For how long have I used the solution?

One to three years...

What do I think about the stability of the solution?

No issues.

How are customer service and support?

Very good

Which solution did I use previously and why did I switch?

Mcafee, switched due to the bad correlation of data.

How was the initial setup?

It was straightforward

Which other solutions did I evaluate?

Splunk and Logrhythm..

What other advice do I have?

QRadar also supports UBA which is a fantastic feature to detect user's malicious activities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Shaikh Jamal Uddin - PeerSpot reviewer
Shaikh Jamal UddinCybersecurity Architecture and Technology Lead at Appxone
Top 20Consultant

you need more time and knowledge to completely understand about QRadar SIEM.

senior0997 - PeerSpot reviewer
Senior Field Manager at a security firm with 11-50 employees
Reseller
Good scalability and straightforward setup, all in all, a good solution
Pros and Cons
  • "It's quite scalable. We have upgraded some solutions from 1000 APS up to 3500 APS to 5000 APS. It's a good solution, they have no scalability issues."
  • "I would like for them to develop a detection management solution. It does not have a detecting management solution in it, you have to buy it as it is, on top of the extended solution."

What is our primary use case?

It is a requirement for all of the banks to have a security solution in Pakistan. That is the reason most of the banks are using it. In the last one and a half years, Pakistani companies are taking security very seriously, so for that reason, they evaluate these solutions. All in all, it's a good solution. 

What needs improvement?

I would like for them to develop a detection management solution. It does not have a detection management solution in it, you have to buy it as it is, on top of the extended solution. 

What do I think about the scalability of the solution?

It's quite scalable. We have upgraded some solutions from 1000 APS up to 3500 APS to 5000 APS. It's a good solution, they have no scalability issues.

How was the initial setup?

The initial setup was straightforward. The deployment time depends on each customer. We have customers who have different infrastructures and their deployments are quite different. If we rack and stack it, around two, three days, maximum a week, but configuration and optimization take up to somewhere between six months and one year.

What other advice do I have?

I would rate it an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
PeerSpot user
IT Manager at a comms service provider with 1,001-5,000 employees
Real User
Contextual and threat-based incident management.

What is most valuable?

  • Paradigm shift, security intelligence 2.0
  • Contextual-based incident management
  • Threat-based incident management
  • A single management console to handle all the data
  • Ease of use
  • Existing integration capabilities
  • Out-of-the-box reports
  • Parser development

How has it helped my organization?

It has helped us in the reduction of VPN frauds via the active monitoring of various frauds.

What needs improvement?

  • There is a scope of improvement in the orchestration layer, such as the SecOps from RSA. RSA Security Analytics bundles their offering with their SecOps (a subset of Archer - Risk Governance tool). This gives them a competitive edge.
  • The reporting and dashboard capabilities require a bit of improvement in terms of fine tuning and bifurcation for the technical and management reports.

For how long have I used the solution?

I have used this solution for four years.

What do I think about the stability of the solution?

There were no stability issues.

How is customer service and technical support?

I would give technical support a rating of 9/10.

How was the initial setup?

The setup was straightforward and the deployment was easy.

What's my experience with pricing, setup cost, and licensing?

The pricing policy is a bit on the higher side. IBM offers discounts when applicable.

Which other solutions did I evaluate?

We looked at other solutions such as RSA enVision and HPE ArcSight.

What other advice do I have?

Trust it, test it, and deploy it.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user634860 - PeerSpot reviewer
Cyber Security Engineer
Vendor
The most valuable feature is the ability to get the logs and analyze them.

What is most valuable?

The most valuable feature is the ability to get the logs and analyze them. These logs help us in terms of analyzing and actually using Watson on them. It's a pretty great tool for intelligence. I think it is really a great product.

How has it helped my organization?

To be able to get the logs and analyze them has improved the way my organization functions. You can see where the source destination is coming from. You can actually see the data and pause the dashboard. It actually helps you to analyze the data the way you are supposed to. Nobody else is doing that right now.

What needs improvement?

I don't have any problems with the solution right now. As I play with the tools, then I will actually come up with different ideas.

I was able to help out with IBM Guardium version 10. I was helping out with a couple of developers who actually developed the application itself.

I want to see more integration between QRadar and other applications like BigFix and a couple of other tools and applications out there. There are a lot of applications out there. QRadar security intelligence might be one of the best right now.

What do I think about the stability of the solution?

There were no stability issues with QRadar. We've had a couple of stability issues with all the applications that I run. I don't want to mention names.

How is customer service and technical support?

I’ve used technical support, and they were OK. I used to work for IBM.

How was the initial setup?

I was involved in the initial setup. It was straightforward and not complex.

Which other solutions did I evaluate?

I work as security engineer for the Department of Justice. We test hundreds of applications. I actually see which ones work best for the infrastructure.

What other advice do I have?

I would suggest QRadar. The security intelligence is one of the best right now.

When looking for a vendor, I want to be able to win them. I want them to accept the fact that I’m looking for a product for what I am doing and I have a couple of requirements.

From there, I can actually tell them what they need to do, or what I need to do, in the environment.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user634782 - PeerSpot reviewer
Security Analyst at a government with 10,001+ employees
Vendor
For vulnerabilities, you see a popup on the screen. We do not have to look for it. It is pushed to us.

What is most valuable?

It's easy for us to see what's happening in the environment. It's very good to see the logs and the analytic stuff.

How has it helped my organization?

We can see the vulnerabilities much easier with the product. You see a popup on the screen. We do not have to look for it. It is pushed to us.

What needs improvement?

It is very expensive; very expensive.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

I think it is scalable.

How is customer service and technical support?

We have used technical support. They are very good and very nice.

Which other solutions did I evaluate?

We didn't evaluate any alternatives. We have yearly talks with the IBM consulting team. We look at the trends.

What other advice do I have?

When choosing a vendor, we look for a stable and trustworthy company. I think QRadar is the best solution you can get.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Security Consultant at a tech services company with 11-50 employees
Consultant
It can collect different types of security feeds and correlate them in real-time with your logs.

What is most valuable?

The most valuable features are:

  • Auto update: QRadar will download new logs from the database on the supported security device, so that it will automatically normalize the new log format and you will not need to rewrite all your rules/offenses again.
  • X-Force/TAXII feed: QRadar can collect different types of security feeds and correlate them in real-time with your logs.

  • Search engine: QRadar is like Excel, i.e., you can add rows and filter like your daily office work, without writing any scripts. So level 1 support also can handle this type of jobs.

How has it helped my organization?

You will learn something that you don't know on the user/machine behaviour.

What needs improvement?

The dashboards and reports may need to improve. We need to export the CSV results to create a report by Excel.

For how long have I used the solution?

I have used this solution for three years.

What do I think about the stability of the solution?

It will slow down, when there are too many people doing a search at the same time, but that depends on your hardware and design.

What do I think about the scalability of the solution?

I did not encounter any scalability issues.

How is customer service and technical support?

You may need to allow remote support for them to help you, for troubleshooting the issues.

How was the initial setup?

The setup is complex, i.e., for the first setup. SIEM is not easy so as to enable logs without any performance issues and the deployment advisor is the key for the project.

What's my experience with pricing, setup cost, and licensing?

You only need to worry about the number of events per second and the number of flows per minute. Storage size is not an issue with QRadar.

Which other solutions did I evaluate?

We did evaluate other options. I think Splunk is the second-best option.

What other advice do I have?

If you have an experienced group of security members, then you may not at all need the advisor for the product. If not, then you will have to find the path to build your team, so as to become more knowledgeable.

Disclosure: My company has a business relationship with this vendor other than being a customer: We are business partners.
PeerSpot user
it_user140676 - PeerSpot reviewer
Information Security Consultant at a tech services company with 51-200 employees
Consultant
Although it provides incident management of the alerts it produces, this could be improved to allow more restrictions

What is most valuable?

IBM Security QRadar has many valuable features. One of the most valuable features of IBM Security QRadar is the ease of extracting information from raw logs/events, whether the log source sending the events is supported by IBM or not (for example, a custom in-house application) and use this information in creating searches, correlation rules, reports, and dashboards. Another feature is scalability; scaling up a deployment to support more events per second is made simple just by “linking” new appliances to the main deployment through configuration steps that only take minutes to complete. I do not know if I can call this a feature, but a “general” feature of QRadar is that it does not require highly technically skilled personnel to administer. The dashboards and configurations through the web UI are easy to read, understand, and change.

What needs improvement?

Although QRadar provides incident management of the alerts it produces, this area could use a little improvement to allow more restrictions on who can close alerts and easily updating alerts with and reading text templates.

For how long have I used the solution?

I have used IBM Security QRadar for nearly two years now. I use it as a user in my organization’s Managed Security Services division where we monitor clients’ environments. I also work with it as an implementer to deploy and customize it for clients.

What was my experience with deployment of the solution?

Any deployment will have issues. The issues that I encounter with deploying QRadar are raised with IBM Support and are usually solved quickly through applying patches or changing individual files to fix the web GUI issue.

What do I think about the stability of the solution?

The causes of stability issues are usually not QRadar, but of misconfigured devices/log sources (for example, sending debug events to QRadar that results in millions of events in a short period of time). However, if a deployment is done correctly, QRadar stays stable.

What do I think about the scalability of the solution?

No, I did not face issues with scalability. One of the great features of QRadar is the ease of scalability. A license upgrade is simply done by purchasing it and applying it through the GUI which only takes minutes to. If an organization wants a larger expansion, all that it has to do is to buy the required hardware with QRadar installed, and “link” it to the main deployment through steps that also take minutes. This new hardware will provide the extra events per second or flows per minute capabilities required for the expansion.

How are customer service and technical support?

IBM provides support in various regions in the world. The level of technical support is good. Once a support ticket is open, the support team tries to fix it directly or passes it on to higher levels, and will involve the QRadar development team if required.

Which solution did I use previously and why did I switch?

No, I did not use a separate solution, although I have read and heard about different solutions from the various clients I have met with. Clients switch to using QRadar because they say that maintaining and administering other solutions becomes a hassle and requires trained personnel. Another reason clients switch to using QRadar because of cost.

How was the initial setup?

The initial setup of QRadar is straightforward. From the installation perspective, IBM provides one ISO file that can be used to install any of the QRadar components, with the activation key deciding which components to install. From the deployment perspective, QRadar has the ability to automatically detect many log sources sending logs. The out-of-the-box dashboards, searches, reports, and correlation rules allows QRadar to start displaying intelligence and insight on devices, network statistics, authentication, and many more, and to start alerting on offenses and policy violations automatically. Coupling this with the automatically detected log sources, a demonstration of QRadar can only take a few hours from the installation, to automatically detecting a log source such as firewall logs, to getting alerts on excessive firewall denies, port scans, etc.

What other advice do I have?

The advice I would give to others is to work with the implementation team to properly fine tune the out-of-the-box “building block rules” and to enter their network hierarchy in QRadar in order for it to give best results and reduce false positive alerts.
Disclosure: My company has a business relationship with this vendor other than being a customer: We're a value added services security company that is a distributor of Q1-Labs QRadar (now IBM).
PeerSpot user
it_user279483 - PeerSpot reviewer
it_user279483Network Engineer at a financial services firm with 10,001+ employees
Real User

I am taking IBM Security Qradar exam c2150-400 early Aug 2015.

reviewer1022949 - PeerSpot reviewer
Team Lead & Principal Software Engineer at a tech services company with 51-200 employees
Real User
Stable SIEM that offers strong visibility
Pros and Cons
  • "It is a very good SIEM."
  • "I think it's a very stable product that provides much more visibility than the other product."
  • "I would like for Yara to be supported by all components."

What is our primary use case?

I deploy the IBM QRadar for many organizations, and I've been performing analyses for those organizations as well.

These organizations use the tool for monitoring of their environment. It's a basic SIEM product. So we just log each and every data source, perform an analysis, and create rules. We also create advanced use cases to cater the advanced threat(s).

What is most valuable?

I am unable to pick one, every component is valuable. It is a very good SIEM.

What needs improvement?

I would like for Yara to be supported by all components. 

For how long have I used the solution?

I have been working with this product for the last five years.

What do I think about the stability of the solution?

I think it's a very stable product that provides much more visibility than the other product.

What do I think about the scalability of the solution?

You can scale the architecture of the QRadar easily by adding licenses.

Small to medium-sized organizations would require one to two people for maintenance while man power for large organizations would be determined by the architecture. 

How are customer service and support?

Customer support needs some improvement as there have been a few cases where we were unable to reach them in time.

How was the initial setup?

I didn't find it to be complex. I think IBM QRadar has a more user-friendly GUI that helps your team work easily within it. Deployment for an all in one will take four to five hours but can vary depending on environment size.

What about the implementation team?

Our in-house team assists our customers with deployment. Our customers are the main POC and we are able to deploy into their environment, make necessary integrations, and create the rules.

What's my experience with pricing, setup cost, and licensing?

Licensing can be costly depending on your architecture.

What other advice do I have?

You receive alerts for misconfigurations which allows your administer to easily reconfigure any issues. 

The organizations themselves are able to monitor all of their information regarding their team including what attacks they are facing on a daily bases.

I would rate this an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.