Try our new research platform with insights from 80,000+ expert users
reviewer952638 - PeerSpot reviewer
Information Security Leader at a computer software company with 1,001-5,000 employees
Real User
Manage and review incidents easily
Pros and Cons
  • "The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents."
  • "The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."

What is our primary use case?

We use IBM QRadar for user behavior analytics and incident handling.

What is most valuable?

The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents.

What needs improvement?

The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity.

For how long have I used the solution?

I have been using IBM QRadar for four years.

Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.

What do I think about the scalability of the solution?

We have three customers using it and these customers have 100 to 300 users.

How are customer service and support?

Getting support sometimes takes time.

How was the initial setup?

The initial setup was quite straightforward.

We had the complete deployment and it was up and running in half a day.

What about the implementation team?

You can implement it by yourself.

What other advice do I have?

I would recommend IBM QRadar to other people who want to start using it.

On a scale of one to ten, I would give QRadar a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Joao Manso - PeerSpot reviewer
CEO at REDSHIFT CONSULTING
Reseller
Top 10
Very powerful with plenty of features and capabilities
Pros and Cons
  • "The product has plenty of features and capabilities."
  • "The usability of interfaces could be improved."

What is our primary use case?

We use this solution both in our company and those of our clients. We are resellers of QRadar. 

What is most valuable?

Curator is the leader of teams in the market. It's a product with plenty of features and capabilities. It's a very powerful solution.

What needs improvement?

The usability of interfaces could be improved and the solution could have better correlation services, as well as faster and updated intelligence interfaces.

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

Technical support has room for improvement.

How was the initial setup?

The initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

Licensing costs are reasonable.

What other advice do I have?

I rate the solution nine out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Buyer's Guide
IBM Security QRadar
January 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
it_user984276 - PeerSpot reviewer
Senior Analyst at a tech services company with 201-500 employees
Real User
We can add anything to it, as it is a good companion to other tools
Pros and Cons
  • "It integrates very easily with other solutions. The solution is flexible. We can add anything to it, as it is a good companion to other tools."
  • "It's user-friendly when compared to other products."
  • "They should introduce some automation into the product."
  • "There was some complexity in the initial setup due to bandwidth issues."

What is our primary use case?

The primary use case is for insurance and product manufacturing. We use it to create rules and Windows firewalls.

How has it helped my organization?

Before implementing this solution, we had no security. After integrating many thing, we received reports letting us know what is compromised.

What is most valuable?

It's user-friendly when compared to other products. New users can easily understand the product.

It integrates very easily with other solutions. The solution is flexible. We can add anything to it, as it is a good companion to other tools.

What needs improvement?

They should introduce some automation into the product.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It has good stability. If there is an issue, we restart the box.

What do I think about the scalability of the solution?

It is easily scalable.

Our team has nine people.

How are customer service and technical support?

The technical support is good.

Which solution did I use previously and why did I switch?

Previously, I was using McAfee Nitro. Comparing with McAfee, QRadar is user-friendly and easy to use.

How was the initial setup?

There was some complexity in the initial setup due to bandwidth issues.

The implementation took two to three days.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Solutions Architect at Micro Strategies
MSP
It has helped us with our response time to threats
Pros and Cons
  • "It showed us where weaknesses were in our environment, so we could actively target those patches first."
  • "Do your research before implementing it, because it is tough to implement."

How has it helped my organization?

It has helped us with our response time to threats. It also showed us where weaknesses were in our environment, so we could actively target those patches first.

What is most valuable?

It works well with IBM products.

What needs improvement?

QRadar's issue is it needs to add behavioral analytics. The product's behavioral engine is weak. It just uses algorithms. It should an equation that is cursively applied. This will provide true behavior.

Network Breach

I have only once experienced a network breach with QRadar. QRadar detected the breach within an hour and the triage investigation took another four hours. Overall, it took about six hours to remediate everything. 

Efficiency of Security Team

With QRadar, everything runs better.

What do I think about the stability of the solution?

It is a very stable product. I cannot say anything bad about it.

What do I think about the scalability of the solution?

It is very scalable. It does a good job.

How are customer service and technical support?

Their Level 1 support is weak, but the support that we worked with to set up our feature sets is good. Their Level 2 and 3 support are good to work with overall, like most companies.

We contacted their technical support about adding more feature sets. We worked with their engineers to set up the feature sets that we wanted to expand upon and deliver the product, which they did.

Which solution did I use previously and why did I switch?

We originally used ArcSight, which got cumbersome and expensive. Also, HPE ruins everything that it touches. Therefore, we moved to QRadar.

How was the initial setup?

It is a pain to set up; basically it is not that easy.

Which other solutions did I evaluate?

We evaluated LogRhythm and Splunk. 

  • LogRhythm had limitations.
  • Splunk was never designed to be a SIEM.

What other advice do I have?

Do your research before implementing it, because it is tough to implement.

Most important criteria when selecting a vendor: support. I say this to every vendor.

It is not always about pricing, which is nice when we start, but when the crap hits the fan. I want the vendor to be there with me. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Partner at a tech services company with 1-10 employees
Real User
It has a high degree of interconnection with other systems
Pros and Cons
  • "We have the abilities to monitor each instance which originates on the process along with the performance of each department."
  • "For the common needs of clients to fulfill requirements, a real integration with Blueworks Live (BPA modeling tool also from IBM) and a more suitable BPM on cloud solution for midsize customers."

What is our primary use case?

  • Origination process in banks.
  • Insurance claims on insurance companies.

How has it helped my organization?

We are a consulting company, but our clients use it to ensure that the process has been followed. We have the abilities to monitor each instance which originates on the process along with the performance of each department. In addition, clients can enter detail in at the instance level.

What is most valuable?

  • UI capabilities
  • High degree of interconnection with other systems.
  • The business activity monitoring on the part of the solution.

What needs improvement?

For the common needs of clients to fulfill requirements, a real integration with Blueworks Live (BPA modeling tool also from IBM) and a more suitable BPM on cloud solution for midsize customers.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

How are customer service and technical support?

The technical support is good enough.

Which solution did I use previously and why did I switch?

We previously used Oracle BPM. We switched for a BPM project with IBM, because it has a better tool at the same price level range.

How was the initial setup?

Always the sizing on any BPM project is challenging, as with any BPM tool.

What's my experience with pricing, setup cost, and licensing?

IBM is a Ferrari if you are beginning with a concept. If it will be a pilot project, take a look at Red Hat Process Automation Manager or jBPM. Be realistic about the users' quantity. A good approach would be to begin with an On Cloud subscription, then later on do a more exact sizing.

Which other solutions did I evaluate?

We evaluated Red Hat and Bonita. We now prefer Red Hat for the price.

What other advice do I have?

Ensure you have the functional skills on BPM and the technical skills on IBM BPM.

We used to be IBM partners, but are not anymore. Now, we are Red Hat partners.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user634779 - PeerSpot reviewer
Security Intelligence at a tech services company with 10,001+ employees
MSP
We can build interactive dashboards around it. Mathematical operators currently cannot be used within the reference maps.

What is most valuable?

The most valuable feature that we found, especially this year, was the ability to build apps over it. Basically, the platform has opened up and we can now customize it, as per our needs and requirements. We can build interactive dashboards and other interesting things around it.

How has it helped my organization?

We are using QRadar to solve our business problems and the IT operation requirements. We are fine tuning the processes that are laid from the InfoSec perspective, such as to detect unauthorized changes happening across the IT environment or the business problems, namely the password sharing issues, which are not easy to detect otherwise.

What needs improvement?

In future versions, the various features that we would like to see are pretty much in line with what QRadar is coming up with, like this IBM QRadar UBA version 2.0 or support for STIX/TAXII. Basically, we have similar milestones there.

There are a few technical requirements that we have opened feature requests for, such as some of our complex use cases that need mathematical operators to be used within the reference maps. That's currently not available.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

There were no scalability issues. With this Event Processor and Data Node concept, I think it is highly scalable.

How is customer service and technical support?

We have been facing a few technical issues and we are working with the technical support and the development team to resolve them.

Sometimes we get a really good response and at times, some of the issues have been floating around for a lot of time. But our IT resources have been assigned for the same and we hope that they should be resolved easily.

How was the initial setup?

I was involved in the setup; it was pretty straightforward. Once you understand the overall architecture, it is pretty much easy to install and work upon.

What other advice do I have?

It should be implemented by the best professionals available within IBM. It is really important to have a clean base installation, so that you can build things on the top of it.

When we are selecting a vendor, first and foremost, we look for the stability of the vendor, and what level of resources they are investing in their research and development. These are a couple of things that we look for while selecting a vendor and of course, the kind of resources we are looking for to get certain engagement and make sure those resources are aligned.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer594315 - PeerSpot reviewer
Assistant IT Manager at a insurance company with 1,001-5,000 employees
Real User
A SIEM solution that's easy to use, but the price could be better
Pros and Cons
  • "I like that it's easy to use and the performance is good."
  • "It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation."

What is our primary use case?

I use QRadar for cybersecurity defense, operation, and to improve performances.

What is most valuable?

I like that it's easy to use and the performance is good.

What needs improvement?

It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation.

For how long have I used the solution?

I have been using IBM QRadar for four years.

What do I think about the stability of the solution?

IBM QRadar is a stable solution, but it could be more stable.

What do I think about the scalability of the solution?

IBM QRadar is a scalable solution. We have about 100 users at the moment.

How are customer service and technical support?

I remember that I opened ten or 20 cases to receive support from IBM over three years.

How was the initial setup?

The initial setup and deployment are very easy. I think it took us about a month to implement this solution. We have a team of two, one manager and one technical, to deploy, manage, and maintain this solution.

What about the implementation team?

We installed this solution with the help of a consultant.

What's my experience with pricing, setup cost, and licensing?

The price could be better. I bought a subscription for three years. 

What other advice do I have?

On a scale from one to ten, I would give IBM QRadar a seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
General manager at a tech services company with 201-500 employees
Real User
Good detect rate with a small number of false positives, and support resolves issues quickly
Pros and Cons
  • "The detection rate is good and the false positive rate is low."
  • "They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required."

What is our primary use case?

We used this product as a SIEM, for information security.

How has it helped my organization?

This product collects all of the system logs and analyzes them to see if there are any security threats, or there have been any attacks. If there are, then it will alert the administrator to take the appropriate actions.

What is most valuable?

The detection rate is good and the false positive rate is low. Having a low false-positive rate is good because it means that if an alert happens then it is very likely a real attack.

QRadar is quite flexible. Out of ten, I would rate flexibility a nine.

What needs improvement?

They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required.

A nice enhancement would be the incorporation of more artificial intelligence and machine learning capabilities.

For how long have I used the solution?

We have used IBM QRadar for approximately two years.

What do I think about the stability of the solution?

I would rate the stability a ten out of ten. We have had the occasional bug or other issue but once we report it to IBM, they give us a resolution quite quickly.

How are customer service and technical support?

Technical support is quick to resolve issues.

Which solution did I use previously and why did I switch?

We developed our own application to use as a SIEM, but we switched to QRadar.

How was the initial setup?

The initial setup is complex and the deployment takes approximately three months.

What's my experience with pricing, setup cost, and licensing?

It would be great if this product were cheaper.

Which other solutions did I evaluate?

We did evaluate other options before selecting this product.

What other advice do I have?

Within the past year, IBM developed a SaaS version of QRadar, which is a nice option.

My advice for anybody who is considering this solution is to implement the latest IBM offerings together. QRadar is just one of the products, and multiple products can be combined to create the best solution for their needs.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.