Try our new research platform with insights from 80,000+ expert users
it_user575124 - PeerSpot reviewer
Sr. Security Engineer at a tech services company with 11-50 employees
Real User
We use it to create use cases and review offenses. One of the valuable features is its correlation engine.

What is most valuable?

  • User-friendly
  • Easy to deploy
  • Easy to create use cases
  • Easy to review an offense
  • Its correlation engine is one of the best

How has it helped my organization?

I usually work on the deployment and fine-tuning of this product. However, I have some operational experience as well. For instance, you can simply audit all the IT equipment in your environment, such as the firewall, the IPS, and the Active Directory (AD) server.

What needs improvement?

It should have built-in blocking capability.

For how long have I used the solution?

I have used this solution for four years.

Buyer's Guide
IBM Security QRadar
February 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the stability of the solution?

On a scale of 100, it is 95% stable.

What do I think about the scalability of the solution?

I did experience some scalability issues in one organization.

How are customer service and support?

The technical support is excellent.

Which solution did I use previously and why did I switch?

We were not using any other solution previously. This was my first solution. I am still working on it. I also have experience with McAfee Nitro and LogRhythm.

How was the initial setup?

The setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing will definitely vary according to your EPS, but it is worth spending money on this product.

Which other solutions did I evaluate?

We looked at other solutions, such as McAfee Nitro and LogRhythm.

What other advice do I have?

Work on sizing as much as you can so you can avoid any issues after deployment. You should also fulfill hardware requirements for this product. Otherwise, you will not get its full functionality.

Disclosure: My company has a business relationship with this vendor other than being a customer: I am a vendor.
PeerSpot user
reviewer1022949 - PeerSpot reviewer
Team Lead & Principal Software Engineer at a tech services company with 51-200 employees
Real User
Stable SIEM that offers strong visibility
Pros and Cons
  • "It is a very good SIEM."
  • "I think it's a very stable product that provides much more visibility than the other product."
  • "I would like for Yara to be supported by all components."

What is our primary use case?

I deploy the IBM QRadar for many organizations, and I've been performing analyses for those organizations as well.

These organizations use the tool for monitoring of their environment. It's a basic SIEM product. So we just log each and every data source, perform an analysis, and create rules. We also create advanced use cases to cater the advanced threat(s).

What is most valuable?

I am unable to pick one, every component is valuable. It is a very good SIEM.

What needs improvement?

I would like for Yara to be supported by all components. 

For how long have I used the solution?

I have been working with this product for the last five years.

What do I think about the stability of the solution?

I think it's a very stable product that provides much more visibility than the other product.

What do I think about the scalability of the solution?

You can scale the architecture of the QRadar easily by adding licenses.

Small to medium-sized organizations would require one to two people for maintenance while man power for large organizations would be determined by the architecture. 

How are customer service and support?

Customer support needs some improvement as there have been a few cases where we were unable to reach them in time.

How was the initial setup?

I didn't find it to be complex. I think IBM QRadar has a more user-friendly GUI that helps your team work easily within it. Deployment for an all in one will take four to five hours but can vary depending on environment size.

What about the implementation team?

Our in-house team assists our customers with deployment. Our customers are the main POC and we are able to deploy into their environment, make necessary integrations, and create the rules.

What's my experience with pricing, setup cost, and licensing?

Licensing can be costly depending on your architecture.

What other advice do I have?

You receive alerts for misconfigurations which allows your administer to easily reconfigure any issues. 

The organizations themselves are able to monitor all of their information regarding their team including what attacks they are facing on a daily bases.

I would rate this an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Security QRadar
February 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Founder at a university with 11-50 employees
Real User
Stable, easy to set up, and has good support
Pros and Cons
  • "I think the QDI is very good."
  • "The threat detection needs improvement, they have many false positives."

What is our primary use case?

This product helps to build a strong architecture, which is important to avoid problems.

What is most valuable?

I think the QDI is very good.

What needs improvement?

The biggest drawback of this solution is the price.

The threat detection needs improvement, they have many false positives.

It is important to have good architecture. If you have problems and you don't have a strong architecture you, will have trouble with this solution.

For how long have I used the solution?

I have been using IBM QRadar for three years.

We are using version 7.4.3

What do I think about the stability of the solution?

It's a stable solution.

How are customer service and technical support?

We have many interactions with L2 support when we needed L3 support. I would rate technical support an eight out of ten.

How was the initial setup?

The initial setup is straightforward. We had no problems.

It took approximately a month to deploy.

What's my experience with pricing, setup cost, and licensing?

This price is a little high, so it's an expensive product. It is a good solution but not a cheap one.

What other advice do I have?

I would rate IBM QRadar a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
General Manager at New System Engineering
Real User
A straightforward solution that minimizes the number of false positive errors
Pros and Cons
  • "It is a very optimized engine."
  • "It is very difficult to activate all of the network equipment, and it would help if it were made easier."

What is our primary use case?

We are a partner and provide this solution to our customers.

What is most valuable?

The most valuable feature is that it reports a very small number of false positives. It is a very optimized engine.

What needs improvement?

It is very difficult to activate all of the network equipment, and it would help if it were made easier. I would also like to see more integration with new devices.

For how long have I used the solution?

Ten years.

What do I think about the stability of the solution?

This is a very stable solution.

How are customer service and technical support?

The quality of technical support depends on the level. Level One support is very good, but if you have Level Two or Level Three then the support is not very reactive.

How was the initial setup?

The initial setup of this solution is not complex.

Deployment normally takes between one and three months.

What about the implementation team?

We have two engineers that are proficient in QRadar, and we handle the implementation for our customers.

Which other solutions did I evaluate?

One of my customers is a McAfee user and is in the process of replacing the solution with IBM QRadar.

What other advice do I have?

I would recommend this product. It is very simple to install, and not a complicated solution. IBM supplies regular software updates.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user923115 - PeerSpot reviewer
Cloud Security Architect at Nordcloud Oy
Real User
It's a state-of-the-art product for security information and event management
Pros and Cons
  • "It's a state-of-the-art product for security information and event management (SIEM)."
  • "There are a lot of great out-of-the-box features included."
  • "The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery."
  • "The released patch quality is poor. IBM should test those patches on their side, not on the client's side."

What is our primary use case?

It is under a non-disclosure agreement (NDA).

How has it helped my organization?

  • It helps because you don't need an army to execute the project when you do the PoC, and when finally going to production. 
  • The abundant out-of-the-box features which are operating wonderfully.

What is most valuable?

  • It's easy to set up.
  • There are a lot of great out-of-the-box features included.
  • It's a state-of-the-art product for security information and event management (SIEM).

What needs improvement?

  • Slow response sometimes and a not-so-helpful staff there. So make the support better, and you could succeed even more.
  • The released patch quality is poor. IBM should test those patches on their side, not on the client's side. So, there are a lot of improvement to do. 
  • I would appreciate if IBM could create another more intuitive, easier way (intuitive UI) to perform advanced searches rather that just counting on regular expressions.

For how long have I used the solution?

One to three years.

How is customer service and technical support?

The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery.  

They are sometimes slow to respond and unhelpful.

What other advice do I have?

I highly recommend this product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user934623 - PeerSpot reviewer
Senior Information Security Analyst at a financial services firm with 501-1,000 employees
Real User
Helps us to discover any threats with their alerts and tracking
Pros and Cons
  • "It helps us discover any threats with their alerts and tracking."
  • "The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not way straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference."

How has it helped my organization?

It helps us discover any threats with their alerts and tracking.

What is most valuable?

QNI is the most valuable feature. 

What needs improvement?

I would like for them to lower the price. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

The system is quite stable, so far we haven't had any problems. Although the initial supply of the appliance was a bit faulty, the processor kept on failing. We were within the warranty so they supplied new ones. After loading logs, the system is very stable and nothing to worry about.

What do I think about the scalability of the solution?

It's very scalable. There are currently five users. We may still onboard more users depending on the requirements and their departmental level.

We do plan to increase usage. 

How are customer service and technical support?

Their support is excellent, they are available when we need them. I'm satisfied so far.

How was the initial setup?

The initial setup wasn't exactly straightforward but the vendor who set it up for was helpful. It was very straightforward with their help. The deployment took two months. 

We require two admins for maintenance. 

What about the implementation team?

We used our own people and the certified IBM vendor for the implementation. We had a very good experience with them. 

What's my experience with pricing, setup cost, and licensing?

We do licenses once a year. 

Which other solutions did I evaluate?

We also looked at LogRhythm.

What other advice do I have?

I would advise someone considering this solution to write down your use cases and evaluate them with the vendor. Evaluate the best solution based on your use cases because you are the ones who are going to use it. The vendor will try and implement and leave you with your problems.

If the solution meets your requirements and solves most of your problems, you're good to go. QRadar is the best solution we have. The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not always straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference. 

I would rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1593615 - PeerSpot reviewer
AVP - Security at a tech services company with 501-1,000 employees
Real User
Scalable, high visibility, and good technical support
Pros and Cons
  • "I have found visibility very helpful for analytics."
  • "This solution is on-premise and many customers are moving to the cloud base solution."

What is our primary use case?

IBM QRadar is typically deployed in a SOC environment for security monitoring. It is used for log and packet capturing. It has some supporting technology, such as data leakage prevention and data encryption.

What is most valuable?

I have found visibility very helpful for analytics.

What needs improvement?

This solution is on-premise and many customers are moving to the cloud base solution.

For how long have I used the solution?

I have been using this solution for approximately one year.

What do I think about the stability of the solution?

I have not had any complaints from my clients about the stability of the solution.

What do I think about the scalability of the solution?

The solution is scalable. Our customers that are using this solution are mainly large-sized companies, such as the government.

How are customer service and technical support?

The technical support is very good.

What other advice do I have?

Nowadays cloud stack security is very good. Some of my customers are planning to build their data center over the cloud, or implement cloud-based services using some of the beneficial services, such as threat intelligence services.

I rate IBM QRadar a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
it_user956985 - PeerSpot reviewer
Sr. Security Engineer at OmnitechIT
Real User
Stable security both in-house and for our customers
Pros and Cons
  • "In addition to using this solution for our security operations center, we are using it for our other customers."
  • "It needs more resilience and functionality."

What is our primary use case?

Our primary use case for this solution for the management of our security services, and our NOC (Network Operations Center) services.

How has it helped my organization?

In addition to using this solution for our security operations center, we are using it for our other customers.

What needs improvement?

It needs more resilience and functionality. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

My impressions of the stability is that it is good.

What do I think about the scalability of the solution?

The scalability is good. Internally we have many customers, but we offer this as a specific consultancy service. I do not know with certainty the number of users for this product in our customer environment.

What about the implementation team?

We used a consultant to assist us with the implementation of this solution.

What's my experience with pricing, setup cost, and licensing?

Our licensing costs for this solution is on a yearly basis.

What other advice do I have?

I would rate this product eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.