Almost every feature is useful. In particular:
- Sense and detect fraud, both insider and advanced threats.
- Sense, track, and link significant incidents and threats.
Almost every feature is useful. In particular:
The tool is already automated in many ways, but there are some additional functions which should be automated, like sending an email, mobile notification, and integration of XFS.
Overall, I love this product.
Needs to be improved:
It's very helpful in meeting compliance monitoring and reporting (PCI DSS, PA DSS, ISO, SOX) requirements.
It captures and processes large volumes of event data, and scales to support hundreds of thousands of events in one unified database.
It also offers high-availability and disaster-recovery options.
There's very high quality in reporting suitable to all most all compliance requirements.
We use it mostly for purchases and regulatory requirements of that process. It would be good, therefore, if there was a standard configuration by default that was offered or proposed during install or configuration to meet PCI requirements, e.g. log archive duration set by default to one year for each device added.
The event Information display might prioritize event ID, user, destination, source, and date/time as the first info gathered in the report.
We're only using the Log Manager.
We are a system integrator and IBM QRadar is one of the security and monitoring products that we implement for our clients. It is used for monitoring applications such as Windows virtual desktop access (VDA) and computer-managed instruction (CMI).
We are using the platform version, which I like.
We have had problems with networking.
I have been using QRadar for about half a year.
We have not tried to scale because it is installed all in one machine.
The initial setup was easy and it took one day to install it.
Overall, I like this product and I think that the features are good enough.
I would rate this solution a seven out of ten.