We use the product to customize rules and detect malicious behavior.
Analyst at a hospitality company with 10,001+ employees
Has real-time detection feature but is not as flexible as Splunk
Pros and Cons
- "The tool's most valuable feature is real-time detection."
- "The solution is not as flexible as Splunk."
What is our primary use case?
What is most valuable?
The tool's most valuable feature is real-time detection.
What needs improvement?
The solution is not as flexible as Splunk.
For how long have I used the solution?
I have been working with the product since 2016.
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
How are customer service and support?
I haven't contacted technical support yet.
Which solution did I use previously and why did I switch?
I worked with Splunk before IBM Security QRadar.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is based on the EPS model.
What other advice do I have?
I prefer Splunk since it gives a lot more freedom and flexibility. I rate the overall solution a six out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Aug 2, 2024
Flag as inappropriateSolutions Architectv at Smarttech247
Useful for threat hunting, investigation, and triage analysis
Pros and Cons
- "The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons."
- "Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances."
What is our primary use case?
We utilize the product for our Security Operations Center operations. Additionally, we extend its use to our customers, employing it for tasks such as threat hunting, investigation, and triage analysis.
What is most valuable?
The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons.
Its scalability is also important. It is also compatible with ISO 27001, DSS API, and various certifications.
As part of our security infrastructure, this tool excels in detecting a wide range of attacks. Its responsiveness surpasses that of alternative solutions. Moreover, the user-friendly interface greatly benefits our analysts. The product is helpful in anomaly detection scenarios.
Additionally, we leverage out-of-the-box content and libraries within the IBM ecosystem. Its user behavior analysis helps us to ensure that our customers are protected.
Correlation plays a pivotal role in our security strategy. It helps us to analyze logs from different sources. This process helps to correlate logs from endpoints.
What needs improvement?
Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances.
Our current query language (KQL) serves its purpose, but there's room for improvement. Consider introducing a more human-friendly language to streamline analyst training. Analysts could then express queries in a manner akin to human language. This change would expedite processes, making it easier for new analysts to adapt.
For how long have I used the solution?
I have been working with the product for five years.
What do I think about the scalability of the solution?
I rate the tool's scalability an eight to nine out of ten.
How are customer service and support?
Troubleshooting delays have been a recurring challenge. Occasionally, responses take two to three days, leading to escalations. While their website’s knowledge base is commendable, troubleshooting scenarios demand more time. My observation is that they may be understaffed.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My company has customers using Splunk and Chronicle SIEM. When comparing Splunk and IBM Security QRadar, they indeed offer similar features, but their business models differ. Chronicle SIEM predominantly operates in the cloud. However, we cannot offer the cloud model if a customer prefers an on-premises solution.
Splunk and IBM Security QRadar both cater to diverse deployment preferences. Splunk boasts a slightly more robust correlation engine than IBM Security QRadar. Splunk tends to be marginally more expensive than IBM Security QRadar.
How was the initial setup?
The number of log sources significantly impacts deployment complexity. The process becomes more complicated for environments with 50 log sources compared to those with fewer sources (e.g., 20 or 10).
Each log source requires a connection to IBM, a task that can take several days or hours, depending on its complexity.
On average, the entire deployment process spans six to eight weeks.
What's my experience with pricing, setup cost, and licensing?
The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it.
What other advice do I have?
I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Buyer's Guide
IBM Security QRadar
December 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
SOC Manager at ALEXBANK
Highly scalable, excellent learning modules, but would like to see a better user interface
Pros and Cons
- "The most valuable feature is the machine learning module."
- "I would like to see some artificial intelligence and alternative solutions."
What is our primary use case?
Our primary use case is in the banking industry in two banks here in Egypt. We generally are monitoring the user behavior of the employees, For example, working after working hours, and signing into the machines after working hours.
What is most valuable?
The most valuable feature is the machine learning module.
What needs improvement?
I would like to see the interface improved along with the tuning and any adjustments when it comes to maintenance. It is not straightforward. I would also like to see some artificial intelligence and alternative solutions.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for almost five years now.
What do I think about the stability of the solution?
I would give stability an eight on a scale of one to ten.
What do I think about the scalability of the solution?
The scalability is not a problem and we have above three thousand in our organization.
How was the initial setup?
The initial setup is extremely easy and straightforward.
What about the implementation team?
The deployment took around two to three days and we did it ourselves in-house. We simply downloaded the application and went from there following the deployment process.
What was our ROI?
We are seeing a return on investment when it comes to profiling the employees.
What's my experience with pricing, setup cost, and licensing?
The pricing is higher but cheaper than others and there are no additional costs.
Which other solutions did I evaluate?
We looked at ArcSight but the cost is more expensive than IBM. ArcSight did have the artificial intelligence model.
What other advice do I have?
I would recommend tuning it to the maximum before going live. I would rate IBM QRadar User Behavior Analytics a seven on a scale of one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Global Security Engineering and Operations Director at a wellness & fitness company with 10,001+ employees
Correlates data across our global enterprise and integrates third-party solutions.
What is most valuable?
- The ability to correlate data across our global enterprise in near real time
- The ability to integrate a lot of third-party solutions
- The machine learning pieces with Watson, indicators of compromise, and utilizing that across the value stream
I look at the solution as the best-of-the-breed product. The fact that it can work with what everybody else is doing in the cyber landscape is really what gives it the edge.
How has it helped my organization?
The solution has improved the efficiency of our security team. These improvements prevent the need for more proactive security activities.
The improvements did not reduce our staff. It's funny, because IBM keeps on having this conversation about staff headcount. It probably sounds good to senior leadership, like to a CIO. The reality is that nobody's looking to decrease the number of staff who they are hiring.
We're looking at refocusing those resources and energy on being able to do additional, higher-value activities. It's more of the case that I don't need as many junior resources. I can focus on some of the things that are a little bit more important.
Our equipment collects billions of pieces of data. We're 100,000-plus EPS per second. The daily list of required investigations for the offenses is manageable.
We've had incidents in our environment. How long it takes QRadar to detect them is always a function of the rules being correlated, the people watching them, and pieces of that nature. I'd say it's in real time. The question is, when it comes to tuning, we want to know if it was tuned appropriately, so it's not lost in the pile of needles.
What needs improvement?
Room for improvement is more in relation to a lot of the features, the automation of incidents themselves, and being able to automate workflow responses.
Overall, I love the product. IBM usually puts good resources and talent behind things. What they fail to do is to bring all the security together and make sure everything inter-operates and creates one pane of glass.
Actually, I don’t want to say "one pane of glass" because we have seen other vendors do that. They fail miserably because they do not understand where people are coming from.
In terms of some of the right-click functionality that is within QRadar, it should work automatically for all the other IBM products. It shouldn't be something that customers develop. There are pieces in which they have to step back and get some of the foundational pieces.
There are pieces that I feel that IBM should do better. They own Guardium, they own AppScan, and they own some of these other pieces of the security infrastructure that need to relate to QRadar or to Watson. It's the foundational pieces that I feel they need some focus on.
Let's do some of the basics really well. I'm looking at it from owning 50 or 60 different security products across a global organization.
They keep on adding products based on a simple feature set that they can do real well, but they can't integrate them into the rest of the security economy. It doesn't make sense to keep on buying products like that. Whether it's IBM or others, there are companies in the endpoint space that are taking over because they're saying, "Hey, we're going to do everything across your gamut of security needs."
IBM needs to look at that and how they are going to integrate across all of the security products and have them work together.
For how long have I used the solution?
We have been using this solution for four years.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
The scalability is great.
How are customer service and technical support?
We don't really use technical support. We're part of some of the engineering and development behind it and we work with a lot of the backend engineers.
Once in a while, we may put something in PMR but most of the time, we are working with the engineers themselves to figure out a solution. They are not really tech support issues.
Which solution did I use previously and why did I switch?
We have used other solutions, but that was years ago. We've had QRadar for four years. Before that, it was the Symantec solution. The landscape for SIEM has changed progressively over the years.
You're not even talking about the same set of requirements around those things. We just needed to upgrade. We needed the speed, the flexibility, and we needed the correlation building block pieces of it.
How was the initial setup?
I was involved in the initial setup. We are an advanced user of QRadar. While the initial setup was not hard for us, it is a lot more complex where we are right now. It works with integrating some of other IBM products into QRadar, and there's work that needs to be done there to make it seamless.
We were able to be operational in a matter of weeks or months, which is not a long time.
What other advice do I have?
When picking a vendor, the most important thing is partnership.
I honestly have nothing but good things to say about the IBM relationship that we have related to QRadar.
Partnership is going be important. Having the right skillset from an engineering standpoint is important to ensure that you don't set up things backwards. You have a high probability of doing it. This is one of those pieces where IBM doesn't “dummify” the solution for you.
On one side for my senior engineers, they don't want it “dummified” because they need to do it. On the other side of it, there are some aspects that don’t need to be this complex.
For the SMB market, those are some of the areas where I counsel people and say they need to get these types of solutions and do these types of processes. Selling something like QRadar to them becomes a little bit more of a burden because of that complexity. It's like a compliance check mark.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Security Engineer at a consumer goods company with 1,001-5,000 employees
It helps our incident handlers find incidents within our environment and track down new threats.
What is most valuable?
The most valuable features are its ease of use and that it provides good return on investments. It's the best solution out there, in my opinion.
How has it helped my organization?
It brings down the time for our incident handlers to find incidents within our environment, to track down new threats and to keep them gainfully employed, by finding the new problems that we see.
What needs improvement?
I'm not really sure in regards to any additional features, because everything I've seen on the roadmap looks good. So, I'm pretty happy with that.
There is always scope for improvement. The QRadar WinCollect feature needs to be improved. The Windows Log collection is sort of problematic and needs to work better.
A little bit more improvement needs to be brought about in the Watson integration and I still need to see how that works. A little more improvement can be brought about in the User Behavior Analytics and Network Analytics. That would be great.
What do I think about the stability of the solution?
We've had no issues with its stability or scalability.
How is customer service and technical support?
The technical support is very good. After the Q1 Labs integration into IBM, they kept the same people. I'm a long-time user and I keep talking to the same people year after year.
What's my experience with pricing, setup cost, and licensing?
It's worth the cost. There are a lot of other options out there that are way more expensive, and that may be better in certain areas, but in my opinion, the overall best solution is QRadar.
What other advice do I have?
First, make sure that it's sized right and read all the manuals, before you do it.
Interoperability with other products is what I look for in a vendor. An open API is the big thing. I want be able to make sure that if I buy something, it will be able to talk with other products. I won't need to keep going down the same path, i.e., if I buy company X, I have to buy company X products all the way; otherwise, they won't talk to each other. Being able to talk with other products really makes a difference.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Information Technology Security Officer at a financial services firm with 5,001-10,000 employees
Useful for infrastructure, application, and network monitoring
Pros and Cons
- "The tool helps with infrastructure, application, and network monitoring."
- "There are areas in IBM Security QRadar that could benefit from improvement. Its ability to customize knowledge for specific purposes could be enhanced. Also, it lacks clarity in presenting details. It is also difficult to see the reports."
What is our primary use case?
The tool helps with infrastructure, application, and network monitoring.
What needs improvement?
There are areas in IBM Security QRadar that could benefit from improvement. Its ability to customize knowledge for specific purposes could be enhanced. Also, it lacks clarity in presenting details. It is also difficult to see the reports.
For how long have I used the solution?
I have been using the product for a year.
How are customer service and support?
The tool's technical support is good.
How would you rate customer service and support?
Neutral
How was the initial setup?
Implementing IBM Security QRadar is not overly complex.
What's my experience with pricing, setup cost, and licensing?
The product is expensive. We have purchased the perpetual license, but we pay for the support.
What other advice do I have?
I rate the tool a seven out of ten. It is a tough product.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Administrator at Zitouna Bank
A scalable tool useful for authentication purposes but needs to provide more product training to its users
Pros and Cons
- "It is a scalable solution."
- "With IBM Security QRadar, my company faced issues with the support we received for the product."
What is our primary use case?
I use IBM Security QRadar in my company for authentication of users and to block the access of a user to the internet. In my company, we have only used the basic version of the solution, and currently, we don't have a license for the product since we didn't renew it. The basic version of the solution fits my company's basic requirements.
What needs improvement?
IBM Security QRadar is not hard to implement and administrate. To serve new use cases or do the tuning and allow correlation rules, you may need training since it is necessary to know the solution. With IBM solutions, you need training to know how to use the different features of the solution. IBM needs to provide training to its users to teach them how to use the case manager and how to tune rules.
For how long have I used the solution?
I have been using IBM Security QRadar since 2020, so I have experience with it for three years. I am a customer of IBM.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
With IBM Security QRadar, my company faced issues with the support we received for the product. Basically, my company faced problems due to the delays or mistakes made by IBM's support team.
I rate the technical support a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is deployed on an on-premises model.
For the product's implementation, my company took two months. To implement all log sources, my company took somewhere between three to five months.
What's my experience with pricing, setup cost, and licensing?
IBM Security QRadar is a very expensive tool.
What other advice do I have?
In the future, my company would want the cloud version of the solution and not its on-prem version.
I rate the overall tool a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Manager at a financial services firm with 1,001-5,000 employees
It has higher availability than other tools and can consolidate all alerts and detections, but its scalability has room for improvement
Pros and Cons
- "What's most valuable in IBM QRadar User Behavior Analytics is its higher availability than other tools."
- "You can scale IBM QRadar User Behavior Analytics, but it has room for improvement."
What is our primary use case?
My use case for IBM QRadar User Behavior Analytics is to consolidate all the logs and events from a different tool so that I can see the alerts from that other tool on the dashboard.
My company connects the Windows event logs to the Xfinity router deployed on the main server, but I have to make some configurations to detect activities.
My team is working on reinforcing IBM QRadar User Behavior Analytics features since the solution has not been used for a while because there's a new generation of engineers in my company. My team has to reconfigure almost every screen, including IBM QRadar User Behavior Analytics.
What is most valuable?
What's most valuable in IBM QRadar User Behavior Analytics is its higher availability than other tools. It consolidates all alerts and detections from the other tools, but my team has to check each tool. As my company lacks the manpower to do that, my team has to do monitoring while working on making each function clear.
What needs improvement?
As a product, IBM QRadar User Behavior Analytics does everything mentioned on the datasheet for my company's version. Still, compatibility is a problem because my company needs to use an updated version of the tool. That version doesn't integrate with many new-generation tools, so this is an area for improvement.
You can scale IBM QRadar User Behavior Analytics, but it has room for improvement.
For how long have I used the solution?
I've been using IBM QRadar User Behavior Analytics for years.
What do I think about the stability of the solution?
IBM QRadar User Behavior Analytics has been stable, and my team has made no significant changes since 2015. The team is working on utilizing it most efficiently.
What do I think about the scalability of the solution?
The scalability of IBM QRadar User Behavior Analytics is a six out of ten.
How are customer service and support?
My company doesn't get support from IBM because it's on a perpetual usage type of contract. My team can configure IBM QRadar User Behavior Analytics but cannot contact IBM for help.
When I used to get technical support for IBM QRadar User Behavior Analytics, I'd say it was a seven out of ten.
What other advice do I have?
The version of IBM QRadar User Behavior Analytics, which my company uses, is a little outdated from 2013. That version doesn't have the log collection feature.
My rating for the version of IBM QRadar User Behavior Analytics I'm using is a seven overall.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?
Stability Issues:
The stability is good.