QRadar is our SIEM solution. Our use cases include authentication between logins, database security, monitoring, and user behavior analytics.
Cyber Security Consultant at raf
Good monitoring functionality that helps us to identify threats, but dealing with support is a struggle
Pros and Cons
- "We can easily monitor many things using this tool."
- "They need to improve their threat intelligence feed and they need to improve their user behavior analytics modules."
What is our primary use case?
How has it helped my organization?
QRadar is helping us to identify ongoing, day-to-day threats. We use it to analyze the risk in our environment, including user behaviors. We can easily monitor many things using this tool.
What is most valuable?
All of the features offered by this product are useful for analysis. Essentially, everything that it offers is critical and we use it.
What needs improvement?
Several things need to be improved.
We have been struggling with the QRadar support team for quite a long time. There are things that they can reproduce in their lab environment and can fix, yet we struggled with them trying to get this done. These issues included things like custom logs. There are many things that they need to improve upon.
This product should support multiple log sources.
They need to improve their threat intelligence feed and they need to improve their user behavior analytics modules.
The risk manager module needs to be improved.
It's not a very user-friendly interface.
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
817,354 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with IBM QRadar for seven years.
What do I think about the stability of the solution?
IBM QRadar is quite stable.
What do I think about the scalability of the solution?
We have approximately 50 users and we keep expanding its usage. It is growing on the infrastructure level, as well as the EPS level.
Three or four administrators are all that is required for the maintenance.
I recommend this product for large enterprises.
How are customer service and support?
We have had a lot of trouble with technical support. As of late, they take too long to respond to our issues. For 99% of our issues, they take too long to respond. It's not instant.
Which solution did I use previously and why did I switch?
I do not have any experience with other SIEM solutions. QRadar is the first one for me.
How was the initial setup?
The initial setup is complex because it is not managed properly.
Our implementation strategy is based on it being a distributed environment.
What about the implementation team?
We completed the implementation and deployment ourselves.
Which other solutions did I evaluate?
We did not evaluate other options prior to selecting QRadar.
What other advice do I have?
This is a good product for large enterprises. Smaller companies should implement an open-source solution but for a large enterprise, QRadar is a good product.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Cybersecurity at a computer software company with 51-200 employees
A highly scalable and stable tool with a responsive support team
Pros and Cons
- "Stability-wise, I rate the solution a ten out of ten."
- "The price of IBM Security QRadar is an area of concern where improvements are required."
What is our primary use case?
I use IBM Security QRadar in my company as it provides features like SIEM, SOAR, and QNI.
What is most valuable?
The most valuable feature of IBM Security QRadar stems from the fact that it is a product that is like a complete suite.
What needs improvement?
The price of IBM Security QRadar is an area of concern where improvements are required. IBM is never known to provide products at a cheap price.
IBM Security QRadar's UI is an area with certain shortcomings where improvements are needed.
In the future, I would like IBM Security QRadar to have a library of adapters or APIs.
The area around recovery time is an aspect of IBM's technical support where improvements are required.
For how long have I used the solution?
I have been using IBM Security QRadar for more than a year. I use the solution's latest version. My company is in the process of being declared as a golden partner of IBM.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution a ten out of ten.
My company currently deals with around four to five organizations comprising medium to large companies where IBM Security QRadar is used.
How are customer service and support?
The solution's technical support is responsive. The only area where I don't agree with IBM Security QRadar's technical support stems from the lack of proper or defined recovery time, even though their response time is good.
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with Splunk. My company deals with Splunk since we had no choice owing to the fact that one or two customers wanted it.
In the past, I was using open-source products, including solutions like Elastic Security and Wazuh.
My company decided to switch from Wazuh to IBM Security QRadar.
How was the initial setup?
The product's deployment phase can be described as an average one.
I rate the deployment process of IBM Security QRadar a seven on a scale of one to ten, where one is difficult, and ten is easy.
The solution is deployed on an on-premises model.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, I rate the price a one, where one is an extremely expensive product, and ten is a cheap product. IBM Security QRadar is an expensive product. A customer gets discounts only when they ask for them from IBM.
The challenge is that if someone submits a request or proposal and finds that the prices of the products our company deals with are too high, we may not even be shortlisted for negotiations. If my company gets shortlisted for the next round, then we get questioned over the high prices.
What other advice do I have?
My company takes care of the maintenance part of the solution for our clients who use IBM Security QRadar in their environments. Nine engineers and one manager take care of the maintenance process of IBM Security QRadar. My company has a lot of certified employees to take care of IBM Security QRadar's maintenance. My company can be considered a powerhouse when it comes to products from IBM.
I recommend the solution to those who plan to use it.
Splunk and IBM are leaders as per Gartner Magic Quadrant. I believe that IBM Security QRadar should be fairly priced for SMEs.
I rate the overall tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
IBM Security QRadar
November 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
817,354 professionals have used our research since 2012.
Cyber Security Student at Baku Higher Oil School
Scalable, easy to use, and has a visualization feature that shows spikes in the system
Pros and Cons
- "The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log."
- "IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others."
What is our primary use case?
We are using IBM QRadar for log reviews, particularly logs that come and go from the IPS, firewall, etc.
We have different dashboards for different technologies such as our firewall, IPS, and domains for our main website, so we use IBM QRadar to observe the logs from our website, and we try to make internal and external connections for better domain security.
What is most valuable?
The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log.
What needs improvement?
IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others.
There isn't any additional feature I'd like added to IBM QRadar at this point because it's sufficient for visualizing the logs.
For how long have I used the solution?
I've been with the company for one and a half months, and I've been using IBM QRadar almost daily, but the solution was deployed five or six months ago.
What do I think about the stability of the solution?
IBM QRadar is a stable solution.
What do I think about the scalability of the solution?
IBM QRadar is a scalable solution. My company currently has seven to eight different accounts on IBM QRadar, so it's a scalable technology. It has no problems with scalability.
How are customer service and support?
I didn't have any problems with IBM QRadar, so I never contacted the technical support team.
Which solution did I use previously and why did I switch?
I'm assuming that the main reason my company chose IBM QRadar is that IBM is one of the biggest tech companies in the world, so IBM products would be more secure and more reliable than other solutions.
How was the initial setup?
As I didn't set up or deploy IBM QRadar, I have no information on whether it was easy or complex to set up.
What's my experience with pricing, setup cost, and licensing?
I have no information about the licensing costs of IBM QRadar, and whether or not it requires a license.
What other advice do I have?
I'm an intern at one of the biggest telecommunication companies, and my company uses IBM QRadar.
My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use. The solution also has many dashboards, and you don't have to write any code or write different scripts to get the information you need. You can do it from the UI of IBM QRadar. The only room for improvement in the solution is that it doesn't support newer technologies, and it's late when it comes to updates.
I'm rating IBM QRadar nine out of ten because my experience with it has been excellent. The only downside to it is that IBM is late with adding new features or supporting new technologies compared to its competitors.
My company is an IBM QRadar customer.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SOC Team Lead at a financial services firm with 1,001-5,000 employees
Flexible, easy to learn, and price fairly
Pros and Cons
- "I have found the most important features to be the flexibility, tech framework, and disk manager."
- "There could be better integration with the solution."
What is our primary use case?
Depending on the organization's needs the solution can monitor different types of security through logs.
What is most valuable?
I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.
What needs improvement?
There could be better integration with the solution.
For how long have I used the solution?
I have been using the solution for approximately three years.
What do I think about the stability of the solution?
Every solution has some bugs and other issues but for the most part, this solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. The amount of users is dependant on what your needs are. You can have many users having access to the solution. For example, out of a 5,000 person network, you could have five with access to it for security.
How are customer service and technical support?
The solution has great support. Whenever we had an issue they were able to give us support within 15 minutes.
How was the initial setup?
The installation was easy but this can depend on what appliances you want to install it on. If it is VMware, then the installation is easy, it took me 30 minutes.
What about the implementation team?
We did use a consultant to do the deployment and we only needed one technician.
What's my experience with pricing, setup cost, and licensing?
The solution is priced fairly, there is a license for the solution, and we pay annually.
What other advice do I have?
I would recommend the solution to others and we plan to continue using it in the future.
I rate IBM QRadar a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Works at a healthcare company with 5,001-10,000 employees
Good visibility of network and endpoints, correlate events to specific point-in-time
Pros and Cons
- "The ability to transition from microscopic to macroscopic view, instantly, is very good."
- "I would like to see a better GUI."
What is our primary use case?
Our primary use case is intrusion prevention and detection. We also use this solution for compliance and assisting in network troubleshooting for IT.
How has it helped my organization?
This has been indispensable in detecting intrusion attempts and many forms of malicious activity.
What is most valuable?
This solution provides amazing visibility into the network and endpoints. The ability to correlate point in time and things happening over time is priceless in today's threat environment.
The rules can look for things both from log sources and from data traversing your network which is unique in the SIEM world and makes QRadar a consistent magic quadrant leader.
The QNI file hash in-flight search is helpful.
The ability to transition from microscopic to macroscopic view, instantly, is very good.
What needs improvement?
I would still like to see a better GUI. improvements have been made but there still a way to go.
There are pretty annoyances like clicking out of a rule setup and instead of going back to search results in the rules, with the rule you selected still highlighted, you get the whole list without your search. Start again. In the new lig source management app if you have a large number of log sources typing a name to filter them by is Java Hell, the high overhead of JIT compiled code means that even two fingered carpal tunnel afflicted users can outpace the type ahead buffer, leaving random intermediate characters on the floor. Needless to say that makes managing log sources sometimes annoying. You can always cut and paste to go around this, but hey for 5 or 6 figures in hardware and software, it aught to keep up with my typing.
But to be fair, these kinds of things are dwarfed by it's awesome ability to ingest and correlate tortured use cases of mind boggling complexity, which is what you REALLY need your SIEM to do. That, QRadar does better than anyone else.
For how long have I used the solution?
I have been using IBM QRadar for more about five years.
What do I think about the scalability of the solution?
Scalability is very good.
What's my experience with pricing, setup cost, and licensing?
This is not a trivial undertaking. You will need at least one experienced user and considerable infrastructure to support this if you use the on-prem version which we did. The cloud version has less overhead but there are some limitations so choose carefully.
Which other solutions did I evaluate?
Other solutions were investigated but none none came close to QRadar's capability.
What other advice do I have?
If you absolutely positively have to catch the bad guys, and you have a heterogeneous environment QRadar is a great choice.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head Of Sales at Cascade Solutions Inc
Modular product that sets up a clear roadmap
Pros and Cons
- "Flexible and valuable product that is modular, so you can easily set up a roadmap for your clients."
- "Each module requires a separate license and a separate cost."
What is most valuable?
From a sales perspective, IBM QRadar is very competitive when it comes to prices. It's a flexible and valuable product. It has a good edge in the region and good references as well. You can easily capitalize and upsell on whatever you sold previously. It's a modular product, so you can set up a roadmap and plan for your customers. This is one of the main advantages of QRadar.
What needs improvement?
Right now, there are a lot of solutions in the market that consider themselves next-gen SIEM solutions, like AzureVM. IBM QRadar can be revised considering the competition, market segment, references, and the maintenance of the landscape.
Some modules can be shared as embedded within the same solution because this would be a compelling edge versus others. When it comes to other products, like LogRhythm for example, they can consider the SOAR and the threat Intel embedded with the SIEM Solution licenses. However, when it comes to IBM, they consider each module as a separate license with a separate cost. So it doesn't make sense to compete if the customer isn't convinced with IBM, because you'd have tough competition when it comes to financials.
For how long have I used the solution?
I have been using QRadar for more than five to six years.
What do I think about the stability of the solution?
IBM QRadar is a stable product.
What other advice do I have?
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technology Officer at a tech services company with 51-200 employees
Great dashboards and visibility; lacks decent support and some maturity
Pros and Cons
- "Improves visibility and has a great new dashboard."
- "The solution lacks some maturity."
What is our primary use case?
We are users and implementers of this solution.
What is most valuable?
I like the new dashboard which enables us to understand how many real threat attempts are made in a day. I also like the QRadar incident response, we installed the QIF last week. The solution has improved visibility so that we've been able to discover that some of our customers have not had any protection and were very vulnerable. It's an important area. I also find that the user behavior analysis is relatively simple. We are customers of QRadar.
What needs improvement?
I think the user management model is very detailed but you really have to know what you're doing just to be able to manage things. I think the solution lacks some maturity. When you put it in a large organization as a security system or a cybersecurity system and you want to enable automation, it's difficult to get that level of maturity.
For how long have I used the solution?
We've been using this solution for about 18 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. We have a total of 19 users in the company. The solution is used extensively and we plan to increase the number of users.
How are customer service and support?
The technical support could be better. I'd rather work with my implementing expert and not the OEM. Although they have the expertise, the development guys are very slow.
Which solution did I use previously and why did I switch?
We tested a few other solutions including AlienVault, Splunk, Micro Focus, and Outside. QRadar was the best of the breed for our needs and for a big system like ours, it's less complex than Splunk or Outside.
How was the initial setup?
The initial setup is complex. Theory is one thing and practice is another. We had to go back and forth with IBM just to find the relevant versions with the relevant operating system to sit on the relevant virtual environment. Then we found a few bugs. We are in a production system in a very big organization so deployment was carried out in stages. It took about a month in total to get things working and to start collecting logs. We had help from IBM Azure.
Maintenance is required, you have to watch it, and work on it on a daily basis.
What's my experience with pricing, setup cost, and licensing?
We pay an annual license fee. On top of that, every model adds to the cost. It's not just the license; the sales people want you to think you're only paying for certain things but we know how it works.
What other advice do I have?
The pre-design and the low-level design should be very, very, specific. It's important to check that the compatibility is there. If not, neither IBM nor OEM will support you.
I would rate the solution more highly but it's very expensive and given the high cost, I would expect quicker and better service from the OEM so I rate the solution seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director of Information Security at a financial services firm with 501-1,000 employees
Scalable with good searching capabilities and good support
Pros and Cons
- "The most valuable feature is the searching capability and real-time operational use."
- "Some of the cloud apps need improvement."
What is our primary use case?
The primary use case of this solution is for monitoring an enterprise data center, globally for 12,000 devices.
How has it helped my organization?
It has improved the way that the organization functions.
What is most valuable?
The most valuable feature is the searching capability and real-time operational use.
What needs improvement?
Some of the cloud apps need improvement.
In the next release, I would like to see improving the stability of some of the add-on applications.
For how long have I used the solution?
I have been using IBM QRadar for two years.
We are using the current version.
What do I think about the stability of the solution?
Stability is moderate.
We have 15 people using this solution in our organization. Their positions vary from Network Engineers, Security Engineers, and Security Analysts.
What do I think about the scalability of the solution?
It's very scalable.
How are customer service and technical support?
Technical support is good.
I would rate them a nine out of ten. Their response time is good.
Which solution did I use previously and why did I switch?
Previously, I did not use another solution.
How was the initial setup?
The initial setup is complex. It's just the nature of the CM tool.
What's my experience with pricing, setup cost, and licensing?
I think that the price is fair, but we can always say that the price could be cheaper.
What other advice do I have?
Like any complex enterprise CM tool, you have to have a strong support organization. People who are good at understanding Linux operating systems. You also need a strong technical support team in-house.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Splunk Enterprise Security
Microsoft Sentinel
Elastic Security
LogRhythm SIEM
Sumo Logic Security
Rapid7 InsightIDR
Fortinet FortiSIEM
AlienVault OSSIM
Cortex XSIAM
Securonix Next-Gen SIEM
USM Anywhere
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- Which is the best SIEM solution for a government organization?