PeerSpot user
Security Consultant at a tech services company with 11-50 employees
Consultant
Some of the valuable features are vulnerability management, cognitive security, and risk management.

What is most valuable?

The SIEM features are what sell this product. Lately, it has been heavily expanded with others. For example vulnerability management, risk management, incident forensics, cognitive security, and user behavior analytics.

Basic SIEM features include log management, reporting, and correlations and alerting. All SIEM products started with those.

Modern SIEM solutions are expanded with additional components that i mentioned.

So today, you will rarely see RFP for only SIEM. It will usually include other requirements. To answer this, vendors started adding additional valuable features.

Lately, Qradar also opened their APIs to the development community, in order to confront Splunk, and that resulted in a large number of additional functionalities in the form of add-ons (Qradar apps).

How has it helped my organization?

We are an IBM business partner. In short, this tool helps our clients have visibility into the IT infrastructure, events, and network traffic.

What needs improvement?

Dashboards!!! Dashboards are one of the most frequent complaints I receive from customers. Customers are complaining about the limited set of graphs and the inability to change colors. Although this might seem trivial, a large number of the same complaints probably mean something.

A lot of bugs are reported for dashboard items. Also, I personally have found that it does not work as indicated by the documentation. The same methodology is used to produce different results for similar searches. Also, customers would like to see near real-time data on the dashboard, which is very hard to achieve according to the mentioned problems.

For how long have I used the solution?

I have been using this since 2011, even before the IBM acquisition.

Buyer's Guide
IBM Security QRadar
May 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,063 professionals have used our research since 2012.

What do I think about the stability of the solution?

We have not had stability issues.

What do I think about the scalability of the solution?

High availability deployments have serious upgrade issues.

How are customer service and support?

Support is great, but sometimes they are a little slow.

Which solution did I use previously and why did I switch?

We did not have any previous solution. We have used only QRadar for the last six years. Even at that time, it was leader in Gartner and so it remained. It is very user friendly.

How was the initial setup?

The initial setup was very easy. Integrating the infrastructure configuration is the biggest problem for any SIEM project.

What's my experience with pricing, setup cost, and licensing?

Licensing was simplified two months ago. I don’t have insight into pricing. But as with any software, the price can probably change depending on your negotiation skills :)

Which other solutions did I evaluate?

We didn’t evaluate other solutions. However, in my career, I saw Splunk, RSA, ArcSight, and AlienVault.

What other advice do I have?

If you are a security officer who wants to protect his job, go for Splunk :) If you are a customer who wants to have an easy tool and save time and resources, definitely go for QRadar.

Disclosure: My company has a business relationship with this vendor other than being a customer: My company is a business partner.
PeerSpot user
it_user631671 - PeerSpot reviewer
Information Security Analyst at a media company with 1,001-5,000 employees
Real User
It takes log files from different viewpoints and puts them together in one place. I would like to see better support.

What is most valuable?

The most valuable feature is the co-ordination of the data it has, such as getting all sorts of log files from different viewpoints and putting it together in one place, so that the incident responders can get all the data they need to see the bigger picture.

How has it helped my organization?

We get more insights into the company's assets and vulnerabilities.

What needs improvement?

It is hard to tell which areas have room from improvement because we always think of new features and inform them to IBM, which they include in the next patch.

We recently went to an IBM conference to look into the Watson feature and see what they could do for us.

I would like to see better support. Their support is good, but I would say, they could do better.

What do I think about the stability of the solution?

For us, it's kind of wonky because we always try to be bleeding edge and always try to do updates. So, we're always pushing the system to its limit. It's pretty stable, but we always have open issues with it, with IBM.

What do I think about the scalability of the solution?

The scaling was done pretty well with IBM and the architecture teams. I think our system has scaled appropriately.

How are customer service and technical support?

The technical support really depends on who you get, at the time you call. There are good guys and bad guys. I can't really say. On a scale of 1 to 5, I would give them a 4/5 rating from our experience. We have a pretty good relationship with them.

Which solution did I use previously and why did I switch?

When I started out, this product was already bought and implemented by my company.

How was the initial setup?

The setup was a mixture of both, i.e., simple and complex.

It was complex because I had never dealt with it before. I had never set up a system like that. At the end, it got better.

What other advice do I have?

You should totally go for it. I've seen a couple systems out there, but I think IBM QRadar is one of the better solutions available.

Professionalism and to always be there when I call are the most important criteria when selecting a vendor. With IBM it's pretty good. We have our sales guy, who is always on top of everything.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Security QRadar
May 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,063 professionals have used our research since 2012.
willie.Na. - PeerSpot reviewer
System Engineer at Trans Business Machines Ltd
Real User
Top 5
Incredible capacity for creating machine models; falls short on documentation
Pros and Cons
  • "The timeline and machine learning features are great."
  • "The solution lacks vendor support."

What is our primary use case?

Our primary use case is logging for any anomalous traffic in terms of access times and deviations when users are in different groups within the AD. When a user deviates from their functionality, it's flagged in the UBA and for VPN traffic. I also use it for geolocation functionality. We are partners of IBM and I'm a system engineer. 

What is most valuable?

The timeline and the machine learning features are great at quickly flagging users who have either left the organization or have dormant accounts. The way that the app has transformed over time is quite phenomenal. One of the major improvements is its capacity for creating machine models. It comes with 16 default machine learning models, where it tracks user activity and changes in profiles and authentications. There are various default machine learning models and I'm able to model those to parameters that suit my needs. It's great that I'm able to implement an unlimited number of use cases on the UBA, putting in as many different kinds of logic as I want. It's a big advantage. 

What needs improvement?

I'd like to see improved support from the vendor. In addition there are things that are not documented on the IBM site. If you'd like to do something at a high level, the information is not available in the documentation and you have to find it elsewhere. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution has never crashed or failed, it's stable. 

What do I think about the scalability of the solution?

We haven't tested scalability and currently have around 100 users. I'm responsible for maintenance.

How are customer service and support?

The customer support is helpful but that's more about it being a good solution. 

How was the initial setup?

The initial setup is straightforward, it's just a download and it installs. It's a matter of configuring a few parameters in terms of tweaking the thresholds that you want the app to fire in on. Installing takes a few seconds, but in terms of letting it land so that you can tweak it and tune the various metrics, takes about a week. 

What's my experience with pricing, setup cost, and licensing?

This is a free solution which is one of the main reasons we chose it. It's just a matter of getting a license for the curator as a platform.

What other advice do I have?

I recommend this solution and rate it seven out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Cybersecurity Business Development Manager at a comms service provider with 10,001+ employees
Real User
Helpful customer support, overall good functionality, and reliable
Pros and Cons
  • "Overall a great solution."
  • "There needs to be better integration with other applications."

What is our primary use case?

I am currently working in the Brazilian operation of my company. I have a project in the airline industry in Brazil. This project improves the correlation of logs. There is another company I ticket to improve the solution, they have chosen to correlate the logs. We have SOC, Security Operation Center in Brazil, with 53 employees. We developed all these solutions in Brazil and it is in operation in 34 countries. 

What is most valuable?

Overall a great solution.

What needs improvement?

There needs to be better integration with other applications.

What do I think about the scalability of the solution?

We have approximately 40 users using the solution.

How are customer service and technical support?

The technical support is good.

How was the initial setup?

The installation is complex.

What about the implementation team?

We do the deployment for the solution.

What other advice do I have?

I rate IBM QRadar a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head of IT Security, Governance and Compliance at a consumer goods company with 10,001+ employees
Real User
Easy to use, provides environment visibility, and assists with incident discovery in advance of problems to the business
Pros and Cons
  • "This is a good tool to have because it gives you the ability to track what is currently happening in your environment."
  • "The modularity could be improved."

What is our primary use case?

We are using QRadar as a managed service.

How has it helped my organization?

This product helps us to find security incidents before they become a problem to the business. We are able to attend to them quicker and we can put protection in place so that should they occur again, we are able to deal with them more easily.

What is most valuable?

The most valuable feature is the ease of use.

What needs improvement?

The modularity could be improved.

For how long have I used the solution?

We have been using IBM QRadar for three years.

What do I think about the stability of the solution?

This is a very stable product.

What do I think about the scalability of the solution?

We have had no issues with scalability and we have approximately 1,500 users. We are not using its full capabilities at the moment because we are still growing. In the next year or two, we will see.

How are customer service and technical support?

I don't deal with IBM directly. Rather, I deal with our service provider and they deal with IBM.

How was the initial setup?

The initial set was very easy for us because we just bought what we were looking for, and not the entire infrastructure.

What about the implementation team?

The company that we subscribe to for this service takes care of the installation, maintenance, and management of it. They give us updates that concern the features we use, so the maintenance doesn't affect us much.

What's my experience with pricing, setup cost, and licensing?

We use QRadar as a managed service and we pay licensing fees to the partner.

What other advice do I have?

This is a good tool to have because it gives you the ability to track what is currently happening in your environment. Otherwise, if you did not have that, you'd only react to an event or an incident that has already caused problems. The proactiveness goes a long way because it saves your environment and your business from being negatively affected.

In summary, this is a good product but there is always room for improvement.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Security Specialist at a comms service provider with 501-1,000 employees
Real User
Not user friendly, doesn't integrate well, and has terrible technical support
Pros and Cons
  • "The solution can scale."
  • "The solution is clunky."

What is our primary use case?

We use the solution for a variety of tasks. We use it, for example, for authentication, network-related authentication, user-related tasks, and Windows UNIX servers. It's a lot. There's a ton of use cases. I really can't sync right now about every single use case, however, the main things are authentication and network-related systems and all flavors of UNIX Windows. 

How has it helped my organization?

It helped our organization in the sense that having it was better than nothing. However, I did not enjoy the product overall and I advised we switch to something else.

What is most valuable?

The user behavior analytics as part of our deployment was okay, even though it was clunky.

The solution can scale.

What needs improvement?

I really didn't like QRadar to be honest. I inherited it. I was part of the reason that we moved over to LogRhythm. The solution just isn't user friendly.

The solution is clunky. 

The interface could be much better.

The integration capabilities within the product are not that great.

For how long have I used the solution?

I've been using the solution for about two years at this point. My team has been using it for two to three years, so we have a total of about five years of experience in all.

What do I think about the stability of the solution?

I wouldn't describe the solution as stable. 

It was really buggy. Like other app integrations, it wasn't straightforward. It was pretty clunky. We tried to integrate Qualys with it and it wasn't effective. To integrate anything took quite a bit of time and energy. It wasn't easy. When it did, it didn't work properly. It wasn't really pulling in the data correctly.

What do I think about the scalability of the solution?

Scalability was hard as it was on-prem. We needed to add more modules, and had to add more of the servers to stack it. It wasn't that a simple task at all. I wouldn't say that it scales well, although technically, you can scale it.

When we were using the solution, we had ten to 15 users on it. They were anyone from Information Security Engineers to regular IT admins.

How are customer service and technical support?

Technical support was awful. We often didn't even have any assistance available to us. On a scale from one to ten, I'd rate them at a three. We were very unsatisfied with the level of support we received. They just simply weren't helpful when it came down to it.

Which solution did I use previously and why did I switch?

The organization didn't previously use a different solution before choosing QRadar.

We actually switched to LogRhythm as I didn't like how the solution was working for the organization.

How was the initial setup?

I didn't handle the initial setup. It was handled before I arrived at the organization.

What other advice do I have?

I'm not sure of which version of the solution we're using.

I wouldn't recommend the solution. I'd probably tell others to shy away and look at other products like possibly Splunk, however, it's a pricey option. LogRhythm is pretty good. We're having some issues with it. That said, for the most part, it's okay. 

Exabeam also seems like it might be a good option. I haven't worked with it personally, however, I've had some experience with a POC.

Overall, I would rate the solution at a three out of ten. We didn't have a good experience with it. If it offered, for example, easier behavior analytics, easier integrations, better interface, supported model integration, and a good user interface to perform analysis I might rate it higher. Basically, it just needs to be much more user-friendly.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user398799 - PeerSpot reviewer
Sr. Security Analyst with 1,001-5,000 employees
Real User
Enables us to integrate with some of the top security products on the market

What is our primary use case?

In recent years, our focus has been the third-party integrations. Like most companies, we have several security products. (I hope most other companies are not relying on a single product). The challenge with a SIEM is taking the data produced by a log source and presenting it in a readable manner for technical and non-technical staff. That can be done with custom-built reports or in dashboards. With the IBM Security App Exchange you add a new extension (i.e. download from the App Exchange site) and configure it.

How has it helped my organization?

Since IBM opened up the API for third-party app integration it has made it increasingly easy to add other tools into the dashboards.

What is most valuable?

Currently, the App Exchange offers over 192 applications that allow QRadar to integrate with some of the top security programs on the market, along with extension add-ons provided by QRadar. Some third-party apps include (but not limited to) Splunk, McAfee, Cisco, Carbon Black, Palo Alto, ObservIT, Exabeam, Gigamon, PhishMe. Extension add-ons by QRadar include report extensions, MS AD extensions, user behavior analytics, etc.

We have a very small team and anytime I can integrate with our other tools, and save time doing so, that is a plus for my company.

What needs improvement?

Keep up with more apps. They need to continue working with other companies to develop apps for integrations. Yes, they currently have 192 apps, but that number is nowhere near the number of security products on the market. That means if your company has a product that is not in the application list then you just have to work a little harder to pull the data you need from the log source.

I'm not against hard work, I'm just trying to work smarter and faster. Time is money, so saving time without compromising the end product is a win for everyone. It would reflect well for IBM because it would show they understand the customers’ needs and it would reflect well internally because we would be able to present cleaner dashboards and reports without hours or days devoted to building them.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

We experienced some memory usage issues with a user behavior app.

What do I think about the scalability of the solution?

We haven't really had any scalability issues. You are always limited to your EPS/FPM licensing, so you have to make sure you don’t exceed those limits.

How is customer service and technical support?

Tech support is excellent.

How was the initial setup?

The initial setup is straightforward.

Which other solutions did I evaluate?

We do a SIEM solutions review every few years. Other options we have evaluated: LogRhythm, Splunk, AlienVault.

What other advice do I have?

Research, and don’t be afraid to do a few PoCs. Also, make sure you have a team for the tool. Most solutions require a team, so if you cannot apply a team towards the tool then hopefully you can use one of the managed SIEM options.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user634794 - PeerSpot reviewer
Director of Cyber Security at a insurance company with 10,001+ employees
Real User
The ability to correlate large amounts of data into rules that provide real-time alerting is valuable.

What is most valuable?

The ability to correlate large amounts of data into rules that provide real-time alerting is the most valuable feature.

How has it helped my organization?

It has provided us with quicker mitigation to threats. We used to do everything manually, so it automated a lot of workflows that in the past, we weren't able to do from an automation perspective.

What needs improvement?

We are still two versions behind, so I don't know specifically what could be improved. I've told all the executives and staff we met at a recent IBM conference that integration with other solutions is important so that we don't have to do a bunch of different things to consider.

What do I think about the stability of the solution?

We are the largest user of QRadar, so the stability is average. There are several vulnerabilities that IBM is working with us on. They don't have a test environment big enough to imitate the stress we put on it. Stability is probably OK for the normal customers, but we break everybody's apps just because of our size.

What do I think about the scalability of the solution?

There are some vulnerabilities that may be further exasperated at our size, so they are trying to fix some of those issues and bring stability, but it's really product issues that don't scale right now.

Which solution did I use previously and why did I switch?

It was functionality which drove us to change. QRadar had better functionality than what we were getting out of the previous solution. Scale was probably also a factor at that time. It was right after IBM bought Q1 Labs, so it was an industry leader along with some others. We did an evaluation and QRadar came out on top.

How was the initial setup?

Initial setup was pretty straightforward. It's a complex solution, but it was straightforward for a large environment.

Which other solutions did I evaluate?

The two big options we evaluated would be IBM and HP. What we understood was that QRadar would be a more simplistic implementation, taking up less time.

What other advice do I have?

Make sure you really understand all the requirements before you implement. I think the group that did this implementation didn't necessarily understand fully what we were going to use it for, so it was maybe designed for smaller things. So, you should really understand the requirements prior to stepping into it. 

If QRadar is going to be a central sort of hub for IBM's security solutions, make sure that the other tools integrate very easily into it. That would probably be the biggest task.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.