IBM QRadar Review

Helpful and presentable reports, but the ticketing system needs to be more automated


What is our primary use case?

We are a cybersecurity service provider, and I manage the QRadar service for my customers.

What is most valuable?

Provided that the report is prebuilt and I can find what I am looking for, the reporting is the most valuable feature in this solution. The reports are very good and very presentable.

What needs improvement?

There are reports that I would like to generate that are either not included, or I cannot find. If there is no report for information that needs to be presented then it is one of the biggest issues for the customer.

The ticketing system is not fully automated and needs to be improved.

There should be an easier permission level that basic users can use to create reports. The users include both end-customers and the technical team.  

The pricing needs to be such that they are more competitive with other vendors.

For how long have I used the solution?

More than one year.

What do I think about the stability of the solution?

This is a very stable solution and I don't think that we have lost it once. This is good compared to our other system that had gone down three times.

What do I think about the scalability of the solution?

I would say that it is ok. I can buy licenses when I need to scale the solution.

How are customer service and technical support?

Our experience with technical support has not been smooth. There is a lot of bureaucracy to get to the technical team. In fact, in some cases, we resolved the issues ourselves and then explained to their technical team how it should be done for other customers.

How was the initial setup?

The initial setup for this solution is complex. There are many different components, and only the IBM technicians have the permission, or credentials, to modify the system online. As a customer, I cannot go in and install it myself. Rather, I am dependent on the IBM professionals.

What about the implementation team?

We used a consultant to assist with the installation of this solution.

Which other solutions did I evaluate?

I have used several other products including ArcSight, AlienVault, and Splunk. Some of these solutions are on-premises or in-house.

I do not like Splunk, but I think that ArcSight is a good solution. ArcSight is complicated, but it is a more mature solution with much greater options than IBM is offering in QRadar.

What other advice do I have?

This is a good solution, but I am familiar with the capabilities of the other products and IBM needs to make some improvements.

I would rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Add a Comment
Guest
Sign Up with Email