We performed a comparison between Aruba IntroSpect and IBM Security QRadar based on real PeerSpot user reviews.
Find out what your peers are saying about IBM, Splunk, Cynet and others in User Entity Behavior Analytics - UEBA."I haven't heard of any issues with stability."
"Roaming feature, application control and firewall features."
"The most valuable feature is the end-user monitoring. If there is any abnormal behavior on the machine, the administrator will be alerted."
"IBM Security QRadar has significantly improved our incident response procedures."
"There are more than 120 extensions in QRadar, which are easy to install and configure. These can improve your analysis of events."
"One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like Scout, Carbon Black, and the rest."
"Provided that the report is prebuilt and I can find what I am looking for, the reporting is the most valuable feature in this solution."
"The product has plenty of features and capabilities."
"It is a very good SIEM."
"It also has a graph that shows the traffic history. I can see what happened yesterday or today. If there's an incident, I can check the traffic behavior on QRadar."
"An engineer can live-monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions."
"The packet analyzer needs improvement."
"Technical support is a little slow."
"I would like to see improvements made to the dashboard, where you can get the information with a simple click."
"Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."
"There are reports that I would like to generate that are either not included, or I cannot find."
"I'd like them to improve the offense. When QRadar detects something, it creates what it calls offenses. So, it has a rudimentary ticketing system inside of it. This is the same interface that was there when I started using it 12 years ago. It just has not been improved. They do allow integration with IBM Resilient, but IBM Resilient is grotesquely expensive. The most effective integration that IBM offers today is with IBM Resilient, which is an instant response platform. It is a very good platform, but it is very expensive. They really should do something with the offense handling because it is very difficult to scale, and it has limitations. The maximum number of offenses that it can carry is 16K. After 16K, you have to flush your offenses out. So, it is all or nothing. You lose all your offenses up until that point in time, and you don't have any history within the offense list of older events. If you're dealing with multiple customers, this becomes problematic. That's why you need to use another product to do the actual ticketing. If you wanted the ticket existence, you would normally interface with ServiceNow, SolarWinds, or some other product like that."
"It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation."
"The whole process for support is something that needs to be improved."
"IBM QRadar Advisor with Watson could be more user-friendly. You need some skills and understanding of what you're looking at, especially if you're going to draw down specific information."
"The product does not have a team for investigating malware."
"We sometimes get an error about the hard drive. Approximately once in two months, we can't find the logs, and they go missing, which is a terrible issue. We are getting support for this issue from our support company."
IBM Security QRadar is a security and analytics platform designed to defend against threats and scale security operations.
Aruba IntroSpect is ranked 24th in User Entity Behavior Analytics - UEBA while IBM Security QRadar is ranked 1st in User Entity Behavior Analytics - UEBA with 197 reviews. Aruba IntroSpect is rated 8.6, while IBM Security QRadar is rated 8.0. The top reviewer of Aruba IntroSpect writes "A straightforward setup for technical users and an overall good product". On the other hand, the top reviewer of IBM Security QRadar writes "A highly stable and scalable solution that provides good technical support". Aruba IntroSpect is most compared with Arista NDR, Cisco Secure Network Analytics, LogRhythm UEBA, Darktrace and SolarWinds NetFlow Traffic Analyzer, whereas IBM Security QRadar is most compared with Microsoft Sentinel, Splunk Enterprise Security, Wazuh, LogRhythm SIEM and Elastic Security.
See our list of best User Entity Behavior Analytics - UEBA vendors.
We monitor all User Entity Behavior Analytics - UEBA reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.