IBM Security QRadar Other Advice

Frank Eargle - PeerSpot reviewer
Information Security Engineer at Glasshouse Systems

Overall, I rate IBM Security QRadar a nine out of ten.

View full review »
Anto Sebastin - PeerSpot reviewer
Technical Presales Engineer at Redington India Limited

I am using the current version of the solution. We do not have a team to analyze malware. Overall, I rate the product a nine out of ten.

View full review »
MUHAMMADNADEEM1 - PeerSpot reviewer
Deputy Director at Board Of Revenue

We chose to work with IBM QRadar mainly because it was widely deployed in our country, Pakistan, with no significant presence of alternatives like Splunk or LogRhythm.

IBM Security QRadar has enhanced our threat detection and management processes by providing comprehensive visibility into network traffic and events. With QRadar, we have end-to-end visibility across our network, enabling us to monitor traffic from origin to destination and analyze all relevant logs and events.

IBM Security QRadar stands out with features like advanced analytics and customizable dashboards, making it effective for our security needs. While it shares common features with other SIEM solutions, these unique capabilities have been instrumental in improving our security.

Integration capabilities play a crucial role in enhancing the overall security posture of IBM QRadar. By integrating with various tools like Active Directory, privilege access management, firewalls, and email security appliances, QRadar aggregates logs from different sources. It then utilizes machine learning, artificial intelligence, and custom rules to analyze this data, helping our security operations center make informed decisions and respond effectively to potential threats.

Overall, I would rate IBM QRadar as a seven out of ten. It is a great tool but operating IBM QRadar requires a higher level of technical expertise.

View full review »
Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,065 professionals have used our research since 2012.
KM
Head of Cyber security analysis at DNV Poland Sp. z o.o.

I rate QRadar UBA eight out of 10. It's a small product doing exactly what it's supposed to do as an integrated part of our SIEM. It looks good and works well. I don't give it a 10 because it is something we have to request. I would love it if UBA was included out of the box like Microsoft.

Regardless of which solution you use, I recommend user behavior analytics. It provides valuable information to the security team. It doesn't matter whether you use Splunk or Microsoft— you should use a UBA solution. 

We will probably stick with QRadar for the foreseeable future. It depends on the developments in the SIEM market. We will probably continue with IBM because changing SIEM is not something you do lightly. As long as we keep the IBM SIEM, we will continue to use QRadar UBA.

View full review »
Artur Marzano - PeerSpot reviewer
Security Analyst at Localiza

I don't recall the exact version of IBM QRadar User Behavior Analytics I'm using, but it's probably the latest one. It's version 4.1.7.

My advice to others looking into implementing IBM QRadar User Behavior Analytics is to have a dedicated team to implement the solution. Some solutions require close knowledge of your environment, so someone would have to know your infrastructure, your network, your users, and your Active Directory environment well. These are things partners aren't able to do well if they are not supported by internal teams inside their company.

I'm rating IBM QRadar User Behavior Analytics seven out of ten.

My company has a contract with another company that is a partner of IBM. The company I'm in is just a customer, not an IBM partner.

View full review »
Lokesh Puthalapattu - PeerSpot reviewer
Senior Marketing Specialist II at Harman International

I rate IBM QRadar User Behavior Analytics an eight out of ten.

View full review »
EM
Director of Incident Response at a retailer with 10,001+ employees

While I use QRadar, I'm in a managerial role, so I'm not living in it every single day as my team members are.

Every situation is different. I know a lot of organizations or a lot of C-suite executives all go to the same kind of conferences each year. Then they all come back singing the same song: "We all have to go to the Cloud."

I’d rate the solution six out of ten.

View full review »
SK
Cyber Security Analyst at Diyar United Company

QRadar supports connectivity with a 2800 vendors, including Cisco and Fortinet FortiGate. These integrations encompass various platforms such as VMs, Linux distributions like Red Hat and CentOS, and Symantec and Microsoft Windows for CRM databases and other server functionalities. Cloud technologies such as Office 365 are also supported.

The tool is flexible and I recommend it.

Overall, I rate the solution a nine out of ten.

View full review »
YE
Technical Analyst at a manufacturing company with 10,001+ employees

I rate the solution a seven out of ten because it is difficult to write script for advanced detection cases and the dashboard is insufficient. 

View full review »
Chetankumar Savalagimath - PeerSpot reviewer
Delivery Manager at a tech services company with 1,001-5,000 employees

It has good integration with AWS. AWS has come up with a Marketplace click-in option that provides direct integration between your AWS and data centers or cloud solutions through a small VPN. It allows you to bring up small environments with 5,000 EPS or 6,000 EPS or even 3,500 EPS or 2,500 EPS very quickly. It is very flexible and not at all tough for a startup engineer to click and bring solutions inside. It is quite easy.

I would rate IBM QRadar an eight out of ten.

View full review »
Artur Marzano - PeerSpot reviewer
Security Analyst at Localiza

I'd recommend QRadar for security teams that are more from the IT world and not so much from the development or data-science world. I think other tools, such as Splunk, are really great too, but QRadar is natively concerned with providing security rules and use cases. If you're looking for a reliable solution for security purposes only, QRadar is probably the way to go.

Overall, on a scale from one to ten, I would give this solution a rating of eight.

View full review »
Mohamed Elprince - PeerSpot reviewer
SOC Manager at ALEXBANK

I would recommend tuning it to the maximum before going live. I would rate IBM QRadar User Behavior Analytics a seven on a scale of one to ten.

View full review »
Elshaday Gelaye - PeerSpot reviewer
Lead Technical Architec at Commercial Bank of Ethiopia

I rate QRadar eight out of 10. 

View full review »
MG
IT Security Administrator at Zitouna Bank

In the future, my company would want the cloud version of the solution and not its on-prem version.

I rate the overall tool a seven out of ten.

View full review »
James Riffenburg - PeerSpot reviewer
Principal Cybersecurity Consultant (Architecture, Engineering, Operations) CISO VCISO at a financial services firm with 10,001+ employees

I give the solution an eight out of ten.

The solution is fairly easy to maintain and the learning curve is reasonable compared to other products to customize the workflow dashboards and get meaningful insight as far as what is happening within our organization. The solution is also fairly straightforward to integrate with different data log sources.

The solution requires three to five people to maintain including one analyst, an engineer, and an architect.

I suggest before using the solution you know what your process is, know what your logging sources are, and plan well because It's really a leadership challenge. The solution is better deployed than other models.

View full review »
DipeshBhawsar - PeerSpot reviewer
Archtect manager at Principal Global Limited

We're an IBM partner. We have platinum support with IBM.

We have segregated our data between on-prem and the cloud. All the on-prem data we have integrated with the QRadar. QRadar itself is an on-prem solution. We have QRadar hardware with us.

At this point, I would not recommend the solution to others. 

I'd rate the solution a six out of ten.

View full review »
BS
CS engineer at AYACOM

I would recommend purchasing a cloud-based license subscription because it doesn't have any limits on the license. You can easily install it in a cloud environment. This cloud pack can be integrated with different types of SIEM solutions. So, you can use one management console to query all of the SIEM systems that you are managing. It is like having one window to manage your SOC. For example, a SOC can operate, manage, or provide services for different types of companies, and all these companies can have different types of SIEM solutions. With the cloud subscription of QRadar, you can cover all companies, which is good in my opinion.

I would recommend both QRadar and Azure Sentinel. It depends on the use case of a customer and the environment that they are using.

I would rate QRadar a seven out of ten. 

View full review »
RR
Cyber Security Specialist at a tech vendor with 10,001+ employees

The version we use depends on when the customer is onboarded. Whenever recent onboarding takes place, we use the most up-to-date versions. However, there are customers that we have been facilitating for the past two or two and a half years and they might be using the previous versions. There are proper version upgrades that happen on a quarterly basis. 

I'd rate the solution seven out of ten.

View full review »
QI
Manager SOC at a comms service provider with 10,001+ employees

I would rate it an eight out of 10.

View full review »
ST
Cyber Security Services Operations Manager at a aerospace/defense firm with 501-1,000 employees

Make sure that you have the buy-in from different teams in the company because you will need help from the network teams. You will potentially need help from IT. 

You need to have a strategy of how you onboard logs into SIEM. Do you take a risk-based approach or do you onboard everything? You should take the time to understand the architecture and the implications of design choices. For instance, QRadar Components communicate with each other using SSH tunnels. The normal practice in security is that if I put a device in a DMZ, then communication between the device on the normal network, which is a higher security zone, and the DMZ, which is a lower security zone, will be initiated from the high-security zone. You would not expect the device in the DMZ to initiate communication back into the normal network. In the case of QRadar, if you put your processes in the DMZ, then it has to communicate with the console, which means that you have to allow the processor to communicate. This has consequences. If you have remote sites or you plan to use cloud-based processes, collectors, etc, and have an internal console, the same communication channels have to exist. So, it requires some careful planning. That's the main thing.

I would rate QRadar an eight out of 10 as compared to other products.

View full review »
Abbasi Poonawala - PeerSpot reviewer
Chief Enterprise Architect at a financial services firm with 10,001+ employees

I would definitely recommend this solution. It is a good solution with good capabilities like integration with CMDB and CVSS score. The dashboard is also really nice. It can help with threat intelligence, and it also has artificial intelligence. It is a futuristic kind of technology because the more AI-driven a product is, the better are the results. We plan to keep using this solution.

I would rate IBM QRadar a seven out of ten.

View full review »
it_user634773 - PeerSpot reviewer
Senior Security Analyst at The Hartford

It's a great product. They're obviously an industry leader right now in this field, if you're looking for SIEM, I would recommend it.

View full review »
DL
Head of Cybersecurity at a computer software company with 51-200 employees

My company takes care of the maintenance part of the solution for our clients who use IBM Security QRadar in their environments. Nine engineers and one manager take care of the maintenance process of IBM Security QRadar. My company has a lot of certified employees to take care of IBM Security QRadar's maintenance. My company can be considered a powerhouse when it comes to products from IBM.

I recommend the solution to those who plan to use it.

Splunk and IBM are leaders as per Gartner Magic Quadrant. I believe that IBM Security QRadar should be fairly priced for SMEs.

I rate the overall tool an eight out of ten.

View full review »
KB
Senior Cyber Security Engineer at a logistics company with 10,001+ employees

I rate IBM QRadar nine out of 10. If you're going to use QRadar, you have to be familiar with it and know all the components. IBM offers free appliances, like data nodes, that offload many processes from the collectors and the processors. 

Every engineer must understand the overall portfolio to add some value to the solutions. If a solution isn't integrated with other solutions, they are only collectors. You need to tune the rules and be up to date with the Mitre Att&ck framework all the time.

View full review »
it_user1369023 - PeerSpot reviewer
Senior Manager Information Security at Conduent (formerly Xerox Services)

I would absolutely recommend this solution. I am pretty okay with it, and I don't have any issues with it. It has some competitors like Splunk and LogRhythm. Symantec has its own SIEM solution. ArcSight, LogRhythm, and Splunk are in the first quadrant for the Gartner research. They are leaders in their products, and they know what they're doing. It also comes down to what your company is into, how does it fit into a particular environment, and how compatible it is with a particular environment. I could have gone on the Splunk path and probably said the same thing for it as well. 

I would rate IBM QRadar a nine out of ten. It is a pretty solid product.

View full review »
Ayoub Jaaouani - PeerSpot reviewer
Solutions Architectv at Smarttech247

I rate the overall product an eight out of ten. 

View full review »
Du Hoac Kim - PeerSpot reviewer
Deputy Manager at sacombank

I would rate IBM QRadar User Behavior Analytics an eight out of ten.

View full review »
MT
IT Solutions Product Manager at SMTSTECH

I would rate it a seven out of 10. It is good, but when a product doesn't behave in a good manner, it creates confusion. Its behavior isn't consistent.

View full review »
it_user634899 - PeerSpot reviewer
Global Security Engineering and Operations Director at a wellness & fitness company with 10,001+ employees

When picking a vendor, the most important thing is partnership.

I honestly have nothing but good things to say about the IBM relationship that we have related to QRadar.

Partnership is going be important. Having the right skillset from an engineering standpoint is important to ensure that you don't set up things backwards. You have a high probability of doing it. This is one of those pieces where IBM doesn't “dummify” the solution for you.

On one side for my senior engineers, they don't want it “dummified” because they need to do it. On the other side of it, there are some aspects that don’t need to be this complex.

For the SMB market, those are some of the areas where I counsel people and say they need to get these types of solutions and do these types of processes. Selling something like QRadar to them becomes a little bit more of a burden because of that complexity. It's like a compliance check mark.

View full review »
it_user632763 - PeerSpot reviewer
Senior Security Engineer at a consumer goods company with 1,001-5,000 employees

First, make sure that it's sized right and read all the manuals, before you do it.

Interoperability with other products is what I look for in a vendor. An open API is the big thing. I want be able to make sure that if I buy something, it will be able to talk with other products. I won't need to keep going down the same path, i.e., if I buy company X, I have to buy company X products all the way; otherwise, they won't talk to each other. Being able to talk with other products really makes a difference.

View full review »
EG
Senior Information Technology Security Officer at a financial services firm with 5,001-10,000 employees

I rate the tool a seven out of ten. It is a tough product. 

View full review »
CV
Information Security Manager at a financial services firm with 1,001-5,000 employees

The version of IBM QRadar User Behavior Analytics, which my company uses, is a little outdated from 2013. That version doesn't have the log collection feature.

My rating for the version of IBM QRadar User Behavior Analytics I'm using is a seven overall.

View full review »
Bobby Sandeep - PeerSpot reviewer
Vice President - Technology & Managed Security Services at Valuepoint Systems

I rate this solution a six out of ten. Regarding advice, using this solution purely depends on the use case. If it meets your use case, then IBM QRadar is good, but other solutions like Securonix are much better.

View full review »
Yaw Agyare - PeerSpot reviewer
Managing Director at Volta River Authority

I rate the solution an eight out of ten. The solution is good but can be improved with enhanced remote control ability. I recommend the solution to new users considering it.

View full review »
DB
Security Sales Consultant at Google, LLC

IBM has recently come out with a new version called Cloud Pak for Security but I haven't used it yet. It contains not just QRadar, but also IBM's resilience incident response products. 

I recommend the solution but because of the issues with pricing and technical support, I rate the solution seven out of 10. 

View full review »
MW
Relationship Manager at a financial services firm with 5,001-10,000 employees

We're a customer and an end-user. We don't have a direct business relationship with IBM.

Overall, I would rate the solution at a nine out of ten. We've been extremely satisfied with the product so far.

I'd recommend the solution, however, depends upon a company's budget and requirements. For small and medium enterprises, QRadar is the best solution, due to its price and performance.

View full review »
SJ
Senior Security Engineer at a tech services company with 1,001-5,000 employees

We recommend QRadar. It is a good product, a good solution.

Every customer should go with IBM QRadar.

On a scale of one to ten, I would give IBM QRadar a nine.

View full review »
AK
Works

We are implementors. Our customers are the ones that use IBM Qradar.

We are an IBM partner.

We strongly recommend to our customers use the latest version of Qradar. It's important for security. We tend to use the latest in general.

Our customer is a government organization, including some ministries. Therefore, they use on-premise deployments only. However, they have some plans for hybrid clouds or private clouds in the next three or four years. That said, it's very hard to say exactly as the work at the ministry is about security. On-premise is deemed to be more secure.

I'd rate the solution at a nine out of ten.

View full review »
RU
Senior Solutions Architect at a manufacturing company with 51-200 employees

I would recommend this solution. If you are looking for a SIEM solution, IBM QRadar is one that you should ideally look for.

I would rate IBM QRadar a nine out of ten.

View full review »
it_user632664 - PeerSpot reviewer
Information Security Analyst at Allegiance Air

Make sure you try them all and then, pick the one that you think would work the best. It's nice to value other people's opinions, but it's better to test all the products and choose what you think would be best, for whatever your need is.

It's very easy and initiative. It's just a good overall solution, compared to the other ones I've used.

View full review »
Khalid Majeed - PeerSpot reviewer
Cyber Security Consultant at Software Productivity Strategists, Inc. (SPS)

New clients should know that it does give good analytics and it will help them save time.

I'd rate the solution seven out of ten. It's a good product.

View full review »
SD
IM Operations Manager at a tech services company with 1,001-5,000 employees

My advice to others is they have to have IBM Qradar set for purpose and it depends on the role that you see your SIEM solution playing in the company. If you're offering it as a service to other companies, or you're an IT service provider or security solution provider, then yes, you probably need an enterprise base that is scalable but not with smaller enterprises.

I do think the IoT component of IBM Qradar is lacking. IBM tried and IoT is not specifically aimed at only cameras or what I call physical access points, integration into what I call scale technology. They are areas that would depend on each business to map out what the requirements are. This is not a McAfee endpoint or a Symantec endpoint device that gives you an alert.

There is more competition and innovative application development in this area we've seen in the last few years.

I rate IBM Qradar a seven out of ten.

View full review »
SD
IM Operations Manager at a tech services company with 1,001-5,000 employees

My advice to others is to shop around because IBM QRadar Advisor with Watson is not for small enterprises, it's aimed at your larger environments that have a multitude of infrastructure and networks that are hybrid across different environments. It integrates into quite a few tools, such as your email system, and file systems. 

This tool is not for everybody. IBM doesn't have the sort of tool that helps a five, ten, or twenty user environment. This is not advisable to go and invest in the solution. There are other tools that you could possibly look at that do probably some of the functions in terms of monitoring your playbooks and integration points that are a little bit easier to map to. However, that is not a tool for every organization out there. The solution is targeting major enterprises.

I rate IBM QRadar Advisor with Watson a seven out of ten.

There are quite a few areas they could improve, such as they have a lot of technical manual configs and orchestration could be better.

View full review »
AK
Cyber Security Consultant at raf

This is a good product for large enterprises. Smaller companies should implement an open-source solution but for a large enterprise, QRadar is a good product.

I would rate this solution a seven out of ten.

View full review »
PK
Solution Architect Cybersecurity at a tech services company with 501-1,000 employees

Before implementing a new solution, you need to understand your network infrastructure completely. You need to determine if third-party integration is supported or not. IBM Qradar supports a lot of third-party integration because third-party tool integration is often required. 

Storage also needs to be defined properly as logs need to be kept for a certain amount of time. If you have to store logs for three to six months, then you'll need to ensure that you've evaluated the storage capacity properly.

Overall, on a scale from one to ten, I would give this solution a rating of eight. We're very satisfied with it. 

View full review »
YS
IT Specialist​ at IT Specialist LLC

I give the solution a seven out of ten.

We have around 20 users.

The solution is of good quality and can be implemented successfully. However, in order to fully utilize its benefits, one must possess expertise in Python programming.

View full review »
Farid Lalayev - PeerSpot reviewer
Cyber Security Student at Baku Higher Oil School

I'm an intern at one of the biggest telecommunication companies, and my company uses IBM QRadar.

My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use. The solution also has many dashboards, and you don't have to write any code or write different scripts to get the information you need. You can do it from the UI of IBM QRadar. The only room for improvement in the solution is that it doesn't support newer technologies, and it's late when it comes to updates.

I'm rating IBM QRadar nine out of ten because my experience with it has been excellent. The only downside to it is that IBM is late with adding new features or supporting new technologies compared to its competitors.

My company is an IBM QRadar customer.

View full review »
Ertugrul Akbas - PeerSpot reviewer
Manager at ANET

IBM QRadar User Behavior Analytics is a good solution. If there is a big enough budget they might be able to afford the solution since it is expensive. If the conditions are okay, then they should select the solution.

I rate IBM QRadar User Behavior Analytics a six out of ten.

View full review »
JM
Sr.Network Engineer at NTT Security


Our environment is binding. We have only monitoring and data central traffic.

I would recommend the solution to others. It is fine for analyzing logs. 

View full review »
DS
SOC Team Lead at a financial services firm with 1,001-5,000 employees

I would recommend the solution to others and we plan to continue using it in the future.

I rate IBM QRadar a nine out of ten.

View full review »
CM
Security Operations Manager at a comms service provider with 501-1,000 employees

We are just a customer and end-users. We don't have a business relationship with IBM.

We are using the latest version of the solution, as we have the cloud version of the product. Whatever the latest version is, IBM upgrades it automatically. We don't need to worry about that on our end.

In general, I would rate the solution at a seven out of ten. If it were cheaper it might rate a bit higher, however, for the most part, it does what we need it to do.

View full review »
DS
Works at a healthcare company with 5,001-10,000 employees

If you absolutely positively have to catch the bad guys, and you have a heterogeneous environment QRadar is a great choice.

View full review »
DS
Vice President & Country Head at Inspira Enterprise

I would rate QRadar UBA seven out of ten.

View full review »
AE
Head Of Sales at Cascade Solutions Inc

I would rate it an eight out of ten. 

View full review »
AI
Chief Technology Officer at a tech services company with 51-200 employees

The pre-design and the low-level design should be very, very, specific. It's important to check that the compatibility is there. If not, neither IBM nor OEM will support you.

I would rate the solution more highly but it's very expensive and given the high cost, I would expect quicker and better service from the OEM so I rate the solution seven out of 10. 

View full review »
AM
Senior Cyber Security Expert at a security firm with 11-50 employees

I don't know what I would recommend for SMEs because we never worked with SMEs, but I would be very careful in recommending QRadar for SMEs. 

I would rate IBM QRadar a nine out of 10.

View full review »
HH
Senior IT Technical Support at a training & coaching company with 1,001-5,000 employees

I'm actually teaching IBM and some services such as IBM QRadar, as part of my work. I'm familiar with Splunk, however, I'm not working with it on a daily basis. I'm teaching that technology to others. I'm not a customer. I'm using it for teaching purposes. I'm working in a training center. I'm not dealing with it on a daily basis, however, I understand how the product works. We do sometimes help integrate it and work as consultants occasionally as well.

While 7.4 is out, we're currently working with version 7.3.

Overall, I would rate the product at an eight out of ten. There's more to be done on it, however, we are mostly pleased with its capabilities.

View full review »
JN
Director of Information Security at a financial services firm with 501-1,000 employees

Like any complex enterprise CM tool, you have to have a strong support organization. People who are good at understanding Linux operating systems. You also need a strong technical support team in-house.

I would rate this solution an eight out of ten.

View full review »
MM
Senior Manager, Security Architecture & Operation, Corporate Security at Omantel

QRadar is not perfect. It's a good security monitoring product that can provide threat intelligence, but it cannot do it alone. You need to integrate with many other things, such as IBM Orchestrator. Also, you need to have X-Force. After these kinds of things are integrated, it works a little bit better.

I would rate this solution a six out of ten.

View full review »
ÖO
B.T. Güvenlik Yöneticisi at a energy/utilities company with 10,001+ employees

There are many good products and solutions on the market, but for implementation and maintenance, I can say that the most important thing is local support.

We do not have any issues with this product, and we have seen the benefits of it. It is easily configured and installed, and we have a local team to support it. It does have issues in terms of user experience, however.

I would rate this solution an eight out of ten.

View full review »
VP
Manager-Cloud Security Operations at a retailer with 10,001+ employees

If you are a medium to large size enterprise, you can surely consider IBM as one of the major contenders for your selection. If you are a small enterprise, QRadar may be too much for you, it may be too complex.

When deciding on a solution, we always consider:

  • Cost-benefit
  • Shelf-life of the solution
  • Security of the solution
View full review »
it_user634836 - PeerSpot reviewer
IT Director at MyEyeDr.

We try to do everything all at once.

Find the right partner to help you do the implementation.

When picking a vendor, we look for the support, the ease of the installation, and the future of the product.

View full review »
it_user632775 - PeerSpot reviewer
Sr. Security Architect at American Airlines

If you have the budget, go for QRadar. It depends on the company size. It's expensive.

View full review »
it_user634848 - PeerSpot reviewer
Security Operation Manager at a transportation company with 10,001+ employees

Ensure that it's scalable and that you have good customer support. Also, take your time doing the implementation.

View full review »
it_user489405 - PeerSpot reviewer
Security Consultant at a tech services company with 11-50 employees

If you are a security officer who wants to protect his job, go for Splunk :) If you are a customer who wants to have an easy tool and save time and resources, definitely go for QRadar.

View full review »
it_user631671 - PeerSpot reviewer
Information Security Analyst at a media company with 1,001-5,000 employees

You should totally go for it. I've seen a couple systems out there, but I think IBM QRadar is one of the better solutions available.

Professionalism and to always be there when I call are the most important criteria when selecting a vendor. With IBM it's pretty good. We have our sales guy, who is always on top of everything.

View full review »
willie.Na. - PeerSpot reviewer
System Engineer at Trans Business Machines Ltd

I recommend this solution and rate it seven out of 10. 

View full review »
JR
Cybersecurity Business Development Manager at a comms service provider with 10,001+ employees

I rate IBM QRadar a ten out of ten.

View full review »
DD
Head of IT Security, Governance and Compliance at a consumer goods company with 10,001+ employees

This is a good tool to have because it gives you the ability to track what is currently happening in your environment. Otherwise, if you did not have that, you'd only react to an event or an incident that has already caused problems. The proactiveness goes a long way because it saves your environment and your business from being negatively affected.

In summary, this is a good product but there is always room for improvement.

I would rate this solution a nine out of ten.

View full review »
RO
Information Security Specialist at a comms service provider with 501-1,000 employees

I'm not sure of which version of the solution we're using.

I wouldn't recommend the solution. I'd probably tell others to shy away and look at other products like possibly Splunk, however, it's a pricey option. LogRhythm is pretty good. We're having some issues with it. That said, for the most part, it's okay. 

Exabeam also seems like it might be a good option. I haven't worked with it personally, however, I've had some experience with a POC.

Overall, I would rate the solution at a three out of ten. We didn't have a good experience with it. If it offered, for example, easier behavior analytics, easier integrations, better interface, supported model integration, and a good user interface to perform analysis I might rate it higher. Basically, it just needs to be much more user-friendly.

View full review »
it_user398799 - PeerSpot reviewer
Sr. Security Analyst with 1,001-5,000 employees

Research, and don’t be afraid to do a few PoCs. Also, make sure you have a team for the tool. Most solutions require a team, so if you cannot apply a team towards the tool then hopefully you can use one of the managed SIEM options.

View full review »
it_user634794 - PeerSpot reviewer
Director of Cyber Security at a insurance company with 10,001+ employees

Make sure you really understand all the requirements before you implement. I think the group that did this implementation didn't necessarily understand fully what we were going to use it for, so it was maybe designed for smaller things. So, you should really understand the requirements prior to stepping into it. 

If QRadar is going to be a central sort of hub for IBM's security solutions, make sure that the other tools integrate very easily into it. That would probably be the biggest task.

View full review »
it_user545001 - PeerSpot reviewer
Security Operations Center Manager at a financial services firm with 1,001-5,000 employees

Evaluate the product based on a full set of requirements and your security analyst workflow. Do not base your decision on the company name or promises of new abilities years down the line.

View full review »
it_user631740 - PeerSpot reviewer
Security Manager at a pharma/biotech company with 1,001-5,000 employees

From an analytics perspective, it's a good tool. But you have to have the resources to own it. It's not only about buying it. It's not only about capacity, but somebody has to care and feed it. It's not one of those things that you can put it in, walk away and just consume the data. If you don't take care of it and feed it, you won't get what you need out of it.

View full review »
UzairKhan - PeerSpot reviewer
Business General Manager at Mutex Systems

Overall, IBM QRadar is very good but no product is perfect.

I would rate this solution a nine out of ten.

View full review »
VK
AVP - Cyber Secuirty at Cloud4C Services

We have nearly two hundred customers making use of the solution.

We have direct contact with Ingram Micro or have a service partner relationship with it, but work directly with IBM as our ISP. 

We are a managed security service provider and wholesale customer of IBM QRadar

We buy a bulk license from IBM QRadar and host around 200 plus customers in a single integration so that all the customer events will be integrated in one solution. We are not integrators and do not resell their services.

As such, we don't buy the license or sell the tools to others. We will buy a license, inclusive of the services, host it with our private cloud and provide services to the end clients.

Our customer base of IBM users is limited. When it comes to a security operations center team, IBM will be looked to for providing security monitoring on an ongoing basis. We must see that it is working as it should be. 

I would recommend this solution to others. 

I rate IBM QRadar as an eight out of ten. 

View full review »
SG
Vice President at a financial services firm with 10,001+ employees

Someone considering implementing IBM QRadar should possess a good knowledge of his own infrastructure. He should have all the documents in place. While IBM provides very good implementation support, a complete inventory and technology detail is required, in respect of how the application is flowing, how the infrastructure is connected, and the version and inventory relationship.

I rate IBM QRadar as an eight out of ten. 

View full review »
SS
Information Security Manager at a tech services company with 1,001-5,000 employees

Here in Pakistan, this solution has already saturated the financial market.

I rate IBM QRadar a five out of ten.

View full review »
AI
Chief Technology Officer at a tech services company with 51-200 employees

This is a good solution, but I am familiar with the capabilities of the other products and IBM needs to make some improvements.

I would rate this solution a seven out of ten.

View full review »
it_user641277 - PeerSpot reviewer
Information Security Analyst at a transportation company with 5,001-10,000 employees

Evaluate your network first. Determine the target audience that you will be monitoring and working on this tool.

It is important to note whether your organization is looking for a compliance-based check mark practice (defensive security), or active threat monitoring and out-of-the-box security posture.

View full review »
MI
Certified AIX I.T Manager at a financial services firm with 10,001+ employees

I rate QRadar an eight out of ten. I would recommend QRadar, as well as LogRhythm, to others considering implementation. 

View full review »
JT
IT Security Analyst at a manufacturing company with 10,001+ employees

I would absolutely recommend QRadar because it has a lot of options to improve or detect some information.

On a scale of one to ten, I would give QRadar a 10.

View full review »
PL
Network Security Engineer at a wellness & fitness company with 10,001+ employees

The most important criteria when selecting a vendor: stability. The security space is tough. Unlike a lot of other spaces, IBM will not be bought anytime soon as a 100 year-old company.

View full review »
it_user246402 - PeerSpot reviewer
Sr SIEM Consultant at a tech services company with 51-200 employees

Every SIEM tool has a certain degree of complexity, especially where use cases and rules are concerned. I advise using Professional Services so your SIEM is configured by trained professionals.

View full review »
JT
Solution Architect at Ostec

We use the solution inside our organization. Our clients use it too. We are a premium partner in our region. 

We're using the latest version of the solution.

I'd rate the solution nine out of ten. It really provides good visibility.

View full review »
Kamal Abdelrahman - PeerSpot reviewer
Country Manager at Magarah

I recommend this solution to others.

I rate IBM QRadar an eight out of ten.

View full review »
it_user927267 - PeerSpot reviewer
Senior Security Architect at a tech services company with 10,001+ employees

There are new things that are coming up in QRadar, such as AI to IBM Watson. This is going to create a huge impact in these types of solutions, because we don't have an artificial intelligence coming in. There are other tools that have artificial intelligence, but IBM QRadar getting integrated with artificial intelligence is the next step.

It should be noted that the QRadar type products are actually changing their strategy. they will move on to the next stage that is called "Threat Hunting." Instead of waiting for some attack to happen and getting an alert, the new solutions will try to find out those suspicious activities in your network or environment and resolve it before it creates havoc.  

View full review »
WP
Vulnerability Manager at a tech services company with 51-200 employees

Just spec it correctly and it will do its job for you. It has an active community. IBM patches the product regularly when problems are picked up. I haven’t heard about a lot of problems from other people using the product. When we only have four hours to respond, an hour can make a difference in waiting for support.

View full review »
it_user639687 - PeerSpot reviewer
Cybersecurity Expert at a financial services firm with 10,001+ employees

Don't forget to hire the right people. They are expensive, but it is far more cost-effective to pay them now than to try to integrate SIEM without professional knowledge and break it (it is especially important in the architecture and integration phase). Because, then you will pay twice and your security monitoring program can be delayed months. In the operation phase, don't forget to invest in training for both analysts and SIEM administrator teams. It is very easy to use this tool the wrong way and then it will give you almost no value.

View full review »
it_user634842 - PeerSpot reviewer
Senior Manager at a pharma/biotech company with 1,001-5,000 employees

The solution seems to be very promising on paper, i.e., in theory, some things look good but practically, after we apply the solution in the next one or two years, we'll come to know more.

You should first conduct an assessment from IBM and the system should follow the selection of the tool. You should not just go by what you want, but instead by what you need. Most of the companies don't know what they need in terms of the security.

View full review »
GR
SOC Manager at Nais Srl

I would rate IBM QRadar an eight out of ten.

View full review »
PP
Management Executive at a security firm with 11-50 employees

On QRadar, we look at the cloud-based uses as opposed to on-premise due to the cost factor. 

In terms of SIEM technologies, in terms of what you can get, I would rate it an eight out of ten. The QRadar platform is phenomenal in terms of what it does.

If you want to get the best out of IBM, spend more time on the rules generation and the modification of the rules.

View full review »
RB
Founder at Halainfosec

There are many competitive tools that are emerging regarding XDR solutions or SO solutions, which are capabilities that QRadar offers.

The competition is very different from the geographical locations.

For the Indian market, locally, they are still working on the old SIEM structure. It is a very generic SIEM model. Western countries, especially North American clients, are advanced in terms of moving the infrastructure to the cloud. Some have OT security and they're also doing some Office 365 advancements and several advanced search engines for endpoint detection.

They are expecting that nothing is left behind without using any licenses. Microsoft provides part of the security services if you go with the EFI license.

As vendors, we need to counter with the important visibility areas, and the critical access, which needs to be monitored as part of security. 

I would rate IBM QRadar a seven out of ten.

View full review »
SP
Senior Security Engineer at a wholesaler/distributor with 10,001+ employees

I would recommend this solution.

I rate IBM QRadar an eight out of ten.

View full review »
Md Saiful Hyder - PeerSpot reviewer
AGM, Enterprise Solutions at Omgea Exim Ltd

We're using the latest version of the solution.

We are a reseller. We're selling the solution to end customers.

Whenever there is a requirement, a security requirement, or an AFM requirement, we actually position IBM QRadar. We proactively promote the solution and the market, so that we can build a community around QRadar. We're trying to build a community around QRadar so that we can increase sales. We need to have local resources to promote the products. Therefore, we are trying to double up that community of QRadar users. We're doing knowledge sharing among our network. We're changing information so that we can have a knowledge-based group so that we can promote the product to more customers.

While I'd recommend the solution, I'd caution that, for any IBM product other than hardware, the local resources are not that great as they are not often available. I can see why some customers are afraid to add this product. It's different from, for example, Oracle, which is doing product training everywhere and is actively certifying people. 

Overall, aside from support issues, we've been happy with the solution. I'd rate the solution nine out of ten.

View full review »
AS
Co-owner and CEO at Data Security Solutions

It is not something like a next-generation firewall, next-generation intrusion prevention, or the most complex tool that you have got, which you can install and configure and then see if it runs smoothly. It is a completely different story in QRadar or any similar technology. These solutions or technologies have to be managed continuously. 

The biggest mistake that innovations people usually make is that they don't plan the total cost of the technology tools for a period of five years, especially because they don't know what kind of new threats are coming out. Despite that, IBM is very early in doing some kind of new content packs and including data enforcement, etc. When new threats are coming in, you effectively need to adjust. The more complex use cases you have, the more complex the responses will be. You might have different systems or you might be working in different time zones.

When buying, people think that 70% to 80% percent of the initial purchase is the total they are going to spend within next year at this time, and then every next year, they will spend like 20% or 25% on the technical support, maintenance, development of the system, etc. When you are talking about a huge, complex, and central cybersecurity threat management system, it is more likely that you are implementing a document management system and some complex CIP systems, etc. The cost of the license and the cost of the hardware initially can make up around 20%, 30%, or less percent of the total budget that is needed for quality management of such solutions for a longer period of time. 

Some people think that if they buy this for 100,000 pounds or euros, the next year, they can buy just annual subscriptions for 25,000 or 20,000. You may have some internal costs for the license, etc. If you are buying for, let's say, 100,000, you might have to make your budget for 200,000 more, because it needs to have certain people who are doing everything with the solution. You need to train them and send them to the IBM international technology academies and events such as Visor to know about its management and maintenance. You probably also need to do some certification, so you need to go for a course for implementation. A lot of internal work should be done to adjust the solution with other departments, and those other departments usually don't like such central, overseeing, and controlled solution. They, later on, learn that they can get a lot of different, useful reports out of it without doing additional work. 

I would rate IBM QRadar an eight out of ten. Every technology has some weaknesses and strengths. It has a lot of points to improve, but based on everything that we have seen in the market and from other customers, this is, so far, at least in Europe, the best solution.

View full review »
FC
Ingénieur d'étude R&D at DOGA

I'm using the latest version of the solution. I'm the only user and I use the desktop version of the solution. I'm basically using it because it's here and I have access to it.

I would recommend the solution to other organizations, however, if it is right for them depends on their need.

Overall, on a scale from one to ten, I'd rate the product at an eight. We've mostly been pretty satisfied with it.

View full review »
it_user1379427 - PeerSpot reviewer
Application Security Architect at Bank Al Habib Limited

What advice would I give? I want the certification to be very honest. I typically like the hands-on with QRadar, they're quite different.

On a scale of one to ten, I would rate IBM QRadar User Behavior Analytics a seven.

I have used other solutions, like LogRhythm, for a few use cases like ransomware detection, etc.. and there were less false positives there. With the ransomware especially, it was very thin there. We actually have very few use cases and there were lots of false positives with QRradar. If I compare the AI function and the logarithms I think it needs some improvement. 

It is a complex product compared to LogRhythm.

View full review »
JK
Lead Security Infrastructure Engineer at a financial services firm with 5,001-10,000 employees

Understand how your analysts need to use SIEM to execute use cases. This platform can collect and normalize data better than just about anything (if you want it to), but it will not be useful if it is not presented in a useful way.

View full review »
WP
Vulnerability Manager at a tech services company with 51-200 employees

Just spec it correctly and it will do its job for you. It has an active community. IBM patches the product regularly when problems are picked up. I haven’t heard about a lot of problems from other people using the product.

View full review »
it_user634800 - PeerSpot reviewer
Security Consultant at Dimension Data

Definitely try it. Do a PoC with a customer. You can get the value for the customer quickly. It's great.

View full review »
it_user642180 - PeerSpot reviewer
Director SOC at a tech services company with 51-200 employees

First, identify the most critical assets to be included in SIEM and then the most critical events of my organization. With that, you avoid bringing unnecessary events into SIEM.

It's a very good and versatile correlator.

View full review »
JJ
Managed Security Product at a comms service provider with 1,001-5,000 employees

I would recommend IBM to others who want to start using it.

On a scale from one to 10, I would rate IBM QRadar a seven.

View full review »
BK
Program Manager at a tech services company

I would rate this solution eight and a half out of ten.

View full review »
WP
Vulnerability Manager at a tech services company with 51-200 employees

QRadar, as a product, might be very straightforward, but to fully understand the product you would need to go for the QRadar training. IBM's training for QRadar is very expensive but it really helps you use the product to its full potential. Before I went to the training, I only used about ten percent of its capability. I would recommend going for the training on the product.

In terms of the number of users, it's not users logging in every day and doing stuff on QRadar. It's a handful of people from the team monitoring QRadar. We could be managing, for example, 50 or 70 customers through one dashboard and about ten people would be monitoring it. The users have a specific role.

The amount of staff required for deployment or maintenance depends on the type of update or patch that's being deployed. For deployment of a new patch it, it could take anything from an hour to about ten hours. It depends on the patch, how big the patch is, and if you've gone through a testing phase or not. So there are multiple dependencies on how long it would take. An average, for me, would be three hours to do certain deployments.

Currently it's being used quite widely. The only downfall of this product would be its price. I wouldn't recommend it for a small company. For larger companies I know it's being widely used.

View full review »
it_user632703 - PeerSpot reviewer
Senior security analyst at a financial services firm with 1,001-5,000 employees

Make sure you understand how many log sources you have in your environment. Kind of get an idea of how many per second you're going to be getting. That way, you have a good idea for your licensing model to start out with. In the past, we had a certain set we thought we were going to have, and then we had to upgrade, and then upgrade again, for the license count.

Also, make sure you're doing correct tuning. Otherwise, you're just going to flood your SOC, and they're gonna' spend too much time sifting through white noise.

View full review »
it_user632781 - PeerSpot reviewer
Cyber Security Manager at a energy/utilities company with 1,001-5,000 employees

It's a very solid product. However, there are a lot of things that can be improved.

Definitely get a team or hire a professional to install this product. Otherwise, I guarantee you're not going to be successful. There is a lot of filtering that needs to be done; otherwise, you are going to get overwhelmed with the events coming in and will have no idea, as to what is right and wrong. You definitely want to hire a trained team or some professionals.

The price is the most important criteria when selecting a vendor. Other factors such as the quality of the product, PoC, how well the team interacts and the support, are always important.

View full review »
NB
IT Security and Business Development Manager at a tech services company with 51-200 employees

I would advise someone considering this solution to evaluate several solutions, compare them, and if there is an option for customization check with the solution provider, and then go for it.

I would rate it a seven out of ten. It's a good solution, we've used it for a long time, but then there are a few issues with security.

View full review »
it_user393954 - PeerSpot reviewer
Application Infrastructure innovation at a financial services firm with 1,001-5,000 employees

If you're going to implement it, implement it using managed services, because it's too complex of a product to try to do yourself.

View full review »
Ashok Kumar Biswas - PeerSpot reviewer
System Engineer (Cybersecurity) at Omgea Exim Ltd

I rate this solution a nine out of ten.

View full review »
Ahmed Hossam - PeerSpot reviewer
SOC Analyst Tier 2 at IP Protocol INC

I would advise potential users to read the manual or the workbook before going forward with the deployment. Try to match the requirements with the company's needs to avoid facing issues in the future. But if you get stuck, you can always ask the community for help.

On a scale from one to ten, I would give IBM QRadar Advisor with Watson a nine.

View full review »
PD
Assistant Engineer at Harel Mallac Technologies Ltd

I would recommend this solution to others.

I rate IBM QRadar a nine out of ten.

View full review »
JW
Solution Security Architect at PT. Sinergy Informasi Pratama

I recommend this solution because I think they provide great support from the sales and technical perspective.

I rate the solution nine out of 10. 

View full review »
MD
Cybersecurity Engineer Consultant at a tech services company with 501-1,000 employees

Think scalability and make sure your product can be integrate into QRadar.

View full review »
MH
Network and Security Technical Team Leader at a wholesaler/distributor with 201-500 employees

IBM needs to invest more into the collaboration with other vendors.

If you want to go to IBM, do not just go for QRadar. You need QRadar and all the products that surround QRadar, especially BigFix, because the product is ten times stronger with it.

Most important criteria when selecting a vendor: 

  • The technical features of the solution.
  • The people in my region at the vendor.
  • The perspective of the project manager on the customer side.
  • Data involved and time of the implementation. 
  • The needs of the customer.
  • The cost of the project.
  • Training involved.
View full review »
SU
Team Lead - Information Security at a computer software company with 10,001+ employees

We are a preferred partner of IBM.

I'd rate the solution at a seven out of ten.

View full review »
RP
Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees

I would recommend this solution to others. We have invested in it and we plan on using it in the future.

I rate IBM QRadar an eight out of ten.

View full review »
GO
Marketing Director at a aerospace/defense firm with 1-10 employees

This kind of solution is essential. The communication network functions very well.

On a scale of one to 10, ten being the best, I would give this product a rating of nine.

View full review »
it_user163854 - PeerSpot reviewer
Security Solution Architect with 1,001-5,000 employees
  • First gather your requirements
  • From that build a business case.
  • Understand that no matter what technology you choose the technology area is 15% of the effort. Your processes are 85%. No process…then 5h1t in …5h1t out.
  • Make sure you know your business reasons for the implementation
View full review »
Muhammad Ali Aziz - PeerSpot reviewer
Senior Manager Cyber Security Services & Solutions at Trillium

I will recommend this solution to potential users.

On a scale from one to ten, I would give IBM QRadar User Behavior Analytics a seven. 

View full review »
JB
Deputy General Manager at a comms service provider with 5,001-10,000 employees

I rate IBM QRadar a nine out of ten.

View full review »
SW
Cyber Security Consultant at Gulf Business Machines

We are resleers of QRadar.

In general, we have been quite happy with the solution. I would rate it nine out of ten.

We get excellent visibility in every aspect. It's easy to handle incidents when you really have everything in one place. You begin to know exactly what's happening on a network, and how the systems are performing and behaving.

When you compare it to other products, what I would advise is you look at how long they have been in business. This product has been in business for a very long time. You also need to look at the other integration factors, such as forensic, as they're very important. When it comes to forensic, nobody does better than what IBM Qradar Forensic does. There are other factors too - like its Watson integration, and all those things really play an equally important role.

It's not only about just the SIM, or your goals towards is going to be in building the SOC, Security Operation Center. It's all about automation as well. The integration should also look into automation capabilities. That way, you will be able to scale it up to build up a proper SOC.

View full review »
DP
Chief Technical Officer at IT Specialist LLC

I like IBM QRadar User Behavior Analytics. I would rate it an eight of ten. It still needs a lot of improvement, but its main advantage is that it's fully integrated with a SIEM system, and it's free of charge.

View full review »
SO
Deputy General Manager - Network Security at a tech services company with 201-500 employees

Our customers are satisfied with the product and they are not looking for anything else. I would recommend the product.

On a scale of one to ten I would rate IBM QRadar User Behavior Analytics a seven.

View full review »
NM
Solution Manager at ZZTL

IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer.

I would rate it an eight out of ten. They should reduce the pricing. 

View full review »
AF
Cyber Security Specialist at AEC

The solution functions very well. It is amazing but there are some bugs with it. The unknown bugs can just come up with the adaptor with the data stored in Qradar. 

On a scale from one to 10, ten being the best, I would rate this product an eight out of 10.

View full review »
SS
Director of Market Enabling Solutions at Raksha Technologies Pvt Ltd

I would rate it a seven out of 10. I have had some challenges integrating this solution.

Each organization is looking for security. If you have a SIEM tool, you can integrate it with all of your security devices, and get all your security logs. This console gives you the entire view, which makes life easier and allows you to take precautionary measures.

People who handle only four or five security devices spread across the globe should go with this SIEM tool.

View full review »
JC
Director, Cybersecurity at a media company with 51-200 employees

The tool gets better value in the hands of an experienced security analyst. 

View full review »
Kamal Abdelrahman - PeerSpot reviewer
Country Manager at Magarah

I rate IBM QRadar User Behavior Analytics an eight out of ten.

View full review »
TG
Sr. Information Security Analyst at a insurance company with 51-200 employees

I would recommend having a third-party vendor.

There are a lot of alerts and a lot of tuning that has to be done. Every time we add new rules to it, an alert goes up. Having the SOC to go through it all first is very beneficial.

For what we do, I would rate IBM QRadar a ten out of ten. We are satisfied with it.

View full review »
BB
Enterprise Architect, CISSP at a tech services company with 1,001-5,000 employees

I would rate this solution an eight out of ten.

View full review »
it_user970365 - PeerSpot reviewer
Cybersecurity Practice Lead at a tech services company with 201-500 employees

My advice is to take your time. It depends on your network, on what you want to gather information from. Make sure that the networking and the cybersecurity teams are working towards a common goal. The solution is very much worth it. You can gather all the information that you need as long as you know first what you need.

This solution is mainly for the Security Operations Center, so there are just three or four users. But it's one of the key tools for us to identify threats and attacks. The users are security operations analysts and threat hunters.

In our case, deployment and maintenance requires just a few people. They are the network administrators and our cybersecurity engineers.

At the moment we have no plans to increase usage. If the company grows, usage should grow as well. The company is growing but, as of the moment, we are planning for expansion. That's why the solutions that we carry are already built for expansion for the next three to five years.

I would rate QRadar at eight out of ten. It's not perfect and the big issues would be the price and it that it takes some time to understand it. But so far, it's one of the best solutions out there.

View full review »
TM
Senior Cybersecurity Consultant at CIA Botswana

I would rate it an eight out of ten. Not a ten because the configuration part of it should be easier. They tried to integrate everything together to be all in one, but it's not easy to configure.

View full review »
it_user634860 - PeerSpot reviewer
Cyber Security Engineer

I would suggest QRadar. The security intelligence is one of the best right now.

When looking for a vendor, I want to be able to win them. I want them to accept the fact that I’m looking for a product for what I am doing and I have a couple of requirements.

From there, I can actually tell them what they need to do, or what I need to do, in the environment.

View full review »
it_user634782 - PeerSpot reviewer
Security Analyst at a government with 10,001+ employees

When choosing a vendor, we look for a stable and trustworthy company. I think QRadar is the best solution you can get.

View full review »
it_user634830 - PeerSpot reviewer
Group CIO at a tech services company with 501-1,000 employees

This is quite an established solution so, I will have no hesitations in recommending it.

View full review »
it_user285759 - PeerSpot reviewer
Security Consultant at a tech services company with 11-50 employees

If you have an experienced group of security members, then you may not at all need the advisor for the product. If not, then you will have to find the path to build your team, so as to become more knowledgeable.

View full review »
it_user140676 - PeerSpot reviewer
Information Security Consultant at a tech services company with 51-200 employees
The advice I would give to others is to work with the implementation team to properly fine tune the out-of-the-box “building block rules” and to enter their network hierarchy in QRadar in order for it to give best results and reduce false positive alerts. View full review »
MB
Information Security Leader at a computer software company with 1,001-5,000 employees

I would recommend IBM QRadar to other people who want to start using it.

On a scale of one to ten, I would give QRadar a nine.

View full review »
it_user632760 - PeerSpot reviewer
Lead Developer

Definitely invest in the QRadar solution.

View full review »
it_user643884 - PeerSpot reviewer
Senior System Administrator at a tech services company with 11-50 employees

You should ask the sales representative to give you the Excel sheet to calculate EPS. Keep in mind that the firewalls, proxies and networking devices such as those will consume lots of EPS, but they do provide really nice information and insight from your network.

On Gartner, this is one of the top 10 SIEM solutions in the market. It is robust and IBM is investing a lot of money to get it running even better than it is running right now. You feel secured when you use it.

This solution is being implemented around the world and every day, a new feature or add-on is created for it.

View full review »
RR
IT Security Manager at a tech services company with 201-500 employees

On a scale of one to ten, I would give IBM QRadar a seven.

Overall, I would of course recommend this product to others because of all its functionalities.

View full review »
OK
Analyst at a tech services company with 501-1,000 employees

I would recommend IBM QRadar. The user interface is really great and it simplifies the task of monitoring your environment.

On a scale of one to ten, I would give IBM QRadar an eight.

View full review »
JS
Cybersecurity Architecture and Technology Lead at Appxone

QRadar also supports UBA which is a fantastic feature to detect user's malicious activities.

View full review »
OU
Technical Consultant at activedge

I think this product adds significant value to organizations seeking a scalable, security integration tool. It does a great job of identifying, classifying, prioritizing, remediating, and mitigating software vulnerabilities. It's a good solution

On a scale of 1 - 10, 10 being the best, I give this product a rating of 9.

View full review »
DA
Senior Server Security Engineer

I would rate it an eight out of ten. Not a ten because of the complex interface. 

View full review »
SO
Member at CIFAL Argentina

Most important criteria when selecting a vendor: Our customers need a cross of different units which make up a better solution for them.

View full review »
it_user634779 - PeerSpot reviewer
Security Intelligence at a tech services company with 10,001+ employees

It should be implemented by the best professionals available within IBM. It is really important to have a clean base installation, so that you can build things on the top of it.

When we are selecting a vendor, first and foremost, we look for the stability of the vendor, and what level of resources they are investing in their research and development. These are a couple of things that we look for while selecting a vendor and of course, the kind of resources we are looking for to get certain engagement and make sure those resources are aligned.

View full review »
BT
Assistant IT Manager at a insurance company with 1,001-5,000 employees

On a scale from one to ten, I would give IBM QRadar a seven.

View full review »
HG
Network Security Engineer at a computer software company with 51-200 employees

I rate IBM QRadar a seven out of ten.

View full review »
KA
AVP - Security at a tech services company with 501-1,000 employees

Nowadays cloud stack security is very good. Some of my customers are planning to build their data center over the cloud, or implement cloud-based services using some of the beneficial services, such as threat intelligence services.

I rate IBM QRadar a ten out of ten.

View full review »
LY
Partner at a tech services company with 1-10 employees

Ensure you have the functional skills on BPM and the technical skills on IBM BPM.

We used to be IBM partners, but are not anymore. Now, we are Red Hat partners.

View full review »
OO
Cyber threat Intelligence Manager at CyberLab Africa

I would recommend this solution to others.

I rate IBM QRadar a seven out of ten.

View full review »
MK
Practice Head at a tech services company with 51-200 employees

I would recommend this solution to others who are looking for an on-premises solution. For a SIEM solution, it is the best one to go with. If they are interested in using the cloud, I would not recommend it. The cloud version of QRadar is QRoC and it is a bit complicated.

I would rate this solution an eight out of ten.

View full review »
LB
Security Engineer at a tech services company with 11-50 employees

The first advice I give my customers before buying SIEM is: "You should understand the solution well before starting the implementation." If they don't understand the solution, they will never be able to use it correctly. This is the first piece. The second point is that they will resist the change made to the setup installation. If they look for the solution, QRadar ATM is the best.

I would rate this solution as nine out of ten. I think there is no perfect product; maybe there will never be a perfect product. When I started to learn IBM QRadar, it was complicated to me in the beginning, because we did the installation for the customer. It is complicated, and the meaning and training were not very clear.

View full review »
AB
IT Manager at a comms service provider with 1,001-5,000 employees

Trust it, test it, and deploy it.

View full review »
MH
Team Lead & Principal Software Engineer at a tech services company with 51-200 employees

You receive alerts for misconfigurations which allows your administer to easily reconfigure any issues. 

The organizations themselves are able to monitor all of their information regarding their team including what attacks they are facing on a daily bases.

I would rate this an eight out of ten.

View full review »
JM
CEO at a tech services company with 11-50 employees

I rate the solution nine out of 10. 

View full review »
AK
Security Analyst at a tech services company with 51-200 employees

We use the solution with multiple customers on a daily basis. We have experience with its installation, configuration and use. 

I rate IBM QRadar as a six or seven out of ten. 

View full review »
AC
General manager at a tech services company with 201-500 employees

Within the past year, IBM developed a SaaS version of QRadar, which is a nice option.

My advice for anybody who is considering this solution is to implement the latest IBM offerings together. QRadar is just one of the products, and multiple products can be combined to create the best solution for their needs.

I would rate this solution an eight out of ten.

View full review »
EK
Network & Cyber Security Engineer at a manufacturing company with 1,001-5,000 employees

I would rate IBM QRadar User Behavior Analytics an eight out of ten.

View full review »
RM
Senior Field Manager at a tech services company

I would rate it an eight out of ten. 

View full review »
DC
Security Solutions Architect at Micro Strategies

Do your research before implementing it, because it is tough to implement.

Most important criteria when selecting a vendor: support. I say this to every vendor.

It is not always about pricing, which is nice when we start, but when the crap hits the fan. I want the vendor to be there with me. 

View full review »
it_user197457 - PeerSpot reviewer
IT Security Manager at a tech services company

It is a good solution.

View full review »
OO
Founder at a university with 11-50 employees

When you go for this solution, you are paying not only for the product but also for integration, good staff to help you, scalability, and many other things. There are many things that you can use in QRadar. It is easy to use.

I would rate IBM QRadar a nine out of ten.

View full review »
VB
Principal Security Architect at a computer software company with 10,001+ employees

If you are only looking at IBM, make sure to evaluate the product thoroughly. Make sure to see the complete list they offer, like more of the competitive features. Explore the options available on the market.

It doesn't really integrate well with other products. 

I would rate it a three out of ten. It is missing key features. 

View full review »
DS
Works at a tech services company with 11-50 employees

I would recommend IBM QRadar because of the security features and the organization. I can recommend the security. Security is nowadays an essential part of IBM QRadar. 

IBM QRadar is probably the best possible solution in the market. I would rate it an eight out of 10.

View full review »
it_user795519 - PeerSpot reviewer
Senior Security Engineer at dig8labs

Overall, it's much better than other products.

In terms of increasing its usage, I have suggested to my organization that it tell customers to use it, its capacity and capabilities, with other tools like Watson.

View full review »
it_user575124 - PeerSpot reviewer
Sr. Security Engineer at a tech services company with 11-50 employees

Work on sizing as much as you can so you can avoid any issues after deployment. You should also fulfill hardware requirements for this product. Otherwise, you will not get its full functionality.

View full review »
YC
Security Consultant at a tech services company with 11-50 employees

I would rate it an eight out of ten. 

View full review »
OO
Founder at a university with 11-50 employees

I would rate IBM QRadar a nine out of ten.

View full review »
KJ
CEO at Xcelliti

This is a good product but there is room for improvement in several areas, including the integration of advanced data mining.

I would rate this solution a six out of ten.

View full review »
LD
Technical Presales at a tech services company with 1,001-5,000 employees

I would recommend this solution to everyone considering using it.

I would rate this solution a nine out of ten.

View full review »
GC
Queretaro at a tech services company with 1-10 employees

I think the tool is very complete and very agile.

I would rate this solution a ten out of ten.

View full review »
MA
General Manager at New System Engineering

I would recommend this product. It is very simple to install, and not a complicated solution. IBM supplies regular software updates.

I would rate this solution an eight out of ten.

View full review »
it_user934623 - PeerSpot reviewer
Senior Information Security Analyst at a financial services firm with 501-1,000 employees

I would advise someone considering this solution to write down your use cases and evaluate them with the vendor. Evaluate the best solution based on your use cases because you are the ones who are going to use it. The vendor will try and implement and leave you with your problems.

If the solution meets your requirements and solves most of your problems, you're good to go. QRadar is the best solution we have. The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not always straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference. 

I would rate it an eight out of ten. 

View full review »
it_user923115 - PeerSpot reviewer
Cloud Security Architect at Nordcloud Oy

I highly recommend this product.

View full review »
it_user640416 - PeerSpot reviewer
Assistant Manager-Information Security at a transportation company with 1,001-5,000 employees

If you have a good budget, then go for IBM QRadar.

View full review »
it_user956985 - PeerSpot reviewer
Sr. Security Engineer at OmnitechIT

I would rate this product eight out of ten.

View full review »
AS
Cyber Security Team Leader at a tech services company with 501-1,000 employees

I would rate this solution a six out of ten. 

View full review »
it_user632667 - PeerSpot reviewer
Cyber Security Engineer at a tech services company with 501-1,000 employees

I would definitely recommend QRadar to anyone looking for an SIEM solution in their organization. This is especially the case for mid- to large-scale enterprise solutions, compared with the competitors.

View full review »
OF
Professional Services at a tech services company with 51-200 employees

I would rate this product a nine out of ten.

View full review »
AT
Software Trainee at a tech services company with 1,001-5,000 employees

Overall, I love this product.

View full review »
SH
Pre-Sale Consultant (Technical) at a tech services company with 51-200 employees

Overall, I like this product and I think that the features are good enough.

I would rate this solution a seven out of ten.

View full review »
Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,065 professionals have used our research since 2012.