it_user632781 - PeerSpot reviewer
Cyber Security Manager at a energy/utilities company with 1,001-5,000 employees
Vendor
In general, if you have any botnets or malware, you identify and mitigate it. The biggest challenge is in the upgrade.

What is most valuable?

It gives me insight and visibility, so I can detect a threat coming in and all the offenses are coming in from monitoring one spot.

How has it helped my organization?

We're centralizing all the logs in one location. So, if you have an incident, you can definitely discover it fairly quickly, as it's in one database. In general terms, if you have any botnets or malware, you identify and mitigate it fairly quickly.

What needs improvement?

The biggest challenge is in the upgrade, e.g., when it comes down to a new OS, you have to wipe it clean and reset everything. It takes time when you have 40-50 devices all over the place. It's impossible sometimes to go out and touch every single one of them. So, then, if it's an automatic process, you can upgrade to the new version in just point and click. However, that's not the case right now.

WinCollect is a challenge also, and I'd highly recommend that the Q1 team should build a lot of Windows-based collectors that simply work. Just like the competitor, Spunk, when you put it in, you don't have to do too much modifications. So, that's a challenge right now.

What do I think about the stability of the solution?

The environment is pretty stable. We just upgraded about a year ago, so it's pretty robust in the environment that we have. It's working really well for us, we've been using it for about 10+ years. We bought it before IBM purchased them.

Buyer's Guide
IBM Security QRadar
May 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,063 professionals have used our research since 2012.

How are customer service and support?

We interact with IBM regularly, so we have a direct tie with them. We're almost like a partner, right now, and we are working very well together.

The technical support is pretty good, i.e., if you get the right person in, it moves pretty fast and issues are resolved fairly quickly. But, you just need to find the right person, which can be a little difficult sometimes.

How was the initial setup?

The setup is very complex; it's not like somebody can walk in and build it. It requires many years of experience to manage and maintain it. You need to have at least an experienced and dedicated team, in order to maintain the environment that we have. It's nothing like a click-and-done type; it requires a lot of care and feeding to manage the environment.

What other advice do I have?

It's a very solid product. However, there are a lot of things that can be improved.

Definitely get a team or hire a professional to install this product. Otherwise, I guarantee you're not going to be successful. There is a lot of filtering that needs to be done; otherwise, you are going to get overwhelmed with the events coming in and will have no idea, as to what is right and wrong. You definitely want to hire a trained team or some professionals.

The price is the most important criteria when selecting a vendor. Other factors such as the quality of the product, PoC, how well the team interacts and the support, are always important.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
President, Consultant, Trainer at MEI Security
Real User
Useful searching capability for multiple, correlated logs
Pros and Cons
  • "This solution has allowed us to correlate logs from multiple sources."
  • "We would like to see better instrumentation for debugging changes in the log flow."

What is our primary use case?

We use this solution for log correlation and alerting.

How has it helped my organization?

This solution has allowed us to correlate logs from multiple sources.

What is most valuable?

The searching capability is good.

What needs improvement?

We would like to see better instrumentation for debugging changes in the log flow.

For how long have I used the solution?

We have been using this solution for four years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Security QRadar
May 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2024.
771,063 professionals have used our research since 2012.
IT Security and Business Development Manager at a tech services company with 51-200 employees
Real User
Enables us to ensure that the data being transferred from one company to another is done securely but it needs better cloud security
Pros and Cons
  • "The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two."
  • "Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them."

What is our primary use case?

Our primary use case is for the security. We use it to make sure that the data that is being transferred from one company to the other is being done securely. 

How has it helped my organization?

The security has improved my organization. 

What is most valuable?

The securing of data is the most important feature because nowadays as cloud has come in, it is especially challenging to secure. We are actually planning for Palo Alto to be a better option because IBM needs better security for their cloud.

What needs improvement?

If IBM provides me with a better service or better options than Palo Alto, I would remain with IBM. As for my knowledge, I recently evaluated Palo Alto that has better security features, especially for a client's email. 

Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them.

If IBM could give us a complete package of on-cloud solutions, firewall, antivirus, and also mobile security, that would make it a lot better. Nowadays people are using mobile and tablets, rather than laptops or computers.

We get updates from IBM directly but then the users have to update. There are challenges where sometimes if we update the client's system, it takes a lot of time to update.

For how long have I used the solution?

More than five years.

What do I think about the stability of the solution?

Stability is very good. It's better than it used to be. 

What do I think about the scalability of the solution?

Scalability is very good. 

Everyone has used this solution for security purposes. We use it daily.

How are customer service and technical support?

The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two. 

How was the initial setup?

The initial setup is fine. The moment we send the packets for an update it's easy but then there are challenges for the users. We have actually changed the hardware, so it got updated. We have to check if the problems are due to the hardware or due to the software.

The initial setup normally will take a day. it depends on the number of users. We have 300 users on the system which took around ten days. 

We require five to ten staff members for deployment and maintenance. 

Which other solutions did I evaluate?

Before we went with IBM, we didn't look at other solutions but recently I looked into switching to Palo Alto and also evaluated Fortinet.

What other advice do I have?

I would advise someone considering this solution to evaluate several solutions, compare them, and if there is an option for customization check with the solution provider, and then go for it.

I would rate it a seven out of ten. It's a good solution, we've used it for a long time, but then there are a few issues with security.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user393954 - PeerSpot reviewer
Application Infrastructure innovation at a financial services firm with 1,001-5,000 employees
Vendor
Using it through IBM's Managed Security Services, they keep us alerted of what events are hitting, and adapting for it. I'd like to see tighter integration with other IBM products.

What is most valuable?

What is valuable is that we're using it through IBM's MSS services, and that they're doing a really good job of keeping us alerted of what events are hitting, and adapting for it.

How has it helped my organization?

It benefits us from a standpoint that we're very immature in our review of how security should be approached, and it's really helped us move up to modern awareness of what's going on on the internet.

What needs improvement?

I'd like to see, and they're getting there, is more integration; tighter integration with some of the other IBM Security products. They're moving a lot tighter to BigFix. BigFix has a lot of power in it, and MaaS360 also has a lot of power in it. I'd like to see those more tightly integrated.

What do I think about the stability of the solution?

We have not had any stability or scalability issues. We're a little concerned about the latest version and the fact that it cannot be upgraded, that it requires a clean install.

How are customer service and technical support?

We have not really used technical support, because it's a managed service, so we call the SOC and they help us. They are very helpful.

Which solution did I use previously and why did I switch?

We just really sold our CIO and CTO on the fact that we need to do better than we are, where we're at today. We had a lot of virus challenges, like most companies, and malware, so we had to figure out how to reduce that.

How was the initial setup?

I was involved in the initial setup. Well, IBM did it, since it was a managed service. It was pretty straightforward.

Which other solutions did I evaluate?

We looked at numerous other players. We chose IBM because it has a lot of power, and you can grow it as much as and however you want it to.

When I am looking for a vendor, I don't look for a VAR, I look for a partner.

What other advice do I have?

If you're going to implement it, implement it using managed services, because it's too complex of a product to try to do yourself.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Ashok Kumar Biswas - PeerSpot reviewer
System Engineer (Cybersecurity) at Omgea Exim Ltd
MSP
Top 5
A scalable solution with great event and flow collectors
Pros and Cons
  • "The event collector, flow collector, PCAP and SOAR are valuable."
  • "The solution is expensive compared to other products."

What is most valuable?

The event collector, flow collector, PCAP and SOAR are valuable.

What needs improvement?

Whenever we connect the span port, its device and health status increase the capacity level. So I suggest the mitigation of that part for IBM. Otherwise, it's a good product. We also continuously have issues with technical support because they do not have a prompt response time.

For how long have I used the solution?

We have been using IBM QRadar for the last five years.

What do I think about the stability of the solution?

I rate the stability a nine out of ten.

What do I think about the scalability of the solution?

I rate the scalability an eight out of ten. We deploy to many customers and have completed many POCs. We have a four-person team.

How are customer service and support?

The technical support is good, but they are not prompt. I rate them a five out of ten.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate the initial setup a ten out of ten. It is deployed on-premises and takes about two to three days to deploy the full environment readiness. But the device integration, rules screening and log onboarding take too long, about three to four months. The deployment was completed in-house.

What's my experience with pricing, setup cost, and licensing?

The solution is expensive compared to other products, and I rate the pricing a five out of ten.

What other advice do I have?

I rate this solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner/Reseller
PeerSpot user
Ahmed Hossam - PeerSpot reviewer
SOC Analyst Tier 2 at IP Protocol INC
Real User
Top 10
An AI-powered incident and risk analysis, triage and response tool with a user-friendly graphical interface
Pros and Cons
  • "I like the graphical interface. It's so good and easy."
  • "Integration could be better. They should make it easy to integrate with other solutions."

What is our primary use case?

First, I used the manual to learn, then I tried to merge it with my company's needs, and there weren't any problems.

What is most valuable?

I like the graphical interface. It's so good and easy.

What needs improvement?

Integration could be better. They should make it easy to integrate with other solutions. 

For how long have I used the solution?

I have been using IBM QRadar Advisor with Watson for three or four years.

What do I think about the stability of the solution?

IBM QRadar Advisor with Watson is a stable solution.

What do I think about the scalability of the solution?

I think IBM QRadar Advisor with Watson is scalable.

How are customer service and support?

We didn't use technical support as the community was very helpful.

How was the initial setup?

The initial setup was difficult the first time, but it got easier after that.

What's my experience with pricing, setup cost, and licensing?

I think my company pays for the license yearly.

What other advice do I have?

I would advise potential users to read the manual or the workbook before going forward with the deployment. Try to match the requirements with the company's needs to avoid facing issues in the future. But if you get stuck, you can always ask the community for help.

On a scale from one to ten, I would give IBM QRadar Advisor with Watson a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Assistant Engineer at Harel Mallac Technologies Ltd
Real User
Simple to manage, reliable, and straightforward installation
Pros and Cons
  • "The solution is easy to use, manage, and review all incidents."
  • "If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."

What is our primary use case?

I use IBM QRadar for user behavior analytics, and mostly incident handling.

What is most valuable?

The solution is easy to use, manage, and review all incidents.

What needs improvement?

If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage.

For how long have I used the solution?

I have been using IBM QRadar for approximately four years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

We have approximately three customers and the total users that are using it would be approximately 200.

How was the initial setup?

The initial installation was straightforward, we were able to have it running in half a day.

What about the implementation team?

I do the implementation and maintenance of the solution.

What's my experience with pricing, setup cost, and licensing?

There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option.

What other advice do I have?

I would recommend this solution to others.

I rate IBM QRadar a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Solution Security Architect at PT. Sinergy Informasi Pratama
Real User
Provides great analysis of event logs, event security; easily manageable with one monitor
Pros and Cons
  • "It can analyze event logs, event security, and give a good consult."
  • "Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."

What is our primary use case?

This is a solution you use when you have many security products that you want to manage in one monitor, one analytic. We are partners with IBM and provide implementation services to our customers. I'm a solution security architect.

What is most valuable?

The most valuable feature is that it can analyze event logs, event security, and give a good consult. When you have SIEM, you can easily manage with one single monitor. QRadar can do a lot of analyses of every security product and will let us know what needs to be done to the log. Sometimes we need security orchestration automated response to support the SOC team.

What needs improvement?

The concern with QRadar is that there are so many features in the dashboard, too many menus that require going to two or three sub-monitors to enter the QRadar. The user interface is good but there are so many features that can be confusing for the administrator. It could be simplified. 

For how long have I used the solution?

I've been using this solution for a year. 

What do I think about the stability of the solution?

I think that QRadar is stable, but I've never worked with other solutions in this area and I have nothing to compare it to. It has dedicated machines and offers great performance. 

What do I think about the scalability of the solution?

The scalability is easy but it comes at a high price.

How are customer service and support?

IBM in Indonesia provides great support.

How was the initial setup?

The initial setup is complex if the data set is large. It really depends on that. We provide maintenance services to our clients so that if they have any trouble, we assist with troubleshooting.

What's my experience with pricing, setup cost, and licensing?

SIEM is quite a pricey solution so we only offer it to enterprise companies that can pay the fees. For smaller companies, it's an extremely expensive product. 

What other advice do I have?

I recommend this solution because I think they provide great support from the sales and technical perspective.

I rate the solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2024
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.