Principal Security Architect at a computer software company with 10,001+ employees
Real User
They have to build more quantitative monitoring, profiling, and make it more predictive
Pros and Cons
  • "In terms of the most valuable features, the log collections and log processing mechanisms are good. They have good dashboards."
  • "They have to build more quantitative monitoring, profiling, and make it more predictive."

What is our primary use case?

Some of these products can be used in any vertical like healthcare, manufacturing, and vehicle. You can use these products in all types of verticals. But I found that there is a limitation in central verticals. These products do not do well in central verticals.

What is most valuable?

In terms of the most valuable features, the log collections and log processing mechanisms are good. They have good dashboards. They probably have the best cloud management log processing. They are going to announce user intended behavior and management features. Compliance monitoring is okay. All these things become a commodity.

What needs improvement?

They have to build more quantitative monitoring, profiling, and make it more predictive.

For how long have I used the solution?

I have been working with IBM QRadar for the last seven to eight years. 

Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
770,292 professionals have used our research since 2012.

What do I think about the stability of the solution?

QRadar is quite stable, but I am not sure about the volume. There is no clear volume. If I were to cross to an enterprise and the stability is not available then it would be a problem.

What do I think about the scalability of the solution?

Augmented solutions are very tough to scale because you already fulfilled how well you fulfill the software and then you will have to limit the scalability. That is a problem.

Our clients are small, medium, and enterprise size. 

How are customer service and support?

Technical support is not that strong from IBM. It definitely does not compare to any standard support organization. It's not that great.

How was the initial setup?

The setup is comparatively easy, it's not that tough. But if you look at the current situation with COVID-19, people or organizations are not looking at how easy the cost of the innovation is. People want a plug and play option. 

It's like if you go to the market you buy a car, you get the key, just sit in the car and drive it out. With traditional companies like IBM, you have to use all the hardware, you have to use all the software, and the setup can take one month, two months, three months depends on or the scope. Nowadays consumers are looking for a souped-up car. They expect the tool to be operational maximum within a week's time or 15 days. That is what is missing in the QRadar.

The time it takes to deploy depends on the project scope. The order of planning can take a month to three months.

You will need three people to set it up. It can get quite expensive in retrospect. I prefer to have a plug and play service

What's my experience with pricing, setup cost, and licensing?

There are more costs in addition to standard licensing; support, building.

What other advice do I have?

If you are only looking at IBM, make sure to evaluate the product thoroughly. Make sure to see the complete list they offer, like more of the competitive features. Explore the options available on the market.

It doesn't really integrate well with other products. 

I would rate it a three out of ten. It is missing key features. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Works at a tech services company with 11-50 employees
Real User
Alerts us about events in our network environment and has superb functionality
Pros and Cons
  • "IBM QRadar is easy to scale, it doesn't affect the environment. In our office, we have around 40 - 50 users, but our clients have more users on their networks. Our organization has staff in the software department that manages IBM QRadar for us."
  • "The quoting and the dashboard session could be improved. It should be more user-friendly."

What is our primary use case?

We are partners with IBM. We do simulations for our clients. Then we resolve the issue that they're facing using IBM QRadar.

How has it helped my organization?

We have integrated IBM QRadar with our firewall and some services that we use. When the logs are about to get full of SQL, IBM QRadar makes a notification. The admin knows that they're about to get full so he just goes and clears them out. That is when we usually use IBM QRadar. On our firewall, when the issue notifications are generated, we don't usually open the firewall but QRadar alerts us about what went down in our environment.

What is most valuable?

The most valuable feature of IBM QRadar is its slow control and even activation. I also like the post notifications on the screen.

What needs improvement?

The quoting and the dashboard session could be improved. It should be more user-friendly.

Otherwise, the overall functionality of IBM QRadar is superb. A better GUI and reporting both would be good additions to the product.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

IBM QRadar is very stable. It doesn't have many errors.

What do I think about the scalability of the solution?

IBM QRadar is easy to scale. We can integrate other devices if we want to. We could go to distributed architecture instead, but we like this product. It doesn't affect the environment. In our office, we have around 40 - 50 users, but our clients have more users on their networks. 

Our organization has staff in the software department that manages IBM QRadar for us. The security division just manages the login. Overall, only two to three staff are required for the management of IBM QRadar. They are more than enough to control the situation because most of it is easy. We definitely have plans to increase our current usage of the solution in the future.

How are customer service and technical support?

Technical support from IBM is not that good here in this region. It's quite helpful to have local support. They don't have much expertise in this product. 

We usually have to go to IBM to resolve the issues if we have them because the overall product is a bit complex. There are not many local resources here in this region with expertise in IBM QRadar.

How was the initial setup?

The initial setup is straightforward. It's very easy. I think anyone can install it within minutes. The deployment of IBM QRadar takes around 20 to 25 minutes if you have a good hard drive.

What about the implementation team?

We deployed IBM QRadar ourselves. We have technicians. We bill the client and do the installation on our own, along with other IBM products

What's my experience with pricing, setup cost, and licensing?

We do licensing on a yearly basis. It's for deployment. If the client wants more services, we support the license. There are no other costs for the product.

Which other solutions did I evaluate?

When I joined the company we were already partners with IBM. I didn't have much experience with other products.

What other advice do I have?

I would recommend IBM QRadar because of the security features and the organization. I can recommend the security. Security is nowadays an essential part of IBM QRadar. 

IBM QRadar is probably the best possible solution in the market. I would rate it an eight out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
770,292 professionals have used our research since 2012.
it_user795519 - PeerSpot reviewer
Senior Security Engineer at dig8labs
Real User
Custom parsing tool makes customization easy, and UI is friendly
Pros and Cons
  • "The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding."
  • "The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria."

How has it helped my organization?

The features make my work easier.

What is most valuable?

The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding. I have used McAfee's SIEM and LogRhythm as well, but because of this feature of QRadar, I don't think their solutions are good.

Customizing it is very easy and it has a user-friendly interface. 

What needs improvement?

The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria. Elasticsearch is a very fast search engine. IBM should consider it as part of QRadar. Currently, QRadar has a very slow search. If I search previous months' data it stops.

For how long have I used the solution?

More than five years.

What do I think about the scalability of the solution?

The scalability is good. I'm quite satisfied with it.

How are customer service and technical support?

Technical support is the area IBM should work on. Support is not that responsive. If I open a support ticket, it takes three to four days for them to respond. They take that much time.

Which solution did I use previously and why did I switch?

I have used different solutions in the organization, but the main reason for switching is the customization. QRadar very much supports customization. Another reason is that, in the market, we can easily get QRadar resources, like an analyst or engineer, as compared to other products. This is a reason that organizations move towards QRadar.

How was the initial setup?

The initial setup was very straightforward. I didn't have to do anything once I installed it and configured it. It was very simple. Other solutions I have worked on, such as McAfee and LogRhythm, are a bit complex. This one is very easy to install and configure.

The deployment takes one to two months, max. The implementation strategy is totally dependent on the number of EPS, the requirements, and the types of log sources. We collect this information and then create our strategy.

I have been an engineer in many firms. I have deployed it by myself. One expert can deploy it. If there are 100,000 EPS you'll need more resources. If you have 5,000 to 10,000 EPS, one person can do it.

What's my experience with pricing, setup cost, and licensing?

IBM has subscriptions plans that run for one year.

What other advice do I have?

Overall, it's much better than other products.

In terms of increasing its usage, I have suggested to my organization that it tell customers to use it, its capacity and capabilities, with other tools like Watson.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user575124 - PeerSpot reviewer
Sr. Security Engineer at a tech services company with 11-50 employees
Consultant
We use it to create use cases and review offenses. One of the valuable features is its correlation engine.

What is most valuable?

  • User-friendly
  • Easy to deploy
  • Easy to create use cases
  • Easy to review an offense
  • Its correlation engine is one of the best

How has it helped my organization?

I usually work on the deployment and fine-tuning of this product. However, I have some operational experience as well. For instance, you can simply audit all the IT equipment in your environment, such as the firewall, the IPS, and the Active Directory (AD) server.

What needs improvement?

It should have built-in blocking capability.

For how long have I used the solution?

I have used this solution for four years.

What do I think about the stability of the solution?

On a scale of 100, it is 95% stable.

What do I think about the scalability of the solution?

I did experience some scalability issues in one organization.

How are customer service and technical support?

The technical support is excellent.

Which solution did I use previously and why did I switch?

We were not using any other solution previously. This was my first solution. I am still working on it. I also have experience with McAfee Nitro and LogRhythm.

How was the initial setup?

The setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing will definitely vary according to your EPS, but it is worth spending money on this product.

Which other solutions did I evaluate?

We looked at other solutions, such as McAfee Nitro and LogRhythm.

What other advice do I have?

Work on sizing as much as you can so you can avoid any issues after deployment. You should also fulfill hardware requirements for this product. Otherwise, you will not get its full functionality.

Disclosure: My company has a business relationship with this vendor other than being a customer: I am a vendor.
PeerSpot user
Security Consultant at a tech services company with 11-50 employees
Consultant
Easy to use and helps me analyze incidents that occur
Pros and Cons
    • "They should provide more manual examples online so that I can learn it myself."

    What is our primary use case?

    I use it to analyze incidents. 

    What is most valuable?

    I like the API and it's easy to use. 

    What needs improvement?

    They should provide more manual examples online so that I can learn it myself. The dashboard also needs improvement. 

    For how long have I used the solution?

    More than five years.

    How was the initial setup?

    We require eight staff members for the maintenance. 

    What's my experience with pricing, setup cost, and licensing?

    It's too expensive. 

    What other advice do I have?

    I would rate it an eight out of ten. 

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Founder at a university with 11-50 employees
    Real User
    Stable, easy to set up, and has good support
    Pros and Cons
    • "I think the QDI is very good."
    • "The threat detection needs improvement, they have many false positives."

    What is our primary use case?

    This product helps to build a strong architecture, which is important to avoid problems.

    What is most valuable?

    I think the QDI is very good.

    What needs improvement?

    The biggest drawback of this solution is the price.

    The threat detection needs improvement, they have many false positives.

    It is important to have good architecture. If you have problems and you don't have a strong architecture you, will have trouble with this solution.

    For how long have I used the solution?

    I have been using IBM QRadar for three years.

    We are using version 7.4.3

    What do I think about the stability of the solution?

    It's a stable solution.

    How are customer service and technical support?

    We have many interactions with L2 support when we needed L3 support. I would rate technical support an eight out of ten.

    How was the initial setup?

    The initial setup is straightforward. We had no problems.

    It took approximately a month to deploy.

    What's my experience with pricing, setup cost, and licensing?

    This price is a little high, so it's an expensive product. It is a good solution but not a cheap one.

    What other advice do I have?

    I would rate IBM QRadar a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    CEO at Xcelliti
    Real User
    Easy to install and use, but the GUI and reporting features need to be improved
    Pros and Cons
    • "It has very rich functionality."
    • "QRadar needs to be more specialized, along the lines of what other SIEM solutions are."

    What is our primary use case?

    We use QRadar to detect and gather information about any product vulnerabilities and any sort of attack on the network. It's able to help detect suspicious activity that is coming into the system.

    We are also selling this product.

    What is most valuable?

    This product is easy to install, integrate, and use.

    It has very rich functionality.

    What needs improvement?

    QRadar needs to be more specialized, along the lines of what other SIEM solutions are. It needs to be more detailed.

    Incorporating an AI component is needed, where the learning feature identifies malicious activities coming into the network.

    The GUI and reporting need to be improved.

    The footprint needs to be optimized because the application footprint is too heavy. The machine requires a very high amount of resources.

    For how long have I used the solution?

    I have been working with IBM QRadar for between three and four years.

    What do I think about the stability of the solution?

    This is a very stable product.

    What do I think about the scalability of the solution?

    QRadar is a scalable solution.

    How are customer service and technical support?

    Technical support is very good.

    What's my experience with pricing, setup cost, and licensing?

    I feel that the price is reasonable but compared to other products that are on the market, such as an offering by Microsoft, it is more expensive.

    What other advice do I have?

    This is a good product but there is room for improvement in several areas, including the integration of advanced data mining.

    I would rate this solution a six out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: partner
    PeerSpot user
    it_user610512 - PeerSpot reviewer
    Technical Security Specialist at a tech services company with 51-200 employees
    Consultant
    Provides log management, application monitoring, vulnerability scanning, full packet capture and risk analysis.

    What is most valuable?

    IBM Security's QRadar Security Intelligence is a multi-feature security monitoring platform that provides log management, SIEM, NetFlow, application monitoring, vulnerability scanning, full packet capture and risk analysis.

    The platform is designed to be deployed as an all-in-one appliance, as discrete components that can be scaled horizontally for distributed and larger environments.

    How has it helped my organization?

    The SIEM solution is considered as a monitoring tool for the network but you can set routing roles and special actions for certain events.

    What needs improvement?

    • The vulnerability scanner is not accurate. It needs more vulnerability signature updates or more regulation templates to be added on.
    • We urgently need to add more report templates.

    Maybe the improvements could be achieved by adding some modules like IPS, IDS and a next generation firewall that is able to start from monitoring the events and processing, then takes actions not only based on signatures but smart intelligent monitoring which would make QRadar into a full SIEM security solution.

    For how long have I used the solution?

    I have been using the solution for three years.

    What do I think about the stability of the solution?

    I didn't find any issues with stability of the product.

    What do I think about the scalability of the solution?

    The scalability of this product is very flexible because of the way that it counts the events that exceed the threshold of licenses it handled with the queue and stores the data for 5 GB, dealing with the events in a first-in, first-out (FIFO) methodology.

    How are customer service and technical support?

    I would rate the technical support as 9/10 for solving issues and 5/10 for responses.

    Which solution did I use previously and why did I switch?

    I didn't previously use another product but I deal with some accounts that used to use other vendors, and they were facing many issues in performance and slowness in processing events.

    How was the initial setup?

    The initial setup is very easy, just like when you install an operating system, and then you do the configuration needed for your environment.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Prosoft is an IBM VAD (value added distributor) in Egypt.
    PeerSpot user
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
    Updated: March 2024
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.