Technical Presales at a tech services company with 1,001-5,000 employees
MSP
Scalable with excellent security analytics
Pros and Cons
  • "This solution has excellent security analytics."
  • "I think that the search speed of this solution could be improved."

What is our primary use case?

I am an integrator of this solution, my customers use this as a SIEM solution for log management.

What is most valuable?

This solution has excellent security analytics.

What needs improvement?

I think that the search speed of this solution could be improved.

What do I think about the scalability of the solution?

This is a scalable solution, we have customers who have scaled.  

Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.

How was the initial setup?

The initial setup is very easy and takes just one day.

What other advice do I have?

I would recommend this solution to everyone considering using it.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Queretaro at a tech services company with 1-10 employees
Reseller
A complete network analysis tool that is agile, versatile, and easy to operate
Pros and Cons
  • "The most valuable features are the versatility of this solution and the variety of things you can do with it."
  • "The initial setup requires that you have somebody with the proper skill set, and it would help if the configuration were easier."

What is our primary use case?

We do not implement this tool ourselves but have experience implementing it for our clients. There are several use cases. The two most important ones are network analysis and UBA.

How has it helped my organization?

It has helped our clients to see how things have changed when comparing the initial behavior, and what is currently happening with the user's internet. It maintains archives on the behavior.

What is most valuable?

The most valuable features are the versatility of this solution and the variety of things you can do with it. 

What needs improvement?

The initial setup requires that you have somebody with the proper skill set, and it would help if the configuration were easier.

For how long have I used the solution?

We have been working with QRadar for less than one year.

What do I think about the stability of the solution?

This is a very stable product.

What do I think about the scalability of the solution?

This is a scalable product that can scale to a large-sized organization.

My client for QRadar is medium-sized.

How was the initial setup?

You need someone with the proper skills to complete the setup. The complexity of it depends on the features that you are looking for, and it can become very complex. The deployment can take between 16 and 20 days, depending on what needs to be configured.

It's a process to deploy, but once you have it configured it's easy to operate.

What about the implementation team?

The deployment can be done in-house.

What's my experience with pricing, setup cost, and licensing?

The pricing is okay, it's comparable to other vendors.

It's not expensive for the resources that it gives you.

What other advice do I have?

I think the tool is very complete and very agile.

I would rate this solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
IBM Security QRadar
March 2024
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.
General Manager at New System Engineering
Real User
A straightforward solution that minimizes the number of false positive errors
Pros and Cons
  • "It is a very optimized engine."
  • "It is very difficult to activate all of the network equipment, and it would help if it were made easier."

What is our primary use case?

We are a partner and provide this solution to our customers.

What is most valuable?

The most valuable feature is that it reports a very small number of false positives. It is a very optimized engine.

What needs improvement?

It is very difficult to activate all of the network equipment, and it would help if it were made easier. I would also like to see more integration with new devices.

For how long have I used the solution?

Ten years.

What do I think about the stability of the solution?

This is a very stable solution.

How are customer service and technical support?

The quality of technical support depends on the level. Level One support is very good, but if you have Level Two or Level Three then the support is not very reactive.

How was the initial setup?

The initial setup of this solution is not complex.

Deployment normally takes between one and three months.

What about the implementation team?

We have two engineers that are proficient in QRadar, and we handle the implementation for our customers.

Which other solutions did I evaluate?

One of my customers is a McAfee user and is in the process of replacing the solution with IBM QRadar.

What other advice do I have?

I would recommend this product. It is very simple to install, and not a complicated solution. IBM supplies regular software updates.

I would rate this solution an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
it_user934623 - PeerSpot reviewer
Senior Information Security Analyst at a financial services firm with 501-1,000 employees
Real User
Helps us to discover any threats with their alerts and tracking
Pros and Cons
  • "It helps us discover any threats with their alerts and tracking."
  • "The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not way straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference."

How has it helped my organization?

It helps us discover any threats with their alerts and tracking.

What is most valuable?

QNI is the most valuable feature. 

What needs improvement?

I would like for them to lower the price. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

The system is quite stable, so far we haven't had any problems. Although the initial supply of the appliance was a bit faulty, the processor kept on failing. We were within the warranty so they supplied new ones. After loading logs, the system is very stable and nothing to worry about.

What do I think about the scalability of the solution?

It's very scalable. There are currently five users. We may still onboard more users depending on the requirements and their departmental level.

We do plan to increase usage. 

How are customer service and technical support?

Their support is excellent, they are available when we need them. I'm satisfied so far.

How was the initial setup?

The initial setup wasn't exactly straightforward but the vendor who set it up for was helpful. It was very straightforward with their help. The deployment took two months. 

We require two admins for maintenance. 

What about the implementation team?

We used our own people and the certified IBM vendor for the implementation. We had a very good experience with them. 

What's my experience with pricing, setup cost, and licensing?

We do licenses once a year. 

Which other solutions did I evaluate?

We also looked at LogRhythm.

What other advice do I have?

I would advise someone considering this solution to write down your use cases and evaluate them with the vendor. Evaluate the best solution based on your use cases because you are the ones who are going to use it. The vendor will try and implement and leave you with your problems.

If the solution meets your requirements and solves most of your problems, you're good to go. QRadar is the best solution we have. The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not always straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference. 

I would rate it an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user923115 - PeerSpot reviewer
Cloud Security Architect at Nordcloud Oy
Vendor
It's a state-of-the-art product for security information and event management
Pros and Cons
  • "It's a state-of-the-art product for security information and event management (SIEM)."
  • "There are a lot of great out-of-the-box features included."
  • "The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery."
  • "The released patch quality is poor. IBM should test those patches on their side, not on the client's side."

What is our primary use case?

It is under a non-disclosure agreement (NDA).

How has it helped my organization?

  • It helps because you don't need an army to execute the project when you do the PoC, and when finally going to production. 
  • The abundant out-of-the-box features which are operating wonderfully.

What is most valuable?

  • It's easy to set up.
  • There are a lot of great out-of-the-box features included.
  • It's a state-of-the-art product for security information and event management (SIEM).

What needs improvement?

  • Slow response sometimes and a not-so-helpful staff there. So make the support better, and you could succeed even more.
  • The released patch quality is poor. IBM should test those patches on their side, not on the client's side. So, there are a lot of improvement to do. 
  • I would appreciate if IBM could create another more intuitive, easier way (intuitive UI) to perform advanced searches rather that just counting on regular expressions.

For how long have I used the solution?

One to three years.

How is customer service and technical support?

The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery.  

They are sometimes slow to respond and unhelpful.

What other advice do I have?

I highly recommend this product.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user640416 - PeerSpot reviewer
Assistant Manager-Information Security at a transportation company with 1,001-5,000 employees
Vendor
Integrates with other applications and systems.

What is most valuable?

SIEM technology is the most valuable feature of this solution, as it can be integrated with almost every application and system. If not, then you may ask IBM to write a parser for it.

How has it helped my organization?

You have the visibility of different events, thus we can resolve the issue.

What needs improvement?

They should provide more integration with more devices.

For how long have I used the solution?

I have been using this solution for three years.

How is customer service and technical support?

I would give the technical support a 8/10 rating. They are excellent.

How was the initial setup?

The setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

The pricing policy is good.

Which other solutions did I evaluate?

We looked at another solution, NitroSecurity Inc.

What other advice do I have?

If you have a good budget, then go for IBM QRadar.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user956985 - PeerSpot reviewer
Sr. Security Engineer at OmnitechIT
Real User
Stable security both in-house and for our customers
Pros and Cons
  • "In addition to using this solution for our security operations center, we are using it for our other customers."
  • "It needs more resilience and functionality."

What is our primary use case?

Our primary use case for this solution for the management of our security services, and our NOC (Network Operations Center) services.

How has it helped my organization?

In addition to using this solution for our security operations center, we are using it for our other customers.

What needs improvement?

It needs more resilience and functionality. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

My impressions of the stability is that it is good.

What do I think about the scalability of the solution?

The scalability is good. Internally we have many customers, but we offer this as a specific consultancy service. I do not know with certainty the number of users for this product in our customer environment.

What about the implementation team?

We used a consultant to assist us with the implementation of this solution.

What's my experience with pricing, setup cost, and licensing?

Our licensing costs for this solution is on a yearly basis.

What other advice do I have?

I would rate this product eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cyber Security Team Leader at a tech services company with 501-1,000 employees
Real User
Enables us to add extensions that provide valuable test ports but is not the best solution on the market
Pros and Cons
  • "The ability to add extensions is the most valuable feature. For example, extensions that provide valuable test ports."
  • "Their technical support is not good. We opened a lot of cases and from my experience, they are not complicated issues but it takes forever to get an answer."

What is our primary use case?

Our primary use case of this solution is for our customer's operations. 

What is most valuable?

The ability to add extensions is the most valuable feature. For example, extensions that provide valuable test ports.

What needs improvement?

I don't think this is the best solution on the market because it takes much longer than ArcSight, for example, which provides more flexibility and capability to create much more complex use cases. Other tools provide more valuable things that you can do for the active channel. 

I would like for them to develop out of the box content that doesn't require too much customization. Most of the out of the box we get from it requires too much customization. I would also like to see dynamic filters and better cross-integration between functions.  

For how long have I used the solution?

Less than one year.

What do I think about the scalability of the solution?

We've only been using it for eight months so we haven't scaled much during this time but it seems to be very scalable. We use it a minimum of eight hours a day.

Which solution did I use previously and why did I switch?

We used ArcSight.

What about the implementation team?

We did the integration ourselves. It was straightforward. 

What's my experience with pricing, setup cost, and licensing?

It is cheaper than ArcSight. 

What other advice do I have?

I would rate this solution a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.