Check Point Security Management vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 23, 2023
 

Categories and Ranking

Check Point Security Manage...
Ranking in Log Management
10th
Average Rating
8.8
Number of Reviews
57
Ranking in other categories
Advanced Threat Protection (ATP) (15th), Threat Intelligence Platforms (3rd)
IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (20th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
 

Mindshare comparison

As of June 2024, in the Log Management category, the mindshare of Check Point Security Management is 0.8%, down from 0.9% compared to the previous year. The mindshare of IBM Security QRadar is 9.5%, up from 7.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
Advanced Threat Protection (ATP)
0.4%
Security Information and Event Management (SIEM)
16.3%
User Entity Behavior Analytics (UEBA)
13.5%
 

Featured Reviews

SanjeevKumar20 - PeerSpot reviewer
Jun 8, 2024
Access to detailed network logs in real time helps us decide and take prompt action to block and fix threats
The most valuable aspects of the solution include: * IPSec VPN Tunneling, * DDoS Protection, * HÀ and Clustering, * Firewall Rules, * Proxy support, * Revision history * Detailed audit log, * Smart Event * Filter syntax. These features are easy to configure and offer multiple options to set them up with cloud services and other vendor firewall products. We can always feel secure if some things go wrong, I'm sure that we can restore to the old one. We can apply centralized proxy settings to get additional databases when we need them. We can get a graphical view of the traffic and provide history when we need it.
Ertugrul Akbas - PeerSpot reviewer
Jun 29, 2022
Scalable, easy to use, but lacking features and modern user interface
IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms. Using the interface of IBM QRadar User Behavior Analytics is the same for years, they should redesign the interface to make it more modern. Some historical queries take a long time, they should improve or change their database. There are some missing operators on the correlation side. For example, some before operated.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Check Point Security Management has improved our organization because all corporate firewalls can be managed with a single interface."
"We love the ability to monitor performance in real-time, and gather critical information about network flows and traffic."
"The firewall's blades are the solution's most valuable feature."
"Check Point Security Management Server offers a wide range of security features, including firewall, intrusion prevention, VPN, application control, and threat prevention capabilities."
"One of the most outstanding characteristics of its centralized administration is its great computing power."
"Check Point management is one of the most complete solutions for managing Check Point Firewall appliances."
"We can easily push the policies to any of our gateways."
"Having the possibility to use Smart Event to check for threats on a broader scale helps after a security incident and also makes it easier to check - instead of looking through different logs."
"Most of the features are good. It is an excellent solution."
"The feature that I have found most valuable is how it monitors the real network. That is its leading security feature."
"It showed us where weaknesses were in our environment, so we could actively target those patches first."
"It's built around Red Hat Linux, which is highly robust."
"An engineer can live-monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions."
"The solution can scale."
"What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own."
"The product provides a complete platform for ingesting the log, doing the correlations and handling the runtime."
 

Cons

"Support is the main area that they need to improve. Our support experience is not very smooth. We are based in Africa, and we don't know whether it is because of our region. I would like a feature where there is a workflow to provide authorization to some users before they're able to create and apply rules. Such a feature should be integrated with the management. It should not be in the box that comes with it."
"I would like it to be the administrator of equipment or Next Generation firewalls (which have to be managed on this platform) and to be able to manage other services (like Harmony) that also belong to Check Point."
"It would be helpful if the documentation and good practice guides are updated. Many are still from R77."
"Some costs are ridiculously high."
"I would like the ability to have an overview, cross-site: One portal that does all firewalls. Also, the user interface is overly complicated."
"I would like this solution to be integrated directly into the Cluster XL equipment."
"Sometimes the security system slows down when it is overloaded."
"In order to work management console, you need some good appliance or you need to provide more CPU and Memory to the appliance."
"They need to improve their threat intelligence feed and they need to improve their user behavior analytics modules."
"I think QRadar is very complex. It's a distributed system and IBM QRadar has an all-in-one solution which is not like that distributed solution but it's a good product. IBM needs to consider the user interface because if we compare it with AlienVault, the AlienVault user interface is fantastic but the IBM QRadar user interface is very complex. They should focus on how to make it easier for the client."
"IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer."
"The initial setup was complex, and it took six months."
"The custom rules could be simplified more or it should be possible to use a different language, other than the ones that the solution is already using. They should add other languages into the mix."
"The solution lacks vendor support."
"IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others."
"The technical support is poor. Mostly because when I open a PMR for IBM, I am stuck with Level 1 staff. As an engineer, nothing that I am bringing them does not require Level 2 or Level 3 support."
 

Pricing and Cost Advice

"Price-wise, it is an expensive solution."
"Do the homework because Check Point is rather expensive."
"The solution is expensive."
"The solution is expensive and there is an annual license."
"This product can be used for 25 security gateways on a basic license."
"Check Point is much cheaper than the competition ($4/server as compared to $17/server)."
"The pricing can be estimated around 3 or 4 out of 10 in terms of expense."
"The price of this product is high."
"A good approach would be to begin with an On Cloud subscription, then later on do a more exact sizing."
"There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option."
"The solution is priced fairly, there is a license for the solution, and we pay annually."
"It could be cheaper, but the value itself is far more important for us than the price. Typically, our clients have yearly subscriptions."
"Only enterprise businesses can afford the tool."
"QRadar is quite expensive. It wouldn't be worth it for a small business..."
"IBM's Qradar is not for small companie. Unfortunately, it would be 'overkill' to place it plainly. The pricing would be too much."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
787,817 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Security Firm
13%
Government
8%
Comms Service Provider
8%
Educational Organization
19%
Computer Software Company
15%
Financial Services Firm
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Check Point Security Management?
The most beneficial features for us are the alert classifications, which help us prioritize critical issues, and the detailed reports that provide insights into attack origins and purposes, such as...
What needs improvement with Check Point Security Management?
The only issue is that, you need to install an application instead of managing it through a browser. Thus, it requires installation. Additionally, it can be slow when multiple users access the mana...
What is your primary use case for Check Point Security Management?
We utilize the security management solution to oversee all our Check Point products, including firewall, IPS, and antivirus policies. It serves as our primary tool for managing all Check Point devi...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

R80.10, R80, R77.30, R77, Check Point R80.10 Security Management, R80 Security Management
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Overview

 

Sample Customers

Hedgetec, Geiger
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Check Point Security Management vs. IBM Security QRadar and other solutions. Updated: June 2024.
787,817 professionals have used our research since 2012.