IBM Security QRadar vs Kaspersky Endpoint Detection and Response Expert comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiEDR
Sponsored
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
7.8
Number of Reviews
32
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Endpoint Detection and Response (EDR)
20th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
Kaspersky Endpoint Detectio...
Ranking in Endpoint Detection and Response (EDR)
18th
Average Rating
8.2
Number of Reviews
44
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2024, in the Endpoint Detection and Response (EDR) category, the mindshare of Fortinet FortiEDR is 7.4%, up from 4.6% compared to the previous year. The mindshare of IBM Security QRadar is 1.5%, up from 0.8% compared to the previous year. The mindshare of Kaspersky Endpoint Detection and Response Expert is 1.7%, up from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR)
Unique Categories:
No other categories found
Log Management
9.5%
Security Information and Event Management (SIEM)
16.3%
No other categories found
 

Featured Reviews

reviewer2166780 - PeerSpot reviewer
Apr 10, 2024
Offers behavior analysis, improved our endpoint security posture but a lot of false positives where things are incorrectly flagged that require manual configuration to allow
I would like to improve the integration process because a big selling point was the ease of integration within the Fortinet ecosystem. I would expect more built-in collaboration to allow for easier threat mitigation across Fortinet systems. The strength of FortiEDR lies in its overall ability to protect us from new threats. We have encountered issues with it as well. We've had a lot of false positives; things incorrectly flagged that require manual configuration to allow. Even worse, after we allow a legitimate program, it sometimes gets flagged again after an update. This has caused a lot of extra work for my team. I would like to see improved heuristics so the system better understands what's legitimate and doesn't keep blocking it after minor updates.
James Riffenburg - PeerSpot reviewer
Oct 18, 2022
The solution uses AI to analyze different logged events, and network activity and create a correlation
I give the solution an eight out of ten. The solution is fairly easy to maintain and the learning curve is reasonable compared to other products to customize the workflow dashboards and get meaningful insight as far as what is happening within our organization. The solution is also fairly straightforward to integrate with different data log sources. The solution requires three to five people to maintain including one analyst, an engineer, and an architect. I suggest before using the solution you know what your process is, know what your logging sources are, and plan well because It's really a leadership challenge. The solution is better deployed than other models.
MA
May 4, 2023
Has good stability and efficient machine-learning features
We use the solution to create a test scenario for detecting a potential threat in the network The solution's cybersecurity policies help us protect some extensions of the primary documents in case of a ransomware attack. Also, in case endpoint servers get compromised, it protects them. Thus, we…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"NGAV and EDR features are outstanding."
"This is stable and scalable."
"The most valuable feature is the analysis, because of the beta structure."
"The main thing is that I feel safe. Because the processes that have been used to get a handle on the attackers are much better than other competitors"
"It is a scalable solution...The initial setup of Fortinet FortiEDR was straightforward."
"Forensics is a valuable feature of Fortinet FortiEDR."
"Fortinet FortiEDR made our clients feel secure and more at ease, knowing that they had an EDR solution that would close the gap in their security posture."
"The solution was relatively easy to deploy."
"The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
"We've found the solution to be scalable."
"Stability-wise, I rate the solution a ten out of ten."
"The solution is relatively easy to use."
"IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
"Vulnerability data, network data and the like, are part of correlation and detection."
"I think the QDI is very good."
"We have the abilities to monitor each instance which originates on the process along with the performance of each department."
"We can scale the solution."
"It's scalable enough for us."
"The product has an easy-to-use EDR module based on signature-based antivirus detection. It is a complete software."
"My impression of the stability of this solution is good. We have not had any issues with stability."
"We have a central console and from there you can monitor all workstations via an agent."
"What I like best about Kaspersky Endpoint Detection and Response is that it can detect any cyber attack and that it's a reliable product in the cybersecurity space. My company has confidence in it as a product for detecting all cyber attacks. It's a reliable product."
"Kaspersky Endpoint Detection and Response is a stable solution."
"It is easy to manage."
 

Cons

"There's room for improvement in the quick response time and technical support for integration issues, especially when dealing with multiple vendors."
"I would like the solution to extend beyond endpoint protection and include other attack surfaces such as other network components."
"I think cloud security and SASE are areas of concern in the product where improvements are required. The tool's cloud version has to be improved in terms of the security it offers."
"I haven't seen the use of AI in the solution."
"The solution's installation from a central installation server could be improved because the engineers had a little bit of trouble getting it installed from a central location."
"It takes about two business days for initial support, which is too slow in urgent situations."
"They can include the automation for the realtime updates. We have a network infrastructure with remote sites. Whenever they send updates, they are not automated. We have to go into the console and push those updates. I wish it was more automated. The update file is currently around 31 MB. It could be smaller."
"Integration with Azure and SaaS provisioning tools could improve Fortinet FortiEDR."
"The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue."
"The released patch quality is poor. IBM should test those patches on their side, not on the client's side."
"The implementation of the solution's technology needs to be simplified."
"I think that the search speed of this solution could be improved."
"I would like for Yara to be supported by all components."
"The dashboard is pathetic and it takes a long time to perform a search."
"I'm not sure about the stability just yet. We've observed a few issues and we raised a supporting ticket for it."
"The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not way straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference."
"The solution does not offer much support to its users in Spanish, so I would like to see them offer more support in Spanish."
"Could include some additional protection."
"The solution could always be more secure."
"Kaspersky Endpoint Detection and Response should continue to improve its protection while adapting to the changing threat ecosystems. Having more advanced features would be a benefit."
"The issue with Kaspersky EDR is the sandbox. I'd like to have the ability to manage it on the cloud as well."
"We'd like to see them improve the automatic response."
"It consumes many system resources."
"The main problem with Endpoint is that Kaspersky is a Russian company, and my clients prefer not to use it."
 

Pricing and Cost Advice

"The pricing is typical for enterprises and fairly priced."
"Fortinet FortiEDR has a yearly subscription."
"I would rate the solution's pricing an eight out of ten."
"While the cost may have been high, we view it as a worthwhile investment due to Fortinet's reliability and long-term performance."
"It is expensive and I would rate it 8 on the scale."
"It's not cheap, but it's not expensive either."
"The pricing is good."
"The solution is not expensive."
"The pricing is higher but cheaper than others and there are no additional costs."
"It is a perpetual license that we have for the event collector. The licensing is done based on the number of events and flows that you receive on this particular device. These are perpetual licenses, which means once you purchase them, they don't expire, which means that the support to IBM is definitely renewed after every one year. We have an enterprise agreement with IBM, which puts the cost in a totally different category as compared to someone who is not an IBM partner and is approaching IBM for this solution. We were able to get massive discounts. To give you an idea, we recently purchased 30,000 event licenses, and it costs around $480,000. It is definitely not a cheap product. We have licenses for about 270,000 events per second and 3 million flows per second. All the appliances and their events and flows are basically clubbed together and charged or rather calculated through a single source. The console receives all the details from all the event processes that we have globally. So, the license that we have is a single license for 270,000 events per second and 3 million flows per second, but that can be managed centrally. I was only part of the secondary purchase, which was 30,000 events per second for about $480,000. You can calculate how much we paid for 270,000 events. Reducing its price would be a compromise. We have already used a lower-priced product in the form of NNT, but we had to get rid of it because it was not doing the job that we actually wanted to do. You get what you pay for."
"Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you."
"Pricing and licensing are competitive. Their new licensing options allow logs to bypass the correlation engine for a flat rate, which is also appealing for log data that is compliance-driven for a small amount of money."
"When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products."
"Only enterprise businesses can afford the tool."
"I think that the price is fair, but we can always say that the price could be cheaper."
"IBM has subscriptions plans that run for one year."
"The price of the solution could be reduced."
"Pricing for Kaspersky Endpoint Detection and Response is so-so when you compare it with its competitors. Its pricing isn't cheap nor expensive."
"Endpoint's pricing is good, especially compared to expensive solutions like Sophos."
"The solution is expensive in comparison to CheckPoint and Fortinet."
"We were on a three-year license to use Kaspersky Endpoint Detection and Response. The price could be better."
"There is an annual license to use Kaspersky Endpoint Detection and Response. The price overall is a bit expensive when compared to other solutions. There are not any additional fees other than the license."
"The solution isn't the cheapest considering what you get. I would rate the pricing as seven out of ten."
"The pricing is reasonable. Not too cheap, not too expensive."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
8%
Manufacturing Company
8%
Financial Services Firm
8%
Educational Organization
19%
Computer Software Company
15%
Financial Services Firm
10%
Government
7%
Computer Software Company
16%
Comms Service Provider
11%
Financial Services Firm
9%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What's the difference between Fortinet's FortiEDR and FortiClient?
I suggest Fortinet’s FortiEDR over FortiClient for several reasons. For starters, FortiEDR guarantees solid protectio...
What do you like most about Fortinet FortiEDR?
We have FortiEDR installed on all our systems. This protects them from any threats.
What is your experience regarding pricing and costs for Fortinet FortiEDR?
The pricing of the solution is on the high end compared to its offerings and capabilities.
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What do you like most about Kaspersky Endpoint Detection and Response Expert?
The integration with our hypervisor is quite smooth, especially within the Kaspersky Enterprise environment. We have ...
What is your experience regarding pricing and costs for Kaspersky Endpoint Detection and Response Expert?
We have a higher-level license, so we have access to all the features, including network inspection and antivirus pro...
What needs improvement with Kaspersky Endpoint Detection and Response Expert?
I find Kaspersky can be quite resource-intensive, consuming a significant amount of RAM and CPU. Another area of impr...
 

Also Known As

enSilo, FortiEDR
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
Kaspersky EDR
 

Overview

 

Sample Customers

Financial, Healthcare, Legal, Technology, Enterprise, Manufacturing ... 
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Ferrari, Insolar, Tael, Republic of Serbia
Find out what your peers are saying about IBM Security QRadar vs. Kaspersky Endpoint Detection and Response Expert and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.