We performed a comparison between IBM Security QRadar, Splunk Enterprise Security, and Stackify based on real PeerSpot user reviews.
Find out what your peers are saying about Splunk, Datadog, Wazuh and others in Log Management."Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure."
"The ability to transition from microscopic to macroscopic view, instantly, is very good."
"I think it's a very stable product that provides much more visibility than the other product."
"The most valuable aspect of the solution is the integration capabilities on offer."
"What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value."
"QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis. There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving. From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected."
"Overall a great solution."
"I have found the most important features to be the flexibility, tech framework, and disk manager."
"Its usability is the best part. It is easy for our developers to use if they want to search their logs, etc."
"The most valuable feature of Splunk Enterprise Security is the comprehensive logging capabilities it provides."
"The solution is very fast and succinct."
"Splunk has helped improve our company's resilience level."
"One key advantage of Splunk over competitors like IBM QRadar is its superior device integration capabilities."
"It allows for transparency into IT metrics for insightful business analytics."
"Positive features include replication capabilities, software development kits, and the architecture."
"We are much faster finding and addressing issues with Splunk."
"The solution is stable and reliable."
"The filter feature on Stackify is one of the features I found valuable. It's awesome. When I want to get the application logs, the solution gives me many filters. For example, if I want to get logs from my test environment, the option is there for me to select the environment from Stackify, and you can also select the particular application, and you'll see the information you need there. The filter feature alone and the fact that Stackify offers a lot of different filters is what I like the most about the solution because I've used other tools with the filter feature, but the filtering was very difficult, versus Stackify that has good filtering. On Stackify, you can filter the information by the last one hour, or the last four hours, and you can also select the date range and specify the timestamp, then the solution will give you the information based on the date range you specified. Another feature I found valuable on Stackify is its rating feature because it tells you how your application is faring. For example, a rating of A means excellent, while a rating of F means very bad, or that your application is not doing well at all. The ratings are from A to F. I also like that Stackify helps you in terms of load management because the solution gives you information on overutilized resources. These are the most valuable features of the solution."
"The deployment is very fast."
"The performance dashboard and the accurate level of details are beneficial."
"They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required."
"I would like to see a better GUI."
"I would suggest QRadar release any documentation or give an online demo, like videos on YouTube. It would increase publicity and public appeal."
"The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging."
"The AQL queries could be better."
"Technical support is good, but not great."
"With IBM Security QRadar, my company faced issues with the support we received for the product."
"Technical support could be improved by a bit."
"It does not give us permission to implement on-premise so we implement them on the cloud."
"Splunk can be an expensive solution. Technical support could be improved as well."
"Splunk does not provide any default threat intelligence like Microsoft Sentinel, but you can integrate any third-party threat intelligence with Splunk. By default, no threat intelligence suite is there, whereas, with IBM QRadar or Microsoft Sentinel, the default feature of threat intelligence is there. It is free. If Splunk can provide a default threat intelligence suite, it would be better."
"Endpoint access is the only issue I can think to mention, even though the endpoint access we have with Cisco is fine."
"Custom visualizations are real hard. While the default visualizations are good, creating enhanced visualizations are complex."
"The solution could use a different licensing model."
"The search could be improved. Now, it is a bit difficult to write search queries because they become quite long, then maintaining those long search queries is a quite challenging."
"The integration with all our tool sets felt like we were reinventing the wheel, which was a pain point for us."
"I would like to be able to see metrics about individual running containers on the host machines."
"I've not used Stackify for a while, and I'm currently using a solution now that's not as good as Stackify. Among the solutions I've been using so far, Stackify has been one of the best for me, but there's always room for improvement. For example, I don't know if it's just me, but when I try to get the log from Stackify, sometimes it doesn't appear in real-time. It takes a few minutes before the logs appear. When I redeploy my solution and the application starts, I don't see the logs immediately, and it would take two to three minutes before I see the logs. I don't know if other customers have a similar experience. It's the wait time for the logs to appear that's a concern for me, could be improved, and is what the Stackify team should be looking into. In terms of any additional feature that I'd like added to the solution, I'm not sure if Stackify has a way to export logs out. I've been trying to do it. On the solution, you can click on a spiral-like icon and it shows you the entire error, and I'd prefer an export button that would let me download the error and save that into a text file, for example, so it'll be available on my local machine for me to reference it, especially because the log keeps going and as you're using the solution, the system keeps pushing messages on to Stackify, so if I'm looking at a particular error at 12:05 PM, for example, by the time I go back to my system and would like to revisit the error at 12:25 PM, on Stackify, the logs would have gone past that level and I won't see it again which makes it difficult. When you now go back to that timestamp, you don't tend to see it immediately, but if the solution had an export feature for me to save that particular error information on my local machine for reference at a later time, I won't have to go back to Stackify. I just go to that log, specifically to that particular export that I've received on my local machine. I can get it and review it, and it would be easier that way versus me going back to Stackify to find that particular error and request that particular information."
"The search feature could be improved."
"It should be easily scalable and configurable in different instances."