IBM Security QRadar vs VMware Carbon Black Cloud comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiEDR
Sponsored
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
7.8
Number of Reviews
32
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Endpoint Detection and Response (EDR)
20th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
VMware Carbon Black Cloud
Ranking in Endpoint Detection and Response (EDR)
27th
Average Rating
8.4
Number of Reviews
18
Ranking in other categories
Security Incident Response (3rd)
 

Mindshare comparison

As of June 2024, in the Endpoint Detection and Response (EDR) category, the mindshare of Fortinet FortiEDR is 7.4%, up from 4.6% compared to the previous year. The mindshare of IBM Security QRadar is 1.5%, up from 0.8% compared to the previous year. The mindshare of VMware Carbon Black Cloud is 0.1%, down from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR)
Unique Categories:
No other categories found
Log Management
9.5%
Security Information and Event Management (SIEM)
16.3%
Security Incident Response
10.0%
 

Featured Reviews

PN
May 1, 2023
The rule creation, monitoring, and inspection profiles are great
We use Fortinet firewalls for perimeter security at six to seven of our locations It provides extreme perimeter security, especially for VPN and application profiles, and seamless security monitoring through FortiAnalyzer. As a firewall the solution is great, we never had any issues. We saw time…
Jacob_Koithra - PeerSpot reviewer
Aug 3, 2022
Good monitoring and dashboards with good blocking capabilities
We use the blocking mode and spam mode for the IPS - XGS 5000 series and use of QRadar as a SIEM Solution for logging and monitoring network security, security analysis, and monitoring for network-related attacks.  The playbook is defined with identified use cases. IPS acted as an inline to the…
Ricardo Franco Mahecha - PeerSpot reviewer
Sep 8, 2023
A highly scalable solution that can be used to get a better view of the security of endpoints and workstations
VMware Carbon Black Cloud is a good home office tool for people working outside the office VMware Carbon Black Cloud helped us to get a better view of the security of endpoints and workstations. The most valuable feature of VMware Carbon Black Cloud is the possibility of securing any PC…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product detects and blocks threats and is more proactive than firewalls."
"Exceptions are easy to create and the interface is easy to follow with a nice appearance."
"This is stable and scalable."
"We have FortiEDR installed on all our systems. This protects them from any threats."
"The console is easy to read. I also like the scanning part and the ability to move assets from one to the other."
"I like FortiClient EMS. FortiEDR has a lot of great features like lockdown mode, remote wipes, and encryption. I can set malware outbreak policies and controls for detecting abnormalities. You can also simulate phishing attacks."
"The solution was relatively easy to deploy."
"Additionally, when it comes to EDR, there are more tools available to assist with client work."
"It is a scalable solution."
"An engineer can live-monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions."
"I have found IBM QRadar to be stable."
"It is very stable. We have not faced interruptions in the past four and a half years."
"The ability to add extensions is the most valuable feature. For example, extensions that provide valuable test ports."
"It is the core of our entire SOX."
"IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through."
"It showed us where weaknesses were in our environment, so we could actively target those patches first."
"Probably the most valuable feature of CB Response is its ability to isolate a host and take it off the network, so it's not spreading anything. We have two security operations centers around the globe. When an SOC analyst sees something on an endpoint, they can use Carbon Black Response to isolate that host from the customer's environment and prevent any kind of lateral spread."
"The detection response and quarantining are very good features."
"We are able to remotely isolate exploited endpoints in seconds and perform a live deep dive of any endpoint into its running processes (as necessary) without the need for extra scripts.​"
"Threat hunting is the most valuable feature of VMware Carbon Black Cloud."
"The most valuable feature of VMware Carbon Black Cloud is the possibility of securing any PC worldwide."
"​The ability to isolate an endpoint with only the host name and a click of a button is a major time saver."
"Carbon Black insures the probability that any ransomware will be stopped before spreading."
"Setting up and managing the setup for this solution is okay. It is stable, scalable, and it runs just fine. No issues with technical support."
 

Cons

"Everything with Fortinet having to do with their cloud services. They need to invest more in their internal infrastructure that they are running in the cloud. One of the things I find with their cloud environment compared to others' is that they go cheap on the equipment. So it causes some performance degradation."
"Cannot be used on mobile devices with a secure connection."
"Making the portal mobile friendly would be helpful when I am out of office."
"Intelligence aspects need improvement"
"There's room for improvement in the quick response time and technical support for integration issues, especially when dealing with multiple vendors."
"The solution should address emerging threats like SQL injection."
"The dashboard isn't easy to access and manage."
"The solution's installation from a central installation server could be improved because the engineers had a little bit of trouble getting it installed from a central location."
"We sometimes get an error about the hard drive. Approximately once in two months, we can't find the logs, and they go missing, which is a terrible issue. We are getting support for this issue from our support company."
"Each module requires a separate license and a separate cost."
"Technical support really needs to be improved. Right now, they aren't where they need to be at all."
"It would be good if the program allowed certain profiles to only see certain customer information."
"For the common needs of clients to fulfill requirements, a real integration with Blueworks Live (BPA modeling tool also from IBM) and a more suitable BPM on cloud solution for midsize customers."
"I would like the rule creation interface to be much more user-friendly in the next release."
"I would like to see a better GUI."
"They need to improve their threat intelligence feed and they need to improve their user behavior analytics modules."
"Setup is incredibly complex and poorly documented. Every time an upgrade was needed we would need to engage Professional Services for troubleshooting help. Certificates and web services proved to be the most significant sticking points. Since the product runs on a Linux platform, perhaps having staff with more Linux experience could have alleviated some difficulty."
"The cloud console has a lot of bugs and issues in the analysis part."
"The product detects too many false positives initially and it could integrate better with other security solutions."
"The biggest issue I encountered was one where old logs were not being overwritten as expected so the system drive kept filling up from time to time. However, support was usually quite responsive and happy to jump on a remote session to take a look at it for us. That log bug has probably been resolved with an update by now."
"Technical support for the solution should be improved because there is a scarcity of support teams in the Middle East."
"We are subscribed to FS-ISAC threat indicator, but have been unsuccessful in adding it to our alliance feeds."
"One area for improvement is the maturity of its vulnerability features."
"The dashboard should be more user-friendly."
 

Pricing and Cost Advice

"Fortinet FortiEDR has a yearly subscription."
"Fortinet FortiEDR is available at a very competitive price compared to the other products in the market."
"The pricing is typical for enterprises and fairly priced."
"It's moderately priced, neither cheap nor expensive."
"It's not cheap, but it's not expensive either."
"The hardware costs about €100,000 and about €20,000 annually for access."
"Offered at a high price"
"While the cost may have been high, we view it as a worthwhile investment due to Fortinet's reliability and long-term performance."
"The solution is priced fairly, there is a license for the solution, and we pay annually."
"There is a license to use this solution, which is paid annually. However, there are subscription options available."
"The solution comes with a high price tag, while some of the competitors provide identical functionality in their offerings at no extra cost."
"IBM's Qradar is not for small companie. Unfortunately, it would be 'overkill' to place it plainly. The pricing would be too much."
"The licensing is also overly complex, as there is a need to buy the work load performance monitoring separately."
"The pricing is always fine."
"It would be great if this product were cheaper."
"It's too expensive. The licensing is also a little bit difficult to understand because you have to license it per event and per number of flows."
"VMware Carbon Black Cloud is an expensive solution."
"Purchase Professional Services up front as part of the implementation package, then renew hours annually to ensure you have adequate support for upgrades and enhancements. Overbuy by at least 10% to account for infrastructure growth."
"We had no issues purchasing through our preferred reseller and were able to get a fair price even when not purchasing direct. Carbon Black Enterprise Response didn’t break the bank, though adding on the matching antivirus and anti-malware components of the Protect product was more than we could afford, even with some discounting. Cb Response is really designed to complement Carbon Black’s Defense product. While Response can be used on its own, coupling with Defense seems like the best strategy if you can afford the price tag."
"The solution is very inexpensive so there is great cost savings to using it."
"Pricing for this solution could be made lower."
"You need to pay for the licensing of the product. The pricing is costly."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
787,817 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Government
8%
Manufacturing Company
8%
Financial Services Firm
8%
Educational Organization
19%
Computer Software Company
15%
Financial Services Firm
10%
Government
6%
Financial Services Firm
16%
Computer Software Company
16%
Energy/Utilities Company
8%
Real Estate/Law Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What's the difference between Fortinet's FortiEDR and FortiClient?
I suggest Fortinet’s FortiEDR over FortiClient for several reasons. For starters, FortiEDR guarantees solid protectio...
What do you like most about Fortinet FortiEDR?
We have FortiEDR installed on all our systems. This protects them from any threats.
What is your experience regarding pricing and costs for Fortinet FortiEDR?
The pricing of the solution is on the high end compared to its offerings and capabilities.
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What do you like most about Carbon Black CB Response?
Threat hunting is the most valuable feature of VMware Carbon Black Cloud.
 

Also Known As

enSilo, FortiEDR
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
Carbon Black CB Response
 

Learn More

 

Overview

 

Sample Customers

Financial, Healthcare, Legal, Technology, Enterprise, Manufacturing ... 
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
ALLETE belk
Find out what your peers are saying about IBM Security QRadar vs. VMware Carbon Black Cloud and other solutions. Updated: May 2024.
787,817 professionals have used our research since 2012.