We changed our name from IT Central Station: Here's why
Queretaro at a tech services company with 1-10 employees
Reseller
Top 20
A complete network analysis tool that is agile, versatile, and easy to operate
Pros and Cons
  • "The most valuable features are the versatility of this solution and the variety of things you can do with it."
  • "The initial setup requires that you have somebody with the proper skill set, and it would help if the configuration were easier."

What is our primary use case?

We do not implement this tool ourselves but have experience implementing it for our clients. There are several use cases. The two most important ones are network analysis and UBA.

How has it helped my organization?

It has helped our clients to see how things have changed when comparing the initial behavior, and what is currently happening with the user's internet. It maintains archives on the behavior.

What is most valuable?

The most valuable features are the versatility of this solution and the variety of things you can do with it. 

What needs improvement?

The initial setup requires that you have somebody with the proper skill set, and it would help if the configuration were easier.

For how long have I used the solution?

We have been working with QRadar for less than one year.

What do I think about the stability of the solution?

This is a very stable product.

What do I think about the scalability of the solution?

This is a scalable product that can scale to a large-sized organization.

My client for QRadar is medium-sized.

How was the initial setup?

You need someone with the proper skills to complete the setup. The complexity of it depends on the features that you are looking for, and it can become very complex. The deployment can take between 16 and 20 days, depending on what needs to be configured.

It's a process to deploy, but once you have it configured it's easy to operate.

What about the implementation team?

The deployment can be done in-house.

What's my experience with pricing, setup cost, and licensing?

The pricing is okay, it's comparable to other vendors.

It's not expensive for the resources that it gives you.

What other advice do I have?

I think the tool is very complete and very agile.

I would rate this solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Country Manager at a tech services company with 11-50 employees
Real User
Top 5Leaderboard
Stable, scalable, and helpful support

What is our primary use case?

The main tool for this operation center for collectings events from different devices, whatever server or network devices, such as switches and routers. It handles anything related to data that can be harmful related to security. Those events can be mapped to promote the threat, it creates another event for promoted threats. We are a service provider and we provide services to our customers. We use IBM QRadar for many types of businesses, such as banks and telecom. It has a good reputation.

What needs improvement?

IBM QRadar has a margin for development, for out-of-the-box use cases. It can be enhanced with better support and automate the use cases for that.

For how long have I used the solution?

I have been using IBM QRadar for approximately two…

What is our primary use case?

The main tool for this operation center for collectings events from different devices, whatever server or network devices, such as switches and routers. It handles anything related to data that can be harmful related to security. Those events can be mapped to promote the threat, it creates another event for promoted threats.

We are a service provider and we provide services to our customers. We use IBM QRadar for many types of businesses, such as banks and telecom. It has a good reputation.

What needs improvement?

IBM QRadar has a margin for development, for out-of-the-box use cases. It can be enhanced with better support and automate the use cases for that.

For how long have I used the solution?

I have been using IBM QRadar for approximately two years.

What do I think about the stability of the solution?

I have found IBM QRadar to be stable.

What do I think about the scalability of the solution?

IBM QRadar is scalable.

How are customer service and support?

The technical support of IBM QRadar is good.

Which solution did I use previously and why did I switch?

IBM QRadar is the best SAN solution we have used compared to the others.

How was the initial setup?

We manage the installation of the solution. It is not something difficult, it is reasonable. It is not that easy for anyone to do, it needs a technical team.

What about the implementation team?

The implementation needs a technical team and we have two engineers for the implementation and maintenance.

What's my experience with pricing, setup cost, and licensing?

There is a license to use this solution, which is paid annually. However, there are subscription options available.

What other advice do I have?

I recommend this solution to others.

I rate IBM QRadar an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
Learn what your peers think about IBM QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
564,143 professionals have used our research since 2012.
Deputy General Manager at a comms service provider with 5,001-10,000 employees
Real User
Top 5Leaderboard
Correlation done well, fair pricing, and knowledgeable technical team
Pros and Cons
  • "When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed."
  • "I have noticed the interface has room for improvement."

What is most valuable?

We are looking for the entire QRadar spectrum but it has many products. QRadar is a kind of program, we are looking for system modelling, point modelling, network side modelling similar to QRadar network inside, and the capability to correlate between the network and endpoint. Most of the SIEM's have to rely on when it comes to network side third party or separate network traffic analysis. When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed.

What needs improvement?

Since we have not used the solution very long my information is limited when it comes to improvements. I have noticed the interface has room for improvement.

For how long have I used the solution?

I have been using the solution for two years. However, my company has not deployed the solution yet and we are in the early stages of testng.

How are customer service and technical support?

The solution has a good technical team.

How was the initial setup?

The installation is complex. There is some overloading that happens, this could be simplified and made easier by allowing all key features on the first level dashboard to be viewed.

What's my experience with pricing, setup cost, and licensing?

When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products. Even though the price can be a little high sometimes there product is number one. They have a wide range of products.

Which other solutions did I evaluate?

We have compared Securonix and many other solutions to this one.

What other advice do I have?

I rate IBM QRadar a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
SOC Team Lead at a financial services firm with 1,001-5,000 employees
Real User
Flexible, easy to learn, and price fairly

What is our primary use case?

Depending on the organization's needs the solution can monitor different types of security through logs.

What is most valuable?

I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.

What needs improvement?

There could be better integration with the solution.

For how long have I used the solution?

I have been using the solution for approximately three years.

What do I think about the stability of the solution?

Every solution has some bugs and other issues but for the most part, this solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. The amount of users is dependant on what your needs are.…

What is our primary use case?

Depending on the organization's needs the solution can monitor different types of security through logs.

What is most valuable?

I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.

What needs improvement?

There could be better integration with the solution.

For how long have I used the solution?

I have been using the solution for approximately three years.

What do I think about the stability of the solution?

Every solution has some bugs and other issues but for the most part, this solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. The amount of users is dependant on what your needs are. You can have many users having access to the solution. For example, out of a 5,000 person network, you could have five with access to it for security. 

How are customer service and technical support?

The solution has great support. Whenever we had an issue they were able to give us support within 15 minutes.

How was the initial setup?

The installation was easy but this can depend on what appliances you want to install it on. If it is VMware, then the installation is easy, it took me 30 minutes.

What about the implementation team?

We did use a consultant to do the deployment and we only needed one technician.

What's my experience with pricing, setup cost, and licensing?

The solution is priced fairly, there is a license for the solution, and we pay annually.

What other advice do I have?

I would recommend the solution to others and we plan to continue using it in the future.

I rate IBM QRadar a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
MUHAMMAD WAQAS
Relationship Manager at a financial services firm with 5,001-10,000 employees
Real User
Reasonably priced with good technical support and offers great performance
Pros and Cons
  • "We've found the technical support to be very good."
  • "The product needs to improve its GUI."

What is most valuable?

The price is very good. It's quite reasonable.

The solution's performance is excellent. The stability is excellent.

We've found the technical support to be very good.

The pricing is very good.

What needs improvement?

The product needs to improve its GUI. The dashboard which they facilitate needs to be modernized. They could make it a lot better and a lot easier to navigate.

For how long have I used the solution?

I've been using the solution for approximately two years or so.

What do I think about the stability of the solution?

The stability of the product has been great. It's from 80% to 90% is stable. There are very few bugs or glitches. It doesn't crash or freeze. If you do run into issues, technical support is quite helpful. 

What do I think about the scalability of the solution?

The product works well for small or medium-sized enterprises.

How are customer service and technical support?

The technical support has been great so far. If you run into any kind of issue, their support is available. They are very helpful and extremely responsive. We're quite satisfied with their level of service. I'd give them a rating of 90% to 95%.

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is quite reasonable.

What other advice do I have?

We're a customer and an end-user. We don't have a direct business relationship with IBM.

Overall, I would rate the solution at a nine out of ten. We've been extremely satisfied with the product so far.

I'd recommend the solution, however, depends upon a company's budget and requirements. For small and medium enterprises, QRadar is the best solution, due to its price and performance.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Director of Information Security at a financial services firm with 501-1,000 employees
Real User
Top 20
Scalable with good searching capabilities and good support
Pros and Cons
  • "The most valuable feature is the searching capability and real-time operational use."
  • "Some of the cloud apps need improvement."

What is our primary use case?

The primary use case of this solution is for monitoring an enterprise data center, globally for 12,000 devices.

How has it helped my organization?

It has improved the way that the organization functions.

What is most valuable?

The most valuable feature is the searching capability and real-time operational use.

What needs improvement?

Some of the cloud apps need improvement.

In the next release, I would like to see improving the stability of some of the add-on applications.

For how long have I used the solution?

I have been using IBM QRadar for two years.

We are using the current version.

What do I think about the stability of the solution?

Stability is moderate.

We have 15 people using this solution in our organization. Their positions vary from Network Engineers, Security Engineers, and Security Analysts.

What do I think about the scalability of the solution?

It's very scalable.

How are customer service and technical support?

Technical support is good.

I would rate them a nine out of ten. Their response time is good.

Which solution did I use previously and why did I switch?

Previously, I did not use another solution.

How was the initial setup?

The initial setup is complex. It's just the nature of the CM tool.

What's my experience with pricing, setup cost, and licensing?

I think that the price is fair, but we can always say that the price could be cheaper.

What other advice do I have?

Like any complex enterprise CM tool, you have to have a strong support organization. People who are good at understanding Linux operating systems. You also need a strong technical support team in-house.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Security Manager at a tech services company with 201-500 employees
Real User
Excellent network monitoring but needs better compatibility
Pros and Cons
  • "The feature that I have found most valuable is how it monitors the real network. That is its leading security feature."
  • "The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good."

What is our primary use case?

Our primary use case is for monitoring global infrastructure.

What is most valuable?

The feature that I have found most valuable is how it monitors the real network. That is its leading security feature.

What needs improvement?

In terms of what could be improved, I'd say do nothing, in its current state it does quite okay for now.

The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good

For how long have I used the solution?

I have been using IBM QRadar for more than five years.

I'm using the latest version of QRadar.

What do I think about the stability of the solution?

The stability is very good. Its operation is very good.

What do I think about the scalability of the solution?

We have less than five people using it.

For us, as a small security company, it is covering our needs and our growth.

How are customer service and technical support?

Customer support is good. When an incident gets raised there is a 10 day response.

How was the initial setup?

The initial setup was complex.

What about the implementation team?

We use the vendor for everything. That is the style of the corporation. For these jobs the responsibility and knowledge is on the vendor's side.

What's my experience with pricing, setup cost, and licensing?

Implementation is over time and the maintenance price for QRadar is competitive.

What other advice do I have?

On a scale of one to ten, I would give IBM QRadar a seven.

Overall, I would of course recommend this product to others because of all its functionalities.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Sr.Network Engineer at a computer software company with 10,001+ employees
MSP
A reliable and scalable solution for network behavior and log analytics
Pros and Cons
  • "The solution is reliable."
  • "I need a solution which will send alerts in the event of any behavior."

What is our primary use case?

We use the solution for network behavior and log analytics. We wish to procure one for behavior analytics.

I am not certain which version we are using. 

There is a need for a behavior analytics solution in the environment. We use the solution to highlight unusual traffic for a single particular link or even single particular user traffic. 

What is most valuable?

The solution will not provide alerts in the event of any particular traffic. It will only alert in the case of a security threat. 

What needs improvement?

I am looking for a solution to replace IBM QRadar. We use it for incident reporting, but I need one for behavior analytics. I need one which will send alerts in the event of any behavior. 

The solution is fine for analyzing logs. We already have basic modules. We require more modules for getting so that we may obtain further details. We essentially use IBM QRadar for analyzing particular logs. 

There are no additional features which should be added or upgraded in the next release. 

What do I think about the stability of the solution?

The solution is reliable. 

What do I think about the scalability of the solution?

The scalability is fine. 

How are customer service and technical support?

Technical support is okay. We have had no issues with them. 

What's my experience with pricing, setup cost, and licensing?

The license is not subscription-based. We have been doing the same deployment for more than ten years. 

The pricing is alright. 

What other advice do I have?


Our environment is binding. We have only monitoring and data central traffic.

I would recommend the solution to others. It is fine for analyzing logs. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Buyer's Guide
Download our free IBM QRadar Report and get advice and tips from experienced pros sharing their opinions.