Try our new research platform with insights from 80,000+ expert users
IT Specialist​ at IT Specialist LLC
Reseller
Easy to deploy, and scalable, but the stability has room for improvement
Pros and Cons
  • "The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing."
  • "The solution is difficult to understand in the beginning and has complex management configurations that can be improved."

What is our primary use case?

Our clients who are implementing or trying to implement a Security Operations Center use the IBM QRadar SIEM solution. This solution helps automate incident processing and provides visibility into the incident management process.

What is most valuable?

The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing.

The integration of our customer's infrastructure with other security management systems, such as Active Directory, firewalls, and vulnerability management systems, is effective.

What needs improvement?

The solution is difficult to understand in the beginning and has complex management configurations that can be improved.

The stability has room for improvement.

The cost has room for improvement.

For how long have I used the solution?

I have been using the solution for two years.

Buyer's Guide
IBM Security QRadar
June 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.

What do I think about the stability of the solution?

I give the stability a seven out of ten. There is sometimes unexpected behavior within the logic of the playbook engine and features.

What do I think about the scalability of the solution?

I give the scalability an eight out of ten.

How are customer service and support?

We have had issues that were not resolved by technical support.

How would you rate customer service and support?

Neutral

How was the initial setup?

For the most part, the initial setup is straightforward and I give it a seven out of ten. The initial deployment and configuration require one month, followed by an additional 11 months of implementing various use cases and processes that need to be automated.

What's my experience with pricing, setup cost, and licensing?

I give the price of the solution a four out of ten. The solution comes with a high price tag, while some of the competitors provide identical functionality in their offerings at no extra cost.

What other advice do I have?

I give the solution a seven out of ten.

We have around 20 users.

The solution is of good quality and can be implemented successfully. However, in order to fully utilize its benefits, one must possess expertise in Python programming.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Khalid Majeed - PeerSpot reviewer
Cyber Security Consultant at Software Productivity Strategists, Inc. (SPS)
Consultant
Reliable with good technical support but needs better visualization
Pros and Cons
  • "The product can scale."
  • "The product can be a bit complex."

What is our primary use case?

We are implementors and implement this solution for our clients, who use it for analytics. 

What is most valuable?

It offers good machine learning. The analysis is very helpful. 

The user activity is effectively flagged. It can pinpoint strange activity. 

It is stable and reliable.

The product can scale.

Technical support is good. 

What needs improvement?

The product can be a bit complex. A lot of things, like visualization, could be better. It would help the customer gain a better understanding. 

For how long have I used the solution?

I've used the solution for five to six years. I've used it for a while now at this point. 

What do I think about the stability of the solution?

It is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. I'd rate the stability eight out of ten. 

What do I think about the scalability of the solution?

The solution is scalable. It can handle thousands of users or maybe even more. I'd rate the scalability nine out of ten. 

We mostly deal with small or medium enterprises. 

How are customer service and support?

Most of the time, technical support is helpful. I am satisfied with the level of service we receive. 

How would you rate customer service and support?

Positive

How was the initial setup?

It is easy to implement. I'd rate the ease of implementation seven out of ten. 

The deployment only takes no more than a few hours. There are configurations and fine-tuning that have to happen after that, and everything could take about a week. 

What about the implementation team?

As implementors, we can implement the solution for our clients. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. It's not expensive compared to other solutions. If you get the console and other licenses, you can easily use it with other QRadar solutions. 

What other advice do I have?

New clients should know that it does give good analytics and it will help them save time.

I'd rate the solution seven out of ten. It's a good product.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Buyer's Guide
IBM Security QRadar
June 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
Bobby Sandeep - PeerSpot reviewer
Vice President - Technology & Managed Security Services at Valuepoint Systems
Real User
A simple and stable solution but the dashboards are old
Pros and Cons
  • "The simplicity of the solution is the best feature."
  • "The dashboards are all legacy and old."

What is most valuable?

The simplicity of the solution is the best feature.

What needs improvement?

The dashboards are all legacy and old. Their cloud support and the content available for cloud and containers are also minimal.

For how long have I used the solution?

We have been using this solution since 2019.

What do I think about the stability of the solution?

I rate the stability a nine out of ten.

What do I think about the scalability of the solution?

I rate the scalability an eight out of ten, and we have about 35 people using it.

How are customer service and support?

I rate the technical support a five out of ten. They need to improve their availability. They have global support, which means we need to wait longer for a response.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate the initial setup a seven out of ten, and it is deployed on-premises. The deployment took about four to six weeks, and we did it in-house.

What was our ROI?

We have seen an ROI.

What's my experience with pricing, setup cost, and licensing?

I rate the price a six out of ten, with ten being affordable and one being expensive. They recently changed their licensing model, and it's more complex.

What other advice do I have?

I rate this solution a six out of ten. Regarding advice, using this solution purely depends on the use case. If it meets your use case, then IBM QRadar is good, but other solutions like Securonix are much better.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
JohnTamakloe - PeerSpot reviewer
Solutions Architect at a tech services company with 51-200 employees
Real User
Top 5
Excellent visibility, good notifications, and helpful support
Pros and Cons
  • "The visibility it gives you into your infrastructure has been great."
  • "The AI engine could be smarter."

What is our primary use case?

We are using it for visibility and compliance.

What is most valuable?

The visibility it gives you into your infrastructure has been great.

The notifications it provides offer valuable information when something is happening in your blind spot.

What needs improvement?

The AI engine could be smarter. 

It is a bit expensive. 

For how long have I used the solution?

I've used the solution for about three years. 

What do I think about the stability of the solution?

The solution is stable. I'd rate it five out of five. It's very reliable. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution scales well, and it's easy to do. I'd rate it five out of five in terms of the ease of scalability. 

We have a lot of users on the solution currently. We have customers on the product as well. There are likely more than 500 users inside and outside the organization. 

How are customer service and support?

Support has been helpful and responsive. There may sometimes be a delay. However, they do get you the information you need. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We've only ever used IBM. 

How was the initial setup?

The setup is a bit complex. I'd rate it two out of five in terms of ease of deployment. It took us a week to get everything up and running. 

We had two engineers working on deployment and maintenance. 

What about the implementation team?

We handled the solution in-house. We did not need outside assistance. 

What was our ROI?

We've seen a good ROI. I'd give it a five out of five. 

What's my experience with pricing, setup cost, and licensing?

It's a bit pricey as a product. I'd rate it a two out of five, with five being the most affordable. It depends on what you buy; the longer you use it, the better the cost. It's an all-inclusive license. You don't need to pay for extra features. 

Which other solutions did I evaluate?

We did look at a few other options. 

What other advice do I have?

We use the solution inside our organization. Our clients use it too. We are a premium partner in our region. 

We're using the latest version of the solution.

I'd rate the solution nine out of ten. It really provides good visibility.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Premium Partners
PeerSpot user
Vice President & Country Head at Inspira Enterprise
Reseller
Excellent risk rating but could keep data longer
Pros and Cons
  • "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
  • "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."

What is most valuable?

QRadar UBA's most valuable feature is the risk rating of users depending on their behavior.

What needs improvement?

QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month. In the next release, I would like to be able to do a historical search of user scores.

For how long have I used the solution?

I've been using QRadar UBA for two and a half years.

What do I think about the stability of the solution?

QRadar UBA is quite stable.

Which other solutions did I evaluate?

QRadar UBA's price is a little more than street price and could be reduced.

What other advice do I have?

I would rate QRadar UBA seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Muhammad Ali Aziz - PeerSpot reviewer
Senior Manager Cyber Security Services & Solutions at Trillium
Real User
Top 10
A User Behavior Analytics (UBA) solution with useful out-of-the-box rules and use cases, but functionality should be more integrated
Pros and Cons
  • "I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot."
  • "IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."

What is most valuable?

I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot.

What needs improvement?

IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on. 

For how long have I used the solution?

We have been using IBM QRadar User Behavior Analytics for about four years.

What do I think about the stability of the solution?

Stability is good, but the investigation system should be better.

What do I think about the scalability of the solution?

IBM QRadar User Behavior Analytics is scalable. You have the EPS and closed license. I think scalability is not an issue because it is available on both the hardware and the software. You can install the software plans if you want, and there is also a hardware plan.

How are customer service and support?

Their technical support is good. I have not faced any issues before, and the technical support is good.

What other advice do I have?

I will recommend this solution to potential users.

On a scale from one to ten, I would give IBM QRadar User Behavior Analytics a seven. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1305144 - PeerSpot reviewer
Technical Presales at a tech services company with 1,001-5,000 employees
MSP
Scalable with excellent security analytics
Pros and Cons
  • "This solution has excellent security analytics."
  • "I think that the search speed of this solution could be improved."

What is our primary use case?

I am an integrator of this solution, my customers use this as a SIEM solution for log management.

What is most valuable?

This solution has excellent security analytics.

What needs improvement?

I think that the search speed of this solution could be improved.

What do I think about the scalability of the solution?

This is a scalable solution, we have customers who have scaled.  

How was the initial setup?

The initial setup is very easy and takes just one day.

What other advice do I have?

I would recommend this solution to everyone considering using it.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kamal Abdelrahman - PeerSpot reviewer
Country Manager at Magarah
Real User
Beneficial portfolio, reliable, and integrates well
Pros and Cons
  • "IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration."
  • "The solution could improve by having more out-of-the-box use cases."

What is our primary use case?

IBM QRadar User Behavior Analytics has a dedicated application for user behavior analytics and must be installed separately on an application server. It is valuable if you created the setup for the use cases. It needs additional customization to have a good value. You will have to point the solution to the suitable data sources that will feed the user analytics in a good manner. You will have good user behavior analytics, based on the created use cases.

What is most valuable?

IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration.

What needs improvement?

The solution could improve by having more out-of-the-box use cases.

For how long have I used the solution?

I have been using IBM QRadar User Behavior Analytics for approximately two years.

What do I think about the stability of the solution?

IBM QRadar User Behavior Analytics is stable.

What do I think about the scalability of the solution?

I have found IBM QRadar User Behavior Analytics to be scalable.

We have approximately 15 clients using this solution.

How are customer service and support?

The support is satisfactory.

How was the initial setup?

The implementation was not easy and was not difficult, it was in the middle.

The full implementation can take approximately two to three months.

What about the implementation team?

We have three people that are supporting IBM QRadar User Behavior Analytics.

What's my experience with pricing, setup cost, and licensing?

There is an annual license required for this solution.

What other advice do I have?

I rate IBM QRadar User Behavior Analytics an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.