Try our new research platform with insights from 80,000+ expert users
reviewer1136397 - PeerSpot reviewer
Team Lead - Information Security at a computer software company with 10,001+ employees
Real User
Easy to set up and reliable, with a simple user-interface
Pros and Cons
  • "We've found the solution to be scalable."
  • "The IBM support can be better."

What is our primary use case?

The use cases that are widely used across the globe are related to ransomware phishing, lateral movement, et cetera.

What is most valuable?

The simple user access model, or the user interface, is something that is very helpful.

The initial setup is not too difficult. 

So far, we have found the product to be stable. 

We've found the solution to be scalable.

What needs improvement?

The IBM support can be better. It's an aspect that needs improvement. 

In future iterations, I'd like to see an advance in office management, the out-of-the-box use cases that are provided. That needs to be part of the requirement.

What do I think about the stability of the solution?

It's a stable solution. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. 

Buyer's Guide
IBM Security QRadar
June 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.

What do I think about the scalability of the solution?

The solution scales well.

We have 45,000 users on the solution right now. 

We do plan to increase usage soon. 

How are customer service and support?

We've dealt with technical support in the past and it was lacking. 

They have provided dedicated time to us, to work on the issue that we are observing right now.

Which solution did I use previously and why did I switch?

We did not use a different solution. We chose this due to the fact that it's an industry-accepted solution. The use cases are easy to configure in multiple things that we considered important while taking the solution.

How was the initial setup?

The deployment was easy. It wasn't overly complex.

It took me around six months to do the implementation. 

What about the implementation team?

We handled the deployment with the assistance of a vendor partner. 

What's my experience with pricing, setup cost, and licensing?

I can't speak to the exact pricing. I've never looked at its commercial costs. 

Which other solutions did I evaluate?

We did consider other options before choosing this product.

What other advice do I have?

We are a preferred partner of IBM.

I'd rate the solution at a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1022949 - PeerSpot reviewer
Team Lead & Principal Software Engineer at a tech services company with 51-200 employees
Real User
Stable SIEM that offers strong visibility
Pros and Cons
  • "It is a very good SIEM."
  • "I think it's a very stable product that provides much more visibility than the other product."
  • "I would like for Yara to be supported by all components."

What is our primary use case?

I deploy the IBM QRadar for many organizations, and I've been performing analyses for those organizations as well.

These organizations use the tool for monitoring of their environment. It's a basic SIEM product. So we just log each and every data source, perform an analysis, and create rules. We also create advanced use cases to cater the advanced threat(s).

What is most valuable?

I am unable to pick one, every component is valuable. It is a very good SIEM.

What needs improvement?

I would like for Yara to be supported by all components. 

For how long have I used the solution?

I have been working with this product for the last five years.

What do I think about the stability of the solution?

I think it's a very stable product that provides much more visibility than the other product.

What do I think about the scalability of the solution?

You can scale the architecture of the QRadar easily by adding licenses.

Small to medium-sized organizations would require one to two people for maintenance while man power for large organizations would be determined by the architecture. 

How are customer service and support?

Customer support needs some improvement as there have been a few cases where we were unable to reach them in time.

How was the initial setup?

I didn't find it to be complex. I think IBM QRadar has a more user-friendly GUI that helps your team work easily within it. Deployment for an all in one will take four to five hours but can vary depending on environment size.

What about the implementation team?

Our in-house team assists our customers with deployment. Our customers are the main POC and we are able to deploy into their environment, make necessary integrations, and create the rules.

What's my experience with pricing, setup cost, and licensing?

Licensing can be costly depending on your architecture.

What other advice do I have?

You receive alerts for misconfigurations which allows your administer to easily reconfigure any issues. 

The organizations themselves are able to monitor all of their information regarding their team including what attacks they are facing on a daily bases.

I would rate this an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
IBM Security QRadar
June 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
reviewer952638 - PeerSpot reviewer
Information Security Leader at a computer software company with 1,001-5,000 employees
Real User
Manage and review incidents easily
Pros and Cons
  • "The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents."
  • "The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."

What is our primary use case?

We use IBM QRadar for user behavior analytics and incident handling.

What is most valuable?

The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents.

What needs improvement?

The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity.

For how long have I used the solution?

I have been using IBM QRadar for four years.

What do I think about the scalability of the solution?

We have three customers using it and these customers have 100 to 300 users.

How are customer service and support?

Getting support sometimes takes time.

How was the initial setup?

The initial setup was quite straightforward.

We had the complete deployment and it was up and running in half a day.

What about the implementation team?

You can implement it by yourself.

What other advice do I have?

I would recommend IBM QRadar to other people who want to start using it.

On a scale of one to ten, I would give QRadar a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Assistant Engineer at Harel Mallac Technologies Ltd
Real User
Simple to manage, reliable, and straightforward installation
Pros and Cons
  • "The solution is easy to use, manage, and review all incidents."
  • "If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."

What is our primary use case?

I use IBM QRadar for user behavior analytics, and mostly incident handling.

What is most valuable?

The solution is easy to use, manage, and review all incidents.

What needs improvement?

If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage.

For how long have I used the solution?

I have been using IBM QRadar for approximately four years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

We have approximately three customers and the total users that are using it would be approximately 200.

How was the initial setup?

The initial installation was straightforward, we were able to have it running in half a day.

What about the implementation team?

I do the implementation and maintenance of the solution.

What's my experience with pricing, setup cost, and licensing?

There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option.

What other advice do I have?

I would recommend this solution to others.

I rate IBM QRadar a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Joao Manso - PeerSpot reviewer
CEO at REDSHIFT CONSULTING
Reseller
Top 10
Very powerful with plenty of features and capabilities
Pros and Cons
  • "The product has plenty of features and capabilities."
  • "The usability of interfaces could be improved."

What is our primary use case?

We use this solution both in our company and those of our clients. We are resellers of QRadar. 

What is most valuable?

Curator is the leader of teams in the market. It's a product with plenty of features and capabilities. It's a very powerful solution.

What needs improvement?

The usability of interfaces could be improved and the solution could have better correlation services, as well as faster and updated intelligence interfaces.

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

Technical support has room for improvement.

How was the initial setup?

The initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

Licensing costs are reasonable.

What other advice do I have?

I rate the solution nine out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Solution Security Architect at PT. Sinergy Informasi Pratama
Real User
Provides great analysis of event logs, event security; easily manageable with one monitor
Pros and Cons
  • "It can analyze event logs, event security, and give a good consult."
  • "Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."

What is our primary use case?

This is a solution you use when you have many security products that you want to manage in one monitor, one analytic. We are partners with IBM and provide implementation services to our customers. I'm a solution security architect.

What is most valuable?

The most valuable feature is that it can analyze event logs, event security, and give a good consult. When you have SIEM, you can easily manage with one single monitor. QRadar can do a lot of analyses of every security product and will let us know what needs to be done to the log. Sometimes we need security orchestration automated response to support the SOC team.

What needs improvement?

The concern with QRadar is that there are so many features in the dashboard, too many menus that require going to two or three sub-monitors to enter the QRadar. The user interface is good but there are so many features that can be confusing for the administrator. It could be simplified. 

For how long have I used the solution?

I've been using this solution for a year. 

What do I think about the stability of the solution?

I think that QRadar is stable, but I've never worked with other solutions in this area and I have nothing to compare it to. It has dedicated machines and offers great performance. 

What do I think about the scalability of the solution?

The scalability is easy but it comes at a high price.

How are customer service and support?

IBM in Indonesia provides great support.

How was the initial setup?

The initial setup is complex if the data set is large. It really depends on that. We provide maintenance services to our clients so that if they have any trouble, we assist with troubleshooting.

What's my experience with pricing, setup cost, and licensing?

SIEM is quite a pricey solution so we only offer it to enterprise companies that can pay the fees. For smaller companies, it's an extremely expensive product. 

What other advice do I have?

I recommend this solution because I think they provide great support from the sales and technical perspective.

I rate the solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer594315 - PeerSpot reviewer
Assistant IT Manager at a insurance company with 1,001-5,000 employees
Real User
A SIEM solution that's easy to use, but the price could be better
Pros and Cons
  • "I like that it's easy to use and the performance is good."
  • "It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation."

What is our primary use case?

I use QRadar for cybersecurity defense, operation, and to improve performances.

What is most valuable?

I like that it's easy to use and the performance is good.

What needs improvement?

It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation.

For how long have I used the solution?

I have been using IBM QRadar for four years.

What do I think about the stability of the solution?

IBM QRadar is a stable solution, but it could be more stable.

What do I think about the scalability of the solution?

IBM QRadar is a scalable solution. We have about 100 users at the moment.

How are customer service and technical support?

I remember that I opened ten or 20 cases to receive support from IBM over three years.

How was the initial setup?

The initial setup and deployment are very easy. I think it took us about a month to implement this solution. We have a team of two, one manager and one technical, to deploy, manage, and maintain this solution.

What about the implementation team?

We installed this solution with the help of a consultant.

What's my experience with pricing, setup cost, and licensing?

The price could be better. I bought a subscription for three years. 

What other advice do I have?

On a scale from one to ten, I would give IBM QRadar a seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1665357 - PeerSpot reviewer
IT Security Manager at a tech services company with 201-500 employees
Real User
Excellent network monitoring but needs better compatibility
Pros and Cons
  • "The feature that I have found most valuable is how it monitors the real network. That is its leading security feature."
  • "The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good."

What is our primary use case?

Our primary use case is for monitoring global infrastructure.

What is most valuable?

The feature that I have found most valuable is how it monitors the real network. That is its leading security feature.

What needs improvement?

In terms of what could be improved, I'd say do nothing, in its current state it does quite okay for now.

The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good

For how long have I used the solution?

I have been using IBM QRadar for more than five years.

I'm using the latest version of QRadar.

What do I think about the stability of the solution?

The stability is very good. Its operation is very good.

What do I think about the scalability of the solution?

We have less than five people using it.

For us, as a small security company, it is covering our needs and our growth.

How are customer service and technical support?

Customer support is good. When an incident gets raised there is a 10 day response.

How was the initial setup?

The initial setup was complex.

What about the implementation team?

We use the vendor for everything. That is the style of the corporation. For these jobs the responsibility and knowledge is on the vendor's side.

What's my experience with pricing, setup cost, and licensing?

Implementation is over time and the maintenance price for QRadar is competitive.

What other advice do I have?

On a scale of one to ten, I would give IBM QRadar a seven.

Overall, I would of course recommend this product to others because of all its functionalities.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.