Try our new research platform with insights from 80,000+ expert users
reviewer1665357 - PeerSpot reviewer
IT Security Manager at a tech services company with 201-500 employees
Real User
Sep 14, 2021
Excellent network monitoring but needs better compatibility
Pros and Cons
  • "The feature that I have found most valuable is how it monitors the real network. That is its leading security feature."
  • "The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good."

What is our primary use case?

Our primary use case is for monitoring global infrastructure.

What is most valuable?

The feature that I have found most valuable is how it monitors the real network. That is its leading security feature.

What needs improvement?

In terms of what could be improved, I'd say do nothing, in its current state it does quite okay for now.

The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good

For how long have I used the solution?

I have been using IBM QRadar for more than five years.

I'm using the latest version of QRadar.

Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability is very good. Its operation is very good.

What do I think about the scalability of the solution?

We have less than five people using it.

For us, as a small security company, it is covering our needs and our growth.

How are customer service and support?

Customer support is good. When an incident gets raised there is a 10 day response.

How was the initial setup?

The initial setup was complex.

What about the implementation team?

We use the vendor for everything. That is the style of the corporation. For these jobs the responsibility and knowledge is on the vendor's side.

What's my experience with pricing, setup cost, and licensing?

Implementation is over time and the maintenance price for QRadar is competitive.

What other advice do I have?

On a scale of one to ten, I would give IBM QRadar a seven.

Overall, I would of course recommend this product to others because of all its functionalities.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1598412 - PeerSpot reviewer
Management Executive at a security firm with 11-50 employees
Real User
Sep 7, 2021
User-friendly, easy to deploy with proper training and offers good coverage
Pros and Cons
  • "What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value."
  • "The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue."

What is our primary use case?

We primarily use the solution for breach management. We use it for identifying rogue IPs and picking up anomalies in terms of the network traffic coming in. We've seen a year of use cases in terms of breach management and incident management. We find IBM QRadar quite relevant in terms of protecting against potential malicious traffic coming into your organization. 

Obviously, it is evolved, and where we're utilizing IBM QRadar is to do other analytical capabilities, which include identity and access management. We've got a unique way where we use the platform to generate a view of all your identities and access that is granted within your environment and so forth. We are able to map that using IBM QRadar, which is not a use case that is normally thought about, however, we found from an analytical point of view, this is what we can do because we get all the information we need here.

What is most valuable?

IBM QRadar is phenomenal as a SIEM SOC solution. In terms of its capability, in terms of its usability, in terms of the SOC solutions or SIEM solutions out there, we find QRadar the most user-friendly. 

It gives you the right coverage as the analytical platform that's coupled with Watson is phenomenal.

From a deployment perspective, we found it very, very good.

What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value.

It's easy to use if you go through the proper training. We find that the current IBM team in South Africa is not as good as the teams abroad, however, if you get the right support and the right training, which we have got, we find it very, very, very customizable and user-friendly. 

What we have done is we do not use a lot of level-one analysts. We use a lot of developers, so we constantly evolve the rule-set. Most of the organizations that have employed QRadar, what they do is they stack it up with level-one and level-two analysts, as opposed to having more security developers who enhance the rule-set, due to the fact that all of the same technologies work on rule-sets. If you can dynamically change the rule-set on the fly, you're good. We have got a different model in terms of the way we operate a SOC, where we have more developers amending the rules, you will lessen the number of false positives that you encounter. The biggest problem with most of the SIEM technologies out there is that you get too many false positives, and again, it impacts your operational SOC. We don't have that issue here. 

What needs improvement?

The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue.

You do need proper training. Better training leads to better implementation. South Africa does not have the most knowledgeable technical support team. One challenge that you have in South Africa is the quality of the IBM resources. They're not up to the level companies need. I have to criticize IBM on that point - the skill level in South Africa and the South African franchise of IBM doesn't necessarily meet the quality of the product.

They can improve on the architecture. It's the way you deploy it. It's your enterprise architecture team that needs to understand it well. Again, due to our unique skillset on it, we deploy it in a very different way where we reduce the consumption of events per second, which reduces the overall cost of it. However, with the architecture, you need to get better guidance from IBM in terms of the way which the architecture is done. 

What I will say about IBM is that if you deploy it stock standard, it can be a very expensive tool, especially with your events per second, and where the way you deploy it architecturally will determine how much it costs you to manage it, as your events per second can be reduced through proper architecture. It's critical to an IBM install that a user understands the architecture and the deployment strategy. 

For how long have I used the solution?

I've been dealing with the solution for a very long time. It's likely been about six years or so at this point. I've used it for a while.

What do I think about the scalability of the solution?

We've got three customers on the solution currently. 

How are customer service and technical support?

Technical support is lacking in South Africa and it doesn't meet the quality of the product. We're not quite satisfied with the level of service of knowledgeability on offer here. 

They need to be faster and more knowledgeable. If you log a ticket to South Africa, they can be quicker and more knowledgeable about issues. It's a problem within South Africa where the skill level of the IBM local team is not to the level it should be. Whether it's training or support, there's a problem. It's not the greatest.

How was the initial setup?

The initial setup can be difficult if you don't have a good understanding of the product, for us, it's not too difficult. 

To do a small deployment takes us about two weeks.

When we did the deployment for one of our clients recently it took us four engineers from our side and four engineers from the outside to deploy it within two weeks. 

What about the implementation team?

We handle deployments for our clients. Occasionally we need outside assistance. 

What was our ROI?

From a return on investment, the client sees in terms of its value from an IBM perspective, is a massive value from the deployment of QRadar.

What's my experience with pricing, setup cost, and licensing?

On-premises is pretty expensive as opposed to the cloud. 

You do need to pay for a year subscription. You are charged at events per second as well. 

What other advice do I have?

On QRadar, we look at the cloud-based uses as opposed to on-premise due to the cost factor. 

In terms of SIEM technologies, in terms of what you can get, I would rate it an eight out of ten. The QRadar platform is phenomenal in terms of what it does.

If you want to get the best out of IBM, spend more time on the rules generation and the modification of the rules.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
reviewer1610610 - PeerSpot reviewer
Network Security Engineer at a computer software company with 51-200 employees
Real User
Aug 24, 2021
Priced well, scalable, but better threat detection needed
Pros and Cons
  • "I have found IBM QRadar to be scalable."
  • "IBM QRadar could improve the plugins and threat detection."

What is our primary use case?

We are using IBM QRadar for threat protection and management.

What needs improvement?

IBM QRadar could improve the plugins and threat detection.

For how long have I used the solution?

I have been using IBM QRadar for approximately seven years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

I have found IBM QRadar to be scalable.

What's my experience with pricing, setup cost, and licensing?

The price of this solution is reasonable.

What other advice do I have?

I rate IBM QRadar a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1388217 - PeerSpot reviewer
Analyst at a tech services company with 501-1,000 employees
Real User
Jul 30, 2021
Easily monitors your environment with good user interface and plug-in integrations
Pros and Cons
  • "One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like Scout, Carbon Black, and the rest."
  • "I would like the rule creation interface to be much more user-friendly in the next release."

What is our primary use case?

We use IBM QRadar to monitor security logs across the network.

What is most valuable?

One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like ForeScout, Carbon Black, and the rest. Additionally, the ability of the agents to filter using XPath query to filter out the specific events you want to pick from, especially Windows log sources, is also very useful. That goes a long way in managing the EPS of the solution.

What needs improvement?

There are two ways you can pull logs: one way is where you can receive logs or send logs using the agents and previous transformation and the other way is where QRadar logs onto the servers using the admin account and then pulls the logs itself. The functionality that I would love to see with that remote pulling is to have the ability to also select what logs its pulling because when you use MSRPC now to receive loads from your log surface, it basically pulls all the events from that server. So even the noisy events that would overshoot your EPS, would also be pulled. So for particularly active or high servers that generate a whole lot of security events, let's say like your SFTP server that has a lot of devices on your network connecting to it, if you try to pull the logs remotely it would overshoot your EPS really quickly.

So if they could improve the functionality of the remote pull to also be able to select the logs that it is pulling from the log sources, that would be very, very effective. The reason for the pull is because the agents are not tamper-proof and any administrator can help shut down the service and uninstall the application and a whole lot of other things. Basically, your listening agent is at the mercy of the administrators, and for a security device or security software, that is a big vulnerability, because anybody can then go into the server, stop the agent, and then run any command or make any change they want to do, which would make your monitoring null and void. It would be good if the agent itself could be tamper-proof. And back to the first point, the reason why I prefer the remote pull is if there's no agent on the server and it's the console logging onto the server, your monitoring is much more secure. Regardless of what changes are being made on the server or what's going on the server, if the server is shut down and then a newer version is brought up with the same hostname and IP address, you would not need to go back in and re-install the agent. The console would just automatically connect back to that server once the IP address and the host are back up.

Additionally, I would like the rule creation interface to be much more user-friendly in the next release.

For how long have I used the solution?

I have been using IBM QRadar every day for the last 12 months.

What do I think about the stability of the solution?

In terms of stability, it is very stable. In the almost two years in the environment, there has been only one issue. It was a disc failure and that was replaced within a week by the OEM.

What do I think about the scalability of the solution?

Scalability might be an issue, but maybe it's because in our environment we do not use the application host. Since we use on-premise appliances we did notice that performance degraded a little when we added some plugins. So the recommendation was that we should have a separate application server that would host the application and then interface with the plugins and interface with the management console. But we do not have that within our environment so I can't speak to whether that would improve performance.

How are customer service and technical support?

IBM tech support has been responsive.

How was the initial setup?

I believe the initial setup was straightforward but I was not here for the setup, although I did not get any complaints.

What's my experience with pricing, setup cost, and licensing?

The license is a yearly one.

What other advice do I have?

I would recommend IBM QRadar. The user interface is really great and it simplifies the task of monitoring your environment.

On a scale of one to ten, I would give IBM QRadar an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cyber threat Intelligence Manager at a security firm with 51-200 employees
Real User
Jul 21, 2021
Beneficial log reporting, excellent technical support, but stability needs improvement
Pros and Cons
  • "The most valuable features are log monitoring, easy-to-fix issues, and problem-solving."
  • "There is a shortage of skilled individuals with knowledge about the solution. There is training required."

What is our primary use case?

We use IBM QRadar for threat protection.

What is most valuable?

The most valuable features are log monitoring, easy-to-fix issues, and problem-solving.

What needs improvement?

There is a shortage of skilled individuals with knowledge about the solution. There should be more training programs to teach and enable users get familiar.

For how long have I used the solution?

I have been using this solution for approximately one year.

What do I think about the stability of the solution?

The stability of the solution could improve.

What do I think about the scalability of the solution?

We have approximately 20 people using this solution in my organization.

How are customer service and technical support?

The technical support is great. Additionally, there are plenty of resources available to increase knowledge about the solution.

Which solution did I use previously and why did I switch?

We have used other solutions in the past.

How was the initial setup?

The installation is not very difficult, I did not have any problems.

What about the implementation team?

We used consultants for the implementation. We have five engineers that do the maintenance of this solution.

What's my experience with pricing, setup cost, and licensing?

There is a license required for this solution.

What other advice do I have?

I would recommend this solution to others.

I rate IBM QRadar a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1348482 - PeerSpot reviewer
Practice Head at a tech services company with 51-200 employees
Real User
Jul 18, 2021
Flexible correlation, easy to use, and stable
Pros and Cons
  • "It is a bit easier to use than other products, such as Splunk or ELK Elasticsearch."
  • "The technical support can be improved a little bit, and the price could be cheaper."

What is our primary use case?

We have a POC environment but have not onboard it to any of our clients.

What is most valuable?

The most valuable feature is the correlation function, which is flexible.

It is a bit easier to use than other products, such as Splunk or ELK Elasticsearch.

What needs improvement?

The technical support can be improved a little bit, and the price could be cheaper.

For how long have I used the solution?

I have been using IMB QRadar for one year.

What do I think about the stability of the solution?

IBM QRadar is a stable solution.

How are customer service and technical support?

Technical support needs improvement.

Which solution did I use previously and why did I switch?

I know a little bit about Splunk and ELK Elasticsearch. We did not have a PoC with Splunk so it was just theoretical, but I did learn about it.

How was the initial setup?

The initial setup is very easy.

What's my experience with pricing, setup cost, and licensing?

IBM QRadar is a little bit expensive compared to other products.

What other advice do I have?

I would recommend this solution to others who are looking for an on-premises solution. For a SIEM solution, it is the best one to go with. If they are interested in using the cloud, I would not recommend it. The cloud version of QRadar is QRoC and it is a bit complicated.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
AVP - Cyber Secuirty at a tech services company with 501-1,000 employees
Real User
Jul 18, 2021
A stable solution which allows a single system to be onboarded for all 200 existing customers for monitoring purposes.
Pros and Cons
  • "No doubt about it, the solution is extremely stable."
  • "The implementation of the solution's technology needs to be simplified."

What is our primary use case?

We are using the current version.

What is most valuable?

The solution supports MSSP models, which most service providers have. This means that a single system can be onboarded for all 200 existing customers for monitoring purposes. 

What needs improvement?

The implementation of the solution's technology needs to be simplified. It is overly complex. 

The integration also must be simplified. 

The licensing is also overly complex, as there is a need to buy the work load performance monitoring separately. These are the different modules we need to buy. 

IBM does not provide a combined, combo suitor solution which the customer can easily look at. The multiple functionalities are segmented and do not allow for an idea which is complete. It makes it difficult for us to do a realistic comparison with other products. I hope that others follow suit. 

For how long have I used the solution?

We have been using IBM QRadar for almost eight-and-a-half years. 

What do I think about the stability of the solution?

No doubt about it, the solution is extremely stable. 

What do I think about the scalability of the solution?

The solution needs to be redesigned to allow for scalability or for extending it to the existing one. There is a need to do long-term planning and migration from an existing to a new one and this cannot be easily accomplished. Storage cannot be added to the installation. One must completely migrate to the new storage to add additional terabytes. 

As such, the solution is not quite scalable. The scalability exists, but it requires migration. 

How are customer service and technical support?

We are very happy with the technical support. 

How was the initial setup?

The initial setup was extremely complex. 

What about the implementation team?

We made use of an integrator. 

What other advice do I have?

We have nearly two hundred customers making use of the solution.

We have direct contact with Ingram Micro or have a service partner relationship with it, but work directly with IBM as our ISP. 

We are a managed security service provider and wholesale customer of IBM QRadar

We buy a bulk license from IBM QRadar and host around 200 plus customers in a single integration so that all the customer events will be integrated in one solution. We are not integrators and do not resell their services.

As such, we don't buy the license or sell the tools to others. We will buy a license, inclusive of the services, host it with our private cloud and provide services to the end clients.

Our customer base of IBM users is limited. When it comes to a security operations center team, IBM will be looked to for providing security monitoring on an ongoing basis. We must see that it is working as it should be. 

I would recommend this solution to others. 

I rate IBM QRadar as an eight out of ten. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1623684 - PeerSpot reviewer
Security Analyst at a tech services company with 51-200 employees
Real User
Jul 15, 2021
Well priced with information granularity, but has lousy tech support and provides false positives of attacks
Pros and Cons
  • "Most valuable features include the granularity of information."
  • "IBM technical support is always terrible."

What is most valuable?

Most valuable features include the granularity of information. Queries provide leads for finding information. We also deal with the Symantec team, which is a different one. 

What needs improvement?

The solution has definite room for improvement. There were certain bugs we had to deal with. Bigger issues involve the quantity of rules involved in its deployment. Also, false positives can be obtained and there is a need to fine tune the solution once every month or two until everything is correct. 

The stability and product support should also be addressed. 

When an offense occurs, the source IP will automatically provide a source username which is not correct. For reasons I don't understand, it uses the team or the name of the last user of the computer and this is not always accurate. This means that there are times that I obtain offenses that are ascribed to my boss and which serve him. The solution ensures that the host is vulnerable to another attack. The solution will estimate that the targeted host is vulnerable to certain attacks. 

Moreover, the solution may provide information of attacks that failed or that are irrelevant, such as vulnerabilities involving modems in which the target host is the Windows Server. This begs the question of why an offense that was and will always be blocked must be generated, such as that involving vulnerability from a modem. 

For how long have I used the solution?

I have been using IBM QRadar for five years. 

What do I think about the scalability of the solution?

When it comes to the scalability of the solution, it is possible to install many apps on top of IBM QRadar which can provide a host of views, such as those involving user behavior and analytics. There is no need to construct an SQL report, for example, as there are many free apps available which can be used to extend one's IBM QRadar functionalities. 

How are customer service and technical support?

:
IBM technical support is always terrible. I have much experience with IBM, dating back 25 years in IT. I worked with IBM as a partner for almost 10 years. The organization is so big that it cannot tell one person from another. One can send an email and then get transferred from one support person to another, needing with the need to reiterate the issue anew with each one. In France they go on vacation and there is no one to whom one can address his issue. They also have problems with directing and redirecting phone calls. 

I found myself in charge of all hardware issues involving IBM. Whenever we had a case with IBM which was escalated, I managed to resolve the issue before them. I would find a solution while they would still be making queries about some version. Sometimes I feel they are buying time. At other times, they start by enquiring about what I did in an attempt to resolve the issue. There are times that they insist on the purchase of a subscription as a condition of benefiting from high level support and at these moments I'm inclined to tell them that they should be paying me for this. 

How was the initial setup?

The initial setup is quite straitforward and not so difficult. 

What's my experience with pricing, setup cost, and licensing?

The pricing is always fine. 

What other advice do I have?

We use the solution with multiple customers on a daily basis. We have experience with its installation, configuration and use. 

I rate IBM QRadar as a six or seven out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.