2021-07-23T09:35:00Z

What SOC product do you recommend?

Hi community members,

I'm a security engineer at a Tech Services company and I'm currently exploring SOC solutions, such as Rapid7 InsightIDR, Splunk, IBM QRadar and ArcSight Analytics.

Based on your experience, which SOC tool/solution would you recommend and why?

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
  • 9
  • 328
12
PeerSpot user
12 Answers
JC
Senior Security Analyst at a financial services firm with 501-1,000 employees
Real User
2021-07-27T14:45:26Z
Jul 27, 2021

For tools I’d recommend: 


-SIEM- LogRhythm


-SOAR- Palo Alto XSOAR


Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic.


Also, remember that any EDR/XDR should integrate to the SIEM/SOAR and a strong threat intel source.


If you consider SOC outsourcing take your time and find one you can integrate like a virtual team member. They are only as good as their depth of knowledge in your business and your on-prem SOC.

EB
Director of Community at PeerSpot (formerly IT Central Station)
Community Manager
Jul 27, 2021

@Jack Callaghan do you also have any good recommendations for an XDR product? 

PeerSpot user
Product comparison that may be of interest to you
KM
IT Infrastructure Analyst at AG Group
Real User
2021-07-26T03:13:53Z
Jul 26, 2021

I haven't used these big-name ones like Splunk etc. but I feel they're overpriced. I think they charge an arm and a leg for each module.


The ROI justification is not there. Why not try a cheaper and robust alternative like Elasticsearch?

Jairo Willian Pereira - PeerSpot reviewer
Information Security Manager at a retailer with 10,001+ employees
Real User
Top 5Leaderboard
2021-08-10T21:08:09Z
Aug 10, 2021

Apache Metron, ELK, OSSIM, Splunk and Qradar (in cost/benefit order for starters).

TS
CEO at Rufusforyou
Reseller
Top 10Leaderboard
2021-07-26T09:03:14Z
Jul 26, 2021

I have no experience with Rapid 7 or InsightIDR. 


IBM Qradar works great but is not easy to install. If it is running it is a great tool. Also depending on the budget, Riverbed security is a tool to consider. Costs are lower than QRadar and easier to implement. 


Or you can use our SaaS solution with QRadar and a lot more built-in. One holistic solution for your complete IT environment.

JC
Senior Security Analyst at a financial services firm with 501-1,000 employees
Real User
2021-07-28T06:02:02Z
Jul 28, 2021

@Evgeny Belenky, ​ I found Stellar to be quite intriguing. 


I would also recommend McAFee’s new console for centralizing and coordinating a well-deployed enterprise solution.

IK
Director at IP Infotech Pvt. Ltd.
Reseller
Top 5Leaderboard
2021-07-28T05:11:54Z
Jul 28, 2021

COMODO MDR 

Find out what your peers are saying about IBM Security QRadar vs. Splunk Enterprise Security and other solutions. Updated: September 2023.
735,226 professionals have used our research since 2012.
JS
Senior Network Architect / Network Team Leader at ICE Consulting. Inc.
Real User
2021-07-26T19:06:05Z
Jul 26, 2021

Disclaimer: ICE Consulting offers SOC as a Service to our Clients.


For SOC Tools we use Securonix and other in-house developed solutions. Securonix provides an all in one package (SIEM, UEBS, & NTA) that we believe is competitively priced for the Small to Mid Market. Their Customer Service seems better than most and they are always highly rated in the Gartner MQ reports. Set-up is not difficult, but is time consuming for the first time, afterwards each client deployment we have added has seemed to get easier and quicker.


Please contact several vendors and ask for demos, talk with the vendor engineers to ensure the solution will workfor your needs... We evaluated Rapid7, AlienVault (ATT Cybersecurity), QRadar, LogRythm, and Securonix before deciding on Securonix. 


Also take your time in evaluating and re-evaluating the products, I took us about about 18 months and over $30K of working with what was utimately the wrong product for us, before moving to Securonix.


Make sure training for the use of the service is included.  We have been able to provide entensive training to out team through the vendor and would not have been able to get out SOC offering off the ground without it.


Good Luck!

IK
Director at IP Infotech Pvt. Ltd.
Reseller
Top 5Leaderboard
2021-07-26T05:52:39Z
Jul 26, 2021

COMODO SOC covers your entire network and also your email. It is very easy to deploy and is very effective for reports. 

IK
Director at IP Infotech Pvt. Ltd.
Reseller
Top 5Leaderboard
2021-07-26T05:26:09Z
Jul 26, 2021

I prefer the COMODO SOC solution because it is a very good and easy to deploy product.

EB
Director of Community at PeerSpot (formerly IT Central Station)
Community Manager
Jul 26, 2021

@Ishan Kukreti, can you please be more specific about it: what features/ other aspects are positive about it? Thanks.

PeerSpot user
KA
Unit Head Titanium (Security Solution) at RapidCompute
Real User
2021-07-26T05:04:26Z
Jul 26, 2021

We are using LogRthythm SIEM complete case management and offer SIEM/SOC as service.

Vendor
2021-08-09T10:08:21Z
Aug 9, 2021

If you are a small and medium-sized business, I recommend UTMStack; this free SIEM (a free community option) includes all essential cybersecurity services, including SOC, at a low price. https://utmstack.com/

Shibu Babuchandran - PeerSpot reviewer
Regional Manager/ Service Delivery Manager at a tech services company with 201-500 employees
Real User
ExpertModerator
2021-08-07T12:29:50Z
Aug 7, 2021

Splunk, ELK, AlienVault. depending on the requirement, outcome and budget.

Related Questions
Liam Brandt - PeerSpot reviewer
User at Catalyic Consulting (Pvt.) Ltd
Mar 22, 2023
Hi community, Please let us know your thoughts in the comments below. Thank you!
See 2 answers
VS
User at RAS Unipers
Mar 14, 2023
Hi, in my opinion, because it is still the best at giving you visibility of what's happening in your IT infrastructure, and at detecting threats. Visibility and detection may seem simple tasks. but actually, they require a lot of capabilities in understanding, integrating, logging, and alarms from a huge multitude of devices. Such tasks go under the line of log ingestion, normalization, etc., and that is far from easy. QRadar has done a lot of work in that direction. Another aspect is event correlation. And here, either you write the correlation rules yourself, spending $$$$ of professional services, and by the way, it'll take forever to test, implement and maintain up to date, or your access to a very long list of preset correlation rules, that are already available and waiting to be activated. Finally, visibility and threat detection is just the beginning of a journey pointed at becoming aware of what's happening in your IT and taking relevant and effective action. There are several other technologies that have to be used to minimize exposure, and contain, and remediate relations to an attack. I believe IBM has a few of those, that can be integrated. But whichever you use at the end of this journey, if the original feed is not correct, not relevant, or not complete, you missed your goal in the first place.My 5 cents :)VS
Jairo Willian Pereira - PeerSpot reviewer
Information Security Manager at a retailer with 10,001+ employees
Mar 22, 2023
I´m not sure about this affirmation. There are a lot of other tools used.
Miriam Tover - PeerSpot reviewer
Service Delivery Manager at PeerSpot
Oct 18, 2022
How do you or your organization use this solution? Please share with us so that your peers can learn from your experiences. Thank you!
2 out of 4 answers
SU
Team Lead - Information Security at LTI - Larsen & Toubro Infotech
Feb 6, 2022
The use cases that are widely used across the globe are related to ransomware phishing, lateral movement, et cetera.
SD
IM Operations Manager at a tech services company with 1,001-5,000 employees
Apr 25, 2022
IBM QRadar Advisor with Watson is aligned with regards to what's happening in the public space in terms of the Phishing attacks that we are seeing prevalent in the market. In the campaigns that which hackers are trying to obtain information, the use cases are very practical. The solution offers quite a bit of protection.
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 12, 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to better connect with peers and other independent experts who provide advice without vendor bias. Our users have ranked these solutions according to their valuable features, and discuss which features they like most and why. You can read user reviews for the Top User Behavior Analytics - UEBA Tools...
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 2, 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to better connect with peers and other independent experts who provide advice without vendor bias. Our users have ranked these solutions according to their valuable features, and discuss which features they like most and why. You can read user reviews for the Top 8 Log Management Tools to help you d...
Ertugrul Akbas - PeerSpot reviewer
Manager at ANET
Oct 9, 2021
There are many comparisons and scoring reports like Gartner. But a small part of their scoring is technical capacity. Other comparisons available on the web or magazines are marketing, sales, and presales documents. They do not include extensive technical analysis. In today’s ever-evolving cybersecurity climate, businesses face more threats than ever before. Finding the right SIEM is crucia...
2 out of 6 comments
CH
Visionary at Whaduu, LLC
Jul 12, 2021
Excellent article.  ArcSight claims to use ML - they are not listed under ML here (?).  Can LogRhythm handle your correlation logic example?  A simple comparison table would be very useful (features, checkmarks).
Ertugrul Akbas - PeerSpot reviewer
Manager at ANET
Jul 12, 2021
@CraigHeartwell, ​thanks for your spelling correction.  ArcSight acquired Interset for ML. Yes, LogRhythm can handle the logic. SIEM Comparison table is on my mind for a long time. I published the Turkish version. I need to work to extend it before publishing.
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 30, 2022
PeerSpot’s valuable crowdsourced user review platform helps technology decision-makers around the world to better collaborate with peers and other independent technical experts to provide advice, share knowledge and expertise without vendor bias.Our trusted users have ranked numerous popular solutions according to their valuable features, and have also made suggestions on where they see room fo...
See 1 comment
RS
Performance and Fault-tolerance Architect with 1,001-5,000 employees
May 30, 2022
Good very informative
Product Comparisons
Related Categories
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 12, 2022
Top 7 User Behavior Analytics (UEBA) Tools 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to...
NC
Content Manager at PeerSpot (formerly IT Central Station)
May 2, 2022
Top 8 Log Management Tools 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to...
Download Free Report
Download our FREE report comparing IBM Security QRadar and Splunk Enterprise Security based on reviews, features, and more! Updated: September 2023.
DOWNLOAD NOW
735,226 professionals have used our research since 2012.