Cisco Umbrella vs. IBM Security QRadar SIEM

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cisco Umbrella
Score 8.8 out of 10
N/A
Cisco now offers OpenDNS Umbrella Web Filtering. Cisco acquired OpenDNS in August 2015, and rebranded the product as Cisco Umbrella.N/A
IBM Security QRadar SIEM
Score 8.7 out of 10
N/A
IBM Security QRadar is security information and event management (SIEM) Software.N/A
Pricing
Cisco UmbrellaIBM Security QRadar SIEM
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cisco UmbrellaIBM Security QRadar SIEM
Free Trial
YesYes
Free/Freemium Version
YesNo
Premium Consulting/Integration Services
YesNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cisco UmbrellaIBM Security QRadar SIEM
Top Pros
Top Cons
Features
Cisco UmbrellaIBM Security QRadar SIEM
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
Cisco Umbrella
-
Ratings
IBM Security QRadar SIEM
8.7
60 Ratings
11% above category average
Centralized event and log data collection00 Ratings9.927 Ratings
Correlation00 Ratings8.960 Ratings
Event and log normalization/management00 Ratings9.527 Ratings
Deployment flexibility00 Ratings7.927 Ratings
Integration with Identity and Access Management Tools00 Ratings8.456 Ratings
Custom dashboards and workspaces00 Ratings7.660 Ratings
Host and network-based intrusion detection00 Ratings9.625 Ratings
Data integration/API management00 Ratings9.07 Ratings
Behavioral analytics and baselining00 Ratings8.339 Ratings
Rules-based and algorithmic detection thresholds00 Ratings9.240 Ratings
Response orchestration and automation00 Ratings7.75 Ratings
Reporting and compliance management00 Ratings7.838 Ratings
Incident indexing/searching00 Ratings8.97 Ratings
Best Alternatives
Cisco UmbrellaIBM Security QRadar SIEM
Small Businesses

No answers on this topic

AlienVault USM
AlienVault USM
Score 8.0 out of 10
Medium-sized Companies

No answers on this topic

Splunk Enterprise
Splunk Enterprise
Score 8.4 out of 10
Enterprises

No answers on this topic

Splunk Enterprise
Splunk Enterprise
Score 8.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Cisco UmbrellaIBM Security QRadar SIEM
Likelihood to Recommend
9.0
(90 ratings)
8.7
(81 ratings)
Likelihood to Renew
8.5
(11 ratings)
9.1
(3 ratings)
Usability
8.7
(7 ratings)
9.1
(1 ratings)
Availability
9.5
(8 ratings)
-
(0 ratings)
Performance
8.0
(1 ratings)
-
(0 ratings)
Support Rating
8.5
(62 ratings)
8.6
(55 ratings)
Online Training
8.0
(1 ratings)
-
(0 ratings)
Implementation Rating
8.6
(9 ratings)
-
(0 ratings)
Ease of integration
8.4
(8 ratings)
8.3
(51 ratings)
Product Scalability
8.0
(1 ratings)
-
(0 ratings)
Vendor post-sale
8.0
(1 ratings)
-
(0 ratings)
Vendor pre-sale
8.0
(1 ratings)
-
(0 ratings)
User Testimonials
Cisco UmbrellaIBM Security QRadar SIEM
Likelihood to Recommend
Cisco
So the well-suited product, it's actually in two areas. One I already touched base on earlier which is the ability to have a federal model where we have the flexibility to set high-level policies from a group perspective while giving the independence of the business unit to operate and model the system to meet their needs. The second one, which is very powerful, especially in the last few years, is the remote workers. I'm able to protect and extend that edge of my security to their endpoint regardless if they are a Cisco Live or if they are at a bar or on a train basically anywhere. So as a chemical company, we have a lot of OT or ICS industrial control systems, which are highly regulated and highly scrutinized and usually require a physical presence while Cisco umbrella is mostly a cloud native type of product. So it doesn't fit well in that environment, which is detached from the internet doing well.
Read full review
IBM
QRadar is very well suited on environments where there are not multiple tenants or domains, we do have success on this kind of scenario. IBM Security QRadar SIEM is less appropriate for environments with multiple tenants, specially when each tenant represent a different End Costumer (such as for MSSP companies), those environments require a high amount of rules and building blocks replications, since each tenant will have its own "BB definitions", servers, rules exception, etc. Also, some information, such as EPS count or EPS dropped are generated by QRadar's own log sources, which takes place on default domain, therefore users associated with different domain can not have access to those logs, even when the information is related to other domain's environment. For example, even if Event Collector 1 is associated to Domain A, the log informing its dropped EPS is generated by System notification, log source that must be associated to Default domain.
Read full review
Pros
Cisco
  • Effective prevention of ransomware and malware by blocking CNC traffic. rendering the malware useless.
  • Good reports, which are readable by non technical users
  • Using Talos for its threat database means that it rarely misses anything
  • Very good knowledgebase available which means that it is easy to learn how to use and implement the product
Read full review
IBM
  • Enables identification and prioritization of vulnerabilities in IT infrastructure for corrective action.
  • Facilitates security incident investigation and forensic analysis.
  • Provides a real-time view of security events, enabling immediate incident response.
  • Can integrate with external threat intelligence sources to enrich data and improve threat detection.
  • Enables the generation of detailed and customized reports.
Read full review
Cons
Cisco
  • Umbrella Virtual Appliances have been buggy in resolving local domain hosts.
  • Integration between other Cisco and Meraki products is complicated.
  • Reporting is not always accurate; for example, if you configure a Meraki access point to use an Umbrella Virtual Appliance, you lose device reporting. All reporting shows up under the AP's IP.
Read full review
IBM
  • Need to spend more time configuring the system to properly interpret and normalize different type of data collected from multiple resources.
  • While Rule creation QRadar uses that rules to detect security threats and generate alerts, but to creating and managing rules is bit complex & tedious work to complete.
  • IBM Security QRadar SIEM is excellent in handling large & complex systems that requires in-depth knowledge and extensive training to configure and maintain the system which includes upgrading, optimization of performance & issue troubleshooting.
Read full review
Likelihood to Renew
Cisco
First off I never give anything a "10" unless it's perfect. LOL - I grade on the curve. I think OpenDNS/Umbrella is a very good product. I think that fact that Cisco absorbed them is one of the proofs of that. I have used the product back when it was free for companies our size. I have not always appreciated the cost - but in the post pandemic cyber chaos, I believe the cost benefit ratio is still very high. I have honestly not looked at other products because Umbrella continues to work to my satisfaction. I consider Umbrella to be one of the key layers in my cyber security strategy.
Read full review
IBM
With the arrival of IBM Security QRadar SIEM at our company, we have a better vision of all the security needs that may arise, it is a very safe software to use that prevents threats from damaging our IT environment, it is impossible to change it for another software.
Read full review
Usability
Cisco
Better features and easy to manage system with great customer support and overall usability is great as it works for hybrid environment with ease as it is having features for on prem users as wells as cloud users with great customer support and great team of trained engineers to support our opeartions.
Read full review
IBM
A very special system to use without problems, the process is very genuine and does not require complicated procedures.
Read full review
Reliability and Availability
Cisco
Cisco Umbrella's availability was great, they got back to me in less than an hour to get my problem solved.
We needed to get our Meraki AP's hooked up to Cisco Umbrella to monitor that specific traffic and they got back to me promptly, they guided me and explained every question I had.
Read full review
IBM
No answers on this topic
Performance
Cisco
our experience with cisco products has always been awesome and same is the case with cisco umbrella .Under umbrella cisco provides flexible and scalable software solution to use across different dept and sites . These softwares are very user friendly ,pages load quickly as these applications are designed for minimum latency and reports are also provided quickely
Read full review
IBM
No answers on this topic
Support Rating
Cisco
We have not had a chance to use Cisco support frequently, but when we needed to troubleshoot some issues that we were having with the agent installation, the support was very responsive and the solution that they offered worked. The only reason I give it one less point is that the turnaround time for non-critical issues is very long.
Read full review
IBM
Customer support is Good of IBM, While Using IBM QRadar its deployment is to slow and suddenly stop working and crashed we have contacted IBM Support and Rised a Ticket within a few minute we get call back from customer support and Query Resolved by them Fast And Rapid Support of Ibm
Read full review
Online Training
Cisco
Quite easy to understand training modules prepared by knowledgeable trainers. Training modules have included all the desired features of these softwares and the content delivery is very good from the respective module trainers and it explains in details the features and apart from that further training material support is also provided if needed.
Read full review
IBM
No answers on this topic
Implementation Rating
Cisco
At the time we were forced to move from Cloud Web Security to Cisco Umbrella, Cisco Umbrella was far from being a direct replacement. It was frustrating and difficult to migrate due to the lack of functionality. This has since been addressed, however we now have legacy rulesets that were built as bandaids that cannot be removed. Hopefully the migration to Secure Access will address this.
Read full review
IBM
No answers on this topic
Alternatives Considered
Cisco
Auto SIG Tunnels is a feature that helps in provisioning tunnels automatically using Cisco Umbrella APIs and so this is one win for choosing Cisco Umbrella over others. With Cisco SD-WAN viptela, the Cisco Umbrella stacks up well because its the same vendor so less complexities and interoperability issues.
Read full review
IBM
IBM Qradar takes the best from its competitors. Reliable and stable but sometimes very expensive, the SIEM from IBM offers a wide range of scenarios in which the customers can suite and size their own infrastructures. IBM Qradar doesn't really needs to stack up againt its competitors because it already sets an example in the SIEM world.
Read full review
Scalability
Cisco
Cisco umbrella provides fleaxible and scalable software solutions which are easy deploy across multiple departments and sites wherever needed and this softwares are very easy to use and provides the best interface along with cisco support for other devices apart from cisco infrastructure but still there is scope for improvement on the inclusion of latest features
Read full review
IBM
No answers on this topic
Return on Investment
Cisco
  • Cisco Umbrella has been an excellent investment for us. The extra protection it provides in a very simple way has been well worth the costs.
  • Cisco Umbrella is very easy to setup and manage and can do most of the things we need with little daily interaction so we are free to work on other systems that need more attention.
  • Utilizing the Cisco Umbrella reporting features, we can determine what systems might need additional attention. If we see systems attempting certain types of access, we quickly know there is likely something on the device that probably needs removed.
  • Specific Cisco Umbrella reports can help us determine if we need to do user education and develop cyber habits.
Read full review
IBM
  • Offense investigation was really helped in tackling the incidents. It was accurate and brief
  • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
  • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
Read full review
ScreenShots