What users are saying about
15 Ratings
Top Rated
87 Ratings
15 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 7.7 out of 100
Top Rated
87 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>
Score 9 out of 100

Likelihood to Recommend

Darktrace

Darktrace would be well suited to any environment really; the only constraint would be the budget. The cost scales on the number of devices to be monitored by the product, so it can be quite expensive in larger environments. Any company that would benefit from having 24/7 monitoring of their network would find that this product would suit that need perfectly. It can also create a number of reports, which is useful if you have any requirement to present periodic figures and statistics for your network. There are also additional features available and in development such as Antigena, which can be configured to allow potential threats to be automatically mitigated; it can block connections to a certain address, using certain ports, or it can enforce "normal behaviour" where it will only allow a machine to communicate in a way that Darktrace has observed before and considers normal. This has huge benefits particularly for 24/7 organisations where you don't have the ability to have someone monitoring the network personally at all times, as it could stop a malware outbreak in its tracks.
Anonymous | TrustRadius Reviewer

IBM QRadar

If you have a small-to-large company looking for a SIEM solution that "does the job" and is easy to deploy/use, QRadar is your tool. If you're looking for a complex solution that supports integration with data-mining solutions (e.g. ELK), then you may need a different solution. Overall, QRadar fits the needs of 99% of the companies. It is one of the easiest SIEM solutions to deploy and use.
Anonymous | TrustRadius Reviewer

Feature Rating Comparison

Security Information and Event Management (SIEM)

Darktrace
IBM QRadar
9.2
Centralized event and log data collection
Darktrace
IBM QRadar
9.5
Correlation
Darktrace
IBM QRadar
9.9
Event and log normalization
Darktrace
IBM QRadar
9.5
Deployment flexibility
Darktrace
IBM QRadar
9.0
Integration with Identity and Access Management Tools
Darktrace
IBM QRadar
8.7
Custom dashboards and views
Darktrace
IBM QRadar
9.1
Host and network-based intrusion detection
Darktrace
IBM QRadar
8.8

Pros

Darktrace

  • It did an ok job of analyzing and collecting data. It used a span (mirrored) port and then using its own algorithm developed flow records.
  • It did an ok job of segmenting traffic into networks - not always correctly, but ok.
  • It tried to identify devices by type - once again, it did ok, but not that great.
Matthew Frederickson | TrustRadius Reviewer

IBM QRadar

  • It allows us to have visibility to potential problems both on premise and in the cloud which was key as we have become a hybrid consumer.
  • It has automated monitoring which has allowed us to see threats faster and also allowed us to be proactive.
  • By having over 20,000 employees, QRadar has also allowed us to be aware of internal threats that are brought into the company by unsuspecting employees.
Anonymous | TrustRadius Reviewer

Cons

Darktrace

  • False positives. Darktrace uses "AI" to create its alerts for "unusual" or "malicious" activity. It is very common to see an alert for completely benign and normal device behavior - PC tries to print for the first time in a while, for example.
  • Antigena actions. To some extent, this is a continuation of the previous point. Darktrace can break the network connectivity of the suspected device automatically. The excessive number of false positives makes administrators reluctant to use this feature, though. Also, the default Antigena actions are not relevant to real-world problems as I saw them in my experience with Darktrace.
Anonymous | TrustRadius Reviewer

IBM QRadar

  • There is a steep learning curve compared to other platforms. Qradar is incredibly powerful but does require some homework.
  • There is a glaring lack of threat feed utilization outside of STIXX/TAXII which remains very limited at this time.
  • May require a considerable amount of tuning during deployment with very little "out of the box" offense information.
Anonymous | TrustRadius Reviewer

Support

Darktrace

Darktrace 9.5
Based on 2 answers
Any time I have had any issue with Darktrace, I've been able to contact an engineer through their support desk, and I have always had a very speedy response. Even when the issue has been caused by something outside of the Darktrace devices, they have still been very keen to try to help and identify what the problem was. The customer portal also has a large number of videos and guides that you can use to educate yourself on the product
Anonymous | TrustRadius Reviewer

IBM QRadar

IBM QRadar 8.5
Based on 4 answers
I've had many issues with QRadar, and the support would hear and respond to my question all the time (more so than in the case of IBM Resilient support). They were very quick to respond, were helpful, and provided remote access.
larbi belmiloud | TrustRadius Reviewer

Alternatives Considered

Darktrace

We have not evaluated others as they seem to be in their own class.
Anonymous | TrustRadius Reviewer

IBM QRadar

Splunk Enterprise Security I've found is the easiest of all major SIEM's to deploy due to its event normalization capabilities. It lags behind QRadar in event correlation but is better in user GUI customization. One issue where QRadar beats it is in cost. Splunk starts off cheap, but as you expand (due to it's licensing model), it quickly becomes very expensive. It is the monster that keeps on feeding.
Douglas Concepcion | TrustRadius Reviewer

Return on Investment

Darktrace

  • We had an ROI just during the POC. DarkTrace helped us identify a ransomware attack and we stopped it before it happened.
  • The weekly reports more than pay for itself within the first few months.
  • The powerful search capability helps us solve problems where other solutions fall short.
Anonymous | TrustRadius Reviewer

IBM QRadar

  • QRadar has helped us improve our rating when going through an IT audit.
  • It has allowed us to answer some security related contract questions much more positively when going through contract negotiation.
  • It helps us to protect our company and investors from Outside and Internal threats.
Anonymous | TrustRadius Reviewer

Pricing Details

Darktrace

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

IBM QRadar

General

Free Trial
Free/Freemium Version
Premium Consulting/Integration Services
Entry-level set up fee?
No

Rating Summary

Likelihood to Recommend

Darktrace
8.0
IBM QRadar
9.3

Support

Darktrace
9.5
IBM QRadar
8.5

Add comparison