Likelihood to Recommend
As a SIEM tool for investigations, Exabeam is the best in class. The AI assigns numeric values to observed logs them presents high scores to the analyst in a simple dashboard. We can see what is a real threat and ignore so many false positives. Exabeam is the best SIEM was used from an alert fatigue perspective. The simple interface allows other teams not just InfoSec to utilize the tool; helpdesk for asset diagnoses, HR for staffing questions, etc.
Read full review
IBM Security QRadar SIEM is well suited in Large & Complex organization as it can handles large volumes of security data from various sources, which makes QRadar an ideal solution from which organizations monitor and manage security events centrally. Also its well suited in High-risk organizations where high level of regulatory compliance and sensitive data such as healthcare, finance, and government, may find QRadar a valuable tool for detecting and preventing security threats. QRadar is less suited where organizations require simple IT environment with limited budget.
Read full review Pros Fast search times, unlike other competing solutions. The ability for engineers to obtain access to the command line interface for troubleshooting, at least for on-premise deployments. License is suitable for organisations with lots of logs to ingest. Hardware required for on premise deployments is well supported. Read full review The tool scans the process and network vulnerability data to identify the security risks in the network. The tool performs in-depth network forensics and replays full network sessions. Gives a threat score and category to each identified IP address or URL, which helps us prioritize threats and offer better analysis. Read full review Cons More and better drop-down menus, some items in threat hunter require you know subsets. Less dashboards, combine AA and DL without having separate logins. More complete playbooks are already built out. You have the structure set up for templates like malware and phishing, go further and completely build them out from start to finish, most companies would just use them and not personalize their configurations. Quarterly health checkup diagnostics of systems sent out to users. Read full review Should onboard any type of data. Dashboarding and advanced queries like statistical analysis and ML features. Parsing and filter out. License model. Instead of java, could be written C to get more efficient and faster environment. Enrichment of data on data pipeline. Replication and loadbalancing on Datanodes and EventProcesssors. Read full review Likelihood to Renew
With the arrival of IBM Security QRadar SIEM at our company, we have a better vision of all the security needs that may arise, it is a very safe software to use that prevents threats from damaging our IT environment, it is impossible to change it for another software.
Read full review Usability
Exabeam is very good at processing lots of logs without excessive licensing costs. It has a professional support team that's very quick to resolve any issues and provides custom parsers quickly and enables our analysts to search vast data sets without having to wait long for results to be returned. The product is getting more mature with new features every major release.
Read full review Support Rating
Exabeam Fusion has so many diffferent out reach meetings, webinars, community virtual coffees, and events that you can always stay abreast of what if happening and get new ideas for use cases. Their support actually answers their phones and can respond in chat instantly. With our cloud deployment Exabeam support teams can instantly see our systems and help us.
Read full review
The response time may vary according to the number of complexity of the problems to be solved, in simple situations such as to solve some integration of all IBM modules or to manage and analyze data from other sources or products, it may be achieved in less than an hour, but if your problem is much more complicated, it may take a few days to solve your problems.
Read full review Alternatives Considered
IBM QRadar is way easier to deploy and use than the other SIEM tools. In literally hours you have a whole environment up and running. Also, QRadar comes with way more out-of-the-box parsers (called DSMs) than any other tool. Also, recently, QRadar released their app store, in which you can download extension packs for your QRadar, so you can easily deploy things such as User Behavior Analytics (UBA) and interactive dashboards
Read full review Return on Investment Reduced time to triage alerts. Reduced number of alerts which need escalation to senior tiers. The ability for analysts to quickly run playbooks for additional information and enrichment. Ability to retain data for longer periods for forensics purposes. Improved search performance compared with other SIEM solutions. Read full review QRadar has helped us improve our rating when going through an IT audit. It has allowed us to answer some security related contract questions much more positively when going through contract negotiation. It helps us to protect our company and investors from Outside and Internal threats. Read full review ScreenShots