TrustRadius: an HG Insights company

IBM Security QRadar SIEM vs. SolarWinds NetFlow Traffic Analyzer (NTA)

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    IBM Security QRadar SIEM

    Score8.9 out of 10
    N/AIBM Security QRadar is security information and event management (SIEM) Software.N/A

    SolarWinds NetFlow Traffic Analyzer (NTA)

    Score8.6 out of 10
    N/ASolarWinds Netflow Traffic Analyzer is a network monitoring tool within the broader SolarWinds ecosystem. It includes core traffic monitoring features, as well as customizable traffic reports and alerts.N/A
    Pricing
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Free Trial
    YesYes
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeOptional
    Additional Details
    More Pricing Information
    Community Pulse
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Considered Both Products
    IBM
    No answer on this topic
    SolarWinds
    Chose SolarWinds NetFlow Traffic Analyzer (NTA)
    The interface on SolarWinds is much better and the time to deploy is much faster with NTA than other products. The ability for junior staff to quickly pick up on the tool is outstanding and it seems to take less expertise to use this product. The output display is easy to …
    Incentivized
    Key User Insights
    Would buy again
    92%
    Would buy again
    67 Answers
    95%
    Would buy again
    42 Answers
    Delivers good value for the price
    97%
    Delivers good value for the price
    61 Answers
    95%
    Delivers good value for the price
    37 Answers
    Happy with the feature set
    96%
    Happy with the feature set
    70 Answers
    95%
    Happy with the feature set
    42 Answers
    Lived up to sales and marketing promises
    86%
    Lived up to sales and marketing promises
    38 Answers
    95%
    Lived up to sales and marketing promises
    36 Answers
    Implementation went as expected
    94%
    Implementation went as expected
    59 Answers
    88%
    Implementation went as expected
    37 Answers
    Features
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of IBM Security QRadar SIEM and SolarWinds NetFlow Traffic Analyzer (NTA)
    Feature
    IBM Security QRadar SIEM
    8.5
    69 Ratings
    7% above category average
    SolarWinds NetFlow Traffic Analyzer (NTA)
    -
    Ratings
    Centralized event and log data collection9.927 Ratings00 Ratings
    Correlation8.669 Ratings00 Ratings
    Event and log normalization/management9.527 Ratings00 Ratings
    Deployment flexibility7.827 Ratings00 Ratings
    Integration with Identity and Access Management Tools8.965 Ratings00 Ratings
    Custom dashboards and workspaces7.569 Ratings00 Ratings
    Host and network-based intrusion detection9.725 Ratings00 Ratings
    Data integration/API management9.07 Ratings00 Ratings
    Behavioral analytics and baselining7.648 Ratings00 Ratings
    Rules-based and algorithmic detection thresholds8.049 Ratings00 Ratings
    Response orchestration and automation7.75 Ratings00 Ratings
    Reporting and compliance management7.947 Ratings00 Ratings
    Incident indexing/searching8.97 Ratings00 Ratings
    Best Alternatives
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    Sumo Logic
    Score8.9 out of 10
    Darktrace
    Score8.3 out of 10
    Enterprises
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    Darktrace
    Score8.3 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Likelihood to Recommend
    8.6
    (89 ratings)
    9.0
    (62 ratings)
    Likelihood to Renew
    8.8
    (5 ratings)
    -
    (0 ratings)
    Usability
    8.0
    (2 ratings)
    10.0
    (11 ratings)
    Availability
    9.0
    (1 ratings)
    -
    (0 ratings)
    Performance
    9.0
    (1 ratings)
    -
    (0 ratings)
    Support Rating
    8.1
    (62 ratings)
    8.0
    (49 ratings)
    In-Person Training
    9.0
    (1 ratings)
    -
    (0 ratings)
    Online Training
    9.0
    (1 ratings)
    8.2
    (1 ratings)
    Implementation Rating
    8.0
    (1 ratings)
    -
    (0 ratings)
    Configurability
    8.0
    (1 ratings)
    -
    (0 ratings)
    Contract Terms and Pricing Model
    9.0
    (1 ratings)
    -
    (0 ratings)
    Ease of integration
    8.1
    (58 ratings)
    -
    (0 ratings)
    Product Scalability
    8.0
    (1 ratings)
    -
    (0 ratings)
    Professional Services
    10.0
    (1 ratings)
    -
    (0 ratings)
    Vendor post-sale
    9.0
    (1 ratings)
    8.2
    (1 ratings)
    Vendor pre-sale
    9.0
    (1 ratings)
    9.1
    (1 ratings)
    User Testimonials
    IBM Security QRadar SIEMSolarWinds NetFlow Traffic Analyzer (NTA)
    Likelihood to Recommend
    IBM
    I would only recommend IBM Security QRadar SIEM in a few situations. For one, it's very easy to setup and use if all your log sources are generic from known vendors. It's also significantly cheaper than Splunk, which is nice if you're trying to save money or be more efficient. I would not recommend IBM Security QRadar SIEM for environments with a lot of custom logs and complicated detection requirements.
    Incentivized
    Read full review
    SolarWinds
    We use and depend on it for status state of our network gear, switches and routers. It does an excellent job of getting you the details you need to confirm all devices and products are working at the level needed. At times, it does tend to flag network switch ports and/or switches themselves as exceeding their rated capacity when frequently it was a quick blip of high traffic due to downloads, or uploads causing the max'ing of the device. Again, you can adjust the settings but then you adjust it too high and miss real activity. It can become nuisance alerting when you tend to then ignore
    Incentivized
    Read full review
    Pros
    IBM
    • Enables identification and prioritization of vulnerabilities in IT infrastructure for corrective action.
    • Facilitates security incident investigation and forensic analysis.
    • Provides a real-time view of security events, enabling immediate incident response.
    • Can integrate with external threat intelligence sources to enrich data and improve threat detection.
    • Enables the generation of detailed and customized reports.
    Incentivized
    Read full review
    SolarWinds
    • The level of customization possible with Network Bandwidth Analyzer is very valuable. Rather than being stuck with a "one-size-fits-all" presentation, an administrator can easily create customized views, reports, and alerts so that users can have a more tailored view of the data provided by Network Bandwidth Analyzer. This has the effect of making the tool more attractive to the end user.
    • The NetFlow Traffic Analyzer piece of Network Bandwidth Analyzer provides the details on bandwidth usage on the network. More than knowing how much bandwidth is being used, one is provided with detailed information on how that bandwidth is being used. This provides invaluable information for capacity planning and even certain forensic tasks faced by the network engineer.
    • The ability to produce network maps provides an easy way to create an attractive and functional NOC/SOC view of the entire network. Both technician and the occasional passerby can quickly determine if there are issues to be addressed. The ability to customize a map with background images and custom icons and stencils can make these maps really pop.
    Incentivized
    Read full review
    Cons
    IBM
    • Need to spend more time configuring the system to properly interpret and normalize different type of data collected from multiple resources.
    • While Rule creation QRadar uses that rules to detect security threats and generate alerts, but to creating and managing rules is bit complex & tedious work to complete.
    • IBM Security QRadar SIEM is excellent in handling large & complex systems that requires in-depth knowledge and extensive training to configure and maintain the system which includes upgrading, optimization of performance & issue troubleshooting.
    Incentivized
    Read full review
    SolarWinds
    • The ability to intuitively and quickly serve up specified information up to a dashboard for general “public” consumption, that cycles through several pages of information.
    • The ability to intuitively set up alerting on bandwidth levels, instead of having to dig through all types of alerts available to find the one needed.
    • Provide a pricing model based on different support levels: if I want only available update installations, don’t make me pay the same amount as those wanting full support.
    Incentivized
    Read full review
    Likelihood to Renew
    IBM
    QRadar is an established and stable product, we have been using it for many years and want to continue to focus on it. Anyone who has used the product and knows it knows how reliable it is and how it facilitates continuous monitoring of threats from outside and inside. it is an exceptional product that is very useful for us.
    Incentivized
    Read full review
    SolarWinds
    No answers on this topic
    Usability
    IBM
    As a grade I give 8 as QRadar is not easy to learn. It requires some time to master it. It also needs a team of people actively working on the product. Once you learn to use it the software works very well and it is easy to correlate and understand detected threats. It only takes time to learn how to use it well and configure it properly.
    Incentivized
    Read full review
    SolarWinds
    As far as rating for usability is concerned I would give 10/10 as NTA is very easy to use. All you need to do is install that module and ask network Team to configure the Netflow towards Server IP. [The] rest is pre-configured and reports are pre-built. Moment you receive the flows from Network all you will have is information about traffic.
    Incentivized
    Read full review
    Support Rating
    IBM
    Customer support is Good of IBM, While Using IBM QRadar its deployment is to slow and suddenly stop working and crashed we have contacted IBM Support and Rised a Ticket within a few minute we get call back from customer support and Query Resolved by them Fast And Rapid Support of Ibm
    Incentivized
    Read full review
    SolarWinds
    I know we could probably pay for it, but it would be nice if we could get to a tier 2 technician faster. Spending a couple of hours on the phone with the level 1 technician, when we have already tried the troubleshooting they are walking us through, is just a waste of time.
    Incentivized
    Read full review
    In-Person Training
    IBM
    The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
    Incentivized
    Read full review
    SolarWinds
    No answers on this topic
    Online Training
    IBM
    The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
    Incentivized
    Read full review
    SolarWinds
    The training offered by SolarWinds is some of the best out there. They have several different videos that go into great detail from initial setup to advanced configurations. In addition to the view at your own pace video, they also have live training for customers that focus on a single product and you can ask questions with the folks who develop the software. I have had good success with their live sessions and getting questions answered.
    Incentivized
    Read full review
    Implementation Rating
    IBM
    Initial patience is required to learn how to use the product, and it takes a dedicated team to use it. One person is not enough, and it's not enough to just set it up and check it once in a while. It has to be used daily and kept under control to be used effectively
    Incentivized
    Read full review
    SolarWinds
    No answers on this topic
    Alternatives Considered
    IBM
    IBM Qradar takes the best from its competitors. Reliable and stable but sometimes very expensive, the SIEM from IBM offers a wide range of scenarios in which the customers can suite and size their own infrastructures. IBM Qradar doesn't really needs to stack up againt its competitors because it already sets an example in the SIEM world.
    Incentivized
    Read full review
    SolarWinds
    SolarWinds NetFlow Traffic Analyzer compared to Wireshark and PRTG Network Monitor beats it by just the simple interface. Though all are manual setup, NTA takes it a step further with graphs and reports that analyze the data for you. In comparing to Extrahop from a bandwidth comparison, Extrahop wins but Extrahop is a lot more than just a bandwidth monitoring and cost.
    Incentivized
    Read full review
    Return on Investment
    IBM
    • Offense investigation was really helped in tackling the incidents. It was accurate and brief
    • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
    • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
    Incentivized
    Read full review
    SolarWinds
    • Be prepared to answer lots of questions. When people see the data in NTA they are going to want to know why App A is talking to App B. Be ready to explain!
    • Hand the keys to the NTA kingdom to the network team. They will thank you. Everyone wants to have friends on the network team, right?
    • Be prepared to invest in some significant compute and storage performance to keep up with your NTA monitoring
    • Running the latest firmware for your network gear is (often) required to take advantage of all the flow-monitoring. You upgrade regularly, right??
    Incentivized
    Read full review
    ScreenShots

    IBM Security QRadar SIEM Screenshots

    Screenshot of QRadar SIEM Cloud native- Threat intelligence preview