A SIEM that works
July 21, 2021

A SIEM that works

Ronald Barrett | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with IBM Security QRadar SIEM

This is our enterprise-wide solution for SIEM. We run this in our IT department and send many different application logs to the SIEM. We use the IBM QRadar tool as one of the applications we display on our 6x6 SOC. The application is fundamental to our security posture, we track log-in failures, VPN connections, lateral movement, and other key pieces of information that we deem important to cybersecurity.
  • Ingest logs from other application
  • Clean graphical displays of key security metrics
  • Filter data events
  • High end analytics
  • Correlation of data events across disparate applications
  • The tool needs a collaboration feature like an internal chat tool
  • Pricing model is very high
  • Pricing structure could be simplified
  • Enhancements could be faster
  • Our organization has been able to expand its security portfolio based on the implementation of IBM QRadar.
  • We have successfully used the tool to identify when others are inspecting our network and put plans in place to address situations pre-emptively.
  • The annual cost is worth the pay, but I would like to see pricing model changes.
IBM QRadar is the best SIEM in its class. We looked at Splunk, but you need a full time person to manage the tool. When we last looked at Splunk it had an enormous overhead cost associated with it.

Do you think IBM Security QRadar SIEM delivers good value for the price?

Yes

Are you happy with IBM Security QRadar SIEM's feature set?

Yes

Did IBM Security QRadar SIEM live up to sales and marketing promises?

Yes

Did implementation of IBM Security QRadar SIEM go as expected?

Yes

Would you buy IBM Security QRadar SIEM again?

Yes

This is by far the best SIEM on the market. The tool does exactly what it is designed to do and is really good at it. The tool is fantastic at acting as the front end for all of your security stack. We use it constantly throughout the day.

IBM Security QRadar SIEM Feature Ratings

Centralized event and log data collection
10
Correlation
10
Event and log normalization/management
10
Deployment flexibility
9
Integration with Identity and Access Management Tools
8
Custom dashboards and workspaces
9
Host and network-based intrusion detection
7
Log retention
7
Data integration/API management
8
Behavioral analytics and baselining
8
Rules-based and algorithmic detection thresholds
8
Response orchestration and automation
8
Reporting and compliance management
9
Incident indexing/searching
8