IBM Qradar SIEM: Unraveling the Cybersecurity Enigma!
August 03, 2023

IBM Qradar SIEM: Unraveling the Cybersecurity Enigma!

Anonymous | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Software Version

Other

Modules Used

  • SIEM
  • SOAR

Overall Satisfaction with IBM Security QRadar SIEM

The IBM QRadar provides quiet robust security incident and event manager. It's functionalities including CRE, tenant management is also very good and functional. The event collector and processor works exceptionally. Also, the X-force threat intel helps to detect and mitigate potential threats in a good manner. The interface is user friendly and allows analysts to analyse the alerts in more efficient manner. The UBA also works as per the expectations and allows to monitor insider threats very efficiently.But we expect more development with the integration of Qradar with various 3rd party tools for example EDR.As a MSSP sometimes it is necessary to put the client demands on front while deploying such powerful tools and integrating it with the 3rd party ones. In conclusion, IBM QRadar SIEM has become an indispensable part of our cybersecurity arsenal. Its sophisticated threat detection, user-friendly interface, and seamless integrations have significantly improved our security operations. We highly recommend IBM QRadar SIEM to any organization looking to enhance their cybersecurity posture and gain better control over their network security.,
  • Log Analysis
  • Log collection
  • Offense investigation
  • User behaviour detection
  • Integration with 3rd party tools including EDRs
  • Syslog integration with some of the latest network devices
  • Interface efficiency
  • Offense investigation was really helped in tackling the incidents. It was accurate and brief
  • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
  • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
We do face issue while integrating it with the existing tools like EDR our clients has. Some of them are not listed on the Qradar standar integration platform.
As a part of core security service provider, we could not stand with the tools that are used as a generic data processor. The compliance, log reading and events are well managed in QRadar compared to other tools

Do you think IBM Security QRadar SIEM delivers good value for the price?

Yes

Are you happy with IBM Security QRadar SIEM's feature set?

Yes

Did IBM Security QRadar SIEM live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of IBM Security QRadar SIEM go as expected?

Yes

Would you buy IBM Security QRadar SIEM again?

Yes

As a MSSP for healthcare and banking sector we use the QRadar as a pilot project for investigating security events and incidents. But for in-house and small environment it's not much suitable as a whole.

IBM Security QRadar SIEM Feature Ratings

Correlation
7
Integration with Identity and Access Management Tools
10
Custom dashboards and workspaces
9
Behavioral analytics and baselining
8
Rules-based and algorithmic detection thresholds
8
Reporting and compliance management
9