IBM Qradar Review
January 03, 2024

IBM Qradar Review

Umair Javed | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Software Version

QRadar Advisor with Watson (legacy branding)

Modules Used

  • SIEM

Overall Satisfaction with IBM Security QRadar SIEM

In our organization we use Qradar for network monitoring been in the SOC Team We monitor logs evets and offences triggered. investigate them take action if required and closed them.
as we have integrated most of our sensitive servers in SIEM so it would help to monitor the activity going on these serves.
  • payload done great job to understand the events
  • the extension integrated in SIEM helps alot
  • offence investigation in siem much easier
  • things where i am facing issue is regex langue.
  • making rules and under standing logic also a difficult task
  • integration of any log source need to done in much easier way
  • the good thing of qradar is it easy to understandable
  • bad thing is that if your stuck while doing some thing you will not get to the point answer
  • improvement required regarding the support team.
i have given this rating this tool help me lay down a job for me and i want to understand and explore new thing revolving around it
regarding the support i wasn't satisficed enough because most of the time team did not respond quickly as required.
Qradar is on my top choice because I have hands-on experience on it. on qradar it is much easier to investigate in case of any incident happend.

Do you think IBM Security QRadar SIEM delivers good value for the price?

Yes

Are you happy with IBM Security QRadar SIEM's feature set?

Yes

Did IBM Security QRadar SIEM live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of IBM Security QRadar SIEM go as expected?

I wasn't involved with the implementation phase

Would you buy IBM Security QRadar SIEM again?

Yes

Trend Micro Vision One, Splunk Application Performance Monitoring (APM), Trend Micro Apex One
monitoring network traffic is much easier while having siem in your organization and the scenario where siem is less apricated is installing adding logs source making rules according to your desire or the last thing ibm support team not proving the good feedback on instant basis in case of any critical scenarios.

IBM Security QRadar SIEM Feature Ratings

Correlation
6
Integration with Identity and Access Management Tools
2
Custom dashboards and workspaces
4
Behavioral analytics and baselining
4
Rules-based and algorithmic detection thresholds
1