Evolving IBM's watsonx Assistant
Overall Satisfaction with IBM watsonx Assistant
Its been a long journey with the IBM QRadar and its new addon watsonx Assistant so i would like to have my long term feedback which includes streamlining of my support workflows of the incidents and offenses that has been triggered over the QRadar its been helping us by providing contextual and helpful insights while triaging any incident with provided steps recommendations which helps reducing time to mitigate the incident and helps with MITRE Mapping as watsonx Assistant fetches all the enrichments such as GEOIP, WHOis and MITRE TTPs
Pros
- Helps in reducing triage time of L1 Analyst
- Provides Threat intel enrichment
- Offers steps based on alert types
- Creating case notes and documentionns
Cons
- currently its been depending upon predefined workbooks which further requires tuning.
- Analysts especially at l1 and l2 levels now spend more time on complex investigations and remediation rather than looking out for basics and data gathering in terms of the eveidances and intels
Quickly analyzes the alert from the QRadar and enriches them with Threat intel and further helps in recommendations and remediation parts helping analyst to prioritize and respond more quicker.
Before analyst spent a lot of time working manually on each of the alerts that has been triggered over the offense board and took more time in pulling evidences from Threat intel checking MITRE attack mappings and deciding next steps now with the help of watsonx Assistant it's been all speeding up
Do you think IBM watsonx Orchestrate delivers good value for the price?
Yes
Are you happy with IBM watsonx Orchestrate's feature set?
Yes
Did IBM watsonx Orchestrate live up to sales and marketing promises?
Yes
Did implementation of IBM watsonx Orchestrate go as expected?
Yes
Would you buy IBM watsonx Orchestrate again?
Yes


Comments
Please log in to join the conversation