
We can integrate events, flows, and vulnerability data, correlate information from different security controls, create our own rules and building blocks, and automate responses. It also offers a solid range of built-in DSMs, so integrating standard technologies is relatively straightforward, while custom log sources can still be handled when needed.
The UI is mature, and the team is working hard to modernize it. QRadar also requires proper sizing, tuning, and engineering to achieve the best performance and ROI. Overall, I see it as a mature enterprise SIEM that gives a SOC team a lot of control over detection, investigation, and response. Review collected by and hosted on G2.com.
The current licensing is mainly based on EPS. It would be beneficial to also offer a log-volume-based licensing model or greater flexibility.
For each device type, QRadar should also provide a ready-made content pack containing recommended use cases, key fields, event IDs, rules, and building blocks. Review collected by and hosted on G2.com.