Sanjib kumar D.
SD
Information Technology Security Specialist
Small-Business (50 or fewer emp.)
"Time Tested Enterprise SIEM with Powerful Integration, Custom Rules, and Automation"
4.5/5
What do you like best about IBM QRadar SIEM?

We can integrate events, flows, and vulnerability data, correlate information from different security controls, create our own rules and building blocks, and automate responses. It also offers a solid range of built-in DSMs, so integrating standard technologies is relatively straightforward, while custom log sources can still be handled when needed.

The UI is mature, and the team is working hard to modernize it. QRadar also requires proper sizing, tuning, and engineering to achieve the best performance and ROI. Overall, I see it as a mature enterprise SIEM that gives a SOC team a lot of control over detection, investigation, and response. Review collected by and hosted on G2.com.

What do you dislike about IBM QRadar SIEM?

The current licensing is mainly based on EPS. It would be beneficial to also offer a log-volume-based licensing model or greater flexibility.

For each device type, QRadar should also provide a ready-made content pack containing recommended use cases, key fields, event IDs, rules, and building blocks. Review collected by and hosted on G2.com.

See what 285 reviewers think of IBM QRadar SIEM

4.4 out of 5 · Verified reviews from real users

Read all reviews