No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2284569 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Real User
Top 10
Feb 18, 2024
Useful for infrastructure, application, and network monitoring
Pros and Cons
  • "The tool helps with infrastructure, application, and network monitoring."
  • "There are areas in IBM Security QRadar that could benefit from improvement. Its ability to customize knowledge for specific purposes could be enhanced. Also, it lacks clarity in presenting details. It is also difficult to see the reports."

What is our primary use case?

The tool helps with infrastructure, application, and network monitoring. 

What needs improvement?

There are areas in IBM Security QRadar that could benefit from improvement. Its ability to customize knowledge for specific purposes could be enhanced. Also, it lacks clarity in presenting details. It is also difficult to see the reports. 

For how long have I used the solution?

I have been using the product for a year. 

How are customer service and support?

The tool's technical support is good. 

Buyer's Guide
IBM Security QRadar
May 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.

How was the initial setup?

Implementing IBM Security QRadar is not overly complex. 

What's my experience with pricing, setup cost, and licensing?

The product is expensive. We have purchased the perpetual license, but we pay for the support. 

What other advice do I have?

I rate the tool a seven out of ten. It is a tough product. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Specialist​ at IT Specialist LLC
Reseller
Apr 16, 2023
Easy to deploy, and scalable, but the stability has room for improvement
Pros and Cons
  • "The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing."
  • "The solution is difficult to understand in the beginning and has complex management configurations that can be improved."

What is our primary use case?

Our clients who are implementing or trying to implement a Security Operations Center use the IBM QRadar SIEM solution. This solution helps automate incident processing and provides visibility into the incident management process.

What is most valuable?

The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing.

The integration of our customer's infrastructure with other security management systems, such as Active Directory, firewalls, and vulnerability management systems, is effective.

What needs improvement?

The solution is difficult to understand in the beginning and has complex management configurations that can be improved.

The stability has room for improvement.

The cost has room for improvement.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

I give the stability a seven out of ten. There is sometimes unexpected behavior within the logic of the playbook engine and features.

What do I think about the scalability of the solution?

I give the scalability an eight out of ten.

How are customer service and support?

We have had issues that were not resolved by technical support.

How would you rate customer service and support?

Neutral

How was the initial setup?

For the most part, the initial setup is straightforward and I give it a seven out of ten. The initial deployment and configuration require one month, followed by an additional 11 months of implementing various use cases and processes that need to be automated.

What's my experience with pricing, setup cost, and licensing?

I give the price of the solution a four out of ten. The solution comes with a high price tag, while some of the competitors provide identical functionality in their offerings at no extra cost.

What other advice do I have?

I give the solution a seven out of ten.

We have around 20 users.

The solution is of good quality and can be implemented successfully. However, in order to fully utilize its benefits, one must possess expertise in Python programming.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
IBM Security QRadar
May 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,311 professionals have used our research since 2012.
Khalid Majeed - PeerSpot reviewer
Cyber Security Consultant at Software Productivity Strategists, Inc. (SPS)
Consultant
Mar 29, 2023
Reliable with good technical support but needs better visualization
Pros and Cons
  • "The product can scale."
  • "The product can be a bit complex."

What is our primary use case?

We are implementors and implement this solution for our clients, who use it for analytics. 

What is most valuable?

It offers good machine learning. The analysis is very helpful. 

The user activity is effectively flagged. It can pinpoint strange activity. 

It is stable and reliable.

The product can scale.

Technical support is good. 

What needs improvement?

The product can be a bit complex. A lot of things, like visualization, could be better. It would help the customer gain a better understanding. 

For how long have I used the solution?

I've used the solution for five to six years. I've used it for a while now at this point. 

What do I think about the stability of the solution?

It is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. I'd rate the stability eight out of ten. 

What do I think about the scalability of the solution?

The solution is scalable. It can handle thousands of users or maybe even more. I'd rate the scalability nine out of ten. 

We mostly deal with small or medium enterprises. 

How are customer service and support?

Most of the time, technical support is helpful. I am satisfied with the level of service we receive. 

How would you rate customer service and support?

Positive

How was the initial setup?

It is easy to implement. I'd rate the ease of implementation seven out of ten. 

The deployment only takes no more than a few hours. There are configurations and fine-tuning that have to happen after that, and everything could take about a week. 

What about the implementation team?

As implementors, we can implement the solution for our clients. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. It's not expensive compared to other solutions. If you get the console and other licenses, you can easily use it with other QRadar solutions. 

What other advice do I have?

New clients should know that it does give good analytics and it will help them save time.

I'd rate the solution seven out of ten. It's a good product.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Bobby Sandeep - PeerSpot reviewer
Vice President - Technology & Managed Security Services at Valuepoint Systems
Real User
Jan 15, 2023
A simple and stable solution but the dashboards are old
Pros and Cons
  • "The simplicity of the solution is the best feature."
  • "The dashboards are all legacy and old."

What is most valuable?

The simplicity of the solution is the best feature.

What needs improvement?

The dashboards are all legacy and old. Their cloud support and the content available for cloud and containers are also minimal.

For how long have I used the solution?

We have been using this solution since 2019.

What do I think about the stability of the solution?

I rate the stability a nine out of ten.

What do I think about the scalability of the solution?

I rate the scalability an eight out of ten, and we have about 35 people using it.

How are customer service and support?

I rate the technical support a five out of ten. They need to improve their availability. They have global support, which means we need to wait longer for a response.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate the initial setup a seven out of ten, and it is deployed on-premises. The deployment took about four to six weeks, and we did it in-house.

What was our ROI?

We have seen an ROI.

What's my experience with pricing, setup cost, and licensing?

I rate the price a six out of ten, with ten being affordable and one being expensive. They recently changed their licensing model, and it's more complex.

What other advice do I have?

I rate this solution a six out of ten. Regarding advice, using this solution purely depends on the use case. If it meets your use case, then IBM QRadar is good, but other solutions like Securonix are much better.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Vice President & Country Head at Inspira Enterprise
Reseller
Aug 11, 2022
Excellent risk rating but could keep data longer
Pros and Cons
  • "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
  • "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
  • "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."
  • "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."

What is most valuable?

QRadar UBA's most valuable feature is the risk rating of users depending on their behavior.

What needs improvement?

QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month. In the next release, I would like to be able to do a historical search of user scores.

For how long have I used the solution?

I've been using QRadar UBA for two and a half years.

What do I think about the stability of the solution?

QRadar UBA is quite stable.

Which other solutions did I evaluate?

QRadar UBA's price is a little more than street price and could be reduced.

What other advice do I have?

I would rate QRadar UBA seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Ahmed Hossam - PeerSpot reviewer
SOC Analyst Tier 2 at IP Protocol INC
Real User
Jul 6, 2022
An AI-powered incident and risk analysis, triage and response tool with a user-friendly graphical interface
Pros and Cons
  • "I like the graphical interface. It's so good and easy."
  • "I like the graphical interface, it's so good and easy."
  • "Integration could be better. They should make it easy to integrate with other solutions."
  • "Integration could be better. They should make it easy to integrate with other solutions."

What is our primary use case?

First, I used the manual to learn, then I tried to merge it with my company's needs, and there weren't any problems.

What is most valuable?

I like the graphical interface. It's so good and easy.

What needs improvement?

Integration could be better. They should make it easy to integrate with other solutions. 

For how long have I used the solution?

I have been using IBM QRadar Advisor with Watson for three or four years.

What do I think about the stability of the solution?

IBM QRadar Advisor with Watson is a stable solution.

What do I think about the scalability of the solution?

I think IBM QRadar Advisor with Watson is scalable.

How are customer service and support?

We didn't use technical support as the community was very helpful.

How was the initial setup?

The initial setup was difficult the first time, but it got easier after that.

What's my experience with pricing, setup cost, and licensing?

I think my company pays for the license yearly.

What other advice do I have?

I would advise potential users to read the manual or the workbook before going forward with the deployment. Try to match the requirements with the company's needs to avoid facing issues in the future. But if you get stuck, you can always ask the community for help.

On a scale from one to ten, I would give IBM QRadar Advisor with Watson a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
reviewer1846212 - PeerSpot reviewer
IM Operations Manager at a tech services company with 1,001-5,000 employees
Real User
Apr 28, 2022
Simplified event quantity, scalable, but source data reports needed
Pros and Cons
  • "IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through."
  • "IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication, is very impressive given that we have hundreds of devices that send event logs through."
  • "IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features."
  • "The technical support from IBM Qradar could improve. I rate the support from IBM Qradar a two out of ten."

What is most valuable?

IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through.

What needs improvement?

IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features.

For how long have I used the solution?

I have been using IBM QRadar for approximately 10 years.

What do I think about the stability of the solution?

The stability of IBM Qradar is good.

What do I think about the scalability of the solution?

IBM Qradar is a scalable solution.

How are customer service and support?

The technical support from IBM Qradar could improve.

I rate the support from IBM Qradar a two out of ten.

How was the initial setup?

The initial setup of IBM Qradar is difficult, you need to know what you are doing to be able to complete the task. It is not easy.

We used three to four specialists to do the implementation depending on how many integration levels you're going to have. If you're managing the flows and going to be managing applications, logical access, patch management, vulnerability management then it can take more time and more people. It depends on the scale that you want to integrate. 

IBM Qradar doesn't come ready for plug and play, for your APIs, integration, and all the other elements you will need a person that knows how to do the IBM QRadar setup. From that perspective, you need to make sure that integration points to the license keys, for validation, and that can be a different challenge if it doesn't work.

What other advice do I have?

My advice to others is they have to have IBM Qradar set for purpose and it depends on the role that you see your SIEM solution playing in the company. If you're offering it as a service to other companies, or you're an IT service provider or security solution provider, then yes, you probably need an enterprise base that is scalable but not with smaller enterprises.

I do think the IoT component of IBM Qradar is lacking. IBM tried and IoT is not specifically aimed at only cameras or what I call physical access points, integration into what I call scale technology. They are areas that would depend on each business to map out what the requirements are. This is not a McAfee endpoint or a Symantec endpoint device that gives you an alert.

There is more competition and innovative application development in this area we've seen in the last few years.

I rate IBM Qradar a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1846212 - PeerSpot reviewer
IM Operations Manager at a tech services company with 1,001-5,000 employees
Real User
Apr 27, 2022
Reliable, suitable for large enterprises, but could be more user-friendly
Pros and Cons
  • "IBM QRadar Advisor with Watson is a stable solution."
  • "IBM QRadar Advisor with Watson is aligned with regards to what's happening in the public space in terms of the phishing attacks that we are seeing prevalent in the market, and the use cases are very practical, offering quite a bit of protection."
  • "IBM QRadar Advisor with Watson could be more user-friendly. You need some skills and understanding of what you're looking at, especially if you're going to draw down specific information."
  • "It is not a reporting tool. It is the worst possible tool to ever expect any reporting."

What is our primary use case?

IBM QRadar Advisor with Watson is aligned with regards to what's happening in the public space in terms of the Phishing attacks that we are seeing prevalent in the market. In the campaigns that which hackers are trying to obtain information, the use cases are very practical. The solution offers quite a bit of protection.  

What needs improvement?

IBM QRadar Advisor with Watson could be more user-friendly. You need some skills and understanding of what you're looking at, especially if you're going to draw down specific information.

Massive improvement is required in reporting. IBM QRadar Advisor with Watson is not a tool that is known for its reporting capability. It's a highly operational tool that you use for monitoring, you can sit and you can watch your alerts, whether it's flows or EPS, and you set up your playbooks directly. It is not a reporting tool. It is the worst possible tool to ever expect any reporting. It's unfortunate it's not a great reporting tool.

In a future release, there could be a bit more intelligence in terms of predictive accuracy and overall predictions. I haven't been too close in the last two, three, or four months, but I certainly would expect that their technology would be simplified to provide predictive analytics as opposed to retrospective looking back and analyzing past historic data.

For how long have I used the solution?

I have been using IBM QRadar Advisor with Watson for approximately 10 years.

What do I think about the stability of the solution?

IBM QRadar Advisor with Watson is a stable solution.

What do I think about the scalability of the solution?

IBM QRadar Advisor with Watson is best suited for large enterprises.

How are customer service and support?

The support from IBM is not great at all. They can offer much better aftermarket support. They don't respond in a timely manner and it's such a challenge to have IBM respond. You have to follow their due diligence process when logging a call on their portal, you need access to their portal, and you have to provide detailed logs, et cetera. If their problem is always about integration, they have to get to the vendors. They can always enhance their support.

I would rate the support from IBM QRadar Advisor with Watson a two out of five.

They do respond but it depends on many factors, such as urgency. When we had an issue with Microsoft integration it took us six weeks to have a solution to the problem.

How was the initial setup?

IBM QRadar Advisor with Watson's initial setup is not straightforward. You have to set up your network infrastructure, IP range, and firewalls, and make sure everything is secure. There's nothing easy about that.

What about the implementation team?

You need application and hardware leads, firewall administrators, network engineers, and server administrators to complete the implementation.

What other advice do I have?

My advice to others is to shop around because IBM QRadar Advisor with Watson is not for small enterprises, it's aimed at your larger environments that have a multitude of infrastructure and networks that are hybrid across different environments. It integrates into quite a few tools, such as your email system, and file systems. 

This tool is not for everybody. IBM doesn't have the sort of tool that helps a five, ten, or twenty user environment. This is not advisable to go and invest in the solution. There are other tools that you could possibly look at that do probably some of the functions in terms of monitoring your playbooks and integration points that are a little bit easier to map to. However, that is not a tool for every organization out there. The solution is targeting major enterprises.

I rate IBM QRadar Advisor with Watson a seven out of ten.

There are quite a few areas they could improve, such as they have a lot of technical manual configs and orchestration could be better.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2026
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.