Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Platform is so Good
What do you like best about the product?
Secruity and Platform from IBM is important thing I like about QRadar SOAR
What do you dislike about the product?
sofar nothing, I have been using partially on the Platform
What problems is the product solving and how is that benefiting you?
Providing real-time insights that enhance the detection and remediation of threats.
- Leave a Comment |
- Mark review as helpful
Qradar - A Complete SIEM Platform
What do you like best about the product?
Qradar is easy to handle tool. Qradar provides a good log or flow search experience. It is easy to handle the offenses as correlation works great and we are able to see any previous offense from the same attacker.
What do you dislike about the product?
There is only one thing which I dislike about Qradar is its dashboard experience. Qradar has very old fashioned dashboard. They added pulse for better dashboards but they discontinued it.
What problems is the product solving and how is that benefiting you?
Qradar is a complete SIEM tool platform which provides great correlation of the events so that we can get concrete offenses rather than false positives. Multiple search filters allow us to get data more accurately and precisely. Using its UEBA we can generate offenses related to user or behaviour anomalies.
My experience with Qradar is awesome and I would definitely recommend to everyone
What do you like best about the product?
Like It detect almost every risk that a endpoint has.
What do you dislike about the product?
It's training material are little confusing and hard
What problems is the product solving and how is that benefiting you?
It detect almost every risk a specific endpoint has and it got me narrow my Defence surface.
QRadar EDR
What do you like best about the product?
I like the Dashboard and the way it's present the overall incident details.
It have the capability to detect the malicious behavior, easy to manage the policies and add exception.
It have the capability to detect the malicious behavior, easy to manage the policies and add exception.
What do you dislike about the product?
I feel it's little bit slow some time while opening incident details. It can be fixed I think in future versions.
What problems is the product solving and how is that benefiting you?
Its serving the purpose of AV, also help us to get secure from Endpoint attacks
It's quite efficient to detect the threats.
It's quite efficient to detect the threats.
IBM SOAR Review
What do you like best about the product?
IBM Soar console is very easy to use,we can create any playbook in a very fast approach and if in case we need oem support just raised a ticket and you find almost in the day we have resolution.
What do you dislike about the product?
Some time all playbooks not going in the same direction for which we have configured to acheive the goal.
What problems is the product solving and how is that benefiting you?
Identify the attacks and doing automation base analysis and then blocking the same iocs.
Best SIEM tool I've worked with for complex environments
What do you like best about the product?
- AQL language have the same syntax as SQL, making it easy and fast to create fine grained searches;
- AQL also makes it easy to create Dashboards, really helpful to our clients;
- Rule creation is easy enough to understand and implement;
- Integration with IBM X-Force is fundamental to our operation;
- New UI's visual builder makes it super easy to search for events and flows;
- Easy to setup multiple domains for everyday use in multiple environments;
- IBM's employees provide great support;
- AQL also makes it easy to create Dashboards, really helpful to our clients;
- Rule creation is easy enough to understand and implement;
- Integration with IBM X-Force is fundamental to our operation;
- New UI's visual builder makes it super easy to search for events and flows;
- Easy to setup multiple domains for everyday use in multiple environments;
- IBM's employees provide great support;
What do you dislike about the product?
- New UI (QRadar UI (v2.32.0)) have less features than the old one, we can't search for offenses as easily: we can't search for offenses that started in an specific date, only predefined timeranges (hour, 12h, 7d, 30d etc);
- Pulse only allows to edit a dashboard if you're the one who created it. All admins should be allowed to edit them;
- We can't create notes on an offense from the new UI, notes are really helpful;
- Report building is terrible, clumsy and slow, and not a lot of customization;
- Pulse only allows to edit a dashboard if you're the one who created it. All admins should be allowed to edit them;
- We can't create notes on an offense from the new UI, notes are really helpful;
- Report building is terrible, clumsy and slow, and not a lot of customization;
What problems is the product solving and how is that benefiting you?
QRadar was our SIEM choice for it's leading position in the industry, it's easy to setup new Log Sources and it's documentation is a great resourse, although sometimes difficult to find (like API and AQL docs). We're using it to sell our SOC as a Service solution and all clients are satisfied with the tool.
Experience with Qradar
What do you like best about the product?
Easy to configure and setup Qradar. User friendly and flexible to analyse the detections.
What do you dislike about the product?
No drawbacks observed since I'm exploring the tool more.
What problems is the product solving and how is that benefiting you?
Making my work less by automated detection and easy to analyse.
Qradar Working experience in corporate
What do you like best about the product?
Dashbord and Layout for understanding for anynon tech user.
What do you dislike about the product?
No same time when the networking traffic is incress that time This tools is not working proparly.
What problems is the product solving and how is that benefiting you?
When we identifying our cloud networking and security that time qradar is helping to in our organization for incressing our detection.
A must have SIEM tool - IBM Qradar
What do you like best about the product?
Qradar acts as a one stop solution to manage, correlate and investigate all the network, application events. The product makes it easy to remediate threats while maintaining the bottom line. IBM Qradar offers a vast insights of all the activities happening across our network. The tool also enables to identify the abnormalities in the user behaviour analytics. The eas of implementation and integration with other platforms is a feather in one's cap for Qradar.
What do you dislike about the product?
As a ardent customer of IBM Qradar for past five years, there is nothing to dislike about the product.
What problems is the product solving and how is that benefiting you?
The tool enables our organization to be more efficent in identifiying the abnormalities and act upon it before hand. IBM Qradar SIEM acts as a one place stop solution for our Security Operations team for everything right from monitoring to acting upon the offense.
QRadar Review by Security analyst
What do you like best about the product?
Ability to automate and variety of dashboards
What do you dislike about the product?
There are set of predefined detection rules but customising those to make it best suitable for our environment is a pain area
What problems is the product solving and how is that benefiting you?
Run time malware detection and file system alert, threat intelligence information is plus
showing 11 - 20