Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Feedback on QRadar
What do you like best about the product?
It gives us accurate results and save us spending time in False positives
What do you dislike about the product?
Unable to analyse the past logs in the Histories
What problems is the product solving and how is that benefiting you?
Man Power
Recommendations to others considering the product:
Need more knowledge Based Articles.
- Leave a Comment |
- Mark review as helpful
Easy, fast, simple, stable, and the best
What do you like best about the product?
Provides real-time visibility, Produces detailed data access and user activity reports
What do you dislike about the product?
For now I don't have some thing that I don't like
What problems is the product solving and how is that benefiting you?
Real-time visibility, security analyst investigations
QRadar is a more aesthetic and intuitive siem, it can be very effective if it is set up correctly.
What do you like best about the product?
API can be configured to pull logs from almost anything
What do you dislike about the product?
There is little assistance in the initial configuration of the siem. A more tailored approach or dedicated team would reduce the internal overhead for clients.
What problems is the product solving and how is that benefiting you?
All of the data you need is available in one place.
Recommendations to others considering the product:
QRadar is a good solution for larger organizations.
User Friendly Interface of Qradar
What do you like best about the product?
Qradar providing the ease of use for analyst and administrator as well. User friendly interface helps to easilu configure new use cases as well search for events is easy as compared to other SIEM. Qradar also offer Jflow and Qflow to analyze the traffic flows.
What do you dislike about the product?
Customizing features having some limits.
What problems is the product solving and how is that benefiting you?
Its a SIEM, to analyze and investigate suspicious traffic.
Single pane security solution
What do you like best about the product?
It comes with a hybrid strategy that really helped us to integrate our multi could as well as on premise infrastructure with it for seamless security vulnerabilities monitoring.
What do you dislike about the product?
The integration process with Azure is bit messy.
What problems is the product solving and how is that benefiting you?
Malicious traffic, DDoS Threat detection, Admin user vulnerability.
Complete SIEM solution
What do you like best about the product?
Huge variety of integrations available with multiple mechanisms
What do you dislike about the product?
Visibility of data is not really good in finding the context of offenses
What problems is the product solving and how is that benefiting you?
Compliance
Correlation
Visibility on every Security Control
Correlation
Visibility on every Security Control
Recommendations to others considering the product:
A complete SIEM solution with multiple integrations and apps available to integrate but at the cost of less graphical context and visibility
All in one siem tool
What do you like best about the product?
Log Sources - QRadar support various range of log sources. Also we can customize and create custom log sources
What do you dislike about the product?
It would be good if the program allowed certain profiles to only see certain customer information
What problems is the product solving and how is that benefiting you?
Increased security of the company
IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
What do you like best about the product?
I like how it integrates TI with SIEM Solution, so it will make it as a single dashboard.
The visualization looks great, the automation seems great.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
The visualization looks great, the automation seems great.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
What do you dislike about the product?
It needs more information for the integration part, Splunk provides it with their apps, for example if you want to integrate splunk with any solution such as Cisco ISE, there's a document for it.
So.. documentation.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
So.. documentation.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
What problems is the product solving and how is that benefiting you?
I'm a person who likes to read a comprehensive document.IBM QRadar seems to be it.IBM QRadar seems to be it.IBM QRadar seems to be it.
As I work as a TI person and in SOC team, adding them both in a single solution made it great for me.
As I work as a TI person and in SOC team, adding them both in a single solution made it great for me.
Recommendations to others considering the product:
Look for the documents and how it is integrated with your other existing solution first.
Then contact IBM for further consulting as it will definitely help you in that part.
IBM QRadar seems to be it.
IBM QRadar seems to be it.
IBM QRadar seems to be it.IBM QRadar seems to be it.
IBM QRadar seems to be it.
IBM QRadar seems to be it.
Then contact IBM for further consulting as it will definitely help you in that part.
IBM QRadar seems to be it.
IBM QRadar seems to be it.
IBM QRadar seems to be it.IBM QRadar seems to be it.
IBM QRadar seems to be it.
IBM QRadar seems to be it.
A good product at optimum cost
What do you like best about the product?
Ease of use to navigate. Correlation engine is good.
What do you dislike about the product?
Rule creating functionality is limited. You can only create rules as per specified template of QRadar. For you to create rule by yourself by writing some query you have to learn AQL.
If I have to learn AQL what is the point of QRadar rule template then. Why not allow rule creating using AQL only.
If I have to learn AQL what is the point of QRadar rule template then. Why not allow rule creating using AQL only.
What problems is the product solving and how is that benefiting you?
Problems are mainly w.r.t organisation compliance.
We have all the logs at a single place and thus helps in effective organization monitoring.
We have all the logs at a single place and thus helps in effective organization monitoring.
Recommendations to others considering the product:
It is a good product but considering changing times and cost involved you should consider a product which can house a datalake or data warehouse. It caters to a lot of your requirements. It can handle 2k EPS as well as 1 Lakh EPS.
IBM QRADAR
What do you like best about the product?
QRADAR provides excellent display of logs which is convenient for user to understand.
What do you dislike about the product?
IBM QRADAR certification is expensive for young professionals., there should be price cutting in it.
What problems is the product solving and how is that benefiting you?
I can save my infrastructure from outside cyber threats.
showing 341 - 350