IBM Security QRadar SIEM v7.4.3 (BYOL)
IBM Security | IBM Security QRadar SIEM v7.4.3 (BYOL)Linux/Unix, Red Hat Enterprise Linux RHEL-7.7 - 64-bit Amazon Machine Image (AMI)
Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
QRadar Review
What do you like best about the product?
Integrations with other products we own.
What do you dislike about the product?
Data Enrichment Methods & EPS Licensing & DSM Parsing
What problems is the product solving and how is that benefiting you?
Internet Related Events
- Leave a Comment |
- Mark review as helpful
Most Powerful tool and easy to operate.
What do you like best about the product?
A good SIEM tool, less complex. effective
What do you dislike about the product?
Some of the features need to be improved.
What problems is the product solving and how is that benefiting you?
SIEM helped with security and detected and prioritized those threats accurately.
Recommendations to others considering the product:
Easy to operate and less complex.
Good and easy way for log analysis and treat hunting
What do you like best about the product?
Treat hunting, logs analysis ,different tools integration
What do you dislike about the product?
No. Nothing all good will the tool .many companies already using in there security operational centres
What problems is the product solving and how is that benefiting you?
Treat hunting,Malware identify,dashboard creations alert generation.access and compromised system issues ,phishing emails logs Ised in Resolving SOC Issues
Recommendations to others considering the product:
Good one used
Best SIEM
What do you like best about the product?
Qradar give the bird eye of network .Recently I have intregrate Cloudflare WAF with Qradar which allow real time monitoring of web server.
What do you dislike about the product?
Qrdar have some bugs which make trouble while integration log source.
What problems is the product solving and how is that benefiting you?
Web seever issue like internal server error 500 , file directory blocking malicious ip.
Easy to use SIEM tool
What do you like best about the product?
The best thing about this tool is it's easy usability in terms of UI, Search queries, result display.
What do you dislike about the product?
There's not really much to dislike except maybe the fact that it could be tiny bit slow sometimes. But that's not a recurring or major issue.
What problems is the product solving and how is that benefiting you?
I am using it to search for logs related to the security incidents in our environment. The quick search queries are very helpful.
Recommendations to others considering the product:
Go for it. It's easy to implement and use.
Digital Enterprise Architect
What do you like best about the product?
Good SIEM solution provide indepth view to network issues
What do you dislike about the product?
Difficulty to get deployed with the sensors
What problems is the product solving and how is that benefiting you?
Netowrk insight view
A SIEM and much more
What do you like best about the product?
One of the most complete SIEMs that allows integrations with multiple elements in a simple way.
What do you dislike about the product?
The way to quote is complicated and can make the solution too expensive.
What problems is the product solving and how is that benefiting you?
It allows you to review the events and obtain the offenses in a simple way and have a total vision of what is happening on the network. In addition to allowing modeling of user behavior.
Recommendations to others considering the product:
Do not think that it will be a more expensive solution than the others, surely there is an architecture capable of being competitive.
Good to have but not something which can be relied upon for 360 degree coverage
What do you like best about the product?
Multiple in-built apps which can be downloaded for multiple tasks like integration of different tools(only what is supported by Qradar) , compliance reports etc.
What do you dislike about the product?
Complexity in integration of new log sources.
Need to be very careful while running searches, if multiple personnel's are doing the search at the same time, then things get stuck up at times and ultimately it leads to cancellation of respective searches.
Complexity in report creation.
Need to be very careful while running searches, if multiple personnel's are doing the search at the same time, then things get stuck up at times and ultimately it leads to cancellation of respective searches.
Complexity in report creation.
What problems is the product solving and how is that benefiting you?
Reliable to check on the data as per the integrated log sources as and when needed.
Rules work as they are expected to work ( fine-tuning has to be made on regular basis , based on the exceptions)
Rules work as they are expected to work ( fine-tuning has to be made on regular basis , based on the exceptions)
Recommendations to others considering the product:
Get it if you want to use it as a good data collection tool
Use it if you are looking for something from reporting,search purposes.
Will recommend to go with UEBA solutions for next level analytics as SIEM will only work on the rules and not on the user's behavior
Use it if you are looking for something from reporting,search purposes.
Will recommend to go with UEBA solutions for next level analytics as SIEM will only work on the rules and not on the user's behavior
IBM Q-Radar
What do you like best about the product?
Integration with Identity and Access Management Tools
It is easy to deploy than most other SIEMs.
It is easy to deploy than most other SIEMs.
What do you dislike about the product?
Not User friendly than most of the other SIEMs I have used.
What problems is the product solving and how is that benefiting you?
Insider threats caused by internal employees.
User Behavior analytics.
User Behavior analytics.
Recommendations to others considering the product:
A solid SIEM solution to implement in enterprise companies.
Qradar Review
What do you like best about the product?
Incident Alerts need to be sorted in better way , reading logs from other system sometimes need a lot of parsing
What do you dislike about the product?
Vulnerability Assessment need to be enhance
What problems is the product solving and how is that benefiting you?
centralized log management for all logs
showing 191 - 200