Notifications
Clear all
Topic starter
30/07/2026 2:25 am
We're moving to a microservices setup and our k8s clusters are generating a ton of logs and events. My team's been told we need a SIEM, and QRadar keeps coming up.
But from what I've seen with tools like Salesforce and Zendesk, enterprise platforms often struggle with modern, dynamic infrastructure. Is QRadar actually good at ingesting and correlating logs from containers, k8s control plane, and cloud APIs without constant manual tuning?
Specifically:
* Does it handle ephemeral IPs and pod labels natively?
* What's the real effort to get actionable alerts, not just raw log storage?
* Are there better options built for this from the ground up?