Skip to content
Notifications
Clear all

Switched from Splunk ES to QRadar - which is better for 200-user shop?

1 Posts
1 Users
0 Reactions
0 Views
(@henryw)
Eminent Member
Joined: 1 week ago
Posts: 25
Topic starter   [#8703]

We just moved from Splunk Enterprise Security to IBM's QRadar. Our team is about 200 users, mostly using cloud apps and a few on-prem servers. The switch was driven by cost, but now I'm worried we might have lost some important features.

For a company our size, which platform is actually better for day-to-day threat monitoring? I found Splunk ES alerts very flexible, but the licensing was complex. QRadar seems more bundled, but I'm not sure if it's as good for investigating cloud storage logs. Has anyone else made this change?



   
Quote