| Firing talent because of age is not so smart I think. Of course I don't know who they fire, etc. But I'm young, yeah, and I want to distance myself from IBM products. Why? I'v been setting IBM Tivoli/Spectrum protect to backup client computers and, ugh, is it ugly, unfriendly and complex piece of software. I'v also touched the server part. Maybe it's just me, the windows guy (but who loves scripting) and it is more appealing to linux-type guys. Then I got feedback from Linux team that they also don't love that product. They should do something about their products or product managers to be more appealing. After 1hr they will present IBM QRadar to us. Perhaps it will be a pretty presentation and so. I just wonder what's it under the hood, when sysadmins put their hands on it - any experiences someone can share? |
QRadar is a glorified syslog server with a query interface (bought by IBM in 2011, formerly developed by Q1 Labs, est 2001), and ... again the fact that Splunk is available (started 2 years after Q1 Labs), that the ELK stack is even mentioned in SIEM circles, that OSSIM an open source alternative is seen as more usable all just point to the conclusion that QRadar too is just salesware :/