IBM's Q1 Labs Leads Field of Eight Security Information and Event Management (SIEM) Vendors, According to New InformationWeek Reports Research

76% overall performance score puts IBM's security information and event management system in top spot, but Novell's SIEM (now owned by NetIQ) is a close second at 75%

Aug 22, 2012

SAN FRANCISCO, Aug. 22, 2012 /PRNewswire/ -- InformationWeek Reports (, a service provider for peer-based IT research and analysis, announced the release of its latest research report. IT Pro Ranking: SIEM encompasses analysis of results from InformationWeek's recent 2012 Security Information and Event Management Vendor Evaluation Survey and guides readers in selecting a SIEM system for their organizations. More than 320 business technology professionals who use or have used or evaluated security information and event management products in the past 12 months responded to this poll.

Research Summary:

InformationWeek asked SIEM users and evaluators to rate 17 products in two major categories: overall performance and SIEM-specific capabilities such as real-time alerts, search and log management. Eight received a sufficient number of responses to be rated: HP/ArcSight, IBM/Q1 Labs, NetIQ, Novell, Quest Software, Splunk, Symantec and Tripwire. We also looked at primary drivers for SIEM use, challenges that users face with these products and other aspects of SIEM operation.


  • 65% of our survey respondents say reliability is a very important factor when evaluating SIEM systems; the No. 2 criterion is performance, followed by flexibility.
  • 53% say application servers are a main source of event data.
  • 45% are currently using or have used or evaluated Symantec's SIEM system in the past 12 months, cited more than any other product. HP/ArcSight and Splunk are tied for second place with 15% each.
  • 34% cite building correlation rules as a main challenge vs. just 14% struggling with poor adoption among IT users.

The report author, Dean Francis, serves as an enterprise architect at technology solutions firm Fusion PPT.

For full access to the research data, members can download now:

"Compliance mandates and security best practices require that IT review event logs; it's 101 stuff," says Lorna Garey, content director of InformationWeek Reports. "But the sheer volume of security data can be overwhelming; our survey asks about 10 major event sources, from firewalls to SANs. To have any hope of spotting anomalies in even a moderately large network requires a SIEM system, and what better way to narrow the shopping list than to listen to what your peers think?"

For more information:
Art Wittmann    
VP & Managing Director, InformationWeek Reports

About InformationWeek Business Technology Network ( )

The InformationWeek Business Technology Network provides IT executives with unique analysis and tools that parallel their work flow—from defining and framing objectives through to the evaluation and recommendation of solutions. Anchored by InformationWeek, the multimedia powerhouse that looks across the enterprise, the network scales across the most critical technology categories with online properties like (security), (networking and communications) and BYTE (consumer technology). The network also provides focused content for key IT targets, such as CIOs, developers, and SMBs via InformationWeek Global CIO, Dr. Dobb's and InformationWeek SMB, as well as vital vertical industries with InformationWeek Financial Services, Government and Healthcare sites. Content is at the nucleus of our information distribution strategy—IT professionals turn to our experts and communities to stay informed, get advice and research technologies to make strategic business decisions.

About UBM TechWeb (

UBM TechWeb, the global leader in technology media and professional information, enables people and organizations to harness the transformative power of technology. Through its three core businesses – media solutions, marketing services and paid content – UBM TechWeb produces the most respected and consumed brands and media applications in the technology market. More than 14.5 million business and technology professionals (CIOs and IT managers, Web & Digital professionals, Software Developers, Government decision makers, and Telecom providers) actively engage in UBM TechWeb's communities and information resources monthly. UBM TechWeb brands include: global face-to-face events such as Interop, Web 2.0, Black Hat and Enterprise Connect; award-winning online resources such as InformationWeek, Light Reading, and Network Computing; and market-leading magazines InformationWeek, Wall Street & Technology, and Advanced Trading. UBM TechWeb is a UBM plc company, a global provider of news distribution and specialist information services with a market capitalization of more than $2.5 billion.