Grafana Loki vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Grafana Loki
Ranking in Log Management
13th
Average Rating
8.0
Number of Reviews
12
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (20th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
 

Featured Reviews

JN
Aug 3, 2023
An easy-to-set-up solution that has a simple dashboard and can be used by non-technical people
We can provide a dashboard really fast with Grafana Loki for nontechnical people. We can generate and provide easy visibility for the people using Grafana Loki The most valuable feature of Grafana Loki is the dashboards which are really simple to create. Grafana Loki's dashboard is really simple…
Jacob_Koithra - PeerSpot reviewer
Aug 3, 2022
Good monitoring and dashboards with good blocking capabilities
We use the blocking mode and spam mode for the IPS - XGS 5000 series and use of QRadar as a SIEM Solution for logging and monitoring network security, security analysis, and monitoring for network-related attacks.  The playbook is defined with identified use cases. IPS acted as an inline to the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I appreciate the capability to process logs from microservices and seamlessly integrate them into Grafana."
"The tool can be used in multi-cluster environments."
"Loki also utilizes the same service discovery mechanism as used by Prometheus. So, whatever labeled metadata you see in Prometheus, you have the exact same metadata in the Loki system. Given this level of intricacy and the attempt to address these challenges, I firmly believe that Loki deserves praise for the work."
"The best feature of Grafana Loki is that it integrates well with our other tool."
"The most valuable features of the solution stem from the fact that it is an open-source tool that is stable and flexible."
"The most valuable feature is the capability to set up alerts, which becomes necessary when we need to receive notifications for specific events."
"We are using Grafana Loki as a database for real-time metrics."
"The most valuable feature of Grafana Loki is the dashboards which are really simple to create."
"What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own."
"This solution has excellent security analytics."
"It'll get you from point A to B."
"Customer service is very good and very helpful."
"It is incredibly easy to deploy. All the appliances are flexible in the roles that they serve and are all managed the in the same way."
"Search capabilities are sufficient for most tasks."
"It is a very optimized engine."
"QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis. There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving. From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected."
 

Cons

"In Grafana Loki, the creation of metrics is not so easy, making it an area that could be made easier."
"We encountered certain limitations when it came to alerting, particularly when dealing with specific data sources."
"We had a well-structured dashboard with a functional query. However, an issue arose when the Kubernetes pod restarted. The statistics from our Grafana query would reset, dropping to zero and starting anew. This was particularly noticeable with linear graphs, which are expected to show consistent growth."
"The solution's scalability depends on the team managing the Grafana instance."
"The correlation of requests is not simple in Grafana Loki and can be improved."
"Visualization-wise, Grafana Loki's dashboard looks a little outdated compared to other open-source visualization tools like Chronograf."
"Enhancing speed could be a game-changer, and while it might vary depending on the application, it's a factor worth exploring."
"The solution has shortcomings regarding security monitoring-oriented features that need improvement."
"Do your research before implementing it, because it is tough to implement."
"This solution is on-premise and many customers are moving to the cloud base solution."
"The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good."
"Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them."
"There should be easier and wider integration opportunities. There should be more opportunities for integration with CTI info sharing areas. On platforms where you exchange CTI, there should be more visibility connected to what we share, what we can reach, or what options are connected to CTI info sharing. This is one area where they could add value because we cannot integrate it easily with QRadar. If a client has a legacy or already existing solutions for CTI, we cannot ask them to forget it because we cannot guarantee that QRadar is able to deliver everything connected to this area."
"I would like for Yara to be supported by all components."
"For the common needs of clients to fulfill requirements, a real integration with Blueworks Live (BPA modeling tool also from IBM) and a more suitable BPM on cloud solution for midsize customers."
"Technical support is good, but not great."
 

Pricing and Cost Advice

"The solution is open source."
"Since we are using the open-source version of Grafana Loki, we are not paying anything for the solution."
"The pricing structure varies based on the number of users; there might be specific taxes to pay for it."
"I use the open-source version of the product."
"My company doesn't need to pay for the licensing cost of the solution."
"You can use the free version of Grafana Loki on-premises."
"I use the solution's open-source version. Grafana Loki is a completely free solution for me."
"We use a free version."
"It's not expensive for the resources that it gives you."
"Our licensing costs for this solution is on a yearly basis."
"The price of this solution is reasonable."
"QRadar is quite expensive. It wouldn't be worth it for a small business..."
"There are additional costs, such as the cost associated with the different hardware required for implementation and deployment. Along with the add-on apps, these are all additional costs, and they require licensing as well."
"Pricing is good."
"Go through a vulnerability assessment review for price breaks. A virtualized solution will also cut down on cost."
"I think my company pays for the license yearly."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Manufacturing Company
10%
Comms Service Provider
8%
Financial Services Firm
6%
Educational Organization
19%
Computer Software Company
15%
Financial Services Firm
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Grafana Loki?
We are using Grafana Loki as a database for real-time metrics.
What is your experience regarding pricing and costs for Grafana Loki?
Since we are using the open-source version of Grafana Loki, we are not paying anything for the solution.
What needs improvement with Grafana Loki?
There are a few features in the solution's enterprise version that are not given in the normal basic version. Visualization-wise, Grafana Loki's dashboard looks a little outdated compared to other ...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Grafana Loki vs. IBM Security QRadar and other solutions. Updated: June 2024.
787,779 professionals have used our research since 2012.