

IBM Security QRadar and Datadog compete in the security information and event management (SIEM) and monitoring space. IBM QRadar appears to have an advantage in environments where large-scale data correlation and incident response are crucial, whereas Datadog leads in user-centric dashboard functionality and seamless cloud integration.
Features: IBM Security QRadar provides comprehensive log management, SIEM capabilities, and application monitoring. Its strengths include adaptability across various environments, impressive data correlation, and real-time alerting. Datadog offers extensive integrations and user-friendly dashboards. It excels in performance monitoring for infrastructure and applications, providing a holistic view of operations, which is particularly beneficial for tech buyers focusing on ease of use and visibility.
Room for Improvement: IBM Security QRadar could improve in incident management, user experience, and dashboard enhancements, as well as refining user behavior analytics. Datadog faces challenges with its complex pricing model, technical issues, and requires better API consistency. Enhancing advanced analytics features, cloud service integrations, and predictive alerting capabilities are areas for advancement.
Ease of Deployment and Customer Service: IBM Security QRadar supports on-premises deployment meeting compliance and data control requirements, with technical support that is generally effective but sometimes slow. Datadog, leveraging its SaaS model, offers easy deployment in public cloud and hybrid settings, with responsive customer service praised for its support of cloud environments. IBM's support system is noted for its geographical coverage, whereas Datadog is applauded for proactive updates and strong community resources.
Pricing and ROI: IBM Security QRadar is seen as costly, with a complex licensing model that can be prohibitive for smaller organizations, but offers significant value in larger enterprises. Datadog's pricing is reasonable for its features, though can escalate with extended logging. Its ROI is supported by rapid deployment and extensive visibility, appealing to organizations seeking scalable and flexible monitoring solutions.
Previously we had thirteen contractors doing the monitoring for us, which is now reduced to only five.
Datadog has delivered more than its value through reduced downtime, faster recovery, and infrastructure optimization.
I believe features that would provide a lot of time savings, just enabling you to really narrow down and filter the type of frustration or user interaction that you're looking for.
With SOAR, the workflow takes one minute or less to complete the analysis.
AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar.
Investing this amount was very much worth it for my organization.
When I have additional questions, the ticket is updated with actual recommendations or suggestions pointing me in the correct direction.
Overall, the entire Datadog comprehensive experience of support, onboarding, getting everything in there, and having a good line of feedback has been exceptional.
I've had a couple instances where I reached out to Datadog's support team, and they have been really super helpful and very kind, even reaching back out after resolving my issues to check if everything's going well.
They assist with advanced issues, such as hardware or other problems, that are not part of standard operations.
Support needs to understand the issue first, then escalate it to the engineering team.
The support is really good; for instance, if a critical ticket is submitted, you will get paged right away as it gets logged, and their analyst will look into it, letting you know as soon as possible so you can work on it.
Datadog's scalability has been great as it has been able to grow with our needs.
We did, as a trial, engage the AWS integration, and immediately it found all of our AWS resources and presented them to us.
Datadog's scalability is strong; we've continued to significantly grow our software, and there are processes in place to ensure that as new servers, realms, and environments are introduced, we're able to include them all in Datadog without noticing any performance issues.
For EPS license, if you increase or exceed the EPS license, you cannot receive events.
Datadog is very stable, as there hasn't been any downtime or issues since I've been here, and it's always on time.
Datadog seems stable in my experience without any downtime or reliability issues.
These incidents are related to log service, indexes, and metric capturing issues.
I think QRadar is stable and currently satisfies my needs.
The product has been stable so far.
It would be great to see stronger AI-driven anomaly detection and predictive analytics to help identify potential issues before they impact performance.
The documentation is adequate, but team members coming into a project could benefit from more guided, interactive tutorials, ideally leveraging real-world data.
In future updates, I would like to see AI features included in Datadog for monitoring AI spend and usage to make the product more versatile and appealing for the customer.
We receive logs from different types of devices and need a way to correlate them effectively.
If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules.
IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
The setup cost for Datadog is more than $100.
Everybody wants the agent installed, but we only have so many dollars to spread across, so it's been difficult for me to prioritize who will benefit from Datadog at this time.
My experience with pricing, setup cost, and licensing is that it is really expensive.
Splunk is more expensive than IBM Security QRadar.
It was costly mainly because of the value you can get right now compared to other solutions.
It depends on how much you want to spend.
Our architecture is written in several languages, and one area where Datadog particularly shines is in providing first-class support for a multitude of programming languages.
Having all that associated analytics helps me in troubleshooting by not having to bounce around to other tools, which saves me a lot of time.
Datadog was able to find the alerts and trigger to notify our team in a very prompt manner before it got worse, allowing us to promptly adjust and remediate the situation in time.
Recently, I faced an incident, a cyber incident, and it was detected in real time.
IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches.
IBM is seeking information about IBM QRadar because a part of QRadar, especially in the cloud, has been sold to Palo Alto.
| Product | Market Share (%) |
|---|---|
| Datadog | 5.7% |
| IBM Security QRadar | 3.8% |
| Other | 90.5% |


| Company Size | Count |
|---|---|
| Small Business | 80 |
| Midsize Enterprise | 46 |
| Large Enterprise | 94 |
| Company Size | Count |
|---|---|
| Small Business | 90 |
| Midsize Enterprise | 36 |
| Large Enterprise | 103 |
Datadog integrates extensive monitoring solutions with features like customizable dashboards and real-time alerting, supporting efficient system management. Its seamless integration capabilities with tools like AWS and Slack make it a critical part of cloud infrastructure monitoring.
Datadog offers centralized logging and monitoring, making troubleshooting fast and efficient. It facilitates performance tracking in cloud environments such as AWS and Azure, utilizing tools like EC2 and APM for service management. Custom metrics and alerts improve the ability to respond to issues swiftly, while real-time tools enhance system responsiveness. However, users express the need for improved query performance, a more intuitive UI, and increased integration capabilities. Concerns about the pricing model's complexity have led to calls for greater transparency and control, and additional advanced customization options are sought. Datadog's implementation requires attention to these aspects, with enhanced documentation and onboarding recommended to reduce the learning curve.
What are Datadog's Key Features?In industries like finance and technology, Datadog is implemented for its monitoring capabilities across cloud architectures. Its ability to aggregate logs and provide a unified view enhances reliability in environments demanding high performance. By leveraging real-time insights and integration with platforms like AWS and Azure, organizations in these sectors efficiently manage their cloud infrastructures, ensuring optimal performance and proactive issue resolution.
IBM Security QRadar (recently acquired by Palo Alto Networks) is a security and analytics platform designed to defend against threats and scale security operations. This is done through integrated visibility, investigation, detection, and response. QRadar empowers security groups with actionable insights into high-priority threats by providing visibility into enterprise security data. Through centralized visibility, security teams and analysts can determine their security stance, which areas pose a potential threat, and which areas are critical. This will help streamline workflows by eliminating the need to pivot between tools.
IBM Security QRadar is built to address a wide range of security issues and can be easily scaled with minimal customization effort required. As data is ingested, QRadar administers automated, real-time security intelligence to swiftly and precisely discover and prioritize threats. The platform will issue alerts with actionable, rich context into developing threats. Security teams and analysts can then rapidly respond to minimize the attackers' strike. The solution will provide a complete view of activity in both cloud-based and on-premise environments as a large amount of data is ingested throughout the enterprise. Additionally, QRadar’s anomaly detection intelligence enables security teams to identify any user behavior changes that could be indicators of potential threats.
IBM QRadar Log Manager
To better help organizations protect themselves against potential security threats, attacks, and breaches, IBM QRadar Log Manager gathers, analyzes, preserves, and reports on security log events using QRadar Sense Analytics. All operating systems and applications, servers, devices, and applications are converted into searchable and actionable intelligent data. QRadar Log Manager then helps organizations meet compliance reporting and monitoring requirements, which can be further upgraded to QRadar SIEM for a more superior level of threat protection.
Some of QRadar Log Manager’s key features include:
Reviews from Real Users
IBM Security QRadar is a solution of choice among users because it provides a complete solution for security teams by integrating network analysis, log management, user behavior analytics, threat intelligence, and AI-powered investigations into a single solution. Users particularly like having a single window into their network and its ability to be used for larger enterprises.
Simon T., a cyber security services operations manager at an aerospace/defense firm, notes, "The most valuable thing about QRadar is that you have a single window into your network, SIEM, network flows, and risk management of your assets. If you use Splunk, for instance, then you still need a full packet capture solution, whereas the full packet capture solution is integrated within QRadar. Its application ecosystem makes it very powerful in terms of doing analysis."
A management executive at a security firm says, "What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value."
We monitor all Log Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.