

IBM Security QRadar and Devo compete in the SIEM category, each offering distinct strengths based on user needs and infrastructure preferences. IBM Security QRadar is favored for its robust feature set while Devo's real-time analytics and cloud-native architecture offer unique value propositions.
Features: IBM Security QRadar offers comprehensive features including log management, NetFlow analysis, and application monitoring. Its ability to efficiently extract information from raw logs and its scalable architecture make it suitable for complex security environments. Devo excels in real-time analytics, boasting a flexible, cloud-native architecture that supports extended data retention for historical data correlation. Users appreciate its ease of use, modular UI, and integration capabilities in multi-tenant environments.
Room for Improvement: IBM Security QRadar needs improvements in incident management capabilities and user interface intuitiveness. Users seek enhanced graphing tools, vulnerability scanning, and smoother integration processes. Devo could refine its GUI and expand its pre-built monitoring integrations. The solution also has room to improve data ingestion and parsing, as well as the interface for data analysis.
Ease of Deployment and Customer Service: IBM Security QRadar offers deployment on-premises or in public and hybrid clouds, supported by global customer service, albeit with varied response effectiveness. Devo's deployment is flexible, enabling strong cloud options. Despite occasional challenges with pricing and technical support processes, its customer service is generally well-received.
Pricing and ROI: IBM Security QRadar is considered a high-cost option tailored for large enterprises, with licensing complexity tied to events per second; however, it provides substantial ROI through risk mitigation. Devo's competitive pricing focuses on ingestion rates for budget predictability, offering good value in reduced operational costs and efficient infrastructure management.
With SOAR, the workflow takes one minute or less to complete the analysis.
AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar.
Investing this amount was very much worth it for my organization.
They assist with advanced issues, such as hardware or other problems, that are not part of standard operations.
Support needs to understand the issue first, then escalate it to the engineering team.
The support is really good; for instance, if a critical ticket is submitted, you will get paged right away as it gets logged, and their analyst will look into it, letting you know as soon as possible so you can work on it.
For EPS license, if you increase or exceed the EPS license, you cannot receive events.
On cloud, you don't see any disconnections or instability.
I think QRadar is stable and currently satisfies my needs.
The product has been stable so far.
This is particularly evident when dealing with failed login attempts and determining true versus false positives.
We receive logs from different types of devices and need a way to correlate them effectively.
If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules.
IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
Splunk is more expensive than IBM Security QRadar.
It was costly mainly because of the value you can get right now compared to other solutions.
It depends on how much you want to spend.
When they see a spike in a line chart for a failed login, which could be a true or false attempt, they can click that spike, and a table widget on the same active board instantly populates with raw logs of data for those specific failed logins.
Recently, I faced an incident, a cyber incident, and it was detected in real time.
IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches.
Compared to ArcSight, Splunk, or any other SIEM tools where you need their processing language such as structured query language, SPL, and in Sentinel there is KQL query languages, IBM Security QRadar doesn't require reliance on query languages.
| Product | Mindshare (%) |
|---|---|
| IBM Security QRadar | 5.2% |
| Devo | 1.2% |
| Other | 93.6% |

| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 11 |
| Company Size | Count |
|---|---|
| Small Business | 91 |
| Midsize Enterprise | 39 |
| Large Enterprise | 105 |
Devo offers powerful visual analytics, real-time data querying, and log integration capabilities within a cloud-native, multi-tenant architecture, supporting extended data retention ideal for long-term analysis and compliance.
Devo is recognized for its Activeboards, which facilitate visual analytics. High-speed search capabilities and real-time analytics enable efficient data manipulation and querying. Its multi-tenant architecture supports effective data segregation and customization tailored to distinct business needs, enhancing its value for handling complex log integrations. With extended data retention of 400 days and a cloud-native architecture, Devo is a robust platform for long-term analysis and compliance requirements. Though opportunities exist to improve browser stability on large searches, SOAR integrations, and its parser capabilities, Devo remains essential for incident response and security monitoring, offering centralized data storage and analysis.
What are Devo's most important features?Devo is extensively used in industries focused on incident response and digital forensics, centralizing data for security monitoring across hybrid environments. Organizations benefit from its ability to store and analyze aggregated logs, creating alerts and dashboards to enhance visibility for network and endpoint activities in multi-domain settings.
IBM Security QRadar offers real-time threat detection, data correlation, and integration with third-party solutions, providing a user-friendly interface, scalability, and extensive reporting capabilities for SIEM needs.
IBM Security QRadar is designed for comprehensive security monitoring in diverse environments, aiding sectors like telecom and finance with advanced threat detection and breach management. It aggregates data and analyzes user behavior, while its customizable and out-of-the-box rules deliver robust security insights and vulnerability management. The platform seeks enhancements in integration, performance, and user interface, with a focus on AI and cloud service compatibility.
What are the most important features of IBM Security QRadar?Telecom, finance, and cloud-based industries implement IBM Security QRadar for threat detection, compliance, and security monitoring. It is deployed for log collection and correlation, user behavior analytics, and ensuring secure data transfer and incident management, focusing on compliance and anomaly detection.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.