Try our new research platform with insights from 80,000+ expert users

IBM Cloud Pak for Security vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Cloud Pak for Security
Average Rating
0.0
Number of Reviews
1
Ranking in other categories
Cloud and Data Center Security (27th)
IBM Security QRadar
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
211
Ranking in other categories
Log Management (7th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (8th), Extended Detection and Response (XDR) (11th)
 

Mindshare comparison

IBM Cloud Pak for Security and IBM Security QRadar aren’t in the same category and serve different purposes. IBM Cloud Pak for Security is designed for Cloud and Data Center Security and holds a mindshare of 0.1%, down 0.2% compared to last year.
IBM Security QRadar, on the other hand, focuses on Security Information and Event Management (SIEM), holds 7.0% mindshare, down 9.4% since last year.
Cloud and Data Center Security Market Share Distribution
ProductMarket Share (%)
IBM Cloud Pak for Security0.1%
Illumio22.8%
Akamai Guardicore Segmentation21.5%
Other55.599999999999994%
Cloud and Data Center Security
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
IBM Security QRadar7.0%
Wazuh10.2%
Splunk Enterprise Security9.2%
Other73.6%
Security Information and Event Management (SIEM)
 

Featured Reviews

reviewer1907040 - PeerSpot reviewer
Great user-friendly interface; provides many functionalities and many free applications
The interface is good and very user-friendly, it's easy for our customers to use. Cloud Pak provides a lot of functionalities and many free applications available from the online shop which can be deployed to your system. It allows for an increase in functionalities even if you've bought the smallest installation.
Mahmoud Younes - PeerSpot reviewer
Reliable installation and diverse use cases provide strong value
IBM Security QRadar has some areas for improvement. We have missed some DSM components. We need to customize logs where there is no DSM or connector for certain products. We can integrate but we have missed the DSM, which is the connector to pass logs coming from different applications. For example, with a university customer, we tried onboarding Canvas service. IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The interface is good and very user-friendly."
"We have worked with other solutions, such as LogRhythm and Splunk. Compared to others, IBM QRadar has the best price-performance ratio so that you are able to reserve minimum costs. It starts settling in fast and gets the first results very quickly. It is also very scalable."
"The threat protection network is the most valuable feature, because when you get an offense, you can actually trace it back to where it originated from, how it originated, and why."
"The most valuable thing about QRadar is that you have a single window into your network, SIEM, network flows, and risk management of your assets. If you use Splunk, for instance, then you still need a full packet capture solution, whereas the full packet capture solution is integrated within QRadar. Its application ecosystem makes it very powerful in terms of doing analysis."
"Most valuable features include the granularity of information."
"It has improved my efficiency."
"We get events and make the correlation, or rules. In IBM, we can implement our customer's rules. We can have very clear status threats and severity of antigens."
"The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
"It is a bit easier to use than other products, such as Splunk or ELK Elasticsearch."
 

Cons

"Lacks sufficient technical support."
"I would suggest QRadar release any documentation or give an online demo, like videos on YouTube. It would increase publicity and public appeal."
"The solution's technical support works, but sometimes, it can take quite a long time to get a solution from technical support."
"IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas."
"IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms."
"Their technical support is not good. We opened a lot of cases and from my experience, they are not complicated issues but it takes forever to get an answer."
"Search capability and indexing still lag behind competitors. We also need to see improved rule based access controls and rule/event tuning."
"This solution is on-premise and many customers are moving to the cloud base solution."
"There is a shortage of skilled individuals with knowledge about the solution. There is training required."
 

Pricing and Cost Advice

Information not available
"The maintenance costs are high."
"There is a license required for this solution."
"IBM QRadar is a little bit expensive compared to other products."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate IBM Security QRadar's pricing a five out of ten."
"IBM's Qradar is not for small companie. Unfortunately, it would be 'overkill' to place it plainly. The pricing would be too much."
"This price is a little high, so it's an expensive product."
"It is cheaper than ArcSight."
"It is a perpetual license that we have for the event collector. The licensing is done based on the number of events and flows that you receive on this particular device. These are perpetual licenses, which means once you purchase them, they don't expire, which means that the support to IBM is definitely renewed after every one year. We have an enterprise agreement with IBM, which puts the cost in a totally different category as compared to someone who is not an IBM partner and is approaching IBM for this solution. We were able to get massive discounts. To give you an idea, we recently purchased 30,000 event licenses, and it costs around $480,000. It is definitely not a cheap product. We have licenses for about 270,000 events per second and 3 million flows per second. All the appliances and their events and flows are basically clubbed together and charged or rather calculated through a single source. The console receives all the details from all the event processes that we have globally. So, the license that we have is a single license for 270,000 events per second and 3 million flows per second, but that can be managed centrally. I was only part of the secondary purchase, which was 30,000 events per second for about $480,000. You can calculate how much we paid for 270,000 events. Reducing its price would be a compromise. We have already used a lower-priced product in the form of NNT, but we had to get rid of it because it was not doing the job that we actually wanted to do. You get what you pay for."
report
Use our free recommendation engine to learn which Cloud and Data Center Security solutions are best for your needs.
869,785 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business89
Midsize Enterprise36
Large Enterprise102
 

Questions from the Community

Ask a question
Earn 20 points
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
When comparing with Splunk, IBM Security QRadar's cost is reasonable. Splunk is more expensive than IBM Security QRadar.
 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
 

Overview

 

Sample Customers

Information Not Available
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Akamai, SentinelOne, Broadcom and others in Cloud and Data Center Security. Updated: September 2025.
869,785 professionals have used our research since 2012.