IBM Security QRadar vs IBM SevOne Network Performance Management (NPM) comparison


Comparison Buyer's Guide

Executive Summary

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
Average Rating
Number of Reviews
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (19th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
IBM SevOne Network Performa...
Ranking in Log Management
Average Rating
Number of Reviews
Ranking in other categories
Network Monitoring Software (41st), Server Monitoring (16th), IT Infrastructure Monitoring (37th), Cloud Monitoring Software (28th)

Mindshare comparison

As of July 2024, in the Log Management category, the mindshare of IBM Security QRadar is 5.0%, down from 6.0% compared to the previous year. The mindshare of IBM SevOne Network Performance Management (NPM) is 0.3%, down from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
Security Information and Event Management (SIEM)
User Entity Behavior Analytics (UEBA)
Network Monitoring Software
Server Monitoring

Featured Reviews

Sep 30, 2022
Real-time detection is quite efficient but the dashboard lacks important visibility for threat hunting
Our company includes 20 senior engineers and analysts who use the solution to detect viruses on Windows servers and critical assets. We also track user activity such as connections during travel.  We have many use cases and playbooks in our portfolio.  Our company uses the solution as our main CM…
Grzegorz Nowak - PeerSpot reviewer
Apr 29, 2024
Improves infrastructure planning by helping us analyze network traffic
We use SevOne to collect and report on network flows SevOne improves infrastructure planning by helping us analyze network traffic. We can look at bandwidth for specific endpoints on the customer's network and analyze traffic to identify issues. For example, maybe some connectors are unavailable.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:


"I have found IBM QRadar to be stable."
"The most valuable features are the AI assistant, which is good at detecting known types of behavior."
"The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well."
"It comes with many rules disabled. You can tune them and modify them according to your enterprise needs and avoid false positives."
"It's hard for me to pinpoint any one feature that's most valuable because it is all about consuming logs and analyzing them. We started using QRadar UBA because we needed something that could analyze Linux authentication information. Other products take care of the Windows platform."
"It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important."
"It has a logical, user-friendly GUI."
"It's user-friendly when compared to other products."
"I like SevOne's network flow reporting."
"We've had great feedback from our customers about SevOne support. They're willing to set up a remote session upon request. You have to go through three tiers of support with most vendors, and they ask a lot of screening questions before they will do a remote session. You need to spend a lot of time before an engineer will host a remote session to look at your problematic system."
"SevOne’s data collection functionality is very good. From a collection point of view, we pull SNMP data, which is simple. It is easy to manipulate the pull in the estate. It is really simple compared to some of the other products that we have used. However, for deferred data, i.e., things that we import or don't pull directly, we tend to have a preplanned integration. So, its Universal Collector is really useful."
"The monitoring of the network is very customizable. That is its unique feature."
"Another useful feature is that SevOne gives you real-time insights into your network performance. It polls every five minutes. That is important for our customers because there are some network teams that are always monitoring their networks."
"In 90% of the cases, new devices are plug-and-play, so when a new version comes out then SevOne has support for it out of the box."
"SevOne has rich API capabilities, giving us the flexibility to control what we collect and customize the collection, creation, and manipulation of now metrics as necessary."
"It also gives us the closest thing to real-time insight into network performance that we have, with just a 10-second delay. It's very important for us to know the health of the infrastructure very quickly."


"The interface is very old. IBM should remake it into a more modern interface."
"Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them."
"SOAR is what is expected the most from QRadar. They have something called SOAR Resilient, and it would be great if that gets induced in SIEM. IBM QRadar (as well as McAfee ESM) should have analytics platform integration. Currently, SIEMs don't have full-fledged integration with analytics where we are able to dump our data in SIEM, and the same data can be called from different analytics applications. We should be able to bring this data to a platform like Hadoop for big data and run the analytics there. Currently, people are seeing the past data and taking some actions in the present, but when it comes to analytics, there should be futuristic data where you can predict something out of your present and past data. Apart from that, I would like to see a full-fledged ITSM tool in QRadar. It sometimes has some technical issues that need to be checked. It requires a dedicated QRadar engineer to completely manage it. It has different module sets, such as event collector and event processor, and some technical glitches come in between. It takes the log but doesn't exactly process it in the way we want."
"I would like to see some artificial intelligence and alternative solutions."
"The dashboard is pathetic and it takes a long time to perform a search."
"There are reports that I would like to generate that are either not included, or I cannot find."
"We would like to see better instrumentation for debugging changes in the log flow."
"There are a lot of things they are working on and a lot of technologies that are not yet there. They should probably work out a better reserve with their ecosystem of business partners and create wider and more in-depth qualities, third-party tools, and add-ons. These things really give immediate business value. For instance, there are many limitations in using SAP, EBS, or Micro-Dynamics. A lot of things that are happening in those platforms could also be monitored and allowed from the cybersecurity risks perspective. IBM might be leaving this gap or empty space for business partners. Some larger organizations might already be doing this. It would be very nice if IBM can make some artificial intelligence part free of charge for all current QRadar users. This would be a big advantage as compared to other competitors. There are companies that are going in different directions. Of course, you can't do everything inside QRadar. In general, it might be very good for all players to provide more use cases, especially regarding data protection and leakage prevention. There are some who are already doing some kind of file integrity or gathering some more information from all possible technologies for building anything related to the user and data analysis, content analysis, and management regarding the data protection."
"The reports are easy to configure but they are a bit outdated in terms of appearance and visualization."
"There are some tweaks and enhancements that I've already requested. One is to be able to make changes per device rather than as a global setting. That has to do with naming. It's minor."
"The reporting of NMS is good, but it could be better."
"High-frequency polling is data-intensive because you're pulling more. If SevOne could figure out a way to manage the impact of high-frequency polling on the system, that would be very popular."
"You need to plan integrations. That has been the biggest bug with SevOne so far. For the things that SevOne pulls directly, those are easy to understand, modify, and put into the database. For things that need to use the Universal Collector or xStats, you need to plan that stuff well in advance."
"Software upgrades can be tricky is not easy."
"When I started using it, I tried adding one of the BroadWorks application servers into SevOne... it created thousands and thousands of objects from that one application server and we immediately ran out of license... It would help, when new objects are discovered, if there were a way to categorize those objects and to pick the part of the object you need..."
"NMS has several areas for improvement. It should be more user-friendly inside of NMS for some of the functionality in there. It's been getting better the last version or two, but the there have been bugs in there whenever I've gone to new versions."

Pricing and Cost Advice

"IBM QRadar is a little bit expensive compared to other products."
"We pay approximately $40,000 to use the solution annually. This solution is a lot less expensive than Splunk."
"Customers have to purchase a license based on the number of users, devices, and applications they want to protect. It allows you to take a license on a subscription basis for three years or five years."
"There are additional costs, such as the cost associated with the different hardware required for implementation and deployment. Along with the add-on apps, these are all additional costs, and they require licensing as well."
"QRadar UBA's price is a little more than street price and could be reduced."
"The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it."
"On a scale of one to ten, I rate the price a one, where one is an extremely expensive product, and ten is a cheap product."
"The pricing is always fine."
"The tool is not expensive. We were able to negotiate with SevOne on pricing."
"There are cheaper solutions available."
"Prices per license are not huge, but they exist."
"The pricing has not evolved with the market, which is one of the reasons we are moving to a new product."
"For the value that you get from SevOne, it's worth the price. There are a lot of cheaper alternatives on the market, and even free options. But they require more staff, more resources, and engineers with more advanced knowledge of monitoring. That's what makes SevOne worth the price."
"The pricing has been fair."
"There are different options available for licensing, with the per-device option being more expensive but more flexible."
"Although I don't have exact details in terms of cost, my experience has been that SevOne is willing to make a deal with the customer."
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
793,295 professionals have used our research since 2012.

Comparison Review

Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…

Top Industries

By visitors reading reviews
Educational Organization
Computer Software Company
Financial Services Firm
Computer Software Company
Financial Services Firm
Manufacturing Company

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What do you like most about SevOne Network Data Platform?
I like the tool’s scalability and real-time reports. Earlier, we struggled to give real-time reports to clients. I also like the tool’s deployment model where we can deploy it either on-premises or...
What is your experience regarding pricing and costs for SevOne Network Data Platform?
The tool is not expensive. We were able to negotiate with SevOne on pricing.
What needs improvement with SevOne Network Data Platform?
SevOne could improve its flexibility because it isn't fully customizable and its out-of-the-box configuration doesn't cover all use cases.

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson

Learn More




Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
ATOS, Devereux, Spark New Zealand, Access4, Rogers Communication, Lumen (formerly known as CenturyLink)
Find out what your peers are saying about IBM Security QRadar vs. IBM SevOne Network Performance Management (NPM) and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.