IBM Security QRadar vs LogRhythm SIEM comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 12, 2023
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
6th
Ranking in Security Information and Event Management (SIEM)
4th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (19th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
LogRhythm SIEM
Ranking in Log Management
8th
Ranking in Security Information and Event Management (SIEM)
7th
Average Rating
8.4
Number of Reviews
167
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Security Information and Event Management (SIEM) category, the mindshare of IBM Security QRadar is 9.5%, up from 9.5% compared to the previous year. The mindshare of LogRhythm SIEM is 3.3%, down from 5.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
Unique Categories:
Log Management
5.0%
User Entity Behavior Analytics (UEBA)
13.3%
 

Featured Reviews

RP
Apr 16, 2021
Flexible, easy to use, and scalable
We are a service provider and we are providing the solution as a managed service for multitenancy security The solution is flexible and easy to use. IBM is going through some problems with its resources currently making its support response time slow. I have been using the solution for a couple…
LV
Nov 22, 2023
The user interface is pretty good compared to other tools, but the product fails if we run big queries
It is an SIEM tool. It gathers logs, parses and normalizes them, and correlates the logs with the rules we write. For example, if an account tries to log in multiple times with the same username, I can write a rule for it. The SIEM tool would analyze the logs and generate alerts based on the rule…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the machine learning module."
"Flexible and valuable product that is modular, so you can easily set up a roadmap for your clients."
"We've found the technical support to be very good."
"I like the graphical interface. It's so good and easy."
"The feature that I find the most useful is that IBM QRadar User Behavior Analytics is free of charge. It's a fully free product that can be installed on top of IBM QRadar SIEM."
"The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
"QRadar has somewhat of a new structure recently from last gen. They have moved from the standard UI based infrastructure."
"The tool is already automated in many ways, but there are some additional functions which should be automated, like sending an email, mobile notification, and integration of XFS."
"The alarm functions have helped us cut down on the manual work. They bubble things up to us instead of our having to go look for stuff. Also, from an operational perspective, day to day, the Case Management functions are really useful for us. They allow us to track what we see in the incidents that we have."
"The ability to drill down and pivot from an event is one of the biggest advantage the product has compared to other things that I have seen in the market."
"It's very easy to create the correlation rules with LogRhythm, and there are some advanced features like SIEM and UEBA, which are also very valuable."
"We have to be able to show the evidence, and LogRhythm does a great job of putting it forward and making it easy to create reports with nice looking dashboards, which show off what we are doing as a security program."
"It supports most standard log sources."
"This solution has improved our organization in many different ways. The biggest benefit is being able to view all information in one dashboard instead of having to look at several different applications and dashboards. I can see information across our entire environment and every aspect of our network."
"Compliance reporting is another great feature of this product. It has built in reports right out of the box."
"AXON has the ability to add and compare use cases."
 

Cons

"The price of IBM Security QRadar is an area of concern where improvements are required."
"The solution lacks vendor support."
"From a functionality point of view there are issues sometimes."
"IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."
"The product does not have a team for investigating malware."
"The solution is difficult to understand in the beginning and has complex management configurations that can be improved."
"The Indian tech support is not helpful."
"For the common needs of clients to fulfill requirements, a real integration with Blueworks Live (BPA modeling tool also from IBM) and a more suitable BPM on cloud solution for midsize customers."
"NextGen SIEM's integration with other software is good but could be improved."
"Parsing is totally controlled by LogRhythm and they do not allow any partner or any third-party to handle this part and this is a key challenge on my end."
"LogRhythm SIEM can improve its user interface. The current interface is quite complex and can be challenging to navigate. While it offers many valuable features, understanding how to access and utilize them efficiently takes time. Simplifying the client console's user interface would significantly enhance the user experience and make it more user-friendly."
"I would like to see case management become more independent from LogRhythm itself."
"I don't think the cloud model in LogRhythm is developed enough."
"There is room for improvement with separate running sources or better integration."
"More detail in the alerts given to avoid additional searches, as often the source or destination associated with the alert is not evidenced."
"The software needs to work on its pricing."
 

Pricing and Cost Advice

"The pricing needs to be such that they are more competitive with other vendors."
"The price of this solution is reasonable."
"There is a license to use this solution, which is paid annually. However, there are subscription options available."
"It would be great if this product were cheaper."
"The licensing is also overly complex, as there is a need to buy the work load performance monitoring separately."
"IBM has subscriptions plans that run for one year."
"There are additional costs, such as the cost associated with the different hardware required for implementation and deployment. Along with the add-on apps, these are all additional costs, and they require licensing as well."
"It's not expensive for the resources that it gives you."
"The product is inexpensive than other tools."
"Look closely at the cost of licensing of other products. This should include setups and the need for support services. I did a RFQ to 2 other vendors before choosing this product."
"Everything is expensive with LogRhythm, and you don't get anything for free."
"The solution has provided us with consistency and increased staff productivity through orchestrated automated work flows by at least 20 percent."
"We did a five-year agreement. We pay close to a quarter of a million dollars for our solution."
"I would rate the tool's pricing around eight out of ten."
"I would recommend that whatever sales quotes to them upfront, they will probably go up. Because they are probably going to outgrow that very quickly or once they start getting everything into it, they are going to have to move up anyway."
"NextGen SIEM's pricing is moderate."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Educational Organization
20%
Computer Software Company
15%
Financial Services Firm
10%
Government
7%
Educational Organization
39%
Computer Software Company
9%
Government
6%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What is the difference between log management and SIEM?
Rony, Daniel's answer is right on the money. There are many solutions for each in the market, a lot depends upon your ability to manage such tools and your budget. A small operation may be best s...
What do you like most about LogRhythm NextGen SIEM?
LogRhythm does a very good job of helping SOCs manage their workflows.
What is your experience regarding pricing and costs for LogRhythm NextGen SIEM?
LogRhythm's pricing and licensing are extremely competitive and it's one of the top three reasons we continue to invest in the platform.
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
LogRhythm NextGen SIEM, LogRhythm, LogRhythm Threat Lifecycle Management, LogRhythm TLM
 

Learn More

 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Macy's, NASA, Fujitsu, US Air Force, EY, Abbott, HD Supply, SAB Miller, UCLA, Raytheon, Amtrak, Cargill
Find out what your peers are saying about IBM Security QRadar vs. LogRhythm SIEM and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.