No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Security QRadar vs NetWitness Endpoint comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
6th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
112
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
IBM Security QRadar
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
217
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (2nd), User Entity Behavior Analytics (UEBA) (2nd), Security Orchestration Automation and Response (SOAR) (5th), Managed Detection and Response (MDR) (7th), Extended Detection and Response (XDR) (10th)
NetWitness Endpoint
Ranking in Endpoint Detection and Response (EDR)
51st
Average Rating
8.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.4%, down from 4.0% compared to the previous year. The mindshare of IBM Security QRadar is 1.9%, up from 1.0% compared to the previous year. The mindshare of NetWitness Endpoint is 0.1%, up from 0.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.4%
IBM Security QRadar1.9%
NetWitness Endpoint0.1%
Other94.6%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
HarshBhardiya - PeerSpot reviewer
SOC Engineer at a outsourcing company with 10,001+ employees
Have managed daily asset and alert monitoring effectively but have encountered limitations with manual processes and interface usability
It's still very manual and doesn't work on its own. It's still in an early stage and not on par where we can consider it a really successful detection system. The accuracy is not there. The UI could be better when compared to Sentinels where we can use flags and tagging. It could be much more user-friendly. IBM Security QRadar has all features and is fully competitive with other SIEM tools, but when it comes to user-friendliness, a new user takes time to get used to it. More intuitive, user-friendly interfaces and more helpful documentation would be beneficial. The query searching and data fetching could be faster. In large to very large organizations with around 5,000 or 6,000 assets or beyond, even with proper configurations and RAM and hardware backing up, the query is fairly slow.
LA
Computer Security Consultant at SECURE SOFT
Machine learning capabilities enhance risk management for financial industry deployments
At my company, we usually use NetWitness Endpoint for our customers with a primary focus on the financial industry, where eighty to ninety percent of our deployments occur NetWitness Endpoint offers the capability of machine learning or artificial intelligence. It provides a risk score for each…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Provides behavior-based detection which offers many benefits over signature-based detection."
"Cortex is a very good total solution on the endpoints."
"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"It collects and caches and the knowledge of machine learning from different customers to take to the cloud. It makes it better to use for everybody. It allows for quick learning and updates and can, therefore, offer zero-day malware security. This sharing of metadata helps make the solution very safe."
"The product's initial setup phase is very easy."
"I can highlight that we have not faced any security incidents with Cortex XDR by Palo Alto Networks, and even though our environment is quite dynamic, we have not faced any security incident with Cortex XDR by Palo Alto Networks until now."
"The live terminal is probably the best thing ever. It gives you the access to get straight onto any machine."
"Cortex XDR is stable, offering high quality and reliable performance."
"It is the core of our entire SOX."
"What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own."
"It's user-friendly when compared to other products."
"The scalability is good."
"The tool is already automated in many ways, but there are some additional functions which should be automated, like sending an email, mobile notification, and integration of XFS."
"I have found its network traffic log, network bit log, and QBI most valuable."
"The feature that I find the most useful is that IBM QRadar User Behavior Analytics is free of charge."
"There are many things I appreciate about IBM Security QRadar; I haven't used any other SIEM before IBM Security QRadar, so for me, it is perfect."
"NetWitness Endpoint offers the capability of machine learning or artificial intelligence."
 

Cons

"Technology evolves every day, so it would be nice if it gets more secure. It can also have more integration with other platforms."
"Enhancing UI simplicity and playbook flexibility are areas that could benefit from more low-code automation options for smoother integrations."
"We would also like to have advanced tech protection and email scanning."
"Cortex XDR by Palo Alto Networks is a very good product, but financially, it is very expensive, so the company should look into that area."
"There are some false positives."
"The technical support is not very good. I find the process difficult."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control."
"Impact on system performance is horrible, adding a lot of delays for users."
"It should have built-in blocking capability."
"The tech support is not that good."
"I have also been working with other SIEM solutions, and I have observed that they have extensive Linux-based and Unix-based integrations."
"We are considering some roadmaps to get out of IBM Security QRadar right now; that's the truth."
"I would like the rule creation interface to be much more user-friendly in the next release."
"The solution could improve by having more out-of-the-box use cases."
"QRadar needs to be improved on the storage side, particularly when the disc exceeded the maximum threshold."
"It is not easy to use. The updates are not very easy."
"NetWitness Endpoint lacks automatic response capabilities. While it can be used for response, the process is manual, requiring the user to manually respond to alerts, which is not ideal."
 

Pricing and Cost Advice

"It is "expensive" and flexible."
"The pricing is a little high. It is per user per year."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"This is an expensive solution."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"It has a yearly renewal."
"It has reasonable pricing for the use cases it provides to the company."
"The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it."
"QRadar is quite expensive. It wouldn't be worth it for a small business..."
"There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option."
"There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk."
"When compared with other SIM solutions, QRadar is considerably less expensive."
"Most of the time, it is easier and cheaper to buy a new product or the QRadar box."
"QRadar UBA's price is a little more than street price and could be reduced."
"The solution has a licensing model that is based on events per second so it scales to need and budget."
Information not available
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
895,990 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
12%
Comms Service Provider
9%
Manufacturing Company
8%
Financial Services Firm
11%
Computer Software Company
10%
Manufacturing Company
7%
Construction Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise20
Large Enterprise51
By reviewers
Company SizeCount
Small Business92
Midsize Enterprise39
Large Enterprise106
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for IBM Security QRadar?
Pricing and the license of EPS were managed by the governance team. I was not responsible for managing those. I was s...
What is your experience regarding pricing and costs for NetWitness Endpoint?
NetWitness Endpoint is neither expensive nor cheap. It is priced intermediately compared to other solutions.
What needs improvement with NetWitness Endpoint?
NetWitness Endpoint lacks automatic response capabilities. While it can be used for response, the process is manual, ...
What is your primary use case for NetWitness Endpoint?
At my company, we usually use NetWitness Endpoint ( /products/netwitness-endpoint-41546-reviews ) for our customers w...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Information Not Available
Find out what your peers are saying about CrowdStrike, SentinelOne, Microsoft and others in Endpoint Detection and Response (EDR). Updated: May 2026.
895,990 professionals have used our research since 2012.