Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs SolarWinds Kiwi Syslog Server comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
5th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
209
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (9th), Extended Detection and Response (XDR) (13th)
SolarWinds Kiwi Syslog Server
Ranking in Log Management
23rd
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
7
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Log Management category, the mindshare of IBM Security QRadar is 3.7%, down from 5.0% compared to the previous year. The mindshare of SolarWinds Kiwi Syslog Server is 1.6%, down from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
Real-time incident detection and user-friendly dashboard benefit daily operations
There are many types of AI, and this AI is very limited in SQL and features. There may be potential for improvement. So far, it seems very limited. It shows some good features in the correlation part, but I think there is room for improvement. For instance, when creating rules, it can suggest more rules, reducing the effort needed. If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules. Sometimes logs I receive don't mean anything, and I need technical stakeholders to share or forward logs, but these are sometimes inadequate. Keywords can help identify insufficient logs. I often lack time to verify logs. Sharing false positive results could be reduced to help my team.
Muhammad Anas - PeerSpot reviewer
Shows login failures and server issues but search functions and filters could be improved
Kiwi Syslog shows login failures and server issues. I'm using version 9.8.1. It's deployed on-premises. There are four people in my organization who are using this solution. They're all infrastructure engineers The best thing about Kiwi Syslog is that it filters logs into different levels. It's…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important."
"The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons."
"The ability to add extensions is the most valuable feature. For example, extensions that provide valuable test ports."
"Integration is very easy and the reporting is good."
"The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
"The feature that I find the most useful is that IBM QRadar User Behavior Analytics is free of charge. It's a fully free product that can be installed on top of IBM QRadar SIEM."
"The most valuable feature is the machine learning module."
"We run 65 servers globally with just two people: an engineering person and me."
"I appreciate that with Kiwi Syslog, we can segregate the logs based on the display, such as using different colors and fonts, which helps greatly in identifying logs by their severity."
"Simplicity is the most valuable feature."
"The most valuable feature of this solution is the alerting based on the security logs."
"I appreciate that with Kiwi Syslog, we can segregate the logs based on the display, such as using different colors and fonts, which helps greatly in identifying logs by their severity."
"The most valuable features of SolarWinds Kiwi Syslog Server include its ability to provide network mapping and deliver information to my customers about their networks through various methods."
"Overall, I rate SolarWinds Kiwi Syslog Server ten out of ten."
"The best thing about Kiwi Syslog is that it filters logs into different levels."
"The most valuable feature of SolarWinds Kiwi Syslog Server is its performance and management. Additionally, the solution integrates well."
 

Cons

"We have had problems with networking."
"QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."
"The dashboard is pathetic and it takes a long time to perform a search."
"I think that the search speed of this solution could be improved."
"I have noticed a few things while working on this. After the restart of the server, sometimes, the services misbehave, and you need to manually start or restart the service. I have seen that specifically with the Tomcat service. Sometimes, when you click on log sources, instead of opening the log source extension, it redirects you over the internet."
"I have also been working with other SIEM solutions, and I have observed that they have extensive Linux-based and Unix-based integrations. They have been able to support some of the Linux-based agents, which is useful to investigate and process the information on the Linux and Unix side."
"In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting."
"The technical support can be improved a little bit, and the price could be cheaper."
"Technical support could definitely be better."
"The Windows log forwarder is not functioning properly. This is a significant concern, as it led to losing a deal due to the inability to provide Windows logs effectively."
"I would like to see better search functions and better filters in the next release."
"SolarWinds Kiwi Syslog Server could improve by reducing the price."
"The Windows log forwarder is not functioning properly."
"I would like to see a more user-friendly and customizable dashboard."
"SolarWinds pricing is perceived as very high in the market, which can be a barrier for many customers."
"There is a need for an on-premises solution, which could lead to easier sales in larger markets."
 

Pricing and Cost Advice

"IBM QRadar is a little bit expensive compared to other products."
"We pay approximately $40,000 to use the solution annually. This solution is a lot less expensive than Splunk."
"IBM's Qradar is not for small companie. Unfortunately, it would be 'overkill' to place it plainly. The pricing would be too much."
"I think that the price is fair, but we can always say that the price could be cheaper."
"It could be cheaper, but the value itself is far more important for us than the price. Typically, our clients have yearly subscriptions."
"It is a perpetual license that we have for the event collector. The licensing is done based on the number of events and flows that you receive on this particular device. These are perpetual licenses, which means once you purchase them, they don't expire, which means that the support to IBM is definitely renewed after every one year. We have an enterprise agreement with IBM, which puts the cost in a totally different category as compared to someone who is not an IBM partner and is approaching IBM for this solution. We were able to get massive discounts. To give you an idea, we recently purchased 30,000 event licenses, and it costs around $480,000. It is definitely not a cheap product. We have licenses for about 270,000 events per second and 3 million flows per second. All the appliances and their events and flows are basically clubbed together and charged or rather calculated through a single source. The console receives all the details from all the event processes that we have globally. So, the license that we have is a single license for 270,000 events per second and 3 million flows per second, but that can be managed centrally. I was only part of the secondary purchase, which was 30,000 events per second for about $480,000. You can calculate how much we paid for 270,000 events. Reducing its price would be a compromise. We have already used a lower-priced product in the form of NNT, but we had to get rid of it because it was not doing the job that we actually wanted to do. You get what you pay for."
"Pricing (based on EPS) will be more accurate."
"I think my company pays for the license yearly."
"We subscribe and pay directly on the website."
"The price of SolarWinds Kiwi Syslog Server could improve."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
11%
Educational Organization
10%
Government
7%
Government
16%
Computer Software Company
9%
Financial Services Firm
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
When comparing with Splunk, IBM Security QRadar's cost is reasonable. Splunk is more expensive than IBM Security QRadar.
What is your experience regarding pricing and costs for SolarWinds Kiwi Syslog Server?
SolarWinds pricing is perceived as very high in the market, which can be a barrier for many customers.
What needs improvement with SolarWinds Kiwi Syslog Server?
The Windows log forwarder is not functioning properly. This is a significant concern, as it led to losing a deal due to the inability to provide Windows logs effectively. It should be more user-fri...
What is your primary use case for SolarWinds Kiwi Syslog Server?
Our primary use case for Kiwi Syslog is for gathering logs necessary for auditing purposes.
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
Kiwi Syslog Server
 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Holy Cross Energy, West Texas A&M University, Medium Enterprise Industrial Manufacturing Company
Find out what your peers are saying about IBM Security QRadar vs. SolarWinds Kiwi Syslog Server and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.