Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs Stackify comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jul 13, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
5th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
209
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (9th), Extended Detection and Response (XDR) (13th)
Stackify
Ranking in Log Management
61st
Average Rating
7.8
Number of Reviews
6
Ranking in other categories
Application Performance Monitoring (APM) and Observability (61st), IT Infrastructure Monitoring (59th)
 

Mindshare comparison

As of August 2025, in the Log Management category, the mindshare of IBM Security QRadar is 3.6%, down from 4.7% compared to the previous year. The mindshare of Stackify is 0.2%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Mahmoud Younes - PeerSpot reviewer
Reliable installation and diverse use cases provide strong value
IBM Security QRadar has some areas for improvement. We have missed some DSM components. We need to customize logs where there is no DSM or connector for certain products. We can integrate but we have missed the DSM, which is the connector to pass logs coming from different applications. For example, with a university customer, we tried onboarding Canvas service. IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
Kalyan Somisetty - PeerSpot reviewer
Simple, easy to configure, and offers trial versions
In the next version, which I want to try, it'll show the comparison of the old responses of the APS. For example, how much time the old response and the new response with the changes. Right now, I cannot differentiate. The graphical interface should be able to capture nicely how much time it has taken and it should be very clear. Sometimes it confuses us. For example, what is this APA for? What were the average responses and how many requests have happened? It needs to give a clear picture. They should enable request and response capturing in the Stackify user interface to show what the request for the APA is. Then, it'll be very good. It should be able to capture the payload. For example, what is the request and what is the response? If it has a nice way of capturing everything then it would be easy. There is no need of using ELK again for logging. As of now, people will use Stackify or maybe Grafana for seeing the stats of the application or responses, however, it doesn't have the capabilities to show everything. People will go for any exception handling or checking the request and response in the ELK. If Stackify can do this future, then it'll be an easier single tool. It is anyway intercepting the logs, application logs. I don't think it's a big matter to capture extra data with the requested response. That requested response capturing also should be configurable since some people want the question response to be captured and for the people that don't want it, we can use that feature. It can be enabled as desired. Many people are using different monitoring tools like ELK, LogStash, and Splunk - many other tools. However, if you can make this kind of performance tool cover everything, then they will not shift to other solutions. It should be easily scalable and configurable in different instances. For example, if the same application is scaled up to differently, it should be easily integrable into Kubernetes pipelines. They should offer plugins to make it more easily integratable. For development enrollment, it should be free to use.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One of the most valuable features is its ability to integrate with other solutions. IBM has a lot of solutions and we have managed to make it work with IBM BigFix and MaaS360, and even Microsoft."
"The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well."
"The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
"The most valuable feature is the machine learning module."
"The event collector, flow collector, PCAP and SOAR are valuable."
"It protect us from multiple authentication values, unauthorized access and antivirus threats."
"It's a state-of-the-art product for security information and event management (SIEM)."
"It does good correlation for events. It does good general analysis, and it has good apps as well."
"The solution is stable and reliable."
"The filter feature on Stackify is one of the features I found valuable. It's awesome. When I want to get the application logs, the solution gives me many filters. For example, if I want to get logs from my test environment, the option is there for me to select the environment from Stackify, and you can also select the particular application, and you'll see the information you need there. The filter feature alone and the fact that Stackify offers a lot of different filters is what I like the most about the solution because I've used other tools with the filter feature, but the filtering was very difficult, versus Stackify that has good filtering. On Stackify, you can filter the information by the last one hour, or the last four hours, and you can also select the date range and specify the timestamp, then the solution will give you the information based on the date range you specified. Another feature I found valuable on Stackify is its rating feature because it tells you how your application is faring. For example, a rating of A means excellent, while a rating of F means very bad, or that your application is not doing well at all. The ratings are from A to F. I also like that Stackify helps you in terms of load management because the solution gives you information on overutilized resources. These are the most valuable features of the solution."
"The performance dashboard and the accurate level of details are beneficial."
"The deployment is very fast."
 

Cons

"It doesn't have a SOAR system by default. You need to purchase it additionally, which is the main problem with QRadar."
"Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances."
"I would suggest QRadar release any documentation or give an online demo, like videos on YouTube. It would increase publicity and public appeal."
"IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas."
"The technical support can be improved a little bit, and the price could be cheaper."
"A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools."
"The price of IBM Security QRadar is an area of concern where improvements are required."
"In terms of additional features, a mobile app would be nice. Also, the reporting is definitely okay, but you have to make sure that everybody with different roles can understand it. There is room for improvement in the reporting."
"The search feature could be improved."
"It should be easily scalable and configurable in different instances."
"I've not used Stackify for a while, and I'm currently using a solution now that's not as good as Stackify. Among the solutions I've been using so far, Stackify has been one of the best for me, but there's always room for improvement. For example, I don't know if it's just me, but when I try to get the log from Stackify, sometimes it doesn't appear in real-time. It takes a few minutes before the logs appear. When I redeploy my solution and the application starts, I don't see the logs immediately, and it would take two to three minutes before I see the logs. I don't know if other customers have a similar experience. It's the wait time for the logs to appear that's a concern for me, could be improved, and is what the Stackify team should be looking into. In terms of any additional feature that I'd like added to the solution, I'm not sure if Stackify has a way to export logs out. I've been trying to do it. On the solution, you can click on a spiral-like icon and it shows you the entire error, and I'd prefer an export button that would let me download the error and save that into a text file, for example, so it'll be available on my local machine for me to reference it, especially because the log keeps going and as you're using the solution, the system keeps pushing messages on to Stackify, so if I'm looking at a particular error at 12:05 PM, for example, by the time I go back to my system and would like to revisit the error at 12:25 PM, on Stackify, the logs would have gone past that level and I won't see it again which makes it difficult. When you now go back to that timestamp, you don't tend to see it immediately, but if the solution had an export feature for me to save that particular error information on my local machine for reference at a later time, I won't have to go back to Stackify. I just go to that log, specifically to that particular export that I've received on my local machine. I can get it and review it, and it would be easier that way versus me going back to Stackify to find that particular error and request that particular information."
"I would like to be able to see metrics about individual running containers on the host machines."
 

Pricing and Cost Advice

"Licensing can be costly depending on your architecture."
"Pricing and licensing are competitive. Their new licensing options allow logs to bypass the correlation engine for a flat rate, which is also appealing for log data that is compliance-driven for a small amount of money."
"I think that the price is fair, but we can always say that the price could be cheaper."
"We pay approximately $40,000 to use the solution annually. This solution is a lot less expensive than Splunk."
"They can give us some scalability and flexibility on pricing. If its pricing can be reduced, it would help a lot of customers in bringing in a new SIEM environment and grow business in the market. If I start a license today and take around 10,000 EPS, and after a month, there is an increase in the number of clients on my platform, I can increase the number of licenses. I can add 5,000 EPS on a yearly basis."
"As for licensing costs, I haven't seen the exact figures, but it is considered somewhat costly. On a scale from one to ten, where one is very expensive and ten is very cheap, I would rate it a six—it’s costly but worth the money."
"It would be great if this product were cheaper."
"It is cheaper than ArcSight."
"The price is variable. It depends on how much data we have received in that particular month. Usually, it goes up to $2,000, or, at times, $3,000 USD per month."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
11%
Government
7%
Manufacturing Company
7%
Financial Services Firm
15%
Computer Software Company
9%
Media Company
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
When comparing with Splunk, IBM Security QRadar's cost is reasonable. Splunk is more expensive than IBM Security QRadar.
Ask a question
Earn 20 points
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
No data available
 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
MyRacePass, ClearSale, Newitts, Carbonite, Boston Software, Children's International, Starkwood Media Group, Fewzion
Find out what your peers are saying about IBM Security QRadar vs. Stackify and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.