


IBM Security QRadar and TrendAI Vision One – Cloud Security compete in the cybersecurity sector. IBM Security QRadar has the upper hand in threat detection capabilities, especially for organizations dealing with vast data sources.
Features: IBM Security QRadar's standout features include advanced threat detection using user behavior analytics, integration with multiple security tools for a comprehensive view, and effective correlation of vast data sources providing real-time alerts. TrendAI Vision One – Cloud Security focuses on server-specific features, intrusion protection systems, and microservice architecture visibility, emphasizing cloud integration for organizations with heavy cloud environments.
Room for Improvement: IBM Security QRadar users note complex upgrades and desire better integration with other solutions, alongside a more intuitive user interface. The technical support for QRadar calls for more responsiveness. TrendAI Vision One could benefit from improved documentation, more automated threat response capabilities, and enhanced data security features.
Ease of Deployment and Customer Service: IBM Security QRadar offers versatile deployment options such as on-premises and hybrid cloud configurations. Customer service experience varies, often dependent on the support agent. TrendAI Vision One – Cloud Security supports cloud-based deployments, providing easier scalability and offering generally satisfactory customer service, though users seek more standardization in integration support.
Pricing and ROI: IBM Security QRadar is characterized by its higher cost, typically appealing to larger enterprises due to its comprehensive data protection and operational efficiencies. Licensing models include EPS and additional module costs, making it more complex. TrendAI Vision One is priced mid-range, offering infrastructure usage-based flexibility ideal for scaling operations in cloud environments. Both platforms guarantee significant ROI, with IBM QRadar's extensive features presenting potential long-term benefits for large-scale deployments.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
With SOAR, the workflow takes one minute or less to complete the analysis.
AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar.
Investing this amount was very much worth it for my organization.
The product has proven to be reliable and compatible with our network infrastructure.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
They assist with advanced issues, such as hardware or other problems, that are not part of standard operations.
Support needs to understand the issue first, then escalate it to the engineering team.
The support is really good; for instance, if a critical ticket is submitted, you will get paged right away as it gets logged, and their analyst will look into it, letting you know as soon as possible so you can work on it.
The technical support is good.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
For EPS license, if you increase or exceed the EPS license, you cannot receive events.
Cortex remains fast and responsive, even with increasing data and alerts.
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Cortex XDR by Palo Alto Networks can be trusted completely.
On cloud, you don't see any disconnections or instability.
I think QRadar is stable and currently satisfies my needs.
The product has been stable so far.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
We receive logs from different types of devices and need a way to correlate them effectively.
If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules.
IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
An integrated appliance from Trend Micro would streamline the process, providing customers with a pre-configured solution and removing dependencies on external hardware.
I would like to see more third-party integrations being added into Trend Vision One - Cloud Security, as it currently has a good amount of integrations but does not allow ingestion from many third-party solutions.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Compared to CrowdStrike, which is very costly, and SentinelOne, which is also very costly, Cortex XDR by Palo Alto Networks is a medium cost-efficient solution.
Splunk is more expensive than IBM Security QRadar.
It was costly mainly because of the value you can get right now compared to other solutions.
It depends on how much you want to spend.
The pricing for Trend Vision One - Cloud Security is very straightforward; we are using credits for calculating the solution that is required, and in terms of setup cost and licensing, it is very flexible.
The Trend Vision One pricing is reasonable.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
Recently, I faced an incident, a cyber incident, and it was detected in real time.
IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches.
Compared to ArcSight, Splunk, or any other SIEM tools where you need their processing language such as structured query language, SPL, and in Sentinel there is KQL query languages, IBM Security QRadar doesn't require reliance on query languages.
We are using Trend Vision One - Cloud Security for getting complete visibility of all the assets that exist within our cloud, and it helps us identify any sort of misconfigurations or fine-tuning that can be done to better our compliance.
| Product | Mindshare (%) |
|---|---|
| Cortex XDR by Palo Alto Networks | 4.5% |
| IBM Security QRadar | 3.3% |
| TrendAI Vision One – Cloud Security | 1.7% |
| Other | 90.5% |


| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 21 |
| Large Enterprise | 54 |
| Company Size | Count |
|---|---|
| Small Business | 92 |
| Midsize Enterprise | 39 |
| Large Enterprise | 107 |
| Company Size | Count |
|---|---|
| Small Business | 12 |
| Midsize Enterprise | 6 |
| Large Enterprise | 10 |
Cortex XDR by Palo Alto Networks provides advanced threat detection with AI-driven endpoint protection and seamless integration, ensuring multi-layered security and automatic threat response.
Cortex XDR is designed to safeguard endpoints against malware and suspicious activities. It offers advanced threat detection and response capabilities using behavioral analysis, AI, and machine learning. It seamlessly integrates with security infrastructures, providing endpoint security, firewall integration, and enhanced visibility in both cloud-based and on-premises environments.
What are the key features of Cortex XDR?Organizations in diverse sectors deploy Cortex XDR to protect against malware, leveraging its advanced threat detection capabilities. Its integration with existing security infrastructures appeals to those seeking comprehensive protection in both cloud and on-premises environments, providing enhanced visibility and threat intelligence.
IBM Security QRadar offers real-time threat detection, data correlation, and integration with third-party solutions, providing a user-friendly interface, scalability, and extensive reporting capabilities for SIEM needs.
IBM Security QRadar is designed for comprehensive security monitoring in diverse environments, aiding sectors like telecom and finance with advanced threat detection and breach management. It aggregates data and analyzes user behavior, while its customizable and out-of-the-box rules deliver robust security insights and vulnerability management. The platform seeks enhancements in integration, performance, and user interface, with a focus on AI and cloud service compatibility.
What are the most important features of IBM Security QRadar?Telecom, finance, and cloud-based industries implement IBM Security QRadar for threat detection, compliance, and security monitoring. It is deployed for log collection and correlation, user behavior analytics, and ensuring secure data transfer and incident management, focusing on compliance and anomaly detection.
TrendAI Vision One – Cloud Security offers comprehensive protection across multi-cloud environments, featuring live detection and response capabilities that enhance security management. It provides advanced analytics, making it an ideal choice for DevOps and hybrid cloud implementations.
TrendAI Vision One – Cloud Security stands out with its centralized dashboard, offering enhanced threat detection and seamless visibility and control over security measures. It ensures robust vulnerability protection, virtual patching, and intrusion prevention without impacting server performance. The platform is compatible across cloud environments, making it suitable for continuous monitoring and protection. Although improvements are needed in pricing, automation, and integration with AWS and Azure, its capacity for live monitoring and compliance ensures a strong defence against threats.
What Are the Key Features?In industries such as corporate cloud infrastructure, data centers, and Kubernetes, TrendAI Vision One – Cloud Security is implemented to secure cloud infrastructure, ensuring intrusion prevention and microservices protection. It integrates well with platforms like AWS and Azure, enables workload and application security, and supports teams by offering continuous monitoring, alerts management, and vulnerability identification.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.