The primary use case of this solution is for monitoring an enterprise data center, globally for 12,000 devices.
Director of Information Security at a financial services firm with 501-1,000 employees
Scalable with good searching capabilities and good support
Pros and Cons
- "The most valuable feature is the searching capability and real-time operational use."
- "Some of the cloud apps need improvement."
What is our primary use case?
How has it helped my organization?
It has improved the way that the organization functions.
What is most valuable?
The most valuable feature is the searching capability and real-time operational use.
What needs improvement?
Some of the cloud apps need improvement.
In the next release, I would like to see improving the stability of some of the add-on applications.
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
For how long have I used the solution?
I have been using IBM QRadar for two years.
We are using the current version.
What do I think about the stability of the solution?
Stability is moderate.
We have 15 people using this solution in our organization. Their positions vary from Network Engineers, Security Engineers, and Security Analysts.
What do I think about the scalability of the solution?
It's very scalable.
How are customer service and support?
Technical support is good.
I would rate them a nine out of ten. Their response time is good.
Which solution did I use previously and why did I switch?
Previously, I did not use another solution.
How was the initial setup?
The initial setup is complex. It's just the nature of the CM tool.
What's my experience with pricing, setup cost, and licensing?
I think that the price is fair, but we can always say that the price could be cheaper.
What other advice do I have?
Like any complex enterprise CM tool, you have to have a strong support organization. People who are good at understanding Linux operating systems. You also need a strong technical support team in-house.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Ingénieur d'étude R&D at DOGA
Easy to use, helps increase development speed and is stable
Pros and Cons
- "The solution is relatively easy to use."
- "The pricing of the solution is a bit high. If they could lower it, that would be ideal."
What is our primary use case?
We primarily use the solution to develop software, for some device controllers.
What is most valuable?
The solution is relatively easy to use.
The product helps increase development speed.
The customization is very good, as are the dashboards and the security.
What needs improvement?
I'm not sure if there are any features missing from the solution. It's pretty complete.
The pricing of the solution is a bit high. If they could lower it, that would be ideal.
For how long have I used the solution?
I've been using the solution for three years or so at this point. It hasn't been too long.
What do I think about the stability of the solution?
The solution is quite stable. It doesn't have bugs or glitches. It doesn't crash on me or freeze. It's reliable.
What do I think about the scalability of the solution?
I only really use the solution myself. I can't speak to the scalability of the solution.
How are customer service and technical support?
I've never had to reach out to technical support. I can't speak to their responsiveness or knowledgeability.
How was the initial setup?
The initial setup was not complex at all. It's pretty straightforward and simple. We didn't face any real issues during the deployment process.
What's my experience with pricing, setup cost, and licensing?
The price can be expensive, however, it's all relative, as it helps speed up development, which can save money for the organization.
The payments for the product are made on a yearly basis.
What other advice do I have?
I'm using the latest version of the solution. I'm the only user and I use the desktop version of the solution. I'm basically using it because it's here and I have access to it.
I would recommend the solution to other organizations, however, if it is right for them depends on their need.
Overall, on a scale from one to ten, I'd rate the product at an eight. We've mostly been pretty satisfied with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
IT Security Analyst at a manufacturing company with 10,001+ employees
Helps us monitor and generate statistics that help to illustrate what is going on in the company
Pros and Cons
- "I have found its network traffic log, network bit log, and QBI most valuable."
- "We need more features in order to create rules to detect or to meet some requirements for other areas, for example, catching the event from other authentication tools."
What is our primary use case?
We have a lot of use cases with IBM QRadar, but our primary use is for monitoring traffic and detecting tricks.
How has it helped my organization?
In terms of how IBM QRadar has improved our company, on peak days it helps us monitor and generate statistics that help to illustrate what is going on in the company. For example, SMB detects ransomware and invalid log-on. If a user is located in the United States, or we expect a login in Russia, or Ukraine, or Kenya, it is very important for us because we can detect what application they are using there, or if a hacker is trying to log in by mobile or another device.
What is most valuable?
I have found its network traffic log, network bit log, and QBI most valuable.
We have a lot of domain controllers in QRadar tracking all the security. It is also useful for identity management.
What needs improvement?
In terms of where it could be improved, this includes its forensics, incident response, and security operation center features. Additionally, some also struggle with the rules. We need more features in order to create rules to detect or to meet some requirements for other areas, such as catching the event from other authentication tools, like in Okta, for example.
In some cases, I have issues because some tools are not integrated in QRadar, such as other tools similar to DLP (Data Loss Prevention). We need to create all the integrations manually because they are not integrated in QRadar. We have a problem, for example, because they have Symantec DLP integrated in QRadar, however, it is not working because it's not detected automatically. It is not converting all the columns, but we do have the option to create manually. This is not difficult because it's very clear in the procedures.
For how long have I used the solution?
I have been using IBM QRadar for seven years.
What do I think about the stability of the solution?
QRadar's stability is great because it is always live and is always catching and monitoring all the information that we need. When we need information, it is here in QRadar.
In terms of maintenance of QRadar, my internet is secured by IBM.
What do I think about the scalability of the solution?
For me, the scalability is good.
At the moment, we have no more than 15 people working on QRadar. This includes analysts, forensics, internet response, and active directory.
How are customer service and technical support?
Tech support is good. Additionally, I can find all the information at IBM.
How was the initial setup?
In some cases, the system or the hardware do not meet the requirements to install one flow collector. Or the menu is not displayed. The menu has 10 options. If the CPU and memory are not enough, the menu shows only five or six options. But this information is not mentioned in the installation process. But it is not complex because the installation is very clear as long as we are meeting all the requirements for the CPU, memory, or the space.
The solution takes maybe four months because we have a lot of integrations.
What other advice do I have?
I would absolutely recommend QRadar because it has a lot of options to improve or detect some information.
On a scale of one to ten, I would give QRadar a 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager Information Security at Conduent (formerly Xerox Services)
A user-friendly, stable, and solid product with internal AI and good scalability
Pros and Cons
- "It is a pretty solid product for the type that it is representing. It is a CM solution as compared to Splunk or ArcSight from HP. It is also user friendly. It comes with some internal AI as well, in which it automatically maps multiple lots from unrelated devices and makes a smart decision to link them back and create an offense based on that. It is a smart tool."
- "A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools."
What is our primary use case?
We are using it from the compliance perspective. We need this solution to comply with HIPAA and PCI because our clients require HIPAA and PCI DSS compliance. We also use it for log management, primarily security logs, and to some extent, for operational activities, even though this tool is actually not meant for operational tasks. We do keep track of errors in our appliances like hardware, storage, and network switches through QRadar.
The main or core solution is on-premises. There is an extended arm, which is in the cloud as well for cloud integration.
How has it helped my organization?
Security incident and event management are actually the core functionalities of this solution. We receive security logs on this product and based on the received logs, we can create offense tickets that are forwarded to Netcool, which is another solution that we have. I don't have experience with that, but our integration is there so that any offense or security event is forwarded to Netcool, and a ticket is automatically generated in ServiceNow for that offense. This level of automation that we have for security-related events is done through this solution. There's no manual work involved, which obviously takes away a lot of load from the individuals who are managing the security side of it.
What is most valuable?
It is a pretty solid product for the type that it is representing i.e. SIEM. It can do automatic correlation based on the traffic that you are receiving to some extent. It has plethora of options available for third party application integration. For e.g CISCO Firepower, Palo Alto Dashboard for CISCO and Palo Alto Firewall respectively. Integration with Cloud based Log Sources is also supported via. parsers that support API Connect. This is helpful when pulling in Logs from AWS, Azure, GCP or other Cloud Based Solution like Carbon Black, Imperva etc.
What needs improvement?
A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools.
For how long have I used the solution?
I have been using this solution for about six months.
What do I think about the stability of the solution?
It is very stable. As long as you have the proper connectivity availability, it is pretty stable.
What do I think about the scalability of the solution?
Our deployment covers North America, South America and part of Europe. The product is easy to deploy and scale. Almost everyone in our organization is using this solution because most of our projects rely on this. Because of the compliance requirement, most of our projects have to be integrated with QRadar. Each business unit or each program that we have in another environment has independent access to the solutions. They might not be the end users, of course, but at least every admin team of every program unit has access to this tool so that they can see what's happening in their environment.
It also supports multi-tenancy. So, if you have multiple clients or multiple tenants in your environment, you can create logical containers for them. From a logical point of view, you can create separate disconnected containers for each client so that they can only see their data.
How are customer service and technical support?
Their technical support is quite good. I would rate them a nine out of ten.
Which solution did I use previously and why did I switch?
Yes, we switched over from NNT to QRardar. This product is more detailed. Expensive but definitely more detailed! :)
How was the initial setup?
It was pretty straightforward. These are hardware appliances. So, you need to rack and stack them. If the rack space, cabling, and other things are already done, which would typically be the responsibility of a data center team, it essentially takes three to five days. But this is only the core deployment. The fine tuning on top of it would take extra time based on the environment and how complex it is.
What about the implementation team?
It was implemented by team that included me. We have an external team for its maintenance.
What's my experience with pricing, setup cost, and licensing?
The IBM QRadar Licensing for the core Events(EPS) and Flows(FPS) is per second based. The licensing is perpetual and surely expensive but the output of the Product makes it worth your money.
What other advice do I have?
I would absolutely recommend this solution. I am pretty okay with it, and I don't have any issues with it. It has some competitors like Splunk and LogRhythm. Symantec has its own SIEM solution. ArcSight, LogRhythm, and Splunk are in the first quadrant for the Gartner research. They are leaders in their products, and they know what they're doing. It also comes down to what your company is into, how does it fit into a particular environment, and how compatible it is with a particular environment. I could have gone on the Splunk path and probably said the same thing for it as well.
I would rate IBM QRadar a nine out of ten. It is a pretty solid product.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Specialist at a comms service provider with 501-1,000 employees
Not user friendly, doesn't integrate well, and has terrible technical support
Pros and Cons
- "The solution can scale."
- "The solution is clunky."
What is our primary use case?
We use the solution for a variety of tasks. We use it, for example, for authentication, network-related authentication, user-related tasks, and Windows UNIX servers. It's a lot. There's a ton of use cases. I really can't sync right now about every single use case, however, the main things are authentication and network-related systems and all flavors of UNIX Windows.
How has it helped my organization?
It helped our organization in the sense that having it was better than nothing. However, I did not enjoy the product overall and I advised we switch to something else.
What is most valuable?
The user behavior analytics as part of our deployment was okay, even though it was clunky.
The solution can scale.
What needs improvement?
I really didn't like QRadar to be honest. I inherited it. I was part of the reason that we moved over to LogRhythm. The solution just isn't user friendly.
The solution is clunky.
The interface could be much better.
The integration capabilities within the product are not that great.
For how long have I used the solution?
I've been using the solution for about two years at this point. My team has been using it for two to three years, so we have a total of about five years of experience in all.
What do I think about the stability of the solution?
I wouldn't describe the solution as stable.
It was really buggy. Like other app integrations, it wasn't straightforward. It was pretty clunky. We tried to integrate Qualys with it and it wasn't effective. To integrate anything took quite a bit of time and energy. It wasn't easy. When it did, it didn't work properly. It wasn't really pulling in the data correctly.
What do I think about the scalability of the solution?
Scalability was hard as it was on-prem. We needed to add more modules, and had to add more of the servers to stack it. It wasn't that a simple task at all. I wouldn't say that it scales well, although technically, you can scale it.
When we were using the solution, we had ten to 15 users on it. They were anyone from Information Security Engineers to regular IT admins.
How are customer service and technical support?
Technical support was awful. We often didn't even have any assistance available to us. On a scale from one to ten, I'd rate them at a three. We were very unsatisfied with the level of support we received. They just simply weren't helpful when it came down to it.
Which solution did I use previously and why did I switch?
The organization didn't previously use a different solution before choosing QRadar.
We actually switched to LogRhythm as I didn't like how the solution was working for the organization.
How was the initial setup?
I didn't handle the initial setup. It was handled before I arrived at the organization.
What other advice do I have?
I'm not sure of which version of the solution we're using.
I wouldn't recommend the solution. I'd probably tell others to shy away and look at other products like possibly Splunk, however, it's a pricey option. LogRhythm is pretty good. We're having some issues with it. That said, for the most part, it's okay.
Exabeam also seems like it might be a good option. I haven't worked with it personally, however, I've had some experience with a POC.
Overall, I would rate the solution at a three out of ten. We didn't have a good experience with it. If it offered, for example, easier behavior analytics, easier integrations, better interface, supported model integration, and a good user interface to perform analysis I might rate it higher. Basically, it just needs to be much more user-friendly.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager, Security Architecture & Operation, Corporate Security at Omantel
Good reporting and integration is easy, but searching is slow and the dashboard needs to be improved
Pros and Cons
- "Integration is very easy and the reporting is good."
- "The dashboard is pathetic and it takes a long time to perform a search."
What is our primary use case?
This is a security monitoring product and the primary use case is to detect strange behavior by users. For example, if we have a user that has not used the service for a long time and then all of a sudden, somebody logs in one night. This is not normal and the system will detect it. This is just one example of many use cases.
What is most valuable?
Integration is very easy and the reporting is good.
What needs improvement?
This is a good product, although it does require some fine-tuning.
The dashboard is pathetic and it takes a long time to perform a search.
The graphics need to be improved.
Providing good support is something that they need to work on.
It would be helpful if IBM published more use cases.
For how long have I used the solution?
We have been using QRadar UBA since 2016.
How are customer service and technical support?
The issue that I have with technical support is related to their large pool of resources. If you are lucky then you get good support, but sometimes you get pathetic support. Suppose you open a ticket, there are times where it will be very good, but the quality is intermittent.
Which solution did I use previously and why did I switch?
I have experience working with Splunk and I find that the searching capabilities are better with it. Also, the processing time in Splunk is better. With QRadar UBA, when you have three, four, or five rules together, it takes more time to respond.
How was the initial setup?
The complexity and length of time required for the initial setup depend on the requirements. There are some out-of-the-box features that can be implemented right away, but some equipment is not supported directly, so you need to write a DSM (device support module).
Implementing a DSM takes some time, although it will depend on the log source. If the log source is fully compatible then it will be very quick. However, if it is not compatible then you will need to do some scripting and other work.
What's my experience with pricing, setup cost, and licensing?
The price of this product is high.
What other advice do I have?
QRadar is not perfect. It's a good security monitoring product that can provide threat intelligence, but it cannot do it alone. You need to integrate with many other things, such as IBM Orchestrator. Also, you need to have X-Force. After these kinds of things are integrated, it works a little bit better.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Application Security Architect at Bank Al Habib Limited
Stable and reliable but needs better integration with extensions
Pros and Cons
- "I really like the feature we have with the logs, that if there are any credit card numbers being used, like a PII, you can just use rejects and you can mask it. This is a really good feature in QRadar."
- "There should be an extension where we can get the reports. This could be an extension to the dashboard with the Guardian or another product with limited technology, for example IPS. Now, we only have IBM. Basically, it needs more and more integration models."
What is our primary use case?
Our primary use case with IBM QRadar User Behavior Analytics is seeing if there are log-ins from the same ID's but from different locations, this is one use case. Or if MAC addresses keep changing, this is another use case. Lastly, if the risk level is high, like with different IP's. These are the three use cases we have.
What is most valuable?
I really like the feature we have with the logs, that if there are any credit card numbers being used, like a PII, you can just use rejects and you can mask it. This is a really good feature in QRadar.
What needs improvement?
In terms of what could be improved, it would be easier if you didn't have to long escape for a bar sync. If you have to, the logs are not automatically barred, so you have to guide the whole atmosphere.
Additionally, there should be integration with IBM Guardian.
Lastly, there should be an extension where we can get the reports. This could be an extension to the dashboard with the Guardian or another product with limited technology, for example IPS. Now, we only have IBM. Basically, it needs more and more integration models.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for a month or two.
What do I think about the stability of the solution?
In terms of stability, in my current company, QRadar is working fine. But in my previous organization that was using QRadar, we experienced some QRadar failures. There were two or three times the data was wiped out instead of transferring to EGA and we had to restart QRadar from scratch and all the data was lost. It happened a lot. Maybe it was due to lack of management since it was a new company.
How are customer service and technical support?
We do have experience with support. We get support from the IBM people in Karachi, Pakistan.
They're good.
How was the initial setup?
The initial setup was really easy, it was really straightforward. I got it done in one day.
What other advice do I have?
What advice would I give? I want the certification to be very honest. I typically like the hands-on with QRadar, they're quite different.
On a scale of one to ten, I would rate IBM QRadar User Behavior Analytics a seven.
I have used other solutions, like LogRhythm, for a few use cases like ransomware detection, etc.. and there were less false positives there. With the ransomware especially, it was very thin there. We actually have very few use cases and there were lots of false positives with QRradar. If I compare the AI function and the logarithms I think it needs some improvement.
It is a complex product compared to LogRhythm.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy General Manager - Network Security at a tech services company with 201-500 employees
Stable and solid security intelligence but lacks some functionalities
Pros and Cons
- "QRadar shows very effective correlations. If you combine all the logins plus user behavior and the current intelligence, it gives a very good correlation for business. I think it reduces the false positives in user activity monitoring because there is a lot of social information to correlate with other data."
- "From a functionality point of view there are issues sometimes."
What is our primary use case?
We use IBM QRadar for monitoring user behavior in order to baseline the user activity. Then we print use cases around those behaviors to see if anything stands out. We can then see if something is going wrong in the enrollment from a user activity point of view.
What is most valuable?
In terms of valuable features, QRadar shows very effective correlations. If you combine all the logins plus user behavior and the current intelligence, it give a very good correlation for business. I think it reduces the false positives in user activity monitoring because we have a lot of social information to correlate with other data.
What needs improvement?
From a functionality point of view, there are issues sometimes. There is a component in QRadar where all these certifications need to be installed, like a UPN. Sometimes we experience functionality issues where the logging, indexing, and searching were not working. I have personally seen it misbehaving. Sometimes we need to restart it. In some cases when it was malfunctioning we needed to contact support to resolve the issue. I don't see any issues in the integration model with a UPN from a usability point of view, but with functionally you can experience a lot of issues.
For how long have I used the solution?
I have been working with IBM QRadar User Behavior Analytics for two years.
What do I think about the stability of the solution?
I have not seen any issues with the stability of the solution either.
What do I think about the scalability of the solution?
I have not seen any issues with the scalability of the solution
How are customer service and technical support?
The technical support is fine now. I was not happy with the support when we started with this solution in 2017. If you look at that first year, 2017 to 2018, they had lots of support issues. We logged the cases and they would only call us back depending on their resources. There were no options to call them on a landline or a hotline number. They needed improvement there. They should have had a dedicated support response. Over the last year I have seen an improvement. I used to wait for a week to get a call back from them, but now, when you have critical tickets they will respond in two or three hours, depending on the criticality of your support case. They have improved.
How was the initial setup?
The initial setup was neither straightforward nor too complex. It did take some effort to implement, but it was manageable. We did not see any issues implementing it. We actually completed it in three to six months. When we initially implemented it we used some fresh use cases and observed the performance but these were all completed in three to six months. The initial deployment took hardly one week.
What's my experience with pricing, setup cost, and licensing?
Regarding the price, it is a bit high for normal customers. It is better for enterprise-class customers where they get a licensing model for MSSP for enterprises.
Which other solutions did I evaluate?
We are a service provider company, so our recommendations depend on the customer's preference. The best we can do is propose the solution based on support, pricing, and their requirements.
What other advice do I have?
Our customers are satisfied with the product and they are not looking for anything else. I would recommend the product.
On a scale of one to ten I would rate IBM QRadar User Behavior Analytics a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Trellix Endpoint Security Platform
Grafana Loki
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?