Try our new research platform with insights from 80,000+ expert users
Founder at a university with 11-50 employees
Real User
Jul 8, 2021
Stable, easy to set up, and has good support
Pros and Cons
  • "I think the QDI is very good."
  • "The threat detection needs improvement, they have many false positives."

What is our primary use case?

This product helps to build a strong architecture, which is important to avoid problems.

What is most valuable?

I think the QDI is very good.

What needs improvement?

The biggest drawback of this solution is the price.

The threat detection needs improvement, they have many false positives.

It is important to have good architecture. If you have problems and you don't have a strong architecture you, will have trouble with this solution.

For how long have I used the solution?

I have been using IBM QRadar for three years.

We are using version 7.4.3

Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's a stable solution.

How are customer service and support?

We have many interactions with L2 support when we needed L3 support. I would rate technical support an eight out of ten.

How was the initial setup?

The initial setup is straightforward. We had no problems.

It took approximately a month to deploy.

What's my experience with pricing, setup cost, and licensing?

This price is a little high, so it's an expensive product. It is a good solution but not a cheap one.

What other advice do I have?

I would rate IBM QRadar a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1607811 - PeerSpot reviewer
Founder at a tech services company with 1-10 employees
Reseller
Jun 27, 2021
Priced well and has good support, but it is resource intensive
Pros and Cons
  • "The flexibility is good in terms of pulling log files."
  • "It's resource-intensive."

What is our primary use case?

We are service providers, and we are always exploring tools to accompany existing tools. I am always searching for the best products to meet my clients' requirements. I always look to understand the technology first, learn what benefits we can get from the product, how competitive is it with other tools such as DarkTrace, and Palo Alto.

We are working with this solution, but it is being managed by another vendor.

We are service providers. We are providing SOC service and MSSP services for our clients. 

We are working on various products, not one specific product. We can provide services for any product, in fact, any security solution.

What is most valuable?

There have been many advancements made in the most recent year. There are many add-ons included in the licenses that I have yet to explore.

There have been many improvements. When I worked with this solution at the core technical level, it was a SIEM solution. Many attributes have been added, such as threat intelligence, SO solutions, automation, and OT security. Many other platforms have been included as part of IBM QRadar.

The flexibility is good in terms of pulling log files.

What needs improvement?

Automation is an area that people are looking for. IBM does have the SO solutions platform, but it would be more useful if they could have predefined use cases rather than using more generic ones. It would be much better if they could customize their use cases.

It's resource-intensive.

The IBM QRadar team has to be proactive and they have to be informative about the product.

They don't want to spend too much money on the SIEM because it is obviously resource-intensive. But the SIEM is a very useful product when you have good resources and good software.

For large organizations, that want to integrate all of the log sources, the pricing will be too expensive. This is the main reason that clients are not interested in SIEM solutions.

For how long have I used the solution?

I have been working with IBM QRadar for approximately four years.

I moved into consulting, at the architectural level. I'm not working at the core level but I know the basics of QRadar and how exactly it functions. 

How are customer service and technical support?

Technical support is good. 

My personal experience was fantastic. They are always good and we have never had any problems.

There are a lot of online resources available.

What's my experience with pricing, setup cost, and licensing?

When compared with other SIEM solutions, QRadar is considerably less expensive. I would like to compare it with Elasticsearch because they have different pricing strategies.

QRadar is events per second, EPS-based, whereas Elasticsearch is resource-based. You have to estimate based on how many resources will be used in the infrastructure, irrespective of log resources and log volumes. 

They are charging based on the resources. 

Which other solutions did I evaluate?

I'm exploring the Elastic Stack Elasticsearch currently. Splunk is out of scope for us right now, we're not interested in that. Sentinel is one that we are interested in.

What other advice do I have?

There are many competitive tools that are emerging regarding XDR solutions or SO solutions, which are capabilities that QRadar offers.

The competition is very different from the geographical locations.

For the Indian market, locally, they are still working on the old SIEM structure. It is a very generic SIEM model. Western countries, especially North American clients, are advanced in terms of moving the infrastructure to the cloud. Some have OT security and they're also doing some Office 365 advancements and several advanced search engines for endpoint detection.

They are expecting that nothing is left behind without using any licenses. Microsoft provides part of the security services if you go with the EFI license.

As vendors, we need to counter with the important visibility areas, and the critical access, which needs to be monitored as part of security. 

I would rate IBM QRadar a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
PeerSpot user
Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
reviewer1590123 - PeerSpot reviewer
Senior Security Engineer at a wholesaler/distributor with 10,001+ employees
Real User
Jun 23, 2021
Effective data correlation features, scalable, and helpful technical support
Pros and Cons
  • "One of the most valuable features of this solution is it has very good data correlation."
  • "In a future release, the solution could provide malware analysis."

What is our primary use case?

This a Security Information and Event Management (SIEM) solution and we use it for many purposes.

What is most valuable?

One of the most valuable features of this solution is it has very good data correlation.

What needs improvement?

In a future release, the solution could provide malware analysis.

For how long have I used the solution?

I have been using this solution for approximately three years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The scalability is good and we have approximately 200 users using this solution.

How are customer service and technical support?

The technical support has been very good in my experience.

How was the initial setup?

The initial setup was straightforward.

What's my experience with pricing, setup cost, and licensing?

There is a license required for this solution. There are some limitations depending on what license you purchase.

What other advice do I have?

I would recommend this solution.

I rate IBM QRadar an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vice President at a financial services firm with 10,001+ employees
Real User
Jun 10, 2021
Provides a complete platform for log ingestion, correlations and runtime
Pros and Cons
  • "The product provides a complete platform for ingesting the log, doing the correlations and handling the runtime."
  • "The solution should enhance its capabilities of UEBA and AI/ML tech modeling."

What is most valuable?

The product provides a very defined solution. It provides a complete platform for ingesting the log, doing the correlations and handling the runtime.

What needs improvement?

The solution should enhance its capabilities of UEBA and AI/ML tech modeling.

For how long have I used the solution?

I have been using IBM QRadar for approximately four years.

What do I think about the stability of the solution?

IBM QRadar is a very stable product.

What do I think about the scalability of the solution?

The product is very scalable and this can be done to a number of endpoints and towers. However, this is not very feasible, as it depends on the available in-house infrastructure. 

How are customer service and technical support?

Technical support is very helpful. They are very knowledgeable. While the geographic location can sometimes pose a challenge, my overall experience with the technical support team has been very positive.

How was the initial setup?

The complexity of the initial setup is intermediate. It is neither straightforward nor complex but somewhere in the middle. A person with experience working in a security operation center and who is experienced with correlation rules and use cases can directly configure into the solution. 

What other advice do I have?

Someone considering implementing IBM QRadar should possess a good knowledge of his own infrastructure. He should have all the documents in place. While IBM provides very good implementation support, a complete inventory and technology detail is required, in respect of how the application is flowing, how the infrastructure is connected, and the version and inventory relationship.

I rate IBM QRadar as an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1584831 - PeerSpot reviewer
Solution Architect Cybersecurity at a tech services company with 501-1,000 employees
Real User
May 26, 2021
Protects our network from various threats
Pros and Cons
  • "The threat hunting capabilities in general are great."

    What is our primary use case?

    We use this solution for advanced threat detection, insider threat monitoring, risk and vulnerability management, and unauthorized traffic detection regarding our network. We can monitor and detect web attacks with it as well. 

    Within our organization, there are roughly 2,000 to 3,000 employees using this solution. As of now, we don't have any plans to increase our usage of IBM QRadar.

    How has it helped my organization?

    The basic use case of this solution is to identify insider threats. Insider threats are the most dangerous kind of threat for any type of organization to secure. This solution identifies who the insider threats are, and also determines if there are any malicious activities taking place inside of an organization itself. In short, it provides us with real-time visibility so we can identify who the insider threats and what malicious activities are occurring inside of our own network. It also protects our web applications from DNS attacks.

    What is most valuable?

    The threat hunting capabilities in general are great. 

    What needs improvement?

    I was going to say that the reporting could be improved, but IBM recently introduced a new cloud-based security service that integrates with QRadar. Now, reporting is much easier than before. I personally can't think of an area for improvement.

    For how long have I used the solution?

    I have been using this solution for two and a half years. 

    What do I think about the stability of the solution?

    This solution is quite stable. 

    How are customer service and technical support?

    We receive 24/7 support via email; however, we don't have to contact support often because we have our own trained team. They handle most issues.

    Which solution did I use previously and why did I switch?

    We used to use Splunk.

    How was the initial setup?

    How complex the initial setup is completely depends on the customer's infrastructure. If there are lots of tools that need to be integrated, then the setup is going to be really complex. I wouldn't say that the initial setup is complex, it's more moderate than anything. 

    Deployment took two to three weeks from beginning to end.

    What's my experience with pricing, setup cost, and licensing?

    The price of this solution is a little high.

    What other advice do I have?

    Before implementing a new solution, you need to understand your network infrastructure completely. You need to determine if third-party integration is supported or not. IBM Qradar supports a lot of third-party integration because third-party tool integration is often required. 

    Storage also needs to be defined properly as logs need to be kept for a certain amount of time. If you have to store logs for three to six months, then you'll need to ensure that you've evaluated the storage capacity properly.

    Overall, on a scale from one to ten, I would give this solution a rating of eight. We're very satisfied with it. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1520922 - PeerSpot reviewer
    Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees
    MSP
    Apr 17, 2021
    Flexible, easy to use, and scalable
    Pros and Cons
    • "The solution is flexible and easy to use."
    • "IBM is going through some problems with its resources currently making its support response time slow."

    What is our primary use case?

    We are a service provider and we are providing the solution as a managed service for multitenancy security.

    What is most valuable?

    The solution is flexible and easy to use.

    What needs improvement?

    IBM is going through some problems with its resources currently making its support response time slow.

    For how long have I used the solution?

    I have been using the solution for a couple of months.

    What do I think about the stability of the solution?

    I find the solution reliable. 

    What do I think about the scalability of the solution?

    The solution is scalable. We have 15 customers using it at the moment.

    How are customer service and technical support?

    The support could be a lot better by being faster.

    Which solution did I use previously and why did I switch?

    We recently switched to this solution from LogRhythm cloud. One of the main reasons we switched solutions was because it is more scalable.

    How was the initial setup?

    The installation was a little difficult and could be made easier.

    Which other solutions did I evaluate?

    We have evaluated Secureonix and this solution is far superior. We did the implementation of Securonix for two customers and we canceled it. We rolled back those clients onto this solution because Securonix failed on both implementations.

    What other advice do I have?

    I would recommend this solution to others. We have invested in it and we plan on using it in the future.

    I rate IBM QRadar an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
    PeerSpot user
    reviewer1421823 - PeerSpot reviewer
    Deputy General Manager at a comms service provider with 5,001-10,000 employees
    Real User
    Mar 12, 2021
    Correlation done well, fair pricing, and knowledgeable technical team
    Pros and Cons
    • "When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed."
    • "I have noticed the interface has room for improvement."

    What is most valuable?

    We are looking for the entire QRadar spectrum but it has many products. QRadar is a kind of program, we are looking for system modelling, point modelling, network side modelling similar to QRadar network inside, and the capability to correlate between the network and endpoint. Most of the SIEM's have to rely on when it comes to network side third party or separate network traffic analysis. When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed.

    What needs improvement?

    Since we have not used the solution very long my information is limited when it comes to improvements. I have noticed the interface has room for improvement.

    For how long have I used the solution?

    I have been using the solution for two years. However, my company has not deployed the solution yet and we are in the early stages of testng.

    How are customer service and technical support?

    The solution has a good technical team.

    How was the initial setup?

    The installation is complex. There is some overloading that happens, this could be simplified and made easier by allowing all key features on the first level dashboard to be viewed.

    What's my experience with pricing, setup cost, and licensing?

    When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products. Even though the price can be a little high sometimes there product is number one. They have a wide range of products.

    Which other solutions did I evaluate?

    We have compared Securonix and many other solutions to this one.

    What other advice do I have?

    I rate IBM QRadar a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    reviewer1216545 - PeerSpot reviewer
    Cybersecurity Business Development Manager at a comms service provider with 10,001+ employees
    Real User
    Mar 1, 2021
    Helpful customer support, overall good functionality, and reliable
    Pros and Cons
    • "Overall a great solution."
    • "There needs to be better integration with other applications."

    What is our primary use case?

    I am currently working in the Brazilian operation of my company. I have a project in the airline industry in Brazil. This project improves the correlation of logs. There is another company I ticket to improve the solution, they have chosen to correlate the logs. We have SOC, Security Operation Center in Brazil, with 53 employees. We developed all these solutions in Brazil and it is in operation in 34 countries. 

    What is most valuable?

    Overall a great solution.

    What needs improvement?

    There needs to be better integration with other applications.

    What do I think about the scalability of the solution?

    We have approximately 40 users using the solution.

    How are customer service and technical support?

    The technical support is good.

    How was the initial setup?

    The installation is complex.

    What about the implementation team?

    We do the deployment for the solution.

    What other advice do I have?

    I rate IBM QRadar a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
    Updated: December 2025
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.