My primary use case is for security monitoring. We activated freeze, proxy and firewalls and we collect data from them. We receive alerts and customize that according to our customer environments.
Senior Security Architect at a tech services company with 10,001+ employees
Has somewhat of a new structure recently compared to the last gen. They have moved from the standard UI based infrastructure.
Pros and Cons
- "QRadar has somewhat of a new structure recently from last gen. They have moved from the standard UI based infrastructure."
- "It has improved my efficiency."
- "The Indian tech support is not helpful."
- "It is not app based."
What is our primary use case?
How has it helped my organization?
It has improved my efficiency. It has also reduced the implementing time. So we have reduced the time we are getting it readily available and you can just do small customizations. We can also do automation, as well using QRadar.
What is most valuable?
QRadar has somewhat of a new structure recently from last gen. They have moved from the standard UI based infrastructure. There are multiple aspects coming in which are actually plugin and play kind of stuff, we don't have to write rules, we don't have to create dashboards and all. For example, on the dashboard we have user behavior analytics. And, it is very helpful for us to use customization and build from scratch.
What needs improvement?
There are other solutions out there that have made it app based. They have a lot of apps available and they are readily integrated with other tools, as well.
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,038 professionals have used our research since 2012.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
It is very stable. I've seen this product grow since it started. It initially started with another company and then it was bought by IBM.
What do I think about the scalability of the solution?
This tool is very user friendly, and is scalable. But, we do use other products in tandem with it.
How are customer service and support?
There are three zones that make up the technical support team, one is Asia Pacific(where the people from India are IBM India they work in that particular region), there are Europe(people from the UK and the Netherlands) and America (the people from the US). When comparing these support teams, the Indian team is lacking.
What was our ROI?
There are an abundance of customers in the market who are actually using QRadar for their security monitoring purposes. This is a real advantage of this solution.
Which other solutions did I evaluate?
We compared it to Splunk. The only difference between QRadar and Splunk is that Splunk works on the data analytics, This makes it easy to help create those data lakes and searches whereas QRadar does not focus on that. The SQL database on the back end, takes some time and it's not so flexible in data storage or data lake creation, so that is the only backfall of QRadar.
Additionally, Splunk is app based, and QRadar is not app based.
What other advice do I have?
There are new things that are coming up in QRadar, such as AI to IBM Watson. This is going to create a huge impact in these types of solutions, because we don't have an artificial intelligence coming in. There are other tools that have artificial intelligence, but IBM QRadar getting integrated with artificial intelligence is the next step.
It should be noted that the QRadar type products are actually changing their strategy. they will move on to the next stage that is called "Threat Hunting." Instead of waiting for some attack to happen and getting an alert, the new solutions will try to find out those suspicious activities in your network or environment and resolve it before it creates havoc.
Disclosure: My company has a business relationship with this vendor other than being a customer: I am a reseller.

Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
It is not a user-friendly program.
Pros and Cons
- "A nice benefit is when we go to the process of selecting our youth cases, they go by building blocks. QRadar links it to building blocks."
- "The initial setup was complex, and it took six months."
- "QRadar needs a lot of fine tuning"
What is our primary use case?
My primary use case for this solution is to monitor security events in our cloud environment.
What is most valuable?
They do have a way to pre-configure or have pre-configurations for companies that are starting and they don't know too much about SIEM or working with SIEMs. The solution uses SIEM to get the information to the managers so I will say that they have an ongoing boarding process that is very good if you are starting because it already has what you need to start up.
In addition, they have more HIPAA. It's a pre-order on QRadar, so when we go to the process of selecting our use cases, they go by building blocks. QRadar links it to building blocks so we don't have too much to cut on it.
What needs improvement?
It is not a user-friendly program. It is a very glorified Excel program. I would love to see a more user-friendly version in a future rollout.
In addition, the management services team needs some improvement. They are, at times, confused with our requests.
Network Breach
Another problem with QRadar, is that they have a very big signal protection. This needs to be fixed. You can only see what you know. Let me give you an example of how I feel. Here is an analogy for you. Let's say you are a cowboy and you're on wild on the plains. You go out there and get your cows back, right? So you have a noose, you have your hat, your boots, your spurs, you are a real cowboy, right? But you are working on a, this is my opinion right? But you are working on building cars. So how would you look being fully dressed in all your gear, selling cars? It's like you are ready and prepared, you have your tools, but you don't like those rulings. You feel like you are in the wrong place.
Efficiency of Security Team
No, it has not improved the efficiency of our security team. They have an integrated mobile with Watson so what this means is when we have an event that has a high magnitude, Watson takes it and investigates, right? So every time I see an offense, I see Watson has gone and investigated this. What am I expecting from AI to do? I want to see location, what happened, what is it, sources, stuff like that. They just give you a routing chart of what I think was involved. I can do that with my bare hands, I don't need Watson to do that. So why am I paying for AI?
For how long have I used the solution?
One to three years.
How are customer service and technical support?
On a scale of one to four, I would rate it a four. We have had some issues. For example, the other day I wanted to add a new correlation. So I opened a ticket for that new correlation. I went to go change my correlation, but they took so long to get the correlations down. I had to go ahead and open the ticket before I got to change the management process.
Which solution did I use previously and why did I switch?
I have used Splunk in the past.
How was the initial setup?
The initial setup was complex, and it took six months.
What's my experience with pricing, setup cost, and licensing?
It is a pricey product. It is very expensive.
Which other solutions did I evaluate?
QRadar needs a lot of fine tuning. I had to schedule meetings with IBM for help. For example, one of the things that we were having difficulties with QRadar is that the detection rules are sent by IBM and we wanted those detection rules. In one case, I know there's new malware out there, BlackIce, but I am not able in QRadar, because it's a managed service, to go in and create a detection rule that say the malware is out.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,038 professionals have used our research since 2012.
Cloud Security Architect at Nordcloud Oy
It's a state-of-the-art product for security information and event management
Pros and Cons
- "It's a state-of-the-art product for security information and event management (SIEM)."
- "There are a lot of great out-of-the-box features included."
- "The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery."
- "The released patch quality is poor. IBM should test those patches on their side, not on the client's side."
What is our primary use case?
It is under a non-disclosure agreement (NDA).
How has it helped my organization?
- It helps because you don't need an army to execute the project when you do the PoC, and when finally going to production.
- The abundant out-of-the-box features which are operating wonderfully.
What is most valuable?
- It's easy to set up.
- There are a lot of great out-of-the-box features included.
- It's a state-of-the-art product for security information and event management (SIEM).
What needs improvement?
- Slow response sometimes and a not-so-helpful staff there. So make the support better, and you could succeed even more.
- The released patch quality is poor. IBM should test those patches on their side, not on the client's side. So, there are a lot of improvement to do.
- I would appreciate if IBM could create another more intuitive, easier way (intuitive UI) to perform advanced searches rather that just counting on regular expressions.
For how long have I used the solution?
One to three years.
How is customer service and technical support?
The quality of technical support depends on the IBM support person. Sometimes, it's hard to get the right person on the other side. A ticket coordinator could be the key to better quality delivery.
They are sometimes slow to respond and unhelpful.
What other advice do I have?
I highly recommend this product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at Global Solutions Services
Log correlation is very useful for processing alerts
Pros and Cons
- "Log correlation is very useful for processing alerts. It serves to follow up alerts in real-time, building an entire workflow."
- "Its architecture is very complicated."
What is our primary use case?
- CRM and billing system
- 100 multiple technology servers: Windows AD, Linux, HP-UX, etc.
- 40 firewall multiple routers
- Cisco Nexus switches
How has it helped my organization?
Log correlation is very useful for processing alerts. It serves to follow up alerts in real-time, building an entire workflow.
What is most valuable?
- DSM parsing
- Log correlation
- X-Force connectivity
- Ease of DSM customisation
- Multiple reports
What needs improvement?
- Data encryption
- Flow encryption
- Third-party compliance
- Its architecture is very complicated.
- Its hardware is Lenovo-based.
For how long have I used the solution?
Three to five years.
Disclosure: My company has a business relationship with this vendor other than being a customer: IBM Partner
Software Trainee at a tech services company with 1,001-5,000 employees
Senses, tracks, and links significant incidents and threats
Pros and Cons
- "Senses, tracks, and links significant incidents and threats."
- "The tool is already automated in many ways, but there are some additional functions which should be automated, like sending an email, mobile notification, and integration of XFS."
What is most valuable?
Almost every feature is useful. In particular:
- Sense and detect fraud, both insider and advanced threats.
- Sense, track, and link significant incidents and threats.
What needs improvement?
The tool is already automated in many ways, but there are some additional functions which should be automated, like sending an email, mobile notification, and integration of XFS.
For how long have I used the solution?
Less than one year.
What other advice do I have?
Overall, I love this product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Market Enabling Solutions at Raksha Technologies Pvt Ltd
In one single pane of glass, we can see all the issues. Though, the architecture could be improved.
Pros and Cons
- "On the back-end, Watson helps me figure out an exact problem, sometimes giving me the result."
- "It saves a lot of time. We integrate the customer's firewall with all their networking devices."
- "This console gives you the entire view, which makes life easier and allows you to take precautionary measures."
- "The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging."
What is our primary use case?
Its primary use case is for people who want to manage all of their logs with analytics and correlate that between different security devices whose logs are related.
This solution is performing well.
How has it helped my organization?
It saves a lot of time. We integrate the customer's firewall with all their networking devices. If there is an issue, it helps us do the proactive work before it becomes a bigger issue. We are able to pinpoint issues and solve them.
Additionally, it is very easy to figure out. In one dashboard, we can see all the issues. There is no need to login to every device. In one single pane of glass, we can see everything.
What is most valuable?
Watson, which is an artificial intelligence, is the most valuable feature. On the back-end, Watson helps me figure out an exact problem, sometimes giving me the result. I never would have imagined this before.
What needs improvement?
The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
It is a combination of multiple factors. The issues is from the customer side, not from QRadar. If you are able to get the right details from the customer, this solution is scalable.
How are customer service and technical support?
I am not involved with technical support because I am in pre-sales.
Which solution did I use previously and why did I switch?
Factors in switching were the console view, as well as Watson. IBM Watson makes a huge difference on the product side.
What's my experience with pricing, setup cost, and licensing?
I do not have control over pricing, though I do help customers with their sizing.
Which other solutions did I evaluate?
I select the vendor based on the customer's requirements. On the customer side, pricing is very important. They also consider the support to be an important factor.
My present organization does mostly IBM business. We have a very good rapport with the IBM team. We have won a lot of cases against competitors. We get trained frequently, so if there is an update, then we are prepared.
We are able to see the rapid growth of IBM through QRadar compared to the other SIEM tools.
What other advice do I have?
I would rate it a seven out of 10. I have had some challenges integrating this solution.
Each organization is looking for security. If you have a SIEM tool, you can integrate it with all of your security devices, and get all your security logs. This console gives you the entire view, which makes life easier and allows you to take precautionary measures.
People who handle only four or five security devices spread across the globe should go with this SIEM tool.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Network Security Engineer at a wellness & fitness company with 10,001+ employees
It is the core of our entire SOX
Pros and Cons
- "It is the core of our entire SOX."
- "Due to the skills shortage, we are able to use it from the standpoint of bringing in a lower level employee or a person who may not have security knowledge."
- "We run 65 servers globally with just two people: an engineering person and me."
- "The technical support is poor. Mostly because when I open a PMR for IBM, I am stuck with Level 1 staff. As an engineer, nothing that I am bringing them does not require Level 2 or Level 3 support."
How has it helped my organization?
QRadar improved risk assessment and vulnerability, plus it has reduced some staff. It has also improved the training abilities of the people who use it, e.g., IR teams. It is the core of our entire SOX. Therefore, we use it for everything through training all the way up through management.
Due to the skills shortage, we are able to use it from the standpoint of bringing in a lower level employee or a person who may not have security knowledge. We can put them in front of the product and they will still have the information that they need and have them at a level where they can run the system. Also, products, like Watson, make it work better.
What needs improvement?
The overall workload automation should be built into it. Part of the efficiency side of it is the ability to take the information as it comes in and assign it into a group. Now, the team leader no longer needs to assign it manually. He manages the workflow as it comes in directly to the individuals. Then, the individuals respond on it. As it closes, it goes back to the workflow, recording the amount of time it took for them to close it. It should show:
- How long did it take to get assigned?
- How long did it take for the person to open it?
Then, you can show that a person may have issues opening network problems.
Network Breach
We have not suffered a network breach.
Efficiency of Security Team
The solution has improved the efficiency of our security team.
Events per Day
We are at 115,000 events per second.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
We run 65 servers with just two people: an engineering person and me.
What do I think about the scalability of the solution?
We have 65 servers globally, and I just got my own.
How is customer service and technical support?
The technical support is poor. Mostly because when I open a PMR for IBM, I am stuck with Level 1 staff. As an engineer, nothing that I am bringing them does not require Level 2 or Level 3 support. Most of the stuff that I open ends up code changes or bug fixes.
Our company is far more mature than most. Our issue is that the support is slow.
How was the initial setup?
It was a whole different product when we installed it.
What other advice do I have?
The most important criteria when selecting a vendor: stability. The security space is tough. Unlike a lot of other spaces, IBM will not be bought anytime soon as a 100 year-old company.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Member at CIFAL Argentina
The scalability is awesome, because QRadar includes other solutions in the same console
Pros and Cons
- "The scalability is awesome, because QRadar includes other solutions in the same console."
- "The user interface needs improvement."
How has it helped my organization?
QRadar improved risk assessment and vulnerability, plus reduced staff.
What is most valuable?
The threat protection integration with other vendors.
What needs improvement?
The user interface needs improvement.
Network Breach
We have not suffered a network breach.
Events per Day
Our deployment collects nearly a 100 events a day. We often wield a backlog.
What do I think about the stability of the solution?
Stability is great.
What do I think about the scalability of the solution?
The scalability is awesome, because QRadar includes other solutions in the same console.
How is customer service and technical support?
I have not used technical support.
How was the initial setup?
I was not involved in the initial setup.
Which other solutions did I evaluate?
We evaluated Check Point, but went with IBM because of price.
What other advice do I have?
Most important criteria when selecting a vendor: Our customers need a cross of different units which make up a better solution for them.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Trellix Endpoint Security Platform
Grafana Loki
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?