I used the IBM QRadar product from 2015 until 2017.
Operations Analyst at a logistics company with 51-200 employees
Helps a company when investigating a case and with preventive actions
Pros and Cons
- "An engineer can live-monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions."
- "QRadar needs to be improved on the storage side, particularly when the disc exceeded the maximum threshold."
What is our primary use case?
How has it helped my organization?
When the WannaCry attack happened, QRadar helped the company a lot with the investigation of the firewall, antivirus, and other appliances.
What is most valuable?
The "Network Activity" feature was really good. An engineer can live monitor all the flow happening in real-time. This would help us a lot while investigating a case, and it would even help us with preventive actions.
What needs improvement?
QRadar needs to be improved on the storage side, particularly when the disc exceeded the maximum threshold.
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,349 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Engineer Consultant at a tech services company with 501-1,000 employees
Its correlation and the parsing features result in good scalability and performance
Pros and Cons
- "The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
- "The weak signal detection with QRadar needs improvement. You can detect what you know, but what is unknown to the rule engine can't be detected."
What is our primary use case?
My use case is the deployment of an X-Force successful connection with a botnet and malware website. An X-Force feed is free with QRadar.
I have been using the product for three years now. I used it for six month at an internship to PoC some different SIEM and for two and a half years as an administrator. Now, I am using it as an architect.
How has it helped my organization?
Previously, we had to do a lot of debugging when we wanted to change our firewall policy to find out which rule was blocking things, etc. With Qradar, when you integrate the logs of the firewall, you have with two clicks, the info in real-time.
What is most valuable?
The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance.
What needs improvement?
The weak signal detection with QRadar needs improvement. You can detect what you know, but what is unknown to the rule engine can't be detected, similar to a base rule of SIEM.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
Sometimes, but not from the system itself, but from the amount of logs it has received.
What do I think about the scalability of the solution?
Not at all.
How are customer service and technical support?
Technical support is good when they using WebEx. By portal, they are slow and inefficient.
Which solution did I use previously and why did I switch?
My service since the beginning has been to only sell and manage QRadar.
How was the initial setup?
It is very easy to deploy. It is not a user-friendly way to deploy, but for IT guys who have the skills of Linux servers, etc., it is easy.
What's my experience with pricing, setup cost, and licensing?
Think what you will integrate into QRadar. It is a SIEM. You need to send it logs, but not everything.
Pricing (based on EPS) will be more accurate.
Which other solutions did I evaluate?
I had the chance to test some other products, and there is a lot of them on the market. However, when you have to deploy and manage it, not just demo it, it is a total different story.
QRadar is not perfect, but I have had the chance to manage ArcSight, Sumo Logic, Unomaly, and RSA for some specific features, and comparatively, QRadar is good
What other advice do I have?
Think scalability and make sure your product can be integrate into QRadar.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
867,349 professionals have used our research since 2012.
Network and Security Technical Team Leader at a wholesaler/distributor with 201-500 employees
A good integration with the artificial intelligence engine of Watson
Pros and Cons
- "It does good correlation for events. It does good general analysis, and it has good apps as well."
- "It has a good integration with the artificial intelligence engine of Watson."
- "IBM needs to invest more into the collaboration with other vendors."
- "The implementation and configuration are not easy."
What is our primary use case?
We work with it in the banking sector. We had torrent limitations and big banks could join them. It has performed well. However, the limitation is not easy, so the product is not easy.
You cannot get the real value of the product unless you combine it with the other products from IBM, like BigFix, the full integration of Vulnerability Management, and so on.
How has it helped my organization?
The product is great. It does good correlation for events. It does good general analysis, and it has good apps as well.
What is most valuable?
- The artificial intelligence ease of integration; it has a good integration with the artificial intelligence engine of Watson.
- There is good collaboration between IBM Cloud and all IBM customers.
What needs improvement?
The implementation and configuration are not easy.
We would like to see user behavior analysis in the next release. IBM claims they have this feature, but I do not see it as mature as in Splunk.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The stability of the solution is great.
What do I think about the scalability of the solution?
Technically, there are no scalability issues.
How is customer service and technical support?
Support is good. The technical engineers seem they know what they are doing. Though, the escalation response is bad. An escalation takes time, because the response time is not as fast as it should be.
How was the initial setup?
The implementation is complex.
What's my experience with pricing, setup cost, and licensing?
It is expensive. It is not a product that I can provide for SMBs. It is a program that I can only provide for really large enterprises.
Also, the maintenance costs are high.
What other advice do I have?
IBM needs to invest more into the collaboration with other vendors.
If you want to go to IBM, do not just go for QRadar. You need QRadar and all the products that surround QRadar, especially BigFix, because the product is ten times stronger with it.
Most important criteria when selecting a vendor:
- The technical features of the solution.
- The people in my region at the vendor.
- The perspective of the project manager on the customer side.
- Data involved and time of the implementation.
- The needs of the customer.
- The cost of the project.
- Training involved.
Disclosure: My company has a business relationship with this vendor other than being a customer.
It has a logical, user-friendly GUI
Pros and Cons
- "IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot."
- "It has a logical, user-friendly GUI."
- "Dashboards and reports could provide better visualization of SIEM activity."
What is our primary use case?
We used QRadar SIEM over Juniper Secure Analytics platform.
The company profile is telecom. The infrastructure has a large geographical spread.
How has it helped my organization?
IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot.
What is most valuable?
- It has a logical, user-friendly GUI.
- Very easy to drill down in offenses and get to the bottom of raw data.
What needs improvement?
Dashboards and reports could provide better visualization of SIEM activity.
An executive or CISO dashboard would be nice to have by default.
For how long have I used the solution?
Three to five years.
What other advice do I have?
The tool gets better value in the hands of an experienced security analyst.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr SIEM Consultant at a tech services company with 51-200 employees
Built-in rules are enabled by default and tunable to meet the specific needs of each organization.
Pros and Cons
- "Network-Based Anomaly Detection (NBAD): Using NetFlow, JFlow, SFlow, or QFlow (all 7 layers), offenses are detected as a response when a rule is triggered."
- "Some UI enhancements would be nice, such as exporting custom event properties and the ability to export rules."
What is our primary use case?
As a PS consultant on projects where the customer is transitioning from a competitor's SIEM to QRadar, they are very pleased when they see the number of quality offenses being caught soon after implementation and integration of log sources just from the out-of-the box rules enabled by default.
How has it helped my organization?
As a Professional Services consultant, I have heard many reports of how QRadar SIEM has quickly identified offenses which the users were unaware of previously. In addition to giving CISO’s gained visibility and increasing security posture, QRadar adheres to an organization's regulatory compliance across a number of industries (i.e. Healthcare, Financial, Retail, Energy and Government)
What is most valuable?
- Correlation Rule Engine, built-in use cases: QRadar has the highest number of built-in use cases among any SIEM on the market. There are many built-in rules that are enabled by default and easily tunable to meet the specific needs of each organization. The correlation engine automates what is a manual process for many SIEM platforms.
- Network-Based Anomaly Detection (NBAD): Using NetFlow, JFlow, SFlow, or QFlow (all 7 layers), offenses are detected as a response when a rule is triggered.
- QRadar Vulnerability Management: Built-in vulnerability scanner or leverage for other supported scanners to either schedule a scan and/or import the results from a scan. Importing the results enriches the assets profile database to quickly identify assets that have known vulnerabilities.
- X-Force Threat Intelligence: Threat intelligence IP reputation feed which leverages a series of international data centers to collect tens of thousands of malware samples, to analyze web pages and URLs, and to run analysis to categorize potentially malicious IP addresses and URLs.
- App Exchange: Many vendors have written apps to enhance QRadar. The apps are free and enhance your SIEM experience by adding rules and custom event properties. In some cases a new tab. You will need to have purchased the third party solution. For example, if you have Palo Alto or Blue Coat, there's a free app for better integration.
What needs improvement?
Some UI enhancements would be nice, such as exporting custom event properties and the ability to export rules.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
We did not encounter any issues with stability.
What do I think about the scalability of the solution?
We did not encounter any issues with scalability.
How are customer service and technical support?
The technical support is very good.
Which solution did I use previously and why did I switch?
We had limited experience with RSA enVision, LogRhythm, and HPE ArcSight. QRadar is much easier and takes less time to implement and maintain.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Go through a vulnerability assessment review for price breaks. A virtualized solution will also cut down on cost.
Which other solutions did I evaluate?
We did not evaluate any other options.
What other advice do I have?
Every SIEM tool has a certain degree of complexity, especially where use cases and rules are concerned. I advise using Professional Services so your SIEM is configured by trained professionals.
Disclosure: My company has a business relationship with this vendor other than being a customer. We are a business partner of IBM.
Solution Architect with 201-500 employees
Improved our organization's total cost of ownership
Pros and Cons
- "Improved our organization's TCO."
- "GUI needs to be improved."
What is our primary use case?
- Users' behavior analytics
- Monitor leakage for data
- Payment card industry compliance
- Integration with end points management system
- Integration with Incident Response and Ticketing System
How has it helped my organization?
- Easy to deploy
- Time to value
- Total cost of ownership (TCO)
- Deployment options for on-premise
- SaaS
- Hybrid
What is most valuable?
- X-Force feed
- Watson for cyber security
- App Exchange
- Scalability and licensing model
- Vulnerability and risk management on network topology
What needs improvement?
Needs to be improved:
- Graphical User Interface (GUI)
- Multi-tenancy and domain(s) segregation.
For how long have I used the solution?
One to three years.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Director at MyEyeDr.
It summarizes all the other security products.
How has it helped my organization?
It has improved our ability to research and detect anomalous behavior and activity within our network. It has really helped us in our ability to research active threats. We saw the threats when we implemented it, and we saw that we had all kinds of deficiencies in our network infrastructure that we were unaware of previously.
What is most valuable?
It has the ability to summarize all the other security products and give us a one-stop-shop dashboard.
IBM has added a new UBA (User Behavior Analytics) app to QRadar that uses the cognitive abilities of Watson to detect and prioritize user activity and risks on the network. It analyzes log activity already recorded so it can begin providing insights quickly after installation.
What needs improvement?
I'm anxious to see the Watson integration. We just finished an upgrade of our appliance so that we can be eligible to do the Watson integration. I'm anxious to see how that works.
What do I think about the stability of the solution?
It works well. We've been using it for a year now. It's helped us greatly to cut down on the time it takes to research a problem or to actually find the problem.
What do I think about the scalability of the solution?
In terms of scalability, so far, so good. What we've purchased so far is well with the infrastructure that we have. I know there are options to buy additional components should I need them.
How are customer service and technical support?
We use a business partner for implementation and support. They are always involved with it. They are not IBM.
Which solution did I use previously and why did I switch?
We weren't previously using a different solution. As security becomes more and more important, we added different security components from IBM, with QRadar being the last one. We needed some way to see all the data, all the information, and get it together in one single source of truth.
How was the initial setup?
I was involved as far as picking and approving the solution. I was not involved in the installation.
What other advice do I have?
We try to do everything all at once.
Find the right partner to help you do the implementation.
When picking a vendor, we look for the support, the ease of the installation, and the future of the product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a tech services company
Some of the valuable features are QM, QRM, and forensics.
What is most valuable?
Some of the valuable features are QM, QRM, and forensics.
How has it helped my organization?
There many use cases.
What needs improvement?
I would like to see SOC.
For how long have I used the solution?
We have been using this for three years.
What was my experience with deployment of the solution?
There were no deployment issues.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
Customer Service:
Customer service is very good.
Technical Support:Technical support is excellent.
Which solution did I use previously and why did I switch?
We used another solution and we switched due to false positives.
How was the initial setup?
The setup was straightforward and not complex.
What about the implementation team?
We used a partner and vendor team and we have expertise in-house.
What was our ROI?
The ROI is acceptable.
What's my experience with pricing, setup cost, and licensing?
It is a bit more expensive than some others, SIEM, but it is more efficient.
Which other solutions did I evaluate?
We evaluated AlienVault, McAfee, and Splunk.
What other advice do I have?
It is a good solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Grafana Loki
Trellix Endpoint Security Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
Damian, regarding rule export, the question is what do you want to do with this export. QRadar as probably you know has CMT tool (Content Management Tool) which will allow you export custom rules. though that has been said. Always is the question what next. if you want to import them to other Qradar system then yes you can, if you think about them in category of Yara rules then no you cannot use this export in third party solutions