Information Security Consultant at a tech services company with 51-200 employees
Although it provides incident management of the alerts it produces, this could be improved to allow more restrictions
What is most valuable?
IBM Security QRadar has many valuable features. One of the most valuable features of IBM Security QRadar is the ease of extracting information from raw logs/events, whether the log source sending the events is supported by IBM or not (for example, a custom in-house application) and use this information in creating searches, correlation rules, reports, and dashboards. Another feature is scalability; scaling up a deployment to support more events per second is made simple just by “linking” new appliances to the main deployment through configuration steps that only take minutes to complete. I do not know if I can call this a feature, but a “general” feature of QRadar is that it does not require highly technically skilled personnel to administer. The dashboards and configurations through the web UI are easy to read, understand, and change.
What needs improvement?
Although QRadar provides incident management of the alerts it produces, this area could use a little improvement to allow more restrictions on who can close alerts and easily updating alerts with and reading text templates.
For how long have I used the solution?
I have used IBM Security QRadar for nearly two years now. I use it as a user in my organization’s Managed Security Services division where we monitor clients’ environments. I also work with it as an implementer to deploy and customize it for clients.
What was my experience with deployment of the solution?
Any deployment will have issues. The issues that I encounter with deploying QRadar are raised with IBM Support and are usually solved quickly through applying patches or changing individual files to fix the web GUI issue.
Buyer's Guide
IBM Security QRadar
October 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,655 professionals have used our research since 2012.
What do I think about the stability of the solution?
The causes of stability issues are usually not QRadar, but of misconfigured devices/log sources (for example, sending debug events to QRadar that results in millions of events in a short period of time). However, if a deployment is done correctly, QRadar stays stable.
What do I think about the scalability of the solution?
No, I did not face issues with scalability. One of the great features of QRadar is the ease of scalability. A license upgrade is simply done by purchasing it and applying it through the GUI which only takes minutes to. If an organization wants a larger expansion, all that it has to do is to buy the required hardware with QRadar installed, and “link” it to the main deployment through steps that also take minutes. This new hardware will provide the extra events per second or flows per minute capabilities required for the expansion.
How are customer service and support?
IBM provides support in various regions in the world. The level of technical support is good. Once a support ticket is open, the support team tries to fix it directly or passes it on to higher levels, and will involve the QRadar development team if required.
Which solution did I use previously and why did I switch?
No, I did not use a separate solution, although I have read and heard about different solutions from the various clients I have met with. Clients switch to using QRadar because they say that maintaining and administering other solutions becomes a hassle and requires trained personnel. Another reason clients switch to using QRadar because of cost.
How was the initial setup?
The initial setup of QRadar is straightforward. From the installation perspective, IBM provides one ISO file that can be used to install any of the QRadar components, with the activation key deciding which components to install. From the deployment perspective, QRadar has the ability to automatically detect many log sources sending logs. The out-of-the-box dashboards, searches, reports, and correlation rules allows QRadar to start displaying intelligence and insight on devices, network statistics, authentication, and many more, and to start alerting on offenses and policy violations automatically. Coupling this with the automatically detected log sources, a demonstration of QRadar can only take a few hours from the installation, to automatically detecting a log source such as firewall logs, to getting alerts on excessive firewall denies, port scans, etc.
What other advice do I have?
The advice I would give to others is to work with the implementation team to properly fine tune the out-of-the-box “building block rules” and to enter their network hierarchy in QRadar in order for it to give best results and reduce false positive alerts.
Disclosure: My company has a business relationship with this vendor other than being a customer. We're a value added services security company that is a distributor of Q1-Labs QRadar (now IBM).
System Engineer (Cybersecurity) at Omgea Exim Ltd
A scalable solution with great event and flow collectors
Pros and Cons
- "The event collector, flow collector, PCAP and SOAR are valuable."
- "The solution is expensive compared to other products."
What is most valuable?
The event collector, flow collector, PCAP and SOAR are valuable.
What needs improvement?
Whenever we connect the span port, its device and health status increase the capacity level. So I suggest the mitigation of that part for IBM. Otherwise, it's a good product. We also continuously have issues with technical support because they do not have a prompt response time.
For how long have I used the solution?
We have been using IBM QRadar for the last five years.
What do I think about the stability of the solution?
I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the scalability an eight out of ten. We deploy to many customers and have completed many POCs. We have a four-person team.
How are customer service and support?
The technical support is good, but they are not prompt. I rate them a five out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate the initial setup a ten out of ten. It is deployed on-premises and takes about two to three days to deploy the full environment readiness. But the device integration, rules screening and log onboarding take too long, about three to four months. The deployment was completed in-house.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive compared to other products, and I rate the pricing a five out of ten.
What other advice do I have?
I rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner/Reseller
Buyer's Guide
IBM Security QRadar
October 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,655 professionals have used our research since 2012.
AVP - Security at a tech services company with 501-1,000 employees
Scalable, high visibility, and good technical support
Pros and Cons
- "I have found visibility very helpful for analytics."
- "This solution is on-premise and many customers are moving to the cloud base solution."
What is our primary use case?
IBM QRadar is typically deployed in a SOC environment for security monitoring. It is used for log and packet capturing. It has some supporting technology, such as data leakage prevention and data encryption.
What is most valuable?
I have found visibility very helpful for analytics.
What needs improvement?
This solution is on-premise and many customers are moving to the cloud base solution.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
I have not had any complaints from my clients about the stability of the solution.
What do I think about the scalability of the solution?
The solution is scalable. Our customers that are using this solution are mainly large-sized companies, such as the government.
How are customer service and technical support?
The technical support is very good.
What other advice do I have?
Nowadays cloud stack security is very good. Some of my customers are planning to build their data center over the cloud, or implement cloud-based services using some of the beneficial services, such as threat intelligence services.
I rate IBM QRadar a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Pre-Sale Consultant (Technical) at a tech services company with 51-200 employees
Easy to set up, but we have had some problems with the networking support
Pros and Cons
- "We are using the platform version, which I like."
- "We have had problems with networking."
What is our primary use case?
We are a system integrator and IBM QRadar is one of the security and monitoring products that we implement for our clients. It is used for monitoring applications such as Windows virtual desktop access (VDA) and computer-managed instruction (CMI).
What is most valuable?
We are using the platform version, which I like.
What needs improvement?
We have had problems with networking.
For how long have I used the solution?
I have been using QRadar for about half a year.
What do I think about the scalability of the solution?
We have not tried to scale because it is installed all in one machine.
How was the initial setup?
The initial setup was easy and it took one day to install it.
What other advice do I have?
Overall, I like this product and I think that the features are good enough.
I would rate this solution a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Splunk Enterprise Security
Microsoft Sentinel
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Grafana Loki
Trellix Endpoint Security Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?

















I am taking IBM Security Qradar exam c2150-400 early Aug 2015.