Try our new research platform with insights from 80,000+ expert users
reviewer1827399 - PeerSpot reviewer
Executive Vice President at a computer software company with 11-50 employees
Real User
Top 20
Sep 26, 2024
Offers ease at rectifying situations involving any anomalies
Pros and Cons
  • "The most valuable feature of the solution is its ability to rectify a situation involving any anomalies expeditiously."
  • "Communication between the silos sometimes becomes an issue, making it an area where improvements are required."

What is our primary use case?

Basically, it is a product that serves as an SIEM solution, and its main competitor is Splunk. Splunk and IBM are lookalike tools. IBM Security QRadar hosts a panel where you can feed just about anything you can think of in terms of electronics as it relates to security, along with other elements of infrastructure. The tool provides notification of events.

What is most valuable?

The most valuable feature of the solution is its ability to rectify a situation involving any anomalies expeditiously.

What needs improvement?

I am dealing with the tool from an arm's length. I am not sitting right in the middle of things in my position. I work in the sales position,and as far as sales marketing is concerned, I am not qualified to speak about what needs improvements in the tool.

IBM is in there with the client, and they pretty well have them covered in a lot of different areas. If the customers are doing their job and they are running the business the way they ought to, then IBM is in a position to do a good job for most of the clients. Communication between the silos sometimes becomes an issue, making it an area where improvements are required.

For how long have I used the solution?

I have been using IBM Security QRadar since 2015 or 2016.

Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,425 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution's stability is pretty good. The tool has been there in my company over a long period of time. It is a solid product. IBM doesn't produce junk, and if it does, then such tools are taken off the market pretty quickly.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution an eight out of ten.

The tool is used by government contractors who are our clients.

The tool offers plug-and-play options, and it does not even involve APIs, making it pretty easy.

IBM Security QRadar's interface is useful. The product is highly competitive. Though Splunk has become a standard tool, IBM Security QRadar is still out there even though it is not number one.

How are customer service and support?

I rate the technical support an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The main difference between Splunk and IBM is that the former one is on the edge in terms of innovation, but the latter one is not that good. Compared to IBM Security QRadar, IBM X-Force is good.

How was the initial setup?

On a scale of one to ten, if ten means easy, I rate the product's initial setup phase as an eight.

As long as you have your policies and if they all relate to security and other areas like infrastructure, then the rules are pretty easy to feed into the product.

The time needed for the product's deployment phase depends on how the entity, the client, has its policies and rules set up. I don't want to say the tool is like a plug and play product because nothing really is in today's market. The tool offers ease of use and integration. I rate the tool a seven to eight for the ease of use and integration it offers.

What was our ROI?

The tool's ability to redeploy resources, like manpower, is about the same as that of other competitors. The benefit the tool offers is the protection and the ability to act on whatever the situation might be quickly, efficiently and terminate whatever is happening. The tool is useful to the bottom and helps with the remediation part.

What's my experience with pricing, setup cost, and licensing?

The tool is priced in a competitive manner. The tool's price is dependent on the installation and the product size, but it is competitive in the marketplace. The marketplace right now is being set by Splunk, which offers a pretty good deal if someone wants it. As a matter of fact, I would say that out of who we are working with right now, Splunk is the major one.

What other advice do I have?

Speaking of how the tool handles real-time threat management in our specific industry, I would say that for our company's services, which are used with Crows Nest Software, we face the product as per the policies and rules that are set up within an entity or a client. For instance, if we see an anomaly, like if I send you an email, and we are within the same company, or I am within this ABC company, and you are external to it. If I am sending you information that I am not allowed to send outside of the company, what happens is we can either stop it ourselves, especially if that is what the instructions are through the policy, or if the client says, then we send such information to IBM Security QRadar and as per the instructions and policy, they can terminate it or do what they will with it after it is terminated.

Speaking about how anomaly detection has impacted security operations, if I consider it from a dollars and cents point of view, I would say that if I am sending you something that is intellectual property and they stop it, it is like you can put a price tag on it after it is leaked, but prior to it, things could seem hard. For instance, if I am a nefarious individual in a company, then in most cases, I would be sending information outside of the organization to somebody who is in the government or serves as a contractor of a nation or a state. They can then take such information and build whatever they want as far as the competition is concerned and be in the competitive marketplace with my product. Such instances happen all the time with government contractors. When I say government contractors, they are those who deal in military hardware development, and, for that matter, they may be involved in a business revolving around air conditioners. In the market concerning air conditioners, there might be someone who has perfected a new way of pulling moisture out of the air and making it into ice cream, which may seem ridiculous.

In the tool, the rules are really external. The good rules are external, and when I say that, it means it goes with the development of your security policies or your policies in general as they relate to security. When sitting down with the client, to be honest, what happens is that if they are installing something like this and they are developing rules and policies to go with it, it acts as an eye-opener for a lot of folks. With some companies, we classify data according to what we are able to pull. Suppose it is data that we have been given access to. In that case, we can determine and produce how it is in a snapshot over a two-week period and sit down with a client or somebody like a consultant firm to help in the area of BPM or something that can be like a spin-off of KPMG, and they do an excellent job of working with us. To prepare policies and rules, and those can be easily, you know, migrated or installed into any product, like Splunk and IBM Security QRadar.

IBM offers Watson for machine learning and artificial intelligence. I feel IBM has done a pretty good job with it.

We have partnered with various groups and companies that enhance their products, and we are continuing to do that. Since we utilize machine learning and AI from the start, we are well-versed in both areas. Additionally, we are working on something innovative with blockchain, as well as collaborating with another company focused on classification. There are companies on the periphery that specialize in the classification of various things, and they do tasks we don't handle on the front end. They provide us with information, and we share it, enabling us to interface more effectively with platforms like Splunk, QRadar, or others.

I rate the tool an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Muluken Mekonene - PeerSpot reviewer
Network Engineer at a outsourcing company with 201-500 employees
Real User
Top 5Leaderboard
Sep 30, 2024
An IBM solution that automatically creates asset profiles by using passive flow data and vulnerability data to discover your network servers and hosts
Pros and Cons
  • "think QRadar is great overall. We’ve had a positive experience with it and recommend it for deployment. However, there are areas for improvement. The technical support is good, and the documentation is valuable, but it could be enhanced, especially regarding integration with other systems. In terms of support and updates, QRadar’s capabilities are crucial for maintaining high security standards. Network and software administrators can monitor all traffic effectively, which reassures clients and drives further adoption."
  • "For future updates, I'd like to see more advanced threat intelligence features integrated with AI. This would help with analyzing traffic patterns and improving protection. QRadar currently doesn't integrate with AI for threat analysis. However, AI could enhance its capabilities by learning traffic patterns and automatically blocking or quarantining suspicious traffic. This would be especially useful when administrators are not actively monitoring. AI could help by analyzing incoming and outgoing traffic and adjusting policies accordingly."

What is our primary use case?

I’m working with the on-prem version of IBM Security QRadar. We initially deployed it with the help of IBM’s professional services for a client, but now we handle deployments ourselves. The process is quite straightforward for us because we gained knowledge from our first implementation and used the available documentation. Deployment takes a couple of hours the first time, including configuration and integration with third-party devices. I usually work with a colleague, so two people handle the deployment. Our environment is well-suited for this, and we’re using it on a virtual appliance. The experience has been smooth and efficient.

We are promoting QRadar to various financial institutions, including banks and microfinances, as a superior option compared to other vendors like Fortinet. While some institutions are using other solutions, we are encouraging them to switch to QRadar for better security.

How has it helped my organization?

We monitor tweets and other activities on the IBM Security QRadar portal. Once, we noticed unusual traffic patterns, like tweets triggering alerts, and we blocked that traffic. We also detected some security issues on the APM through the portal, which was a great experience. As for integration, we’ve successfully integrated QRadar with other security products like Cisco, Fortinet, and Check Point. Initially, we worked with IBM’s professional services to guide us through the integration process, and after that, we were able to follow their steps to integrate third-party devices ourselves.

QRadar has a significant impact on operational costs for clients. For example, we’re recommending QRadar to several banks due to its effectiveness in handling high traffic and preventing scams. The banks we’ve worked with are very satisfied and are encouraging others to deploy QRadar as well.

What is most valuable?

I think QRadar is great overall. We’ve had a positive experience with it and recommend it for deployment. However, there are areas for improvement. The technical support is good, and the documentation is valuable, but it could be enhanced, especially regarding integration with other systems.

In terms of support and updates, QRadar’s capabilities are crucial for maintaining high security standards. Network and software administrators can monitor all traffic effectively, which reassures clients and drives further adoption.

What needs improvement?


For future updates, I'd like to see more advanced threat intelligence features integrated with AI. This would help with analyzing traffic patterns and improving protection. QRadar currently doesn't integrate with AI for threat analysis. However, AI could enhance its capabilities by learning traffic patterns and automatically blocking or quarantining suspicious traffic. This would be especially useful when administrators are not actively monitoring. AI could help by analyzing incoming and outgoing traffic and adjusting policies accordingly.

For how long have I used the solution?

I have been using IBM Security Qradar for last one years.

What's my experience with pricing, setup cost, and licensing?

As for licensing costs, I haven't seen the exact figures, but it is considered somewhat costly. On a scale from one to ten, where one is very expensive and ten is very cheap, I would rate it a six—it’s costly but worth the money.

What other advice do I have?

Overall, I would rate IBM QRadar as a ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
IBM Security QRadar
December 2025
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,425 professionals have used our research since 2012.
Ayoub Jaaouani - PeerSpot reviewer
Solutions Architectv at a tech consulting company with 51-200 employees
Real User
Top 5
Feb 16, 2024
Useful for threat hunting, investigation, and triage analysis
Pros and Cons
  • "The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons."
  • "Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances."

What is our primary use case?

We utilize the product for our Security Operations Center operations. Additionally, we extend its use to our customers, employing it for tasks such as threat hunting, investigation, and triage analysis.

What is most valuable?

The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons.

Its scalability is also important. It is also compatible with ISO 27001, DSS API, and various certifications.

As part of our security infrastructure, this tool excels in detecting a wide range of attacks. Its responsiveness surpasses that of alternative solutions. Moreover, the user-friendly interface greatly benefits our analysts. The product is helpful in anomaly detection scenarios.

Additionally, we leverage out-of-the-box content and libraries within the IBM ecosystem. Its user behavior analysis helps us to ensure that our customers are protected. 

Correlation plays a pivotal role in our security strategy. It helps us to analyze logs from different sources. This process helps to correlate logs from endpoints. 

What needs improvement?

Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances.

Our current query language (KQL) serves its purpose, but there's room for improvement. Consider introducing a more human-friendly language to streamline analyst training. Analysts could then express queries in a manner akin to human language. This change would expedite processes, making it easier for new analysts to adapt.

For how long have I used the solution?

I have been working with the product for five years. 

What do I think about the scalability of the solution?

I rate the tool's scalability an eight to nine out of ten. 

How are customer service and support?

Troubleshooting delays have been a recurring challenge. Occasionally, responses take two to three days, leading to escalations. While their website’s knowledge base is commendable, troubleshooting scenarios demand more time. My observation is that they may be understaffed.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

My company has customers using Splunk and Chronicle SIEM. When comparing Splunk and IBM Security QRadar, they indeed offer similar features, but their business models differ. Chronicle SIEM predominantly operates in the cloud. However, we cannot offer the cloud model if a customer prefers an on-premises solution.

Splunk and IBM Security QRadar both cater to diverse deployment preferences. Splunk boasts a slightly more robust correlation engine than IBM Security QRadar. Splunk tends to be marginally more expensive than IBM Security QRadar.

How was the initial setup?

The number of log sources significantly impacts deployment complexity. The process becomes more complicated for environments with 50 log sources compared to those with fewer sources (e.g., 20 or 10).

Each log source requires a connection to IBM, a task that can take several days or hours, depending on its complexity.

On average, the entire deployment process spans six to eight weeks.

What's my experience with pricing, setup cost, and licensing?

The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it. 

What other advice do I have?

I rate the overall product an eight out of ten. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Anto Sebastin - PeerSpot reviewer
Technical Presales Engineer at a computer software company with 11-50 employees
Real User
Jul 24, 2023
A scalable and easy-to-deploy incident management tool that provides good support
Pros and Cons
  • "It allows us to search data both on-premises and on the cloud."
  • "The product does not have a team for investigating malware."

What is our primary use case?

The product is a threat detection and response solution. It is useful for consultants or security analysts. It is an incident management tool.

What is most valuable?

We had enabled federated search. It allows us to search data both on-premises and on the cloud. We can check the functional insights. We use keywords for threat investigation. We use the product mostly for AWS delivery models.

What needs improvement?

Most people handling QRadar in organizations are IT engineers. They do not have experience with the tool. They read from manual documentation. If there is an emergency to search for details about malware, we need a response team’s help. Sophos has a team called Managed Threat Response. The team conducts investigations in our network. This feature is not available in IBM Security QRadar. They only provide technical support. The product does not have a team for investigating malware.

For how long have I used the solution?

I have been using the solution for one year.

What do I think about the stability of the solution?

The tool is stable. SIEM is important for every company. It is needed if any attack occurs.

What do I think about the scalability of the solution?

We deployed the solution for an enterprise business. I rate the scalability of the tool an eight out of ten.

How was the initial setup?

I rate the ease of setup an eight out of ten.

What about the implementation team?

The deployment takes almost half a day. If the environment is good, we can deploy the solution in 25 to 30 minutes. It will be helpful to have people who have knowledge of malware analysis and know specific languages that are relevant to the domain to deploy the tool.

What's my experience with pricing, setup cost, and licensing?

In India, the solution is expensive. Only enterprise businesses can afford the tool. We need more than 3000 people in the organization to use it. We might have to pay for technical support separately.

Which other solutions did I evaluate?

We use Sophos now. Sophos provides us with a team called MTR. The team analyzes the vulnerabilities in our network. We need to pay separately for it. However, compared to us, they have better product knowledge. This kind of support is not available in QRadar. It will be great if IBM adds these features.

What other advice do I have?

I am using the current version of the solution. We do not have a team to analyze malware. Overall, I rate the product a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Dmytro Petrashchuk - PeerSpot reviewer
CTO at a tech services company with 201-500 employees
Reseller
Top 10
Aug 7, 2024
Offers flexibility in the area of pricing, specifically to resellers
Pros and Cons
  • "I am generally satisfied with the product."
  • "The solution's technical support works, but sometimes, it can take quite a long time to get a solution from technical support."

What needs improvement?

I think that the main weakness is the tool's architecture. The tool still provides a secured analytic application, although we have heard for many years that the solution is going to move to a container kind of architecture, which ArcSight, for example, made years ago. IBM Security QRadar's analysis part is sometimes a bit buggy. The interfaces sometimes could give users an inconsistent experience because different developers wrote several different GUIs at different times. Sometimes, the user experience is not so consistent. There were outdated areas of IBM Security QRadar, but you can still find some rudimentary parts that could sometimes be a weakness.

What my company misses at the moment revolves around the fact that the tool had a great feature around risk management, which the tool deprecated several years ago, and I think that it could be helpful in the present. The tool's user and entity behavior analytics application could be improved significantly because our recent experience shows that it is still kind of useless, but the customers and we also need it. More artificial intelligence and machine learning will be helpful in the tool.

For how long have I used the solution?

I have been using IBM Security QRadar since 2012. My company is a customer, a partner, and a reseller of IBM.

How are customer service and support?

The solution's technical support works, but sometimes, it can take quite a long time to get a solution from technical support. Generally, we are satisfied because we just understand how it works and that you shouldn't expect much from the technical support. It is not so bad, but sometimes it could be longer than you can expect. I rate the technical support a six to seven out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

My company has not worked with any other products before IBM Security QRadar. In our organization, we used different SIEM solutions, specifically ArcSight, FortiSIEM, and Rapid7. We repeatedly returned to IBM Security QRadar and didn't continue with any of its competitors.

What's my experience with pricing, setup cost, and licensing?

I think the pricing is quite flexible. As a reseller, we had chances to win bids with IBM Security QRadar against Splunk, ArcSight, and even McAfee with better pricing around six or seven years ago. We won the deals with better pricing. Pricing could be flexible. It could depend on the number of assets used by the enterprise or on the number of events per second, allowing customers to choose what fits him or her the best.

Which other solutions did I evaluate?

My company is looking for different products in the market since we are upset with the recent news about the deal between IBM and Palo Alto. I think the deal doesn't touch the on-premises IBM Security QRadar, and both companies have only agreed to give Palo Alto the authorization for the cloud version, making it a reason why we continue to use the on-premises version.

What other advice do I have?

I am generally satisfied with the product.

Considering that there is still room for improvement and that the vendor could improve it to be made faster than it is at the moment, it is still a good product.

I rate the tool an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Frank Eargle - PeerSpot reviewer
Information Security Engineer at a computer software company with 11-50 employees
Real User
Nov 3, 2023
A highly stable and scalable solution that provides good technical support
Pros and Cons
  • "The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
  • "IBM Security QRadar’s GUI could be improved."

What is our primary use case?

I've got use cases where we monitor positive controls wherein something doesn't allow something to happen. It alarms when somebody changes the control.

What is most valuable?

The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability.

What needs improvement?

IBM Security QRadar’s GUI could be improved.

For how long have I used the solution?

I have been using IBM Security QRadar for 12 years.

What do I think about the stability of the solution?

I rate IBM Security QRadar ten out of ten for stability.

What do I think about the scalability of the solution?

Around five to ten users are using the solution in our organization.

I rate IBM Security QRadar ten out of ten for scalability.

How was the initial setup?

The solution's initial setup is pretty difficult. I rate IBM Security QRadar a four or five out of ten for the ease of its initial setup.

What about the implementation team?

Based on the size and the number of use cases, the solution's deployment can take three or four days to a few months.

What's my experience with pricing, setup cost, and licensing?

IBM Security QRadar is about 50% less expensive than Splunk. SIEM solutions charge by the amount of data, whether EPS or gigabytes. They directly incentivize you not to put things in it, which doesn't make sense since the goal is to put everything in it. They'd make it where you can't afford to do it.

On a scale from one to ten, where one is cheap and ten is expensive, I rate IBM Security QRadar's pricing a five out of ten.

What other advice do I have?

Overall, I rate IBM Security QRadar a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner/customer
PeerSpot user
Mohamed Elprince - PeerSpot reviewer
SOC Manager at a financial services firm with 1,001-5,000 employees
Real User
Dec 18, 2022
Highly scalable, excellent learning modules, but would like to see a better user interface
Pros and Cons
  • "The most valuable feature is the machine learning module."
  • "I would like to see some artificial intelligence and alternative solutions."

What is our primary use case?

Our primary use case is in the banking industry in two banks here in Egypt. We generally are monitoring the user behavior of the employees, For example, working after working hours, and signing into the machines after working hours.

What is most valuable?

The most valuable feature is the machine learning module.

What needs improvement?

I would like to see the interface improved along with the tuning and any adjustments when it comes to maintenance. It is not straightforward. I would also like to see some artificial intelligence and alternative solutions.

For how long have I used the solution?

I have been using IBM QRadar User Behavior Analytics for almost five years now.

What do I think about the stability of the solution?

I would give stability an eight on a scale of one to ten.

What do I think about the scalability of the solution?

The scalability is not a problem and we have above three thousand in our organization.

How was the initial setup?

The initial setup is extremely easy and straightforward.

What about the implementation team?

The deployment took around two to three days and we did it ourselves in-house. We simply downloaded the application and went from there following the deployment process.

What was our ROI?

We are seeing a return on investment when it comes to profiling the employees.

What's my experience with pricing, setup cost, and licensing?

The pricing is higher but cheaper than others and there are no additional costs.

Which other solutions did I evaluate?

We looked at ArcSight but the cost is more expensive than IBM. ArcSight did have the artificial intelligence model.

What other advice do I have?

I would recommend tuning it to the maximum before going live. I would rate IBM QRadar User Behavior Analytics a seven on a scale of one to ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2518323 - PeerSpot reviewer
Analyst at a hospitality company with 10,001+ employees
Real User
Top 10
Aug 2, 2024
Has real-time detection feature but is not as flexible as Splunk
Pros and Cons
  • "The tool's most valuable feature is real-time detection."
  • "The solution is not as flexible as Splunk."

What is our primary use case?

We use the product to customize rules and detect malicious behavior. 

What is most valuable?

The tool's most valuable feature is real-time detection. 

What needs improvement?

The solution is not as flexible as Splunk. 

For how long have I used the solution?

I have been working with the product since 2016. 

How are customer service and support?

I haven't contacted technical support yet. 

Which solution did I use previously and why did I switch?

I worked with Splunk before IBM Security QRadar.

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is based on the EPS model. 

What other advice do I have?

I prefer Splunk since it gives a lot more freedom and flexibility. I rate the overall solution a six out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.