There are many use cases for this solution. One example is we are using this solution to monitor user site access to band sites.
Information Security Manager at a tech services company with 1,001-5,000 employees
Easy to set up but support is lacking
Pros and Cons
- "The initial setup of QRadar is not complex because we have done it before and we are used to the development. It is getting easier all the time."
- "The solution is highly used here in Pakistan and in many sectors, they could improve it by having more SIEM connectors."
What is our primary use case?
What needs improvement?
The solution is highly used here in Pakistan and in many sectors, they could improve it by having more SIEM connectors.
For how long have I used the solution?
I have been using this solution for approximately four years.
What do I think about the stability of the solution?
The stability is good until you upgrade to a new version. You have to properly shut down services when you are doing some maintenance activities every three to four months. There might be some problems that you do not expect. We have had some complaints from users regarding operation.
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
How are customer service and support?
We have had bad experiences with support from IBM. We are not satisfied with the support and they have made me very angry. My customers have had similar experiences.
How was the initial setup?
The initial setup of QRadar is not complex because we have done it before and we are used to the development. It is getting easier all the time.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk.
Which other solutions did I evaluate?
I am evaluating Splunk.
What other advice do I have?
Here in Pakistan, this solution has already saturated the financial market.
I rate IBM QRadar a five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Works
Stable, functional out of the box, and offers good integration capabilities
Pros and Cons
- "Technical support is good overall."
- "The reporting system could use some upgrading."
What is our primary use case?
We make some special demos that we sell to our customers. We work as a technical support L1/L2 for our customers in these cases as well.
The solution allows organizations to check people who work from home or in the office. It can help a company understand who is connected from home.
Sometimes people give a login and password to colleagues. The security can see the situation when someone logs in locally, and they can see a remote connection. They can see this is from the login and password. They'd be able to tell if something was shared and could dig deep to figure out if it is a breach or if it is something that has been properly shared.
What is most valuable?
The SOAR features are very good.
The product is able to handle special requests.
It can effectively search local files.
We are able to deploy in two or more different locations.
The solution is functional right out of the box and it's a pretty simple system with different kinds of solutions that address different types of problems.
The initial setup is pretty straightforward.
The solution is stable.
The product can scale.
Technical support is good overall.
Qradar has a lot of integration capabilities with different security products.
If we talk about functionality in general for SIEM systems, it's good.
What needs improvement?
In terms of the government sector, sometimes they do not have enough money to buy a full SIEM. That's why they ask about some parts of the SIEM system or core. It can be expensive.
It would be ideal if they offered a barebone setup alongside an appliance. It's very interesting for different kinds of customers. Most of them prefer the core appliance, yet some of them prefer barebone.
It would be ideal if the solution offered new connectors to other systems.
The reporting system could use some upgrading.
For how long have I used the solution?
We've been using the solution for at least the last 12 months or so.
What do I think about the stability of the solution?
The stability is good. there are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability of the product is very good. Sometimes we get requests for specific functionality and usually, we can accommodate that.
How are customer service and technical support?
Generally, we are happy with technical support. They are helpful and responsive.
How was the initial setup?
The initial setup is very simple for our customers due to the fact that the first step is a demo for a customer. We need about 5 to 15 working days to make this demo. We talk about making a core system. It's not difficult to make over the Qradar SIEM. After that, if the customer needs some special function for, for example, different parts of the organization, we can propose some separate parts of SIEM. That's about two or eight weeks away.
In general, for a SIEM project, you are looking at a deployment time of about two til eight months.
What about the implementation team?
As integrators, we can help advise clients and assist in the deployment process.
What's my experience with pricing, setup cost, and licensing?
IBM Qradar has an interesting scheme for payments. They have annual payments for customers who use subscriptions for some services. I can't see any problem with the current financial scheme for this product generally. It's okay.
What other advice do I have?
We are implementors. Our customers are the ones that use IBM Qradar.
We are an IBM partner.
We strongly recommend to our customers use the latest version of Qradar. It's important for security. We tend to use the latest in general.
Our customer is a government organization, including some ministries. Therefore, they use on-premise deployments only. However, they have some plans for hybrid clouds or private clouds in the next three or four years. That said, it's very hard to say exactly as the work at the ministry is about security. On-premise is deemed to be more secure.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
IBM Security QRadar
June 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
858,327 professionals have used our research since 2012.
SOC Team Lead at a financial services firm with 1,001-5,000 employees
Flexible, easy to learn, and price fairly
Pros and Cons
- "I have found the most important features to be the flexibility, tech framework, and disk manager."
- "There could be better integration with the solution."
What is our primary use case?
Depending on the organization's needs the solution can monitor different types of security through logs.
What is most valuable?
I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.
What needs improvement?
There could be better integration with the solution.
For how long have I used the solution?
I have been using the solution for approximately three years.
What do I think about the stability of the solution?
Every solution has some bugs and other issues but for the most part, this solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. The amount of users is dependant on what your needs are. You can have many users having access to the solution. For example, out of a 5,000 person network, you could have five with access to it for security.
How are customer service and technical support?
The solution has great support. Whenever we had an issue they were able to give us support within 15 minutes.
How was the initial setup?
The installation was easy but this can depend on what appliances you want to install it on. If it is VMware, then the installation is easy, it took me 30 minutes.
What about the implementation team?
We did use a consultant to do the deployment and we only needed one technician.
What's my experience with pricing, setup cost, and licensing?
The solution is priced fairly, there is a license for the solution, and we pay annually.
What other advice do I have?
I would recommend the solution to others and we plan to continue using it in the future.
I rate IBM QRadar a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Operations Manager at a comms service provider with 501-1,000 employees
Flexible and very scalable with a straightforward setup
Pros and Cons
- "The solution is quite flexible."
- "Technical support really needs to be improved. Right now, they aren't where they need to be at all."
What is our primary use case?
We mostly use the product for PCI compliance.
What is most valuable?
We pay a little bit extra for Watson, and the Watson feature enables the analyst to go through and triage things much faster. It's quite useful for us and worth the smaller extra bit of money.
The solution is quite flexible.
We enjoy the fact that it is cloud-based.
The initial setup was very straightforward.
The solution is very scalable.
We've found the stability to be mostly very good.
What needs improvement?
Technical support really needs to be improved. Right now, they aren't where they need to be at all.
The solution is very expensive. We'd appreciate the product more if it came at a lower price point.
What do I think about the stability of the solution?
It is generally very stable. We've had odd little breakages, however, generally, nothing major has gone wrong. The performance is good. It's a reliable product.
What do I think about the scalability of the solution?
The scalability aspect of the product is very good. That was one of the reasons that we bought it. If a company needs to expand it, it can do so with relative ease. It's not hard.
Currently, all the members of the tech ops team use the product, and there are five of them.
We may not increase usage; we may switch to something else. That has yet to be determined. It's not set in stone.
How are customer service and technical support?
We've used technical support in the past and we haven't been satisfied with the level of service on offer.
Trying to get answers out of IBM is like trying to get blood out of a stone. They need to be more helpful and responsive. Right now, they aren't either of those things.
How was the initial setup?
The initial setup was not difficult or complex. It was very straightforward. A company should have too much trouble with the process.
The deployment process was very, very quick as well. There is a collector deployed on our network. We spun that out. You point your log sources at it, you point it at some IP addresses that IBM gives you, and it just works.
What about the implementation team?
We did not use an integrator or consultant for the deployment. We handled it ourselves, with our own staff. Everything was done in-house.
What's my experience with pricing, setup cost, and licensing?
The product is not a cheap solution. it's quite expensive.
We do also pay more in order to use Watson.
Which other solutions did I evaluate?
We're currently evaluating other options to see if we want to switch off of this product in the future. Nothing has been decided. I'm currently doing some preliminary research. We're always looking for solutions that are better or cheaper.
What other advice do I have?
We are just a customer and end-users. We don't have a business relationship with IBM.
We are using the latest version of the solution, as we have the cloud version of the product. Whatever the latest version is, IBM upgrades it automatically. We don't need to worry about that on our end.
In general, I would rate the solution at a seven out of ten. If it were cheaper it might rate a bit higher, however, for the most part, it does what we need it to do.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Solutions Architect at a manufacturing company with 51-200 employees
A stable SIEM solution with centralized control and built-in AI/ML
Pros and Cons
- "QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis. There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving. From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected."
- "When it comes to what could be better, it is always what others are trying to do and what is the roadmap. It can have more integration. It should have more flexible RESTful APIs for integration with applications. These are the things that are always in demand for any of the SIEM solutions, not only for QRadar. Integration is ever-evolving. Nowadays, different versions of mobile handsets are there and data is getting scattered. Users are using their personal handsets to keep the data of the organization. So, it should have a more flexible integration, irrespective of the flavor of the firmware and iOS or Android version. It should have an API that can seamlessly get integrated. It should also provide more flexible control and a more advanced or analytical view to see what exactly is happening across the globe or network. From wherever a user is connecting and accessing the enterprise data, it should give real-time visibility and predictive visibility about what exactly is happening. These things are already there, but there should be more advanced control in terms of managing the security."
What is our primary use case?
We provide cloud services to the users, and we have our own cloud setup over here. The major use case is when clients require the SOC to be set up.
Setting up the SOC itself is a huge investment. A customer has to invest a lot to build up the whole SOC environment, so, rather than the customer investing in the SOC environment and building up the SOC, we provide it as a service. Customers don't need to do any up-front investment. They use our service. We manage their security tools and security environment as per the compliance guidelines that come from the Indian government. We follow all those practices, and we help them procure more for their network and infrastructure.
What is most valuable?
QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis.
There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving.
From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected.
What needs improvement?
When it comes to what could be better, it is always what others are trying to do and what is the roadmap. It can have more integration. It should have more flexible RESTful APIs for integration with applications. These are the things that are always in demand for any of the SIEM solutions, not only for QRadar.
Integration is ever-evolving. Nowadays, different versions of mobile handsets are there and data is getting scattered. Users are using their personal handsets to keep the data of the organization. So, it should have a more flexible integration, irrespective of the flavor of the firmware and iOS or Android version. It should have an API that can seamlessly get integrated. It should also provide more flexible control and a more advanced or analytical view to see what exactly is happening across the globe or network. From wherever a user is connecting and accessing the enterprise data, it should give real-time visibility and predictive visibility about what exactly is happening. These things are already there, but there should be more advanced control in terms of managing the security.
For how long have I used the solution?
I have been using this solution for five years.
What do I think about the stability of the solution?
It is absolutely stable. It depends upon how the implementation has been done. We definitely have the skills to do this kind of implementation. We ensure that a customer's environment is absolutely protected.
What do I think about the scalability of the solution?
It is very scalable, but it also depends upon how the implementation was done. We are providing services to one of the major brands in India. They have somewhere around 30,000 devices. We are currently managing more than 1 lakh QRadar users.
How are customer service and technical support?
QRadar has a good technical team. They provide timely support whenever a ticket is raised.
How was the initial setup?
Deployment of such solutions always takes time because these solutions are not simple. You should have the expertise and you should understand what is really needed for the business. We understand the real business need, and accordingly, we implement the policies.
What about the implementation team?
We have been managing some of the security tools for the past 11 years. We have expert engineers who can help our customers with installation, configuration, planning, designing, and other things.
If you have an environment of 5,000 or 10,000 devices, three to five people should be enough to manage it.
What's my experience with pricing, setup cost, and licensing?
Customers have to purchase a license based on the number of users, devices, and applications they want to protect. It allows you to take a license on a subscription basis for three years or five years.
What other advice do I have?
I would recommend this solution. If you are looking for a SIEM solution, IBM QRadar is one that you should ideally look for.
I would rate IBM QRadar a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Head of IT Security, Governance and Compliance at a consumer goods company with 10,001+ employees
Easy to use, provides environment visibility, and assists with incident discovery in advance of problems to the business
Pros and Cons
- "This is a good tool to have because it gives you the ability to track what is currently happening in your environment."
- "The modularity could be improved."
What is our primary use case?
We are using QRadar as a managed service.
How has it helped my organization?
This product helps us to find security incidents before they become a problem to the business. We are able to attend to them quicker and we can put protection in place so that should they occur again, we are able to deal with them more easily.
What is most valuable?
The most valuable feature is the ease of use.
What needs improvement?
The modularity could be improved.
For how long have I used the solution?
We have been using IBM QRadar for three years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
We have had no issues with scalability and we have approximately 1,500 users. We are not using its full capabilities at the moment because we are still growing. In the next year or two, we will see.
How are customer service and technical support?
I don't deal with IBM directly. Rather, I deal with our service provider and they deal with IBM.
How was the initial setup?
The initial set was very easy for us because we just bought what we were looking for, and not the entire infrastructure.
What about the implementation team?
The company that we subscribe to for this service takes care of the installation, maintenance, and management of it. They give us updates that concern the features we use, so the maintenance doesn't affect us much.
What's my experience with pricing, setup cost, and licensing?
We use QRadar as a managed service and we pay licensing fees to the partner.
What other advice do I have?
This is a good tool to have because it gives you the ability to track what is currently happening in your environment. Otherwise, if you did not have that, you'd only react to an event or an incident that has already caused problems. The proactiveness goes a long way because it saves your environment and your business from being negatively affected.
In summary, this is a good product but there is always room for improvement.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managed Security Product at a comms service provider with 1,001-5,000 employees
Excellent artificial intelligence component with tricky licensing fees
Pros and Cons
- "The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well."
- "The features that could be improved include the licensing model and the dashboards and all those presentations. Overall, the user experience part can be improved."
What is our primary use case?
IBM QRadar is a FIM component within the security operation center we were deploying in the customer environment. We are managing their cyber defense capability.
What is most valuable?
The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well.
What needs improvement?
The features that could be improved include the licensing model and the dashboards and all those presentations. Overall, the user experience part can be improved.
Additionally, the coverage, the connectors, and the flex connectors for legacy systems and other aspects could be improved. This is something they can work on and improve.
For how long have I used the solution?
I have been using IBM QRadar for more than two years.
What do I think about the stability of the solution?
It is a stable product.
It takes two to three people for its management, but it purely depends on the scope of the security operations center, the SOC.
What do I think about the scalability of the solution?
It is scalable.
It's kind of non-direct user component. It sits under the security operations center, so it won't be visible to the user, but it will be covering devices and users. It can support 100 to 10,000 devices. So it's kind of a back instance.
In terms of plans to increase usage, I'm currently in a management level, so I'm no longer into the directly technical part. But if there is a requirement, IBM QRadar is definitely one of my preferences.
How are customer service and technical support?
IBM technical support is good.
Which solution did I use previously and why did I switch?
We were using ArcSight from Micro Focus, but we were having some challenges integrating with the systems, with the APIs, and with the connectors. That's why we moved to IBM.
How was the initial setup?
The initial setup is at an intermediate, medium level. It's not that straightforward, but not that complex either. The only thing is that their licensing model is a bit complex because they charge for a couple of components like EPS and NetFlow, so that kind of licensing charging is a bit tricky. But all in all, it's a medium, not that complex.
I think it was set up within a month. But use-case finalization and other configurations took another month. It's kind of a two to three month project to move to production completely.
What's my experience with pricing, setup cost, and licensing?
Our licensing is yearly. But it's based on Event Per Second, which is one of the models. Storage capacity for log management is also considered with the fees. Licensing is a bit complex in IBM, as well. Different aspects needs to be considered.
What other advice do I have?
I would recommend IBM to others who want to start using it.
On a scale from one to 10, I would rate IBM QRadar a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
AGM, Enterprise Solutions at Omgea Exim Ltd
Flexible and scalable with good stability
Pros and Cons
- "This is a distributed application, meaning that a customer can stack small and then scale it so that they can expand pretty effectively. You can use, basically, the same product in an SMB or a large enterprise."
- "Right now, if you look at the compatibility, if you need to deploy QRadar in a physical appliance you have only two choices of server, their own or a Lenovo server. In today's world, you cannot keep something tied to such a big brand. Clients want to be able to use whatever type of server they want."
What is our primary use case?
We primarily use the solution for some compliance, including military compliance such as PCIDSL, ISO 27001, and ISO 27002, and then some other specifications around them. There are also some industries that need to analyze the log and events, and then build and create some rules to put forward.
What is most valuable?
The solution has very good Watson Analyzer integration. It's one of the key differentiators if you compare it to other solutions.
The solution offers very good BSM support. There's 400 BSM support out of the box. That's a huge advantage. with it, you are actually adding almost all the devices that are available in an IT environment.
This is a distributed application, meaning that a customer can stack small and then scale it so that they can expand pretty effectively. You can use, basically, the same product in an SMB or a large enterprise.
You can deploy the solution and leave it. It's very unfussy.
When it comes to deployment, it's very flexible.
What needs improvement?
Right now, if you look at the compatibility, if you need to deploy QRadar in a physical appliance you have only two choices of server, their own or a Lenovo server. In today's world, you cannot keep something tied to such a big brand. Clients want to be able to use whatever type of server they want. It's very limiting for many. You need that flexibility to deploy on any Intel platform.
IBM doesn't have people in every corner of the world. Oracle, for example, is actively training and certifying people so that companies will have access to local connections. IBM is lacking this, and therefore it can be difficult to get qualified support when a customer needs it. They should try to replicate the Oracle approach to training and certifications.
For how long have I used the solution?
I've been using the solution for the last three years or so. It's been a while.
What do I think about the stability of the solution?
The solution is very stable. It's reliable. You don't need to worry about bugs or glitches. It doesn't crash or freeze. It's pretty much a set and forget kind of setup.
What do I think about the scalability of the solution?
The solution scales well. It's stackable, which means you can start small if you want and then just stack more and more. It's perfect for any size of organization, from small to large.
We have sold this solution to six organizations, however, as a whole, we have around 10 customers in Bangladesh. Their sizes vary.
How are customer service and technical support?
In terms of some of the IBM support we recently have received, we've had some issues. While it should be 24/7 support, sometimes we have to wait an extended period. Our customers have had to wait an extended amount of time - in some case like two or three months. Some support we used to get was from the US team and they were good. However, support from elsewhere isn't really that great, and certainly not up to their level of service.
How was the initial setup?
The initial setup is not complex at all. It's very straightforward.
Since it is coming with a predefined image, anybody can actually deploy this on a VM or ia physical appliance. The deployment is flexible.
A control installation takes four to five hours to initialize the console. After that, deployment is dependant on the customer requirements. However, simply initializing the appliance takes two to four hours depending on the allocated resources, therefore, it's quite quick.
What about the implementation team?
From a product perspective, we have three persons in the product team. However, in the deployment and support team, we have five people. We tend to sell and help implement this product to our customers.
What other advice do I have?
We're using the latest version of the solution.
We are a reseller. We're selling the solution to end customers.
Whenever there is a requirement, a security requirement, or an AFM requirement, we actually position IBM QRadar. We proactively promote the solution and the market, so that we can build a community around QRadar. We're trying to build a community around QRadar so that we can increase sales. We need to have local resources to promote the products. Therefore, we are trying to double up that community of QRadar users. We're doing knowledge sharing among our network. We're changing information so that we can have a knowledge-based group so that we can promote the product to more customers.
While I'd recommend the solution, I'd caution that, for any IBM product other than hardware, the local resources are not that great as they are not often available. I can see why some customers are afraid to add this product. It's different from, for example, Oracle, which is doing product training everywhere and is actively certifying people.
Overall, aside from support issues, we've been happy with the solution. I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Microsoft Sentinel
Splunk Enterprise Security
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Trellix Endpoint Security Platform
Grafana Loki
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?