ArcSight Logger vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

ArcSight Logger
Ranking in Log Management
20th
Average Rating
7.8
Number of Reviews
31
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Number of Reviews
198
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (20th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (11th)
 

Market share comparison

As of June 2024, in the Log Management category, the market share of ArcSight Logger is 1.7% and it increased by 11.2% compared to the previous year. The market share of IBM Security QRadar is 8.2% and it increased by 3.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
Unique Categories:
No other categories found
Security Information and Event Management (SIEM)
16.3%
User Entity Behavior Analytics (UEBA)
13.5%
 

Featured Reviews

HF
Sep 16, 2019
An extremely customizable and scalable enterprise-level solution with great stability
We are using the on-premises deployment model. There are people who say "Oh, ArcSight is losing its position and it's complex or it's not a good solution." I do not agree. I know that the biggest companies in the world are still working with ArcSight. It's the most comprehensive solution. It contains many features that are useful for enterprise-level organizations. If a company has a team that wants to go deeper and get the most features out of developing a real SOC, they should look for a very robust, scalable, multi-tenant solution. The solution should also be able to manage data analytics and to offer User Behavior Analytics. Arcsight offers this. This particular solution is perfect for big companies. Smaller companies should look for integrated solutions that do not necessarily scale. I would rate the solution nine out of ten.
SK
Feb 12, 2024
A security solution to manage logs from multiple devices
We use IBM Security QRadar for storage. These tools are setting high tools on the usage of the logs from multiple devices. It manages millions of logs from multiple devices, such as firewalls, routers, switches, etc. The solution is stable and has better support than LogRhythm. It doesn't have…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The log digestion features from threat intelligence platforms like Recorded Future or Talos are valuable."
"It's a robust, mature product and you can do some really complex operations and analytics."
"We haven't had any crashes or bugs. It is stable."
"The ability to customize the solution in great detail is its most valuable features. We can customize the use cases and also have the ability to do scripting. We can personalize our dashboard as well. The scalability the solution offers is quite impressive."
"We check a lot of logs in ArcSight Logger because we're running a massive database platform."
"In terms of ArcSight Logger's most valuable feature, it is their scalability. ArcSight's real advantage is its scalability because they have two layers, including the logger layer."
"The most valuable feature is the level of detail that you can see about certain events, even when they do not come up in the console."
"The machine learning is a good feature."
"IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
"Customer service is very good and very helpful."
"The most valuable feature is the machine learning module."
"One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like Scout, Carbon Black, and the rest."
"This is a distributed application, meaning that a customer can stack small and then scale it so that they can expand pretty effectively. You can use, basically, the same product in an SMB or a large enterprise."
"This solution provides me with various alarms, and I have found security issues with some of my other products."
"The solution is quite flexible."
"It is a pretty solid product for the type that it is representing. It is a CM solution as compared to Splunk or ArcSight from HP. It is also user friendly. It comes with some internal AI as well, in which it automatically maps multiple lots from unrelated devices and makes a smart decision to link them back and create an offense based on that. It is a smart tool."
 

Cons

"The initial setup was a little bit complex."
"In the next release, I want to see more intelligence."
"The console in older versions is not user-friendly."
"Using the ArcSight Logger dashboard is not particularly intuitive or efficient, so it is important to be trained in its use."
"It would be better if the product is cheaper."
"It's not a new product and is a bit complex. So, it requires a person dedicated to working on it and to know about it in and out. It is a huge product, and the search operation is a bit complicated for a new user or someone who has not used it for long. So for that person, it becomes a bit difficult."
"The solution must provide readymade connectors for different applications."
"I would like to see better scheduling in the next release of this solution."
"The modularity could be improved."
"It is not app based."
"The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria."
"A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools."
"The whole process for support is something that needs to be improved."
"QRadar needs to be more specialized, along the lines of what other SIEM solutions are."
"The custom rules could be simplified more or it should be possible to use a different language, other than the ones that the solution is already using. They should add other languages into the mix."
"The advanced planning management (APM) features should be included."
 

Pricing and Cost Advice

"The pricing is quite harsh."
"I would rate the product a seven out of ten since it's an enterprise product."
"Pricing is reasonable compared to similar tools on the market. They offer perpetual licenses."
"We have a lifetime license, so we don't pay a monthly fee."
"ArcSight Logger is very expensive compared to their competitors, but when we talk to the customer and explain what the features are and how we can scale, they understand. Still, ArcSight is more expensive than the competition."
"ArcSight is an expensive solution."
"I rate the product’s pricing a seven out of ten, where one is inexpensive, and ten is expensive."
"It's not cheap at all as it's a big product and has been in the market for quite some time now."
"When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products."
"There are additional costs, such as the cost associated with the different hardware required for implementation and deployment. Along with the add-on apps, these are all additional costs, and they require licensing as well."
"The pricing is always fine."
"Licensing can be costly depending on your architecture."
"An X-Force feed is free with QRadar."
"There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk."
"There is a license to use this solution, which is paid annually. However, there are subscription options available."
"It could be cheaper, but the value itself is far more important for us than the price. Typically, our clients have yearly subscriptions."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
14%
Government
11%
Comms Service Provider
7%
Educational Organization
19%
Computer Software Company
15%
Financial Services Firm
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about ArcSight Logger?
We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
What is your experience regarding pricing and costs for ArcSight Logger?
The pricing isn't the problem. We have a lifetime license, so we don't pay a monthly fee.
What needs improvement with ArcSight Logger?
The solution has room for improvement. We're currently upgrading to the newer version, where they have something like Kafka, a hub for all solutions feeding information into Logger. However, I thin...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

Micro Focus Arcsight Logger, HPE Arcsight Logger
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

China Merchants Bank, Bank AlJazira, Banca Intesa
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about ArcSight Logger vs. IBM Security QRadar and other solutions. Updated: June 2024.
787,061 professionals have used our research since 2012.