Try our new research platform with insights from 80,000+ expert users

Datadog vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 1, 2024
 

Categories and Ranking

Datadog
Ranking in Log Management
3rd
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
187
Ranking in other categories
Application Performance Monitoring (APM) and Observability (1st), Network Monitoring Software (2nd), IT Infrastructure Monitoring (2nd), Container Monitoring (1st), Cloud Monitoring Software (1st), AIOps (1st), Cloud Security Posture Management (CSPM) (6th)
IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Number of Reviews
204
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (14th)
 

Mindshare comparison

As of November 2024, in the Log Management category, the mindshare of Datadog is 6.1%, down from 8.6% compared to the previous year. The mindshare of IBM Security QRadar is 4.7%, down from 5.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Kevin Palmer - PeerSpot reviewer
Sep 19, 2024
Useful log aggregation and management with helpful metrics aggregation
Datadog provides us value in three major ways: First, Datadog provides best-in-class functionality in many, if not all, of the products to which we subscribe (infrastructure, APM, log management, serverless, synthetics, real user monitoring, DB monitoring). In my experience with other tools that provide similar functionality, Datadog provides the largest feature set with the most flexibility and the best performance. Second, Datadog allows us to access all of those services in one place. Having to learn and manage only one tool for all of those purposes is a major benefit. Third, Datadog provides significant connectivity between those services so that we can view, summarize, organize, translate and correlate our data with maximum effect. Not needing to manually integrate them to draw lines between those pieces of information is a huge time savings for us.
Muzzamil Hussain - PeerSpot reviewer
Aug 1, 2024
Is easy to integrate and doesn't require maintenance
One major drawback we are facing is in the area of IBM Security QRadar integration with flat file databases. IBM Security QRadar does not support flat file database integration. We are currently facing an issue with respect to the database, which you normally call a NoSQL database. There is no direct integration mechanism available with IBM Security QRadar. We have to approach IBM and generate a ticket so that they can develop a custom method for the integration. In database integration, we are facing issues with IBM Security QRadar. The solution does not support the integration of flat file databases. Certain organizations have flat file databases. IBM does not support direct integration with some databases. We had to create a plug, and we requested IBM to develop a parser, but it is taking IBM a couple of months to develop it. I think a flat-file database should be supported directly instead of developing a parser plugin. There should be a more refined threat intelligence platform, and cross-integration should be possible with locally available threat intelligence platforms.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution's SaaS model is easy to manage and works well in single- or multi-cloud environments."
"The observability on offer is the most useful aspect of the product."
"It helps us better manage our logs."
"Several critical dashboards were created years ago and are still in use today."
"The web app has a real-time support chat window in which a support engineer is chatting with you within a minute."
"The initial setup was straightforward from my own experience, helping integrate within the application and service levels."
"The application performance monitoring is pretty good."
"The biggest thing I liked was the combination of all the things - monitoring, log aggregation, and profiling."
"Provided that the report is prebuilt and I can find what I am looking for, the reporting is the most valuable feature in this solution."
"The most valuable thing about QRadar is that you have a single window into your network, SIEM, network flows, and risk management of your assets. If you use Splunk, for instance, then you still need a full packet capture solution, whereas the full packet capture solution is integrated within QRadar. Its application ecosystem makes it very powerful in terms of doing analysis."
"It's user-friendly when compared to other products."
"One of the most valuable features is its ability to integrate with other solutions. IBM has a lot of solutions and we have managed to make it work with IBM BigFix and MaaS360, and even Microsoft."
"The solution is quite flexible."
"We have worked with other solutions, such as LogRhythm and Splunk. Compared to others, IBM QRadar has the best price-performance ratio so that you are able to reserve minimum costs. It starts settling in fast and gets the first results very quickly. It is also very scalable."
"The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
"IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
 

Cons

"The dashboard could be improved. It would be helpful to get a view of specific things that we need to monitor for our application."
"Presently, the billing CSV reports provide insights into billing-related information yet are somewhat limited in functionality, typically offering reports with only three columns."
"I often have issues with the UI in my browser."
"In the past two years, there have been a couple of outages."
"The pricing should be less of a surprise."
"Network device and performance monitoring could be improved, as we've faced some limitations in this area."
"I would like testing for data in the future."
"I would like the tooling to have better integration in Slack, specifically sending out reminders to the relevant people to take breaks, do a retrospective, and specify with emojis which messages to log."
"If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."
"I'd like them to improve the offense. When QRadar detects something, it creates what it calls offenses. So, it has a rudimentary ticketing system inside of it. This is the same interface that was there when I started using it 12 years ago. It just has not been improved. They do allow integration with IBM Resilient, but IBM Resilient is grotesquely expensive. The most effective integration that IBM offers today is with IBM Resilient, which is an instant response platform. It is a very good platform, but it is very expensive. They really should do something with the offense handling because it is very difficult to scale, and it has limitations. The maximum number of offenses that it can carry is 16K. After 16K, you have to flush your offenses out. So, it is all or nothing. You lose all your offenses up until that point in time, and you don't have any history within the offense list of older events. If you're dealing with multiple customers, this becomes problematic. That's why you need to use another product to do the actual ticketing. If you wanted the ticket existence, you would normally interface with ServiceNow, SolarWinds, or some other product like that."
"IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer."
"I don't look at only the features and benefits; I also look at the price. It is a bit expensive when compared with other solutions. It is expensive for specific deployment topologies, and the decision-makers go for alternatives like ArcSight. It should also have more AI features or capabilities for better threat intelligence. The more it uses machine learning, the better would be the dashboard, analytics, and other things."
"There should be easier and wider integration opportunities. There should be more opportunities for integration with CTI info sharing areas. On platforms where you exchange CTI, there should be more visibility connected to what we share, what we can reach, or what options are connected to CTI info sharing. This is one area where they could add value because we cannot integrate it easily with QRadar. If a client has a legacy or already existing solutions for CTI, we cannot ask them to forget it because we cannot guarantee that QRadar is able to deliver everything connected to this area."
"The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."
"IBM QRadar has a margin for development, for out-of-the-box use cases. It can be enhanced with better support and automate the use cases for that."
"The technical support is poor. Mostly because when I open a PMR for IBM, I am stuck with Level 1 staff. As an engineer, nothing that I am bringing them does not require Level 2 or Level 3 support."
 

Pricing and Cost Advice

"Pricing and licensing are reasonable for what they give you. You get the first five hosts free, which is fun to play around with. Then it's about four dollars a month per host, which is very affordable for what you get out of it. We have a lot of hosts that we put a lot of custom metrics into, and every host gives you an allowance for the number of custom metrics."
"If you do your homework, you'll find that if you're really concerned with cost, it's good."
"The solution's pricing depends on project volume."
"The solution is fairly priced but history and log storage can get costly depending on your needs."
"It costs the same amount it would if we were hosting it ourselves, so we are incredibly happy with the cost."
"The price of Datadog is reasonable. Other solutions are more expensive, such as AppDynamics."
"I am not satisfied with its licensing. Its payment is based on the exported data, and there was an explosion of the data for three or four weeks. My customer was not alerted, and there was no way for them to see that there has been an explosion of data. They got a big invoice for one or two months. The pricing model of Datadog is based on the data. The customer was quite surprised about not being alerted about this explosion of data. They should provide some kind of alert when there is an increase in usage."
"This solution is budget friendly."
"IBM's Qradar is not for small companie. Unfortunately, it would be 'overkill' to place it plainly. The pricing would be too much."
"The price of this solution is a little high."
"The maintenance costs are high."
"The product is expensive. We have purchased the perpetual license, but we pay for the support."
"The price of this product is high."
"Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you."
"The license is not subscription-based."
"There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Educational Organization
37%
Computer Software Company
10%
Financial Services Firm
10%
Manufacturing Company
7%
Educational Organization
22%
Computer Software Company
14%
Financial Services Firm
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Any advice about APM solutions?
There are many factors and we know little about your requirements (size of org, technology stack, management systems, the scope of implementation). Our goal was to consolidate APM and infra monitor...
Datadog vs ELK: which one is good in terms of performance, cost and efficiency?
With Datadog, we have near-live visibility across our entire platform. We have seen APM metrics impacted several times lately using the dashboards we have created with Datadog; they are very good c...
Which would you choose - Datadog or Dynatrace?
Our organization ran comparison tests to determine whether the Datadog or Dynatrace network monitoring software was the better fit for us. We decided to go with Dynatrace. Dynatrace offers network ...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

Adobe, Samsung, facebook, HP Cloud Services, Electronic Arts, salesforce, Stanford University, CiTRIX, Chef, zendesk, Hearst Magazines, Spotify, mercardo libre, Slashdot, Ziff Davis, PBS, MLS, The Motley Fool, Politico, Barneby's
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Datadog vs. IBM Security QRadar and other solutions. Updated: October 2024.
815,854 professionals have used our research since 2012.