Try our new research platform with insights from 80,000+ expert users

Exabeam vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024
 

Categories and Ranking

Exabeam
Ranking in Security Information and Event Management (SIEM)
12th
Ranking in User Entity Behavior Analytics (UEBA)
2nd
Ranking in Security Orchestration Automation and Response (SOAR)
8th
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
18
Ranking in other categories
Security Incident Response (5th), Threat Intelligence Platforms (8th), AI-Powered Cybersecurity Platforms (5th)
IBM Security QRadar
Ranking in Security Information and Event Management (SIEM)
4th
Ranking in User Entity Behavior Analytics (UEBA)
1st
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.0
Number of Reviews
204
Ranking in other categories
Log Management (6th), Endpoint Detection and Response (EDR) (18th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (14th)
 

Mindshare comparison

As of November 2024, in the Security Information and Event Management (SIEM) category, the mindshare of Exabeam is 1.1%, down from 1.6% compared to the previous year. The mindshare of IBM Security QRadar is 9.5%, up from 9.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM)
 

Featured Reviews

Stephen-Armstrong - PeerSpot reviewer
Sep 11, 2024
The SIEM provides a user-friendly UI experience
I use Exabeam for it's end-to-end detection and it's user event behavioural Analytics, i find it a useful SIEM for investigating unusual behaviour by clicking into an incident from the main dashboard. From here we can go into the details of the incident, which are shown by the individual risk…
Muzzamil Hussain - PeerSpot reviewer
Aug 1, 2024
Is easy to integrate and doesn't require maintenance
One major drawback we are facing is in the area of IBM Security QRadar integration with flat file databases. IBM Security QRadar does not support flat file database integration. We are currently facing an issue with respect to the database, which you normally call a NoSQL database. There is no direct integration mechanism available with IBM Security QRadar. We have to approach IBM and generate a ticket so that they can develop a custom method for the integration. In database integration, we are facing issues with IBM Security QRadar. The solution does not support the integration of flat file databases. Certain organizations have flat file databases. IBM does not support direct integration with some databases. We had to create a plug, and we requested IBM to develop a parser, but it is taking IBM a couple of months to develop it. I think a flat-file database should be supported directly instead of developing a parser plugin. There should be a more refined threat intelligence platform, and cross-integration should be possible with locally available threat intelligence platforms.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The way it can connect with AWS is very useful, and the integrations are pretty good."
"The most valuable feature of Exabeam is the timeline creation based on log sources, which helps in security investigations."
"Exabeam Fusion SIEM has a good performance and more advantages than traditional solutions."
"The user interface and the timelines they use are the most valuable features. The price model is very simple so that one can understand it easily and there are no surprises within it."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"The Exabeam SIEM has a user friendly UI interface."
"The ThreatHunter in Advanced Analytics is the most valuable. It helps analyze compromised assets and provides analysis for any entity within my client's environment."
"It is user-friendly and quite simple to use."
"It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important."
"We've found the solution to be scalable."
"The monitoring and dashboards are great."
"The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log."
"Integrations are quite a useful and key feature of this solution. It has integration with the CVSS score, which is a central point for all the data and scores about the threats. There is an IBM Bluemix dashboard that is integrated with the CVSS score."
"think QRadar is great overall. We’ve had a positive experience with it and recommend it for deployment. However, there are areas for improvement. The technical support is good, and the documentation is valuable, but it could be enhanced, especially regarding integration with other systems. In terms of support and updates, QRadar’s capabilities are crucial for maintaining high security standards. Network and software administrators can monitor all traffic effectively, which reassures clients and drives further adoption."
"The scalability is very good. It's not a problem."
"It showed us where weaknesses were in our environment, so we could actively target those patches first."
 

Cons

"I believe if it were more flexible it would be a better product."
"The solution's reporting and dashboarding could be improved."
"One area for the solution's improvement is integration capabilities, particularly out-of-the-box integration which sometimes requires additional professional services."
"The only problem is that the UI is not very impressive."
"The customer service and support are not satisfactory."
"They need to focus on more of the MITRE ATT&CK Framework and coverage. They claim they cover about 70 to 80%. I'm not sure if it's really quite that much, however."
"Exabeam needs to improve its adaptive nature towards rules and its capability to understand the entire client environment faster."
"We still have questions surrounding hardware deployment."
"The user interface is a bit difficult to get used to."
"With IBM Security QRadar, my company faced issues with the support we received for the product."
"The IBM support can be better."
"The solution should include remote action capabilities."
"There should be easier and wider integration opportunities. There should be more opportunities for integration with CTI info sharing areas. On platforms where you exchange CTI, there should be more visibility connected to what we share, what we can reach, or what options are connected to CTI info sharing. This is one area where they could add value because we cannot integrate it easily with QRadar. If a client has a legacy or already existing solutions for CTI, we cannot ask them to forget it because we cannot guarantee that QRadar is able to deliver everything connected to this area."
"For future updates, I'd like to see more advanced threat intelligence features integrated with AI. This would help with analyzing traffic patterns and improving protection. QRadar currently doesn't integrate with AI for threat analysis. However, AI could enhance its capabilities by learning traffic patterns and automatically blocking or quarantining suspicious traffic. This would be especially useful when administrators are not actively monitoring. AI could help by analyzing incoming and outgoing traffic and adjusting policies accordingly."
"If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."
"IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."
 

Pricing and Cost Advice

"Exabeam is not a cheap solution."
"The platform is not extremely expensive compared to its direct competitors; I would rate its pricing around six out of ten."
"Exabeam Fusion SIEM's pricing is reasonable."
"They have a great model for pricing that can be based either on user count or gigabits per day."
"The solution is expensive."
"There is an annual license required to use Exabeam Fusion SIEM. The price of the solution should be reduced."
"There is an annual license required for this solution."
"Pricing and licensing are competitive. Their new licensing options allow logs to bypass the correlation engine for a flat rate, which is also appealing for log data that is compliance-driven for a small amount of money."
"The pricing is good."
"The maintenance costs are high."
"I think my company pays for the license yearly."
"It is costlier as compared to the other alternatives available in the market."
"The solution has a licensing model that is based on events per second so it scales to need and budget."
"It is cheaper than ArcSight."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
12%
Manufacturing Company
10%
Government
7%
Educational Organization
22%
Computer Software Company
14%
Financial Services Firm
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What do you like most about Exabeam Fusion SIEM?
The solution's initial setup process is easy.
What is your experience regarding pricing and costs for Exabeam Fusion SIEM?
I do not have much information about the pricing. However, I am aware that Exabeam is cheaper than Palo Alto based on discussions in meetings.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

Hulu, ADP, Safeway, BBCN Bank
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Exabeam vs. IBM Security QRadar and other solutions. Updated: November 2024.
815,854 professionals have used our research since 2012.