Try our new research platform with insights from 80,000+ expert users

Grafana Loki vs IBM Security QRadar comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

Grafana Loki
Ranking in Log Management
7th
Average Rating
8.2
Reviews Sentiment
8.0
Number of Reviews
17
Ranking in other categories
No ranking in other categories
IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
204
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (14th)
 

Mindshare comparison

As of December 2024, in the Log Management category, the mindshare of Grafana Loki is 6.8%, up from 1.4% compared to the previous year. The mindshare of IBM Security QRadar is 4.5%, down from 5.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

CarlosPimentel - PeerSpot reviewer
Efficient log filtering enhances quick network troubleshooting
We use Grafana Loki for various verticals including manufacturing, finance, health, and aerospatial sectors. It primarily helps in monitoring security and access to devices. Grafana dashboards are used to track access success and failure and audit commands issued on devices Loki significantly…
Muzzamil Hussain - PeerSpot reviewer
Is easy to integrate and doesn't require maintenance
One major drawback we are facing is in the area of IBM Security QRadar integration with flat file databases. IBM Security QRadar does not support flat file database integration. We are currently facing an issue with respect to the database, which you normally call a NoSQL database. There is no direct integration mechanism available with IBM Security QRadar. We have to approach IBM and generate a ticket so that they can develop a custom method for the integration. In database integration, we are facing issues with IBM Security QRadar. The solution does not support the integration of flat file databases. Certain organizations have flat file databases. IBM does not support direct integration with some databases. We had to create a plug, and we requested IBM to develop a parser, but it is taking IBM a couple of months to develop it. I think a flat-file database should be supported directly instead of developing a parser plugin. There should be a more refined threat intelligence platform, and cross-integration should be possible with locally available threat intelligence platforms.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Loki significantly saves time in troubleshooting by quickly pinpointing network issues."
"The effectiveness of filters is pivotal for optimizing the search process and extracting the specific information we need from the extensive log data."
"Grafana Loki is easy to monitor and detect errors."
"There are new features like that pilot code and things like that for profiling."
"The most valuable feature is the capability to set up alerts, which becomes necessary when we need to receive notifications for specific events."
"The most valuable feature of the solution is the tool's GUI. The solution's GUI is very user-friendly."
"The log collection feature is good and the solution is easily understandable. v"
"I appreciate the capability to process logs from microservices and seamlessly integrate them into Grafana."
"IBM QRadar is great help from its security event monitoring to data center and NOC troubleshooting of issues hard for other departments to spot."
"The most valuable feature of the solution is its ability to rectify a situation involving any anomalies expeditiously."
"It's hard for me to pinpoint any one feature that's most valuable because it is all about consuming logs and analyzing them. We started using QRadar UBA because we needed something that could analyze Linux authentication information. Other products take care of the Windows platform."
"The threat hunting capabilities in general are great."
"It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important."
"The scalability is very good. It's not a problem."
"The rule engine is very easy to use — very flexible."
"The most valuable features would have to be the products' ability to customize vulnerability management settings."
 

Cons

"There is a need for some change in the alerting types of the product. In short, a few changes in the alert area are needed due to minor shortcomings."
"It's not intended for proprietary services, so you have to struggle with configuration a lot."
"The solution's scalability depends on the team managing the Grafana instance."
"The platform's stability needs improvement."
"Visualization-wise, Grafana Loki's dashboard looks a little outdated compared to other open-source visualization tools like Chronograf."
"It would be beneficial if Loki could directly access Windows Server logs or events directly from the servers."
"The Docker container partition feature needs improvement as they do not reuse the space and goes into a pending state."
"In Grafana Loki, the creation of metrics is not so easy, making it an area that could be made easier."
"The solution is not as flexible as Splunk."
"The usability of interfaces could be improved."
"The reporting system could use some upgrading."
"The product can be a bit complex."
"It is very difficult to activate all of the network equipment, and it would help if it were made easier."
"Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."
"Ideally we would like a mobile version so that any alert that comes in will notify us in a mobile app, or by using SMS integration."
"A lot of information that we receive for the devices is IP-based, but it would help if we could have a default dashboard in which we can add more details about the assets for which we are receiving the information. For example, if it is a Windows or Linux device, we only get the IP for that particular device. We don't really get the name and other details of that particular device. For that, you have to drill down into your own asset management system. It would be good to have a place where we can probably add this information so that we don't have to look into other tools."
 

Pricing and Cost Advice

"I find the licensing structure quite reasonable, as the free license effectively meets my requirements."
"Grafana Loki is a free, open-source solution."
"My company doesn't need to pay for the licensing cost of the solution."
"You can use the free version of Grafana Loki on-premises."
"The solution is open source."
"The cost is less than other paid services like CloudWatch."
"Since we are using the open-source version of Grafana Loki, we are not paying anything for the solution."
"Grafana Loki is an open-source solution."
"I think my company pays for the license yearly."
"The pricing needs to be such that they are more competitive with other vendors."
"The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it."
"The pricing is always fine."
"The maintenance costs are high."
"It's too expensive. The licensing is also a little bit difficult to understand because you have to license it per event and per number of flows."
"It is costlier as compared to the other alternatives available in the market."
"IBM has subscriptions plans that run for one year."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Comms Service Provider
9%
Financial Services Firm
9%
Manufacturing Company
9%
Educational Organization
23%
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Grafana Loki?
We are using Grafana Loki as a database for real-time metrics.
What is your experience regarding pricing and costs for Grafana Loki?
We use the open-source version of Loki. The cloud version is competitively priced compared to other market solutions.
What needs improvement with Grafana Loki?
It would be beneficial if Loki could directly access Windows Server logs or events directly from the servers.
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
 

Learn More

 

Overview

 

Sample Customers

Information Not Available
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Find out what your peers are saying about Grafana Loki vs. IBM Security QRadar and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.