Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs IBM SevOne Network Performance Management (NPM) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
204
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (14th)
IBM SevOne Network Performa...
Ranking in Log Management
46th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
53
Ranking in other categories
Network Monitoring Software (41st), Server Monitoring (19th), IT Infrastructure Monitoring (41st), Cloud Monitoring Software (31st)
 

Mindshare comparison

As of December 2024, in the Log Management category, the mindshare of IBM Security QRadar is 4.5%, down from 5.6% compared to the previous year. The mindshare of IBM SevOne Network Performance Management (NPM) is 0.3%, down from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Muzzamil Hussain - PeerSpot reviewer
Is easy to integrate and doesn't require maintenance
One major drawback we are facing is in the area of IBM Security QRadar integration with flat file databases. IBM Security QRadar does not support flat file database integration. We are currently facing an issue with respect to the database, which you normally call a NoSQL database. There is no direct integration mechanism available with IBM Security QRadar. We have to approach IBM and generate a ticket so that they can develop a custom method for the integration. In database integration, we are facing issues with IBM Security QRadar. The solution does not support the integration of flat file databases. Certain organizations have flat file databases. IBM does not support direct integration with some databases. We had to create a plug, and we requested IBM to develop a parser, but it is taking IBM a couple of months to develop it. I think a flat-file database should be supported directly instead of developing a parser plugin. There should be a more refined threat intelligence platform, and cross-integration should be possible with locally available threat intelligence platforms.
Grzegorz Nowak - PeerSpot reviewer
Improves infrastructure planning by helping us analyze network traffic
We use SevOne to collect and report on network flows SevOne improves infrastructure planning by helping us analyze network traffic. We can look at bandwidth for specific endpoints on the customer's network and analyze traffic to identify issues. For example, maybe some connectors are unavailable.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is the core of our entire SOX."
"This solution has allowed us to correlate logs from multiple sources."
"We have worked with other solutions, such as LogRhythm and Splunk. Compared to others, IBM QRadar has the best price-performance ratio so that you are able to reserve minimum costs. It starts settling in fast and gets the first results very quickly. It is also very scalable."
"The visibility it gives you into your infrastructure has been great."
"The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
"We find predictive analysis capabilities valuable."
"The most valuable feature is user behavior analytics (UBA)."
"The solution is reliable."
"Scalability. I have never had to worry about how to handle really big environments."
"We find that the reporting is particularly valuable in terms of not only communicating with our peer teams but also with the executives."
"Flexible architecture: You can extend the system and its capacity by attaching another cluster pair."
"We've had great feedback from our customers about SevOne support. They're willing to set up a remote session upon request. You have to go through three tiers of support with most vendors, and they ask a lot of screening questions before they will do a remote session. You need to spend a lot of time before an engineer will host a remote session to look at your problematic system."
"The comprehensiveness of this solution's collection of network performance and flow data is one of the basics in the field for what it does. It meets all of our needs. So for all those areas, for the most straightforward collection capabilities, right up to NetFlow and even telemetry, it meets all those demands. Not only just basic or fundamental SNMP collection capability, but the product also supports what we need for the future with telemetry streaming. So it's very comprehensive."
"The modules and the performance management reports that come with data insights are two of the most valuable features. I also find the reports for Wi-Fi, Netflow, LAN, and WAN for monitoring to be very good."
"SevOne provides support for all universal connectors. They internally work with other data sources to get features implemented. We have an SD-WAN implementation and use other app data to monitor performance. If you pull that data into one centralized location, that is very useful for management."
"The network data collection has been very flexible for us. It's been thorough in areas that were lacking. They have a team that I've worked with to add other pieces to it. So if it's missing something out of the box, they work with me to add it. I was able to collect that data. It's not perfect, but it's pretty thorough."
 

Cons

"IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer."
"The solution is expensive compared to other products."
"The dashboard and reports are not user-friendly or efficient so are of little help with threat hunting activity."
"The architecture could be improved. I got stuck for a long time trying to understand the architecture, as it is quite challenging."
"Do your research before implementing it, because it is tough to implement."
"The quoting and the dashboard session could be improved. It should be more user-friendly."
"Technical support is good, but not great."
"Some UI enhancements would be nice, such as exporting custom event properties and the ability to export rules."
"The one area with room for improvement is probably administration. They added data insights to make a better user experience, but I'd like to see some improvements in the way the system's administered."
"The GUI: both the dashboard/user view and the admin tool."
"NMS has several areas for improvement. It should be more user-friendly inside of NMS for some of the functionality in there. It's been getting better the last version or two, but the there have been bugs in there whenever I've gone to new versions."
"We need to be thinking about streaming telemetry protocols. They already have the port for enhanced visualization, which they already have through Data Insight."
"We previously have had discussions on some reporting enhancements. So, we raised a feature request, which was delivered from SevOne."
"Their virtualization solution is not compatible with our Kubernetes environment, which is one of the reasons we are ending our relationship with them."
"Would benefit with the addition of AI modules for proactive data insights."
"The method of searching for SIP and the way to create the groups."
 

Pricing and Cost Advice

"QRadar UBA's price is a little more than street price and could be reduced."
"The solution has a licensing model that is based on events per second so it scales to need and budget."
"Pricing is good."
"It's too expensive."
"QRadar is quite expensive. It wouldn't be worth it for a small business..."
"Pricing (based on EPS) will be more accurate."
"An X-Force feed is free with QRadar."
"I would like for them to lower the price."
"Have a bank of licenses, because it is about the number of objects (RAM, ports, CPU, etc.)."
"There are cheaper solutions available."
"Although I don't have exact details in terms of cost, my experience has been that SevOne is willing to make a deal with the customer."
"Many tools price things based on the number of KPIs that you're collecting around a device. In many cases, there could be hundreds of metrics that you need to collect. SevOne provides device-level pricing. That gives us the flexibility to turn on, and expand on, the metrics that we're collecting around those devices, without taking a financial hit."
"It is inexpensive compared to other monitoring tools."
"The tool is not expensive. We were able to negotiate with SevOne on pricing."
"For the value that you get from SevOne, it's worth the price. There are a lot of cheaper alternatives on the market, and even free options. But they require more staff, more resources, and engineers with more advanced knowledge of monitoring. That's what makes SevOne worth the price."
"There are different options available for licensing, with the per-device option being more expensive but more flexible."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Educational Organization
23%
Computer Software Company
15%
Financial Services Firm
10%
Manufacturing Company
6%
Manufacturing Company
15%
Computer Software Company
15%
Financial Services Firm
15%
Educational Organization
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What do you like most about SevOne Network Data Platform?
I like the tool’s scalability and real-time reports. Earlier, we struggled to give real-time reports to clients. I also like the tool’s deployment model where we can deploy it either on-premises or...
What is your experience regarding pricing and costs for SevOne Network Data Platform?
The tool is not expensive. We were able to negotiate with SevOne on pricing.
What needs improvement with SevOne Network Data Platform?
SevOne could improve its flexibility because it isn't fully customizable and its out-of-the-box configuration doesn't cover all use cases.
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
SevOne
 

Learn More

 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
ATOS, Devereux, Spark New Zealand, Access4, Rogers Communication, Lumen (formerly known as CenturyLink)
Find out what your peers are saying about IBM Security QRadar vs. IBM SevOne Network Performance Management (NPM) and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.