Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs IBM SevOne Network Performance Management (NPM) comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
207
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (17th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (12th)
IBM SevOne Network Performa...
Ranking in Log Management
48th
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
53
Ranking in other categories
Network Monitoring Software (40th), Server Monitoring (19th), IT Infrastructure Monitoring (45th), Cloud Monitoring Software (28th)
 

Mindshare comparison

As of March 2025, in the Log Management category, the mindshare of IBM Security QRadar is 3.9%, down from 5.2% compared to the previous year. The mindshare of IBM SevOne Network Performance Management (NPM) is 0.3%, down from 0.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
Real-time incident detection and user-friendly dashboard benefit daily operations
There are many types of AI, and this AI is very limited in SQL and features. There may be potential for improvement. So far, it seems very limited. It shows some good features in the correlation part, but I think there is room for improvement. For instance, when creating rules, it can suggest more rules, reducing the effort needed. If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules. Sometimes logs I receive don't mean anything, and I need technical stakeholders to share or forward logs, but these are sometimes inadequate. Keywords can help identify insufficient logs. I often lack time to verify logs. Sharing false positive results could be reduced to help my team.
Grzegorz Nowak - PeerSpot reviewer
Improves infrastructure planning by helping us analyze network traffic
We use SevOne to collect and report on network flows SevOne improves infrastructure planning by helping us analyze network traffic. We can look at bandwidth for specific endpoints on the customer's network and analyze traffic to identify issues. For example, maybe some connectors are unavailable.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution provides me with various alarms, and I have found security issues with some of my other products."
"The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding."
"It has improved my efficiency."
"Most of our clients are interested in automation. The automation part is good because they are able to detect threats and vulnerabilities in real time. It's very fast."
"IBM QRadar has improved my organization by introducing many functions. It collects logs from all of our systems in the organization and has functioned very well. It alerts and correlates the aggregate events or offenses we receive through all the applications we use."
"It is very stable. We have not faced interruptions in the past four and a half years."
"The product has plenty of features and capabilities."
"What's most valuable in IBM QRadar User Behavior Analytics is its higher availability than other tools."
"The comprehensiveness of this solution's collection of network performance and flow data is one of the basics in the field for what it does. It meets all of our needs. So for all those areas, for the most straightforward collection capabilities, right up to NetFlow and even telemetry, it meets all those demands. Not only just basic or fundamental SNMP collection capability, but the product also supports what we need for the future with telemetry streaming. So it's very comprehensive."
"One of the most valuable features is the graphs, which you can build instantly. I have used some open-source platforms in the past, but they are not as good. With SevOne, the sampling in the graph can be every few seconds, not just every few minutes, and that's really helpful. It's really fast."
"The monitoring of the network is very customizable. That is its unique feature."
"I like SevOne's network flow reporting."
"It's a great solution for highlighting and discovering useful information regarding our network's elements."
"In 90% of the cases, new devices are plug-and-play, so when a new version comes out then SevOne has support for it out of the box."
"The SMP and the xStats, which is for flat file integration, are both useful for integrating the various metrics that the device provides to monitor the performance of those systems."
"Its ability to monitor practically any type of network device via SNMP is most valuable. This is the main functionality that we're using. If a network device exposes a metric, such as interface utilization, SevOne will monitor it for us."
 

Cons

"The technical support can be improved a little bit, and the price could be cheaper."
"They should speed up the incident response and also, at the same time, reduce the amount of manual effort that is required."
"IMB should reduce the pricing, or reduce some of the features for a more economical solution for the customer."
"The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue."
"The solution is highly used here in Pakistan and in many sectors, they could improve it by having more SIEM connectors."
"The solution is clunky."
"The AI engine could be smarter."
"QRadar needs a lot of fine tuning"
"The GUI: both the dashboard/user view and the admin tool."
"You need to plan integrations. That has been the biggest bug with SevOne so far. For the things that SevOne pulls directly, those are easy to understand, modify, and put into the database. For things that need to use the Universal Collector or xStats, you need to plan that stuff well in advance."
"Telemetry is hot these days, and IBM can improve SevOne's support for telemetry correction. Reporting is another feature that could be better. It provides the bare minimum functionality, which is good enough for most engineers, but the management isn't advanced. The new portal provides a much lighter view and better visualization, but the management is not so good."
"High-frequency polling is data-intensive because you're pulling more. If SevOne could figure out a way to manage the impact of high-frequency polling on the system, that would be very popular."
"When I started using it, I tried adding one of the BroadWorks application servers into SevOne... it created thousands and thousands of objects from that one application server and we immediately ran out of license... It would help, when new objects are discovered, if there were a way to categorize those objects and to pick the part of the object you need..."
"One area that requires a little bit of improvement is the topology of visualization and being able to map out connections, end-to-end. It's able to do that, but it's not as impressive as we would like it to be. We would like to understand the different interface types and the connection points better, through the visualization. Heatmaps also need further development."
"The customizations are very hard. The person doing it has to be very good at analytics and has to be very good in all languages"
"The reporting of NMS is good, but it could be better."
 

Pricing and Cost Advice

"The price of this solution is reasonable."
"think the pricing is quite flexible."
"There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk."
"As for licensing costs, I haven't seen the exact figures, but it is considered somewhat costly. On a scale from one to ten, where one is very expensive and ten is very cheap, I would rate it a six—it’s costly but worth the money."
"QRadar is quite expensive. It wouldn't be worth it for a small business..."
"Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you."
"The license is not subscription-based."
"There is an annual license required for this solution."
"Prices per license are not huge, but they exist."
"Have a bank of licenses, because it is about the number of objects (RAM, ports, CPU, etc.)."
"Many tools price things based on the number of KPIs that you're collecting around a device. In many cases, there could be hundreds of metrics that you need to collect. SevOne provides device-level pricing. That gives us the flexibility to turn on, and expand on, the metrics that we're collecting around those devices, without taking a financial hit."
"A blocking point is the high upfront cost because it is challenging to get it accepted and the purchase approved."
"The pricing has not evolved with the market, which is one of the reasons we are moving to a new product."
"The tool is not expensive. We were able to negotiate with SevOne on pricing."
"There are different options available for licensing, with the per-device option being more expensive but more flexible."
"Choose a SevOne partner who can provide SevOne as a service and can deliver professional services and maintenance."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
841,302 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
14%
Financial Services Firm
10%
Government
6%
Financial Services Firm
15%
Manufacturing Company
15%
Computer Software Company
15%
Legal Firm
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
The cost depends. The price I negotiated varies by region and relationship with the OEM. Cost is not shared due to another procurement team handling negotiations, but it was reasonable as far as I ...
What do you like most about SevOne Network Data Platform?
I like the tool’s scalability and real-time reports. Earlier, we struggled to give real-time reports to clients. I also like the tool’s deployment model where we can deploy it either on-premises or...
What is your experience regarding pricing and costs for SevOne Network Data Platform?
The tool is not expensive. We were able to negotiate with SevOne on pricing.
What needs improvement with SevOne Network Data Platform?
SevOne could improve its flexibility because it isn't fully customizable and its out-of-the-box configuration doesn't cover all use cases.
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
SevOne
 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
ATOS, Devereux, Spark New Zealand, Access4, Rogers Communication, Lumen (formerly known as CenturyLink)
Find out what your peers are saying about IBM Security QRadar vs. IBM SevOne Network Performance Management (NPM) and other solutions. Updated: March 2025.
841,302 professionals have used our research since 2012.