Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs VMware Aria Operations for Logs comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 5, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security QRadar
Ranking in Log Management
6th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
207
Ranking in other categories
Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (18th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (10th), Extended Detection and Response (XDR) (13th)
VMware Aria Operations for ...
Ranking in Log Management
16th
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
25
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2025, in the Log Management category, the mindshare of IBM Security QRadar is 4.5%, down from 5.5% compared to the previous year. The mindshare of VMware Aria Operations for Logs is 1.2%, down from 1.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Log Management
 

Featured Reviews

Md. Shahriar Hussain - PeerSpot reviewer
Real-time incident detection and user-friendly dashboard benefit daily operations
There are many types of AI, and this AI is very limited in SQL and features. There may be potential for improvement. So far, it seems very limited. It shows some good features in the correlation part, but I think there is room for improvement. For instance, when creating rules, it can suggest more rules, reducing the effort needed. If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules. Sometimes logs I receive don't mean anything, and I need technical stakeholders to share or forward logs, but these are sometimes inadequate. Keywords can help identify insufficient logs. I often lack time to verify logs. Sharing false positive results could be reduced to help my team.
LarsChristensen - PeerSpot reviewer
Efficient troubleshooting with precise log filtering and an easy setup
The tool could benefit from improved filter settings and dashboarding. While there are dashboards available, they are often created by community members and may not work after updates. It would be beneficial to have a roadmap for these dashboards to ensure consistent functionality. It would also be advantageous if the tool could process even large amounts of data faster, though this may be more related to data movement challenges rather than the software itself.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The correlation and the parsing are important features, since it is very important for a SIEM to have a good scalability and performance."
"The threat hunting capabilities in general are great."
"IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
"The tool helps with infrastructure, application, and network monitoring."
"We run 65 servers globally with just two people: an engineering person and me."
"We've found the solution to be scalable."
"The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding."
"Integration is very easy and the reporting is good."
"The system's management and its alerts are the most valuable aspects of the solution."
"The ability to narrow into a specific time to filter heavy hitters and anomalies is extremely valuable."
"The interface of the solution is good."
"It is very scalable and can handle a large workload."
"I like the interface."
"What I like is that you can have different storage locations for different applications."
"One of the things I like about it is its interface. When it comes to generating reports on VMs and stuff, it's very quick. This is very handy for the technical team, who need to generate reports quickly. So that's really good."
"The root cause analysis feature is very valuable."
 

Cons

"IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."
"The implementation of the solution's technology needs to be simplified."
"I would like for them to develop a detection management solution. It does not have a detecting management solution in it, you have to buy it as it is, on top of the extended solution."
"In terms of what could be improved, I would say the script which we have to create for custom actions. QRadar needs to improve that feature. Additionally, QRadar has to provide the playbooks designing features."
"They should introduce some automation into the product."
"They should provide more manual examples online so that I can learn it myself."
"The technical support can be improved a little bit, and the price could be cheaper."
"The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria."
"The solution should be more user-friendly. The user interface and dashboard could be simplified."
"Log retention should have more options for user control."
"I think that it should be able to integrate with other third-party backup and recovery solutions, more that it does now."
"The pricing of the solution could be improved."
"Technical support should be improved."
"I don't use the solution on a day to day basis, so I'm not sure what specifically can be improved."
"The tool could benefit from improved filter settings and dashboarding."
"It needs better integration with third-party analytics tools."
 

Pricing and Cost Advice

"When compared with other SIM solutions, QRadar is considerably less expensive."
"The solution has a licensing model that is based on events per second so it scales to need and budget."
"QRadar UBA's price is a little more than street price and could be reduced."
"It is costlier as compared to the other alternatives available in the market."
"An X-Force feed is free with QRadar."
"It is expensive. It is not a product that I can provide for SMBs. It is a program that I can only provide for really large enterprises."
"There is a license required for this solution and it is an annual payment. I have found all solutions in the category to be expensive, including Splunk."
"The price of this solution is a little high."
"Pricing is good because it is part of the suite package. It comes in a bundle for us."
"I rate the product's price a six on a scale of one to ten, where one is cheap, and ten is expensive."
"The licensing cost for vRealize Log Insight is a little higher, so in terms of cost, it all depends upon what kind of environment you have. If you have a complete virtualized environment, or at least you're using a ninety-five percent virtualized environment, then vRealize Log Insight will play a very good role because it is a VMware component, so it has very tight integration with other VMware components and systems. This means you don't have to procure any other monitoring and management tool, and you don't need a separate automation tool. vRealize Log Insight will have an upper hand if your environment is purely virtualized on VMware. If you're using a mix of physical and virtual components, for example, a 50:50 ratio, then you need to have a third-party component to manage overall monitoring."
"The license cost for any other monitoring tool is too high compared to this product."
"Pricing could always be lower. If it were free, I would be more satisfied."
"I think it is a reasonably priced product."
"The pricing has been updated recently."
"It is not cheap. But it is worth it."
report
Use our free recommendation engine to learn which Log Management solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
14%
Financial Services Firm
10%
Manufacturing Company
6%
Computer Software Company
16%
Government
15%
Financial Services Firm
12%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about IBM QRadar?
The event collector, flow collector, PCAP and SOAR are valuable.
What do you like most about vRealize Log Insight?
The events are notably more descriptive, aiding in security and event analysis. We've also integrated Sky Collector, providing valuable insights and solutions for troubleshooting.
What is your experience regarding pricing and costs for vRealize Log Insight?
One major advantage of VMware compared to Splunk is pricing. VMware is licensed based on hardware rather than the amount of data, making it much cheaper. Splunk, often paid by the terabytes, become...
What needs improvement with vRealize Log Insight?
The tool could benefit from improved filter settings and dashboarding. While there are dashboards available, they are often created by community members and may not work after updates. It would be ...
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, QRadar, IBM QRadar User Behavior Analytics, IBM QRadar Advisor with Watson
vRealize Log Insight
 

Learn More

Video not available
 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Wildlands Adventure Zoo, Medic Mobile, IBM, Seventy Seven Energy, Baystate Health, Osis, Oxford University, Columbia University, Siemens, Cardinal Health, Ashdod Port, Vasakronan, Sydney Adventist Hospital, University of Derby
Find out what your peers are saying about IBM Security QRadar vs. VMware Aria Operations for Logs and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.