We are implementors and implement this solution for our clients, who use it for analytics.
Cyber Security Consultant at Software Productivity Strategists, Inc. (SPS)
Reliable with good technical support but needs better visualization
Pros and Cons
- "The product can scale."
- "The product can be a bit complex."
What is our primary use case?
What is most valuable?
It offers good machine learning. The analysis is very helpful.
The user activity is effectively flagged. It can pinpoint strange activity.
It is stable and reliable.
The product can scale.
Technical support is good.
What needs improvement?
The product can be a bit complex. A lot of things, like visualization, could be better. It would help the customer gain a better understanding.
For how long have I used the solution?
I've used the solution for five to six years. I've used it for a while now at this point.
Buyer's Guide
IBM Security QRadar
February 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. I'd rate the stability eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It can handle thousands of users or maybe even more. I'd rate the scalability nine out of ten.
We mostly deal with small or medium enterprises.
How are customer service and support?
Most of the time, technical support is helpful. I am satisfied with the level of service we receive.
How would you rate customer service and support?
Positive
How was the initial setup?
It is easy to implement. I'd rate the ease of implementation seven out of ten.
The deployment only takes no more than a few hours. There are configurations and fine-tuning that have to happen after that, and everything could take about a week.
What about the implementation team?
As implementors, we can implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. It's not expensive compared to other solutions. If you get the console and other licenses, you can easily use it with other QRadar solutions.
What other advice do I have?
New clients should know that it does give good analytics and it will help them save time.
I'd rate the solution seven out of ten. It's a good product.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer

System Engineer at Trans Business Machines Ltd
Incredible capacity for creating machine models; falls short on documentation
Pros and Cons
- "The timeline and machine learning features are great."
- "The solution lacks vendor support."
What is our primary use case?
Our primary use case is logging for any anomalous traffic in terms of access times and deviations when users are in different groups within the AD. When a user deviates from their functionality, it's flagged in the UBA and for VPN traffic. I also use it for geolocation functionality. We are partners of IBM and I'm a system engineer.
What is most valuable?
The timeline and the machine learning features are great at quickly flagging users who have either left the organization or have dormant accounts. The way that the app has transformed over time is quite phenomenal. One of the major improvements is its capacity for creating machine models. It comes with 16 default machine learning models, where it tracks user activity and changes in profiles and authentications. There are various default machine learning models and I'm able to model those to parameters that suit my needs. It's great that I'm able to implement an unlimited number of use cases on the UBA, putting in as many different kinds of logic as I want. It's a big advantage.
What needs improvement?
I'd like to see improved support from the vendor. In addition there are things that are not documented on the IBM site. If you'd like to do something at a high level, the information is not available in the documentation and you have to find it elsewhere.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
The solution has never crashed or failed, it's stable.
What do I think about the scalability of the solution?
We haven't tested scalability and currently have around 100 users. I'm responsible for maintenance.
How are customer service and support?
The customer support is helpful but that's more about it being a good solution.
How was the initial setup?
The initial setup is straightforward, it's just a download and it installs. It's a matter of configuring a few parameters in terms of tweaking the thresholds that you want the app to fire in on. Installing takes a few seconds, but in terms of letting it land so that you can tweak it and tune the various metrics, takes about a week.
What's my experience with pricing, setup cost, and licensing?
This is a free solution which is one of the main reasons we chose it. It's just a matter of getting a license for the curator as a platform.
What other advice do I have?
I recommend this solution and rate it seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Buyer's Guide
IBM Security QRadar
February 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
IT Solutions Product Manager at a computer software company with 11-50 employees
It is very easy to install and configure, but after restarting the server, you need to manually start some of the services
Pros and Cons
- "What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own."
- "I have noticed a few things while working on this. After the restart of the server, sometimes, the services misbehave, and you need to manually start or restart the service. I have seen that specifically with the Tomcat service. Sometimes, when you click on log sources, instead of opening the log source extension, it redirects you over the internet."
What is our primary use case?
I am a Product Manager. I am managing the inventory and the logs. For R&D purposes, we downloaded various SIEM solutions from the internet to analyze their performance, and QRadar was one of them. I downloaded the Community Edition of QRadar to check its capabilities and see how to integrate various log sources in our network. It is in my lab, and I have tested it with a few hardware devices and a few computers and servers.
What is most valuable?
What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own.
What needs improvement?
I have noticed a few things while working on this. After the restart of the server, sometimes, the services misbehave, and you need to manually start or restart the service. I have seen that specifically with the Tomcat service.
Sometimes, when you click on log sources, instead of opening the log source extension, it redirects you over the internet.
There are two types of dashboards in QRadar. One is the conventional or old one, and the other one is Pulse. The Pulse dashboard is better, but we would like to have more options in the dashboard.
Additionally, if possible, there should be a single product for SIEM and SOAR. Instead of having QRadar and Resilient separately, there should be a combined solution to benefit from both. Furthermore, there should be a built-in mechanism to configure it in the cluster mode and high availability mode.
For how long have I used the solution?
I tested this product in the last two, three months. It is not implemented in our company.
How was the initial setup?
Its installation is very simple. You can install it and configure it very easily.
Which other solutions did I evaluate?
We are looking at implementing a SIEM solution, and currently, we're comparing various commercial and open-source SIEM solutions. We have tested Wazuh, which is an open-source SIEM solution, but we have not finalized anything.
What other advice do I have?
I would rate it a seven out of 10. It is good, but when a product doesn't behave in a good manner, it creates confusion. Its behavior isn't consistent.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Technology Officer at a tech services company with 51-200 employees
Great dashboards and visibility; lacks decent support and some maturity
Pros and Cons
- "Improves visibility and has a great new dashboard."
- "The solution lacks some maturity."
What is our primary use case?
We are users and implementers of this solution.
What is most valuable?
I like the new dashboard which enables us to understand how many real threat attempts are made in a day. I also like the QRadar incident response, we installed the QIF last week. The solution has improved visibility so that we've been able to discover that some of our customers have not had any protection and were very vulnerable. It's an important area. I also find that the user behavior analysis is relatively simple. We are customers of QRadar.
What needs improvement?
I think the user management model is very detailed but you really have to know what you're doing just to be able to manage things. I think the solution lacks some maturity. When you put it in a large organization as a security system or a cybersecurity system and you want to enable automation, it's difficult to get that level of maturity.
For how long have I used the solution?
We've been using this solution for about 18 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. We have a total of 19 users in the company. The solution is used extensively and we plan to increase the number of users.
How are customer service and support?
The technical support could be better. I'd rather work with my implementing expert and not the OEM. Although they have the expertise, the development guys are very slow.
Which solution did I use previously and why did I switch?
We tested a few other solutions including AlienVault, Splunk, Micro Focus, and Outside. QRadar was the best of the breed for our needs and for a big system like ours, it's less complex than Splunk or Outside.
How was the initial setup?
The initial setup is complex. Theory is one thing and practice is another. We had to go back and forth with IBM just to find the relevant versions with the relevant operating system to sit on the relevant virtual environment. Then we found a few bugs. We are in a production system in a very big organization so deployment was carried out in stages. It took about a month in total to get things working and to start collecting logs. We had help from IBM Azure.
Maintenance is required, you have to watch it, and work on it on a daily basis.
What's my experience with pricing, setup cost, and licensing?
We pay an annual license fee. On top of that, every model adds to the cost. It's not just the license; the sales people want you to think you're only paying for certain things but we know how it works.
What other advice do I have?
The pre-design and the low-level design should be very, very, specific. It's important to check that the compatibility is there. If not, neither IBM nor OEM will support you.
I would rate the solution more highly but it's very expensive and given the high cost, I would expect quicker and better service from the OEM so I rate the solution seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Sales Consultant at Google, LLC
Great detection capability; lacks features such as predictive identification of threads
Pros and Cons
- "Vulnerability data, network data and the like, are part of correlation and detection."
- "Pricing model could be more cost-effective."
What is our primary use case?
I was initially a reseller before selling the solution from within IBM. I'm currently a freelance security sales consultant.
What is most valuable?
A valuable feature is the detection capability. I like that the solution can use data other than log data which means that things like vulnerability data, network data and the like, are part of the correlation and detection.
What needs improvement?
I think they could change their pricing model to be more cost effective. It currently relies on data ingestion. I'd like to see IBM extend their capability with the solution to include more than just fault finding, features such as predictive identification of threads. Having better support for things like MITRE and the ATT&CK chain, and using all of the known attacks that are out there when they're actually spotting events and correlations.
For how long have I used the solution?
I've used this solution for 10 years.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and technical support?
Technical support is pretty good, but sometimes when the problems are complex they can be slow to respond.
How was the initial setup?
The initial setup is very easy. I think it's one of the easiest SIMs to use.
What other advice do I have?
IBM has recently come out with a new version called Cloud Pak for Security but I haven't used it yet. It contains not just QRadar, but also IBM's resilience incident response products.
I recommend the solution but because of the issues with pricing and technical support, I rate the solution seven out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Senior Cyber Security Expert at a security firm with 11-50 employees
Robust and suitable for large companies with critical infrastructure
Pros and Cons
- "It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important."
- "There should be easier and wider integration opportunities. There should be more opportunities for integration with CTI info sharing areas. On platforms where you exchange CTI, there should be more visibility connected to what we share, what we can reach, or what options are connected to CTI info sharing. This is one area where they could add value because we cannot integrate it easily with QRadar. If a client has a legacy or already existing solutions for CTI, we cannot ask them to forget it because we cannot guarantee that QRadar is able to deliver everything connected to this area."
What is most valuable?
It is suitable for large companies with critical infrastructure. For our clients, robustness, availability at a high level, and the level of references and experiences connected to the solution are important. They need to know that other energy players are also using it.
What needs improvement?
There should be easier and wider integration opportunities. There should be more
opportunities for integration with CTI info sharing areas. On platforms where you exchange CTI, there should be more visibility connected to what we share, what we can reach, or what options are connected to CTI info sharing. This is one area where they could add value because we cannot integrate it easily with QRadar. If a client has a legacy or already existing solutions for CTI, we cannot ask them to forget it because we cannot guarantee that QRadar is able to deliver everything connected to this area.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the scalability of the solution?
We have five to ten customers of this solution. My impression is that it can cost a lot to scale upwards. It didn't bother us in most cases, but that could be a problem for SMEs at times.
How are customer service and technical support?
Their support during the operation seems fine. I'm a consultant, and very often, I am offsite. I am not there when clients get into operating QRadar in the long run. So, I know more about implementation than the operation itself.
How was the initial setup?
It requires expertise. If you have the right personnel, you can manage. It wouldn't be easy for a client and admins to set it up without proper support or support from QRadar itself.
What about the implementation team?
Setting it up requires an assistant like us. QRadar plays a role there, but that's not enough. There is also the language barrier. Not every Hungarian company is good in English, and IBM naturally doesn't have full Hungarian support.
It requires cooperation between clients and us. Typically, we send a team of five people that includes tech guys, a project manager, and maybe one process guy, if needed. Generally, you don't have 360-degree professionals, so you have someone good in networking, someone good in log management or log analysis, and so on. Because of that, we need this kind of team.
The client also has a few people. Typically, we send in more people than the client. These are not full-time people on our side and client-side.
What's my experience with pricing, setup cost, and licensing?
It could be cheaper, but the value itself is far more important for us than the price. Typically, our clients have yearly subscriptions.
What other advice do I have?
I don't know what I would recommend for SMEs because we never worked with SMEs, but I would be very careful in recommending QRadar for SMEs.
I would rate IBM QRadar a nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Operations Manager at a comms service provider with 501-1,000 employees
Flexible and very scalable with a straightforward setup
Pros and Cons
- "The solution is quite flexible."
- "Technical support really needs to be improved. Right now, they aren't where they need to be at all."
What is our primary use case?
We mostly use the product for PCI compliance.
What is most valuable?
We pay a little bit extra for Watson, and the Watson feature enables the analyst to go through and triage things much faster. It's quite useful for us and worth the smaller extra bit of money.
The solution is quite flexible.
We enjoy the fact that it is cloud-based.
The initial setup was very straightforward.
The solution is very scalable.
We've found the stability to be mostly very good.
What needs improvement?
Technical support really needs to be improved. Right now, they aren't where they need to be at all.
The solution is very expensive. We'd appreciate the product more if it came at a lower price point.
What do I think about the stability of the solution?
It is generally very stable. We've had odd little breakages, however, generally, nothing major has gone wrong. The performance is good. It's a reliable product.
What do I think about the scalability of the solution?
The scalability aspect of the product is very good. That was one of the reasons that we bought it. If a company needs to expand it, it can do so with relative ease. It's not hard.
Currently, all the members of the tech ops team use the product, and there are five of them.
We may not increase usage; we may switch to something else. That has yet to be determined. It's not set in stone.
How are customer service and technical support?
We've used technical support in the past and we haven't been satisfied with the level of service on offer.
Trying to get answers out of IBM is like trying to get blood out of a stone. They need to be more helpful and responsive. Right now, they aren't either of those things.
How was the initial setup?
The initial setup was not difficult or complex. It was very straightforward. A company should have too much trouble with the process.
The deployment process was very, very quick as well. There is a collector deployed on our network. We spun that out. You point your log sources at it, you point it at some IP addresses that IBM gives you, and it just works.
What about the implementation team?
We did not use an integrator or consultant for the deployment. We handled it ourselves, with our own staff. Everything was done in-house.
What's my experience with pricing, setup cost, and licensing?
The product is not a cheap solution. it's quite expensive.
We do also pay more in order to use Watson.
Which other solutions did I evaluate?
We're currently evaluating other options to see if we want to switch off of this product in the future. Nothing has been decided. I'm currently doing some preliminary research. We're always looking for solutions that are better or cheaper.
What other advice do I have?
We are just a customer and end-users. We don't have a business relationship with IBM.
We are using the latest version of the solution, as we have the cloud version of the product. Whatever the latest version is, IBM upgrades it automatically. We don't need to worry about that on our end.
In general, I would rate the solution at a seven out of ten. If it were cheaper it might rate a bit higher, however, for the most part, it does what we need it to do.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Security Manager at a comms service provider with 1,001-5,000 employees
It is very stable. We have not faced interruptions in the past four and a half years.
Pros and Cons
- "It is very stable. We have not faced interruptions in the past four and a half years."
- "It has improved comprehensive visibility for what is going on in the perimeters, and on the inside, as well."
- "Technical support is good, but not great."
What is our primary use case?
We are a telecom company, and we use it for IT systems, for telecom systems and on various different levels of applications. We use it for web servers, routers, firewalls, and other security components. Our SIEM solution serves technical and non technical business units including customer care, engineering, revenue assurance, and anti fraud.
How has it helped my organization?
Instant continuous monitoring so that we can take action immediately and be proactive as much as possible with handling hacking and attacking attempts. Also, It has improved comprehensive visibility for what is going on in the perimeters, and on the inside, as well. We also use it for testing our controls if it is performing well or not. We can say that the visibility, monitoring, testing and reliability of our controls is all assisted by this solution. The most important benefit we get is from the SIEM solution.
What is most valuable?
The most valuable features are the diversity of logs type that enable us to monitors what is going on from different perspectives and reduces the likelihood that we will miss important attempts. There are different events and flows, and there is diversity from getting the information from different sources. We can also see that there are no false positives. It is well-tuned and the rules are covering everything that we need.
What needs improvement?
There are some weaknesses with the QRadar Risk Manager. It has some weaknesses because of the connectivity with other vendors. It is limited. There are some vendors that you cannot connect QRadar Risk Manager with, so we you cannot get the maximum benefit of the product.
For how long have I used the solution?
Five years.
What do I think about the stability of the solution?
It is very stable. We have not faced interruptions in the past four and a half years.
What do I think about the scalability of the solution?
It's great! This is one of the major features of the solution.
How are customer service and technical support?
Technical support is good, but not great.
How was the initial setup?
It was straightforward, but we had to do some customization.
What about the implementation team?
When choosing a vendor, we always consider:
- Scalability
- Diversity of Connecting Systems
- Storage
Which other solutions did I evaluate?
We considered another solution from HP and ArcSight.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Sumo Logic Security
Fortinet FortiSIEM
Cortex XSIAM
AlienVault OSSIM
Securonix Next-Gen SIEM
Google Chronicle Suite
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?