I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot.
Senior Manager Cyber Security Services & Solutions at Trillium
A User Behavior Analytics (UBA) solution with useful out-of-the-box rules and use cases, but functionality should be more integrated
Pros and Cons
- "I think this is a good product for enterprises because of the performance and out-of-the-box rules and use cases. If they want to reach the maturity level early, they can use these out-of-the-box rules and use cases. That will help them a lot."
- "IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on."
What is most valuable?
What needs improvement?
IBM QRadar User Behavior Analytics is good, but I think the functionality should be much more integrated. You should have easy access to the artifacts if you are doing a particular investigation. It's good, but other team solutions like LogRhythm are actually merging the functionality. So, I think that is something IBM can work on.
For how long have I used the solution?
We have been using IBM QRadar User Behavior Analytics for about four years.
What do I think about the stability of the solution?
Stability is good, but the investigation system should be better.
Buyer's Guide
IBM Security QRadar
April 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,716 professionals have used our research since 2012.
What do I think about the scalability of the solution?
IBM QRadar User Behavior Analytics is scalable. You have the EPS and closed license. I think scalability is not an issue because it is available on both the hardware and the software. You can install the software plans if you want, and there is also a hardware plan.
How are customer service and support?
Their technical support is good. I have not faced any issues before, and the technical support is good.
What other advice do I have?
I will recommend this solution to potential users.
On a scale from one to ten, I would give IBM QRadar User Behavior Analytics a seven.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Country Manager at Magarah
Beneficial portfolio, reliable, and integrates well
Pros and Cons
- "IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration."
- "The solution could improve by having more out-of-the-box use cases."
What is our primary use case?
IBM QRadar User Behavior Analytics has a dedicated application for user behavior analytics and must be installed separately on an application server. It is valuable if you created the setup for the use cases. It needs additional customization to have a good value. You will have to point the solution to the suitable data sources that will feed the user analytics in a good manner. You will have good user behavior analytics, based on the created use cases.
What is most valuable?
IBM QRadar User Behavior Analytics has easy architecture, has a good portfolio and integration.
What needs improvement?
The solution could improve by having more out-of-the-box use cases.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for approximately two years.
What do I think about the stability of the solution?
IBM QRadar User Behavior Analytics is stable.
What do I think about the scalability of the solution?
I have found IBM QRadar User Behavior Analytics to be scalable.
We have approximately 15 clients using this solution.
How are customer service and support?
The support is satisfactory.
How was the initial setup?
The implementation was not easy and was not difficult, it was in the middle.
The full implementation can take approximately two to three months.
What about the implementation team?
We have three people that are supporting IBM QRadar User Behavior Analytics.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required for this solution.
What other advice do I have?
I rate IBM QRadar User Behavior Analytics an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
IBM Security QRadar
April 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,716 professionals have used our research since 2012.
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
Can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent.
Pros and Cons
- "Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure."
- "AI is superb but need improvements."
What is our primary use case?
Find the malicious activity via filter, don't rely on the rules which trigger the offenses and fix the suspicious activities.
How has it helped my organization?
Gaining application visibility and anomaly detection helping IT personnel to quickly identify meaningful deviations. For example, QRadar SIEM can detect off-hours or excessive usage of an application or cloud-based service, or network activity patterns that are inconsistent with historical, moving-average profiles and seasonal usage patterns.
What is most valuable?
Providing real-time visibility for threat detection and prioritization - QRadar SIEM provides contextual and actionable surveillance across the entire IT infrastructure, helping organizations detect and remediate threats often missed by other security solutions. These threats can include inappropriate use of applications; insider fraud; and advanced, “low and slow” threats easily lost in the “noise” of millions of events..
What needs improvement?
Artificial Intelligence is superb, QRadar correlate the events smartly and remove the same events but need improvements.
For how long have I used the solution?
One to three years...
What do I think about the stability of the solution?
No issues.
How are customer service and technical support?
Very good
Which solution did I use previously and why did I switch?
Mcafee, switched due to the bad correlation of data.
How was the initial setup?
It was straightforward
Which other solutions did I evaluate?
Splunk and Logrhythm..
What other advice do I have?
QRadar also supports UBA which is a fantastic feature to detect user's malicious activities.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Field Manager at a security firm with 11-50 employees
Good scalability and straightforward setup, all in all, a good solution
Pros and Cons
- "It's quite scalable. We have upgraded some solutions from 1000 APS up to 3500 APS to 5000 APS. It's a good solution, they have no scalability issues."
- "I would like for them to develop a detection management solution. It does not have a detecting management solution in it, you have to buy it as it is, on top of the extended solution."
What is our primary use case?
It is a requirement for all of the banks to have a security solution in Pakistan. That is the reason most of the banks are using it. In the last one and a half years, Pakistani companies are taking security very seriously, so for that reason, they evaluate these solutions. All in all, it's a good solution.
What needs improvement?
I would like for them to develop a detection management solution. It does not have a detection management solution in it, you have to buy it as it is, on top of the extended solution.
What do I think about the scalability of the solution?
It's quite scalable. We have upgraded some solutions from 1000 APS up to 3500 APS to 5000 APS. It's a good solution, they have no scalability issues.
How was the initial setup?
The initial setup was straightforward. The deployment time depends on each customer. We have customers who have different infrastructures and their deployments are quite different. If we rack and stack it, around two, three days, maximum a week, but configuration and optimization take up to somewhere between six months and one year.
What other advice do I have?
I would rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
IT Manager at a comms service provider with 1,001-5,000 employees
Contextual and threat-based incident management.
What is most valuable?
- Paradigm shift, security intelligence 2.0
- Contextual-based incident management
- Threat-based incident management
- A single management console to handle all the data
- Ease of use
- Existing integration capabilities
- Out-of-the-box reports
- Parser development
How has it helped my organization?
It has helped us in the reduction of VPN frauds via the active monitoring of various frauds.
What needs improvement?
- There is a scope of improvement in the orchestration layer, such as the SecOps from RSA. RSA Security Analytics bundles their offering with their SecOps (a subset of Archer - Risk Governance tool). This gives them a competitive edge.
- The reporting and dashboard capabilities require a bit of improvement in terms of fine tuning and bifurcation for the technical and management reports.
For how long have I used the solution?
I have used this solution for four years.
What do I think about the stability of the solution?
There were no stability issues.
How is customer service and technical support?
I would give technical support a rating of 9/10.
How was the initial setup?
The setup was straightforward and the deployment was easy.
What's my experience with pricing, setup cost, and licensing?
The pricing policy is a bit on the higher side. IBM offers discounts when applicable.
Which other solutions did I evaluate?
We looked at other solutions such as RSA enVision and HPE ArcSight.
What other advice do I have?
Trust it, test it, and deploy it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Engineer
The most valuable feature is the ability to get the logs and analyze them.
What is most valuable?
The most valuable feature is the ability to get the logs and analyze them. These logs help us in terms of analyzing and actually using Watson on them. It's a pretty great tool for intelligence. I think it is really a great product.
How has it helped my organization?
To be able to get the logs and analyze them has improved the way my organization functions. You can see where the source destination is coming from. You can actually see the data and pause the dashboard. It actually helps you to analyze the data the way you are supposed to. Nobody else is doing that right now.
What needs improvement?
I don't have any problems with the solution right now. As I play with the tools, then I will actually come up with different ideas.
I was able to help out with IBM Guardium version 10. I was helping out with a couple of developers who actually developed the application itself.
I want to see more integration between QRadar and other applications like BigFix and a couple of other tools and applications out there. There are a lot of applications out there. QRadar security intelligence might be one of the best right now.
What do I think about the stability of the solution?
There were no stability issues with QRadar. We've had a couple of stability issues with all the applications that I run. I don't want to mention names.
How is customer service and technical support?
I’ve used technical support, and they were OK. I used to work for IBM.
How was the initial setup?
I was involved in the initial setup. It was straightforward and not complex.
Which other solutions did I evaluate?
I work as security engineer for the Department of Justice. We test hundreds of applications. I actually see which ones work best for the infrastructure.
What other advice do I have?
I would suggest QRadar. The security intelligence is one of the best right now.
When looking for a vendor, I want to be able to win them. I want them to accept the fact that I’m looking for a product for what I am doing and I have a couple of requirements.
From there, I can actually tell them what they need to do, or what I need to do, in the environment.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a government with 10,001+ employees
For vulnerabilities, you see a popup on the screen. We do not have to look for it. It is pushed to us.
What is most valuable?
It's easy for us to see what's happening in the environment. It's very good to see the logs and the analytic stuff.
How has it helped my organization?
We can see the vulnerabilities much easier with the product. You see a popup on the screen. We do not have to look for it. It is pushed to us.
What needs improvement?
It is very expensive; very expensive.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
I think it is scalable.
How is customer service and technical support?
We have used technical support. They are very good and very nice.
Which other solutions did I evaluate?
We didn't evaluate any alternatives. We have yearly talks with the IBM consulting team. We look at the trends.
What other advice do I have?
When choosing a vendor, we look for a stable and trustworthy company. I think QRadar is the best solution you can get.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at a tech services company with 11-50 employees
It can collect different types of security feeds and correlate them in real-time with your logs.
What is most valuable?
The most valuable features are:
- Auto update: QRadar will download new logs from the database on the supported security device, so that it will automatically normalize the new log format and you will not need to rewrite all your rules/offenses again.
- X-Force/TAXII feed: QRadar can collect different types of security feeds and correlate them in real-time with your logs.
- Search engine: QRadar is like Excel, i.e., you can add rows and filter like your daily office work, without writing any scripts. So level 1 support also can handle this type of jobs.
How has it helped my organization?
You will learn something that you don't know on the user/machine behaviour.
What needs improvement?
The dashboards and reports may need to improve. We need to export the CSV results to create a report by Excel.
For how long have I used the solution?
I have used this solution for three years.
What do I think about the stability of the solution?
It will slow down, when there are too many people doing a search at the same time, but that depends on your hardware and design.
What do I think about the scalability of the solution?
I did not encounter any scalability issues.
How is customer service and technical support?
You may need to allow remote support for them to help you, for troubleshooting the issues.
How was the initial setup?
The setup is complex, i.e., for the first setup. SIEM is not easy so as to enable logs without any performance issues and the deployment advisor is the key for the project.
What's my experience with pricing, setup cost, and licensing?
You only need to worry about the number of events per second and the number of flows per minute. Storage size is not an issue with QRadar.
Which other solutions did I evaluate?
We did evaluate other options. I think Splunk is the second-best option.
What other advice do I have?
If you have an experienced group of security members, then you may not at all need the advisor for the product. If not, then you will have to find the path to build your team, so as to become more knowledgeable.
Disclosure: My company has a business relationship with this vendor other than being a customer: We are business partners.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
LogRhythm SIEM
Rapid7 InsightIDR
Cortex XSIAM
Fortinet FortiSIEM
AlienVault OSSIM
Sumo Logic Security
Securonix Next-Gen SIEM
Google Chronicle Suite
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
you need more time and knowledge to completely understand about QRadar SIEM.