No more typing reviews! Try our Samantha, our new voice AI agent.
Elshaday Gelaye - PeerSpot reviewer
Lead Technical Architec at Commercial Bank of Ethiopia
Real User
Apr 5, 2022
It lets you filter by the source and destination IPs to get detailed information
Pros and Cons
  • "It also has a graph that shows the traffic history. I can see what happened yesterday or today. If there's an incident, I can check the traffic behavior on QRadar."
  • "QRadar allows you to filter by the source and destination IPs and see detailed logs on that."
  • "QRadar's performance has room for improvement because it cannot handle the volume. I need massive amounts of logs from various devices in our existing network architecture. IBM needs to improve QRadar's capacity to handle more logs."
  • "QRadar's performance has room for improvement because it cannot handle the volume."

What is our primary use case?

We use QRadar to collect logs and monitor user activity and traffic from one network to another. The SOC team is in a room watching the logs from the tool live most of the time. 

QRadar monitors all internet activity and the output of every device configured to send a log. All traffic from various networking devices passes through the QRadar servers, and we can view it live.

We have two data centers, and QRadar is deployed in one. It comes with two physical appliances to allow failover capability. There's a management interface that binds them together, and we set up an interface for each device connected to the network that sends a log.  

What is most valuable?

QRadar allows you to filter by the source and destination IPs and see detailed logs on that. For example, if a user is trying to access a server using a malicious port like 4.5.0, I can get valuable data and take action from other devices. 

It also has a graph that shows the traffic history. I can see what happened yesterday or today. If there's an incident, I can check the traffic behavior on QRadar.

What needs improvement?

I would like to see QRadar add more integration and interoperability. For instance, we are not able to send logs from Windows servers. We can send logs to the QRadar server from network devices and other types of servers. However, we have more than a hundred Windows servers that still don't use QRadar. 

For how long have I used the solution?

Our company has been using QRadar for the last five years. We implemented it in 2017.

Buyer's Guide
IBM Security QRadar
September 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,801 professionals have used our research since 2012.

What do I think about the stability of the solution?

QRadar's performance has room for improvement because it cannot handle the volume. I need massive amounts of logs from various devices in our existing network architecture. IBM needs to improve QRadar's capacity to handle more logs. 

Usually, disk space is the issue. When it runs out of space, we need to stop logs from different network devices, especially the firewall, before it starts working. 

What do I think about the scalability of the solution?

It's hard for me to estimate the number of QRadar users because all of our banking traffic and user activity will pass through QRadar. At the higher end, more than 25,000 active users might use QRadar.

How are customer service and support?

I was directly involved with the IBM support team during the implementation, and we received training for some time after. The service has been excellent and supportive. 

When we needed to upgrade, our security team invited the IBM technician back, and it was very smooth. Now, they are planning to set up redundancy in our second data center. Generally speaking, the support is good, and they check in about once a month remotely. I am directly involved with them, but I hear positive feedback from the team. 

What about the implementation team?

The initial setup was configured in Linux on the server. We had a technical guy from IBM who came from Kenya. We only prepared the environment, like setting up the rack, but an IBM technician took care of the implementation. We also rely on the vendor for support and activities that require professional expertise.

What was our ROI?

I rate QRadar eight out of 10 for return on investment. We get a lot of valuable data from QRadar.

What other advice do I have?

I rate QRadar eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2518323 - PeerSpot reviewer
Analyst at a hospitality company with 10,001+ employees
Real User
Aug 2, 2024
Has real-time detection feature but is not as flexible as Splunk
Pros and Cons
  • "The tool's most valuable feature is real-time detection."
  • "The solution is not as flexible as Splunk."

What is our primary use case?

We use the product to customize rules and detect malicious behavior. 

What is most valuable?

The tool's most valuable feature is real-time detection. 

What needs improvement?

The solution is not as flexible as Splunk. 

For how long have I used the solution?

I have been working with the product since 2016. 

How are customer service and support?

I haven't contacted technical support yet. 

Which solution did I use previously and why did I switch?

I worked with Splunk before IBM Security QRadar.

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is based on the EPS model. 

What other advice do I have?

I prefer Splunk since it gives a lot more freedom and flexibility. I rate the overall solution a six out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
IBM Security QRadar
September 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
912,801 professionals have used our research since 2012.
Information Security Manager at a financial services firm with 1,001-5,000 employees
Real User
Feb 15, 2023
It has higher availability than other tools and can consolidate all alerts and detections, but its scalability has room for improvement
Pros and Cons
  • "What's most valuable in IBM QRadar User Behavior Analytics is its higher availability than other tools."
  • "You can scale IBM QRadar User Behavior Analytics, but it has room for improvement."

What is our primary use case?

My use case for IBM QRadar User Behavior Analytics is to consolidate all the logs and events from a different tool so that I can see the alerts from that other tool on the dashboard.

My company connects the Windows event logs to the Xfinity router deployed on the main server, but I have to make some configurations to detect activities.

My team is working on reinforcing IBM QRadar User Behavior Analytics features since the solution has not been used for a while because there's a new generation of engineers in my company. My team has to reconfigure almost every screen, including IBM QRadar User Behavior Analytics.

What is most valuable?

What's most valuable in IBM QRadar User Behavior Analytics is its higher availability than other tools. It consolidates all alerts and detections from the other tools, but my team has to check each tool. As my company lacks the manpower to do that, my team has to do monitoring while working on making each function clear.

What needs improvement?

As a product, IBM QRadar User Behavior Analytics does everything mentioned on the datasheet for my company's version. Still, compatibility is a problem because my company needs to use an updated version of the tool. That version doesn't integrate with many new-generation tools, so this is an area for improvement.

You can scale IBM QRadar User Behavior Analytics, but it has room for improvement.

For how long have I used the solution?

I've been using IBM QRadar User Behavior Analytics for years.

What do I think about the stability of the solution?

IBM QRadar User Behavior Analytics has been stable, and my team has made no significant changes since 2015. The team is working on utilizing it most efficiently.

What do I think about the scalability of the solution?

The scalability of IBM QRadar User Behavior Analytics is a six out of ten.

How are customer service and support?

My company doesn't get support from IBM because it's on a perpetual usage type of contract. My team can configure IBM QRadar User Behavior Analytics but cannot contact IBM for help.

When I used to get technical support for IBM QRadar User Behavior Analytics, I'd say it was a seven out of ten.

What other advice do I have?

The version of IBM QRadar User Behavior Analytics, which my company uses, is a little outdated from 2013. That version doesn't have the log collection feature.

My rating for the version of IBM QRadar User Behavior Analytics I'm using is a seven overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Du Hoac Kim - PeerSpot reviewer
Deputy Manager at sacombank
Real User
Nov 26, 2022
Straightforward and basic deployment, with reliable features, and genuine satisfaction
Pros and Cons
  • "The most valuable feature currently is security behaviors and the pdf files."
  • "The product is very stable."
  • "I would like to see more integration in place after the security lock."

What is most valuable?

The most valuable features currently are the security behaviors and pdf files.

What needs improvement?

I would like to see more integration in place after the security lock.

For how long have I used the solution?

I have been using IBM QRadar User Behavior Analytics for a couple of years now.

What do I think about the stability of the solution?

The product is very stable.

How was the initial setup?

The initial setup was straightforward and took three to four months to deploy.

What about the implementation team?

We used a vendor team to assist us in the process of deployment.

What other advice do I have?

I would rate IBM QRadar User Behavior Analytics an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Yaw Agyare - PeerSpot reviewer
Manager at Volta River Authority
Real User
Top 5
Nov 11, 2022
Great predictive analysis capabilities and provides good visibility
Pros and Cons
  • "We find predictive analysis capabilities valuable."
  • "Our primary use case for the solution is providing visibility for what occurs in our security system and IT assets."
  • "The solution should include remote action capabilities."

What is our primary use case?

Our primary use case for the solution is providing visibility for what occurs in our security system and IT assets. So all our event logs and information from a setting and criticality level go there. Additionally, there's AI used to trigger alerts when things are going bad, and then we can action them.

What is most valuable?

We find predictive analysis capabilities valuable.

What needs improvement?

The solution should include remote action capabilities.

For how long have I used the solution?

We have been using the solution for approximately three years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is scalable. Over 1,000 people in our organization use the solution.

How was the initial setup?

The initial setup is moderate, and it is neither easy nor difficult. However, it took approximately one week to complete the implementation.

What about the implementation team?

We implemented it through a vendor team.

Which other solutions did I evaluate?

We chose this solution because it was provided to us through software as a service.

What other advice do I have?

I rate the solution an eight out of ten. The solution is good but can be improved with enhanced remote control ability. I recommend the solution to new users considering it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Farid Lalayev - PeerSpot reviewer
Cyber Security Student at Baku Higher Oil School
Real User
Sep 22, 2022
Scalable, easy to use, and has a visualization feature that shows spikes in the system
Pros and Cons
  • "The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log."
  • "My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use."
  • "IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others."

What is our primary use case?

We are using IBM QRadar for log reviews, particularly logs that come and go from the IPS, firewall, etc.

We have different dashboards for different technologies such as our firewall, IPS, and domains for our main website, so we use IBM QRadar to observe the logs from our website, and we try to make internal and external connections for better domain security.

What is most valuable?

The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log.

What needs improvement?

IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others.

There isn't any additional feature I'd like added to IBM QRadar at this point because it's sufficient for visualizing the logs.

For how long have I used the solution?

I've been with the company for one and a half months, and I've been using IBM QRadar almost daily, but the solution was deployed five or six months ago.

What do I think about the stability of the solution?

IBM QRadar is a stable solution.

What do I think about the scalability of the solution?

IBM QRadar is a scalable solution. My company currently has seven to eight different accounts on IBM QRadar, so it's a scalable technology. It has no problems with scalability.

How are customer service and support?

I didn't have any problems with IBM QRadar, so I never contacted the technical support team.

Which solution did I use previously and why did I switch?

I'm assuming that the main reason my company chose IBM QRadar is that IBM is one of the biggest tech companies in the world, so IBM products would be more secure and more reliable than other solutions.

How was the initial setup?

As I didn't set up or deploy IBM QRadar, I have no information on whether it was easy or complex to set up.

What's my experience with pricing, setup cost, and licensing?

I have no information about the licensing costs of IBM QRadar, and whether or not it requires a license.

What other advice do I have?

I'm an intern at one of the biggest telecommunication companies, and my company uses IBM QRadar.

My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use. The solution also has many dashboards, and you don't have to write any code or write different scripts to get the information you need. You can do it from the UI of IBM QRadar. The only room for improvement in the solution is that it doesn't support newer technologies, and it's late when it comes to updates.

I'm rating IBM QRadar nine out of ten because my experience with it has been excellent. The only downside to it is that IBM is late with adding new features or supporting new technologies compared to its competitors.

My company is an IBM QRadar customer.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
JohnTamakloe - PeerSpot reviewer
Solutions Architect at ostec
Real User
Top 5Leaderboard
Aug 23, 2022
Excellent visibility, good notifications, and helpful support
Pros and Cons
  • "The visibility it gives you into your infrastructure has been great."
  • "The visibility it gives you into your infrastructure has been great, and the notifications it provides offer valuable information when something is happening in your blind spot."
  • "The AI engine could be smarter."

What is our primary use case?

We are using it for visibility and compliance.

What is most valuable?

The visibility it gives you into your infrastructure has been great.

The notifications it provides offer valuable information when something is happening in your blind spot.

What needs improvement?

The AI engine could be smarter. 

It is a bit expensive. 

For how long have I used the solution?

I've used the solution for about three years. 

What do I think about the stability of the solution?

The solution is stable. I'd rate it five out of five. It's very reliable. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution scales well, and it's easy to do. I'd rate it five out of five in terms of the ease of scalability. 

We have a lot of users on the solution currently. We have customers on the product as well. There are likely more than 500 users inside and outside the organization. 

How are customer service and support?

Support has been helpful and responsive. There may sometimes be a delay. However, they do get you the information you need. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We've only ever used IBM. 

How was the initial setup?

The setup is a bit complex. I'd rate it two out of five in terms of ease of deployment. It took us a week to get everything up and running. 

We had two engineers working on deployment and maintenance. 

What about the implementation team?

We handled the solution in-house. We did not need outside assistance. 

What was our ROI?

We've seen a good ROI. I'd give it a five out of five. 

What's my experience with pricing, setup cost, and licensing?

It's a bit pricey as a product. I'd rate it a two out of five, with five being the most affordable. It depends on what you buy; the longer you use it, the better the cost. It's an all-inclusive license. You don't need to pay for extra features. 

Which other solutions did I evaluate?

We did look at a few other options. 

What other advice do I have?

We use the solution inside our organization. Our clients use it too. We are a premium partner in our region. 

We're using the latest version of the solution.

I'd rate the solution nine out of ten. It really provides good visibility.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Premium Partners
PeerSpot user
reviewer1886673 - PeerSpot reviewer
Director of Incident Response at a retailer with 10,001+ employees
Real User
Aug 16, 2022
Robust and reliable but needs some fine-tuning
Pros and Cons
  • "It'll get you from point A to B."
  • "I equate QRadar to a robust solution."
  • "There should be more opportunity for community kind of distribution where, for example, if there was a zero-day threat targeting companies."
  • "Out of the box, it's just not one of those things that I leverage as a single source of truth regarding the user behavior analytics aspect of it."

What is our primary use case?

The UBA component is something that is there. However, it's something that honestly hasn't been leveraged as much. It's probably not a UBA feature like the ones we’ve used in the past. In any case, the UBA feature is there. You can look at the users and look at any risky activity or use cases. I tend to look at it. However, it's not my main source in terms of leveraging it as a UBA.

What is most valuable?

I equate QRadar to a robust solution. You get all the live sources. If you have someone there fine-tuning the solution and creating rules for the team to ensure the fence is alert. It's a robust solution.

In the past, I've heard the term that it's like a Cadillac, a trusted Cadillac. It'll get you from point A to B. It does what integration is supposed to do.

What needs improvement?

It needs a little bit perhaps more fine-tuning on the SIM aspect of it. Out of the box, it's just not one of those things that I leverage as a single source of truth regarding the user behavior analytics aspect of it.

With QRadar, IBM has had ample time to innovate, make changes to the interface, and keep up with some of the competitors. Yet, IBM delays innovating QRadar, since, once people are tied into it, they stick to the SIM as that's what they're used to. Right now, you have many other players in the market, like Datadog, Sumo Logic, and Splunk. Splunk has a ton of connectors as well, which is making it more appealing for other people to look at other solutions, especially when they're trying to look at a cloud-native solution.

There should be more opportunity for community kind of distribution where, for example, if there was a zero-day threat targeting companies. I know that many other solutions now provide ease of use in terms of sharing rules and for identifying and tracking some of these zero-day vulnerabilities out there. Radar needs to do the same.

For how long have I used the solution?

I’ve been using the solution for about four years or so.

What do I think about the stability of the solution?

The stability's great. The solution is robust. It's trusted. Depending on how you have it deployed if it's a standalone appliance or it's high availability paired so that you have redundancy, the solution is reliable.

What do I think about the scalability of the solution?

Anywhere from 25 to 50 users are using it. The primary users are security operations. However, then you do have some folks on the infrastructure side that also leverage QRadar. It wasn't always the case. That said, once we provided access to the infrastructure team, they enjoy using QRadar for looking at logs, and troubleshooting. That would involve the networking team and the server team. They also leverage it as well.

How are customer service and support?

Overall, the IBM team is responsive in regards to ticketing. Obviously, you have to create a ticket with IBM and they will get someone to get on a WebEx with you within a reasonable amount of time depending on the urgency.

They will help resolve issues and create cases. The support is there in terms of having any issues or QRadar is generating errors. Support will guide you and record the session and help remove any issues or obstacles that you have, so I definitely would rate them high on the support aspect of it.

How was the initial setup?

I didn't set it up. Probably part of the engineering team set it up.

What's my experience with pricing, setup cost, and licensing?

I do not know the exact cost. It's a bit tricky as some of it is tied into pre-contracts that we have. Some parts of the company do prepaid funds for certain solutions. It's different. It varies.

What other advice do I have?

While I use QRadar, I'm in a managerial role, so I'm not living in it every single day as my team members are.

Every situation is different. I know a lot of organizations or a lot of C-suite executives all go to the same kind of conferences each year. Then they all come back singing the same song: "We all have to go to the Cloud."

I’d rate the solution six out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Jacob_Koithra - PeerSpot reviewer
Project & Program manager at Shell Grp
Real User
Aug 4, 2022
Good monitoring and dashboards with good blocking capabilities
Pros and Cons
  • "The monitoring and dashboards are great."
  • "It helped our organization to identify and prevent security attacks."
  • "The playbook guide which specifies the rules for security use cases needs to be provided to support in case the organization needs help."
  • "The QRadar implementation guide, especially in cluster environment, is complicated to deploy in an enterprise level."

What is our primary use case?

We use the blocking mode and spam mode for the IPS - XGS 5000 series and use of QRadar as a SIEM Solution for logging and monitoring network security, security analysis, and monitoring for network-related attacks. 

The playbook is defined with identified use cases. IPS acted as an inline to the firewall. It helped to track and sniff the packet and match the details. It helped to reduce the insider and outsider attacks. The traffic is analyzed and helped users to know the patters and access level in the network and resource being used.

How has it helped my organization?

It helped our organization to identify and prevent security attacks.

We need to come with new releases and understand what will happen and how the customer will be able to manage and update the system what are ways in which user behavior and access to various resources in the network could be tracked and alerted in more robust manner. 

There needs to be proper patch management which is done in a controlled environment with a proper newsletter update. The new releases from the company in terms of product and services needs to be updated to product managers in organization.

What is most valuable?

The monitoring and dashboards are great. 

What needs improvement?

The user behavior analysis could be better. The playbook guide which specifies the rules for security use cases needs to be provided to support in case the organization needs help. The security playbook needs more help when it comes to QRadar. The QRadar implementation guide, especially in cluster environment, is complicated to deploy in an enterprise level. The support of SIEM of QRadar is complicated and when we encounter implementation issues it needs quick response. The skilled resources are really important for support.

For how long have I used the solution?

I have deployed the solution for 230 sites across globe using for past seven years.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ertugrul Akbas - PeerSpot reviewer
Manager at ANET
Real User
Top 20
Jul 2, 2022
Scalable, easy to use, but lacking features and modern user interface
Pros and Cons
  • "IBM QRadar User Behavior Analytics's most important feature is its ease of use."
  • "When we started using IBM QRadar User Behavior Analytics's add-on or extension, we received more than 17 new use cases and our organization has benefited from using IBM QRadar User Behavior Analytics."
  • "IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms."

What is our primary use case?

We are mainly using predefined rules on IBM QRadar User Behavior Analytics

How has it helped my organization?

When we started using IBM QRadar User Behavior Analytics's add-on or extension, we received more than 17 new use cases. Our organization has benefited from using IBM QRadar User Behavior Analytics.

What is most valuable?

IBM QRadar User Behavior Analytics's most important feature is its ease of use. 

What needs improvement?

IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms.

Using the interface of IBM QRadar User Behavior Analytics is the same for years, they should redesign the interface to make it more modern. Some historical queries take a long time, they should improve or change their database. There are some missing operators on the correlation side. For example, some before operated.

For how long have I used the solution?

I have been using IBM QRadar User Behavior Analytics for approximately three years.

What do I think about the stability of the solution?

IBM QRadar User Behavior Analytics is stable most of the time. However, it works on the client-side which requires a lot of system resources, such as RAM. In some cases, if the work is high, the stability deteriorates, but mainly it is stable.

What do I think about the scalability of the solution?

The scalability of IBM QRadar User Behavior Analytics is good. 

We have two people using this solution. We do not have plans to increase usage.

How are customer service and support?

We use a consultancy company for support and are not directly connected to IBM support.

How was the initial setup?

The deployment of IBM QRadar User Behavior Analytics is very easy when compared to other machine learning solutions. The full deployment took approximately three weeks with less than 5,000 EPAs.

What about the implementation team?

We used a consultant that help us deploy and do maintenance for IBM QRadar User Behavior Analytics.

What was our ROI?

I rate the return on investment of IBM QRadar User Behavior Analytics a four out of five.

What's my experience with pricing, setup cost, and licensing?

IBM QRadar User Behavior Analytics is an application framework and you can install many applications without any additional costs.

I rate the price of IBM QRadar User Behavior Analytics a four out of five.

What other advice do I have?

IBM QRadar User Behavior Analytics is a good solution. If there is a big enough budget they might be able to afford the solution since it is expensive. If the conditions are okay, then they should select the solution.

I rate IBM QRadar User Behavior Analytics a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.