Depending on the organization's needs the solution can monitor different types of security through logs.
SOC Team Lead at a financial services firm with 1,001-5,000 employees
Flexible, easy to learn, and price fairly
Pros and Cons
- "I have found the most important features to be the flexibility, tech framework, and disk manager."
- "There could be better integration with the solution."
What is our primary use case?
What is most valuable?
I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.
What needs improvement?
There could be better integration with the solution.
For how long have I used the solution?
I have been using the solution for approximately three years.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,227 professionals have used our research since 2012.
What do I think about the stability of the solution?
Every solution has some bugs and other issues but for the most part, this solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. The amount of users is dependant on what your needs are. You can have many users having access to the solution. For example, out of a 5,000 person network, you could have five with access to it for security.
How are customer service and support?
The solution has great support. Whenever we had an issue they were able to give us support within 15 minutes.
How was the initial setup?
The installation was easy but this can depend on what appliances you want to install it on. If it is VMware, then the installation is easy, it took me 30 minutes.
What about the implementation team?
We did use a consultant to do the deployment and we only needed one technician.
What's my experience with pricing, setup cost, and licensing?
The solution is priced fairly, there is a license for the solution, and we pay annually.
What other advice do I have?
I would recommend the solution to others and we plan to continue using it in the future.
I rate IBM QRadar a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Operations Manager at a comms service provider with 501-1,000 employees
Flexible and very scalable with a straightforward setup
Pros and Cons
- "The solution is quite flexible."
- "Technical support really needs to be improved. Right now, they aren't where they need to be at all."
What is our primary use case?
We mostly use the product for PCI compliance.
What is most valuable?
We pay a little bit extra for Watson, and the Watson feature enables the analyst to go through and triage things much faster. It's quite useful for us and worth the smaller extra bit of money.
The solution is quite flexible.
We enjoy the fact that it is cloud-based.
The initial setup was very straightforward.
The solution is very scalable.
We've found the stability to be mostly very good.
What needs improvement?
Technical support really needs to be improved. Right now, they aren't where they need to be at all.
The solution is very expensive. We'd appreciate the product more if it came at a lower price point.
What do I think about the stability of the solution?
It is generally very stable. We've had odd little breakages, however, generally, nothing major has gone wrong. The performance is good. It's a reliable product.
What do I think about the scalability of the solution?
The scalability aspect of the product is very good. That was one of the reasons that we bought it. If a company needs to expand it, it can do so with relative ease. It's not hard.
Currently, all the members of the tech ops team use the product, and there are five of them.
We may not increase usage; we may switch to something else. That has yet to be determined. It's not set in stone.
How are customer service and technical support?
We've used technical support in the past and we haven't been satisfied with the level of service on offer.
Trying to get answers out of IBM is like trying to get blood out of a stone. They need to be more helpful and responsive. Right now, they aren't either of those things.
How was the initial setup?
The initial setup was not difficult or complex. It was very straightforward. A company should have too much trouble with the process.
The deployment process was very, very quick as well. There is a collector deployed on our network. We spun that out. You point your log sources at it, you point it at some IP addresses that IBM gives you, and it just works.
What about the implementation team?
We did not use an integrator or consultant for the deployment. We handled it ourselves, with our own staff. Everything was done in-house.
What's my experience with pricing, setup cost, and licensing?
The product is not a cheap solution. it's quite expensive.
We do also pay more in order to use Watson.
Which other solutions did I evaluate?
We're currently evaluating other options to see if we want to switch off of this product in the future. Nothing has been decided. I'm currently doing some preliminary research. We're always looking for solutions that are better or cheaper.
What other advice do I have?
We are just a customer and end-users. We don't have a business relationship with IBM.
We are using the latest version of the solution, as we have the cloud version of the product. Whatever the latest version is, IBM upgrades it automatically. We don't need to worry about that on our end.
In general, I would rate the solution at a seven out of ten. If it were cheaper it might rate a bit higher, however, for the most part, it does what we need it to do.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,227 professionals have used our research since 2012.
Founder at a tech services company with 1,001-5,000 employees
A stable SIEM solution with centralized control and built-in AI/ML
Pros and Cons
- "QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis. There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving. From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected."
- "When it comes to what could be better, it is always what others are trying to do and what is the roadmap. It can have more integration. It should have more flexible RESTful APIs for integration with applications. These are the things that are always in demand for any of the SIEM solutions, not only for QRadar. Integration is ever-evolving. Nowadays, different versions of mobile handsets are there and data is getting scattered. Users are using their personal handsets to keep the data of the organization. So, it should have a more flexible integration, irrespective of the flavor of the firmware and iOS or Android version. It should have an API that can seamlessly get integrated. It should also provide more flexible control and a more advanced or analytical view to see what exactly is happening across the globe or network. From wherever a user is connecting and accessing the enterprise data, it should give real-time visibility and predictive visibility about what exactly is happening. These things are already there, but there should be more advanced control in terms of managing the security."
What is our primary use case?
We provide cloud services to the users, and we have our own cloud setup over here. The major use case is when clients require the SOC to be set up.
Setting up the SOC itself is a huge investment. A customer has to invest a lot to build up the whole SOC environment, so, rather than the customer investing in the SOC environment and building up the SOC, we provide it as a service. Customers don't need to do any up-front investment. They use our service. We manage their security tools and security environment as per the compliance guidelines that come from the Indian government. We follow all those practices, and we help them procure more for their network and infrastructure.
What is most valuable?
QRadar, Splunk, and ArcSight are SIEM solutions with built-in AI/ML features. They can do the complete investigation and alert the admin about what is happening. They can also do the root cause analysis.
There are many other features that come with QRadar. It has a more granular log, so you can integrate with various non-IT as well as IT-based components. You can get unstructured data to the SIEM data, and you can identify more what is happening in the network or what is happening in the central head office. You can also identify what is happening between your remote offices. You can also use it to identify what the users in the field are doing on their devices and how things are moving.
From the integration point of view, it is very centric. It gives complete control centrally. If a user is not connected to the system, whenever he comes online, we can see the policy updates over the Internet, and we can ensure that the data that is supposed to be protected is protected.
What needs improvement?
When it comes to what could be better, it is always what others are trying to do and what is the roadmap. It can have more integration. It should have more flexible RESTful APIs for integration with applications. These are the things that are always in demand for any of the SIEM solutions, not only for QRadar.
Integration is ever-evolving. Nowadays, different versions of mobile handsets are there and data is getting scattered. Users are using their personal handsets to keep the data of the organization. So, it should have a more flexible integration, irrespective of the flavor of the firmware and iOS or Android version. It should have an API that can seamlessly get integrated. It should also provide more flexible control and a more advanced or analytical view to see what exactly is happening across the globe or network. From wherever a user is connecting and accessing the enterprise data, it should give real-time visibility and predictive visibility about what exactly is happening. These things are already there, but there should be more advanced control in terms of managing the security.
For how long have I used the solution?
I have been using this solution for five years.
What do I think about the stability of the solution?
It is absolutely stable. It depends upon how the implementation has been done. We definitely have the skills to do this kind of implementation. We ensure that a customer's environment is absolutely protected.
What do I think about the scalability of the solution?
It is very scalable, but it also depends upon how the implementation was done. We are providing services to one of the major brands in India. They have somewhere around 30,000 devices. We are currently managing more than 1 lakh QRadar users.
How are customer service and technical support?
QRadar has a good technical team. They provide timely support whenever a ticket is raised.
How was the initial setup?
Deployment of such solutions always takes time because these solutions are not simple. You should have the expertise and you should understand what is really needed for the business. We understand the real business need, and accordingly, we implement the policies.
What about the implementation team?
We have been managing some of the security tools for the past 11 years. We have expert engineers who can help our customers with installation, configuration, planning, designing, and other things.
If you have an environment of 5,000 or 10,000 devices, three to five people should be enough to manage it.
What's my experience with pricing, setup cost, and licensing?
Customers have to purchase a license based on the number of users, devices, and applications they want to protect. It allows you to take a license on a subscription basis for three years or five years.
What other advice do I have?
I would recommend this solution. If you are looking for a SIEM solution, IBM QRadar is one that you should ideally look for.
I would rate IBM QRadar a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head of IT Security, Governance and Compliance at a consumer goods company with 10,001+ employees
Easy to use, provides environment visibility, and assists with incident discovery in advance of problems to the business
Pros and Cons
- "This is a good tool to have because it gives you the ability to track what is currently happening in your environment."
- "The modularity could be improved."
What is our primary use case?
We are using QRadar as a managed service.
How has it helped my organization?
This product helps us to find security incidents before they become a problem to the business. We are able to attend to them quicker and we can put protection in place so that should they occur again, we are able to deal with them more easily.
What is most valuable?
The most valuable feature is the ease of use.
What needs improvement?
The modularity could be improved.
For how long have I used the solution?
We have been using IBM QRadar for three years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
We have had no issues with scalability and we have approximately 1,500 users. We are not using its full capabilities at the moment because we are still growing. In the next year or two, we will see.
How are customer service and technical support?
I don't deal with IBM directly. Rather, I deal with our service provider and they deal with IBM.
How was the initial setup?
The initial set was very easy for us because we just bought what we were looking for, and not the entire infrastructure.
What about the implementation team?
The company that we subscribe to for this service takes care of the installation, maintenance, and management of it. They give us updates that concern the features we use, so the maintenance doesn't affect us much.
What's my experience with pricing, setup cost, and licensing?
We use QRadar as a managed service and we pay licensing fees to the partner.
What other advice do I have?
This is a good tool to have because it gives you the ability to track what is currently happening in your environment. Otherwise, if you did not have that, you'd only react to an event or an incident that has already caused problems. The proactiveness goes a long way because it saves your environment and your business from being negatively affected.
In summary, this is a good product but there is always room for improvement.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managed Security Product at a comms service provider with 1,001-5,000 employees
Excellent artificial intelligence component with tricky licensing fees
Pros and Cons
- "The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well."
- "The features that could be improved include the licensing model and the dashboards and all those presentations. Overall, the user experience part can be improved."
What is our primary use case?
IBM QRadar is a FIM component within the security operation center we were deploying in the customer environment. We are managing their cyber defense capability.
What is most valuable?
The feature that I have found most valuable is its artificial intelligence component, Watson. Its contribution is pretty good from a machine-learning artificial intelligence perspective. This compliments the orchestration automation component, as well.
What needs improvement?
The features that could be improved include the licensing model and the dashboards and all those presentations. Overall, the user experience part can be improved.
Additionally, the coverage, the connectors, and the flex connectors for legacy systems and other aspects could be improved. This is something they can work on and improve.
For how long have I used the solution?
I have been using IBM QRadar for more than two years.
What do I think about the stability of the solution?
It is a stable product.
It takes two to three people for its management, but it purely depends on the scope of the security operations center, the SOC.
What do I think about the scalability of the solution?
It is scalable.
It's kind of non-direct user component. It sits under the security operations center, so it won't be visible to the user, but it will be covering devices and users. It can support 100 to 10,000 devices. So it's kind of a back instance.
In terms of plans to increase usage, I'm currently in a management level, so I'm no longer into the directly technical part. But if there is a requirement, IBM QRadar is definitely one of my preferences.
How are customer service and technical support?
IBM technical support is good.
Which solution did I use previously and why did I switch?
We were using ArcSight from Micro Focus, but we were having some challenges integrating with the systems, with the APIs, and with the connectors. That's why we moved to IBM.
How was the initial setup?
The initial setup is at an intermediate, medium level. It's not that straightforward, but not that complex either. The only thing is that their licensing model is a bit complex because they charge for a couple of components like EPS and NetFlow, so that kind of licensing charging is a bit tricky. But all in all, it's a medium, not that complex.
I think it was set up within a month. But use-case finalization and other configurations took another month. It's kind of a two to three month project to move to production completely.
What's my experience with pricing, setup cost, and licensing?
Our licensing is yearly. But it's based on Event Per Second, which is one of the models. Storage capacity for log management is also considered with the fees. Licensing is a bit complex in IBM, as well. Different aspects needs to be considered.
What other advice do I have?
I would recommend IBM to others who want to start using it.
On a scale from one to 10, I would rate IBM QRadar a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Chief Enterprise Architect at a financial services firm with 1,001-5,000 employees
It has good integrations, easy scalability, and strong technical support, but needs better pricing and more AI features
Pros and Cons
- "Integrations are quite a useful and key feature of this solution. It has integration with the CVSS score, which is a central point for all the data and scores about the threats. There is an IBM Bluemix dashboard that is integrated with the CVSS score."
- "I don't look at only the features and benefits; I also look at the price. It is a bit expensive when compared with other solutions. It is expensive for specific deployment topologies, and the decision-makers go for alternatives like ArcSight. It should also have more AI features or capabilities for better threat intelligence. The more it uses machine learning, the better would be the dashboard, analytics, and other things."
What is our primary use case?
It is used to dive deep into threat analysis. It is a SIEM solution that can be hooked up with some of the endpoint security or threat discovery solutions such as Forescout, Qualys, Sophos, and MDM. After the endpoint security or threat discovery solution discovers the threat, QRadar takes it further from that point onwards and allows you to go deep into the threat analysis. It has a lot of integrations, such as with CMDB, and it can do the asset classification. It can also tell the CVSS score. These are the capabilities or use cases.
What is most valuable?
Integrations are quite a useful and key feature of this solution. It has integration with the CVSS score, which is a central point for all the data and scores about the threats. There is an IBM Bluemix dashboard that is integrated with the CVSS score.
What needs improvement?
I don't look at only the features and benefits; I also look at the price. It is a bit expensive when compared with other solutions. It is expensive for specific deployment topologies, and the decision-makers go for alternatives like ArcSight.
It should also have more AI features or capabilities for better threat intelligence. The more it uses machine learning, the better would be the dashboard, analytics, and other things.
For how long have I used the solution?
I have been using this solution for five years.
What do I think about the scalability of the solution?
You can scale it easily in the cloud with a given deployment topology. We have somewhere around 50 plus users.
How are customer service and technical support?
IBM is very strong on the technical support side. They have proper support available across different regions. After the implementation is done, the admin within the organization is in touch with IBM technical support for any day-to-day support requirements.
Which solution did I use previously and why did I switch?
We have been switching for some time between Micro Focus ArcSight and IBM QRadar.
How was the initial setup?
For cloud deployment, you need to go for IBM Bluemix Cloud, and you can deploy easily on a private cloud. You create the stack and use the Bluemix Cloud formation template. If you have the IBM Bluemix Cloud subscription, you can deploy it easily within maybe half a day or one day. You can create all the resources by using the Bluemix Cloud formation template.
For deployment, you need a small team of two or three because it just needs the team to provision the resources on the IBM Bluemix Cloud. For support, we need a bigger team of around 10 plus people.
What's my experience with pricing, setup cost, and licensing?
It is costlier as compared to the other alternatives available in the market.
What other advice do I have?
I would definitely recommend this solution. It is a good solution with good capabilities like integration with CMDB and CVSS score. The dashboard is also really nice. It can help with threat intelligence, and it also has artificial intelligence. It is a futuristic kind of technology because the more AI-driven a product is, the better are the results. We plan to keep using this solution.
I would rate IBM QRadar a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Ingénieur d'étude R&D at a manufacturing company with 51-200 employees
Easy to use, helps increase development speed and is stable
Pros and Cons
- "The solution is relatively easy to use."
- "The pricing of the solution is a bit high. If they could lower it, that would be ideal."
What is our primary use case?
We primarily use the solution to develop software, for some device controllers.
What is most valuable?
The solution is relatively easy to use.
The product helps increase development speed.
The customization is very good, as are the dashboards and the security.
What needs improvement?
I'm not sure if there are any features missing from the solution. It's pretty complete.
The pricing of the solution is a bit high. If they could lower it, that would be ideal.
For how long have I used the solution?
I've been using the solution for three years or so at this point. It hasn't been too long.
What do I think about the stability of the solution?
The solution is quite stable. It doesn't have bugs or glitches. It doesn't crash on me or freeze. It's reliable.
What do I think about the scalability of the solution?
I only really use the solution myself. I can't speak to the scalability of the solution.
How are customer service and technical support?
I've never had to reach out to technical support. I can't speak to their responsiveness or knowledgeability.
How was the initial setup?
The initial setup was not complex at all. It's pretty straightforward and simple. We didn't face any real issues during the deployment process.
What's my experience with pricing, setup cost, and licensing?
The price can be expensive, however, it's all relative, as it helps speed up development, which can save money for the organization.
The payments for the product are made on a yearly basis.
What other advice do I have?
I'm using the latest version of the solution. I'm the only user and I use the desktop version of the solution. I'm basically using it because it's here and I have access to it.
I would recommend the solution to other organizations, however, if it is right for them depends on their need.
Overall, on a scale from one to ten, I'd rate the product at an eight. We've mostly been pretty satisfied with it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Specialist at a comms service provider with 501-1,000 employees
Not user friendly, doesn't integrate well, and has terrible technical support
Pros and Cons
- "The solution can scale."
- "The solution is clunky."
What is our primary use case?
We use the solution for a variety of tasks. We use it, for example, for authentication, network-related authentication, user-related tasks, and Windows UNIX servers. It's a lot. There's a ton of use cases. I really can't sync right now about every single use case, however, the main things are authentication and network-related systems and all flavors of UNIX Windows.
How has it helped my organization?
It helped our organization in the sense that having it was better than nothing. However, I did not enjoy the product overall and I advised we switch to something else.
What is most valuable?
The user behavior analytics as part of our deployment was okay, even though it was clunky.
The solution can scale.
What needs improvement?
I really didn't like QRadar to be honest. I inherited it. I was part of the reason that we moved over to LogRhythm. The solution just isn't user friendly.
The solution is clunky.
The interface could be much better.
The integration capabilities within the product are not that great.
For how long have I used the solution?
I've been using the solution for about two years at this point. My team has been using it for two to three years, so we have a total of about five years of experience in all.
What do I think about the stability of the solution?
I wouldn't describe the solution as stable.
It was really buggy. Like other app integrations, it wasn't straightforward. It was pretty clunky. We tried to integrate Qualys with it and it wasn't effective. To integrate anything took quite a bit of time and energy. It wasn't easy. When it did, it didn't work properly. It wasn't really pulling in the data correctly.
What do I think about the scalability of the solution?
Scalability was hard as it was on-prem. We needed to add more modules, and had to add more of the servers to stack it. It wasn't that a simple task at all. I wouldn't say that it scales well, although technically, you can scale it.
When we were using the solution, we had ten to 15 users on it. They were anyone from Information Security Engineers to regular IT admins.
How are customer service and technical support?
Technical support was awful. We often didn't even have any assistance available to us. On a scale from one to ten, I'd rate them at a three. We were very unsatisfied with the level of support we received. They just simply weren't helpful when it came down to it.
Which solution did I use previously and why did I switch?
The organization didn't previously use a different solution before choosing QRadar.
We actually switched to LogRhythm as I didn't like how the solution was working for the organization.
How was the initial setup?
I didn't handle the initial setup. It was handled before I arrived at the organization.
What other advice do I have?
I'm not sure of which version of the solution we're using.
I wouldn't recommend the solution. I'd probably tell others to shy away and look at other products like possibly Splunk, however, it's a pricey option. LogRhythm is pretty good. We're having some issues with it. That said, for the most part, it's okay.
Exabeam also seems like it might be a good option. I haven't worked with it personally, however, I've had some experience with a POC.
Overall, I would rate the solution at a three out of ten. We didn't have a good experience with it. If it offered, for example, easier behavior analytics, easier integrations, better interface, supported model integration, and a good user interface to perform analysis I might rate it higher. Basically, it just needs to be much more user-friendly.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Dynatrace
Splunk Enterprise Security
Fortinet FortiEDR
Darktrace
Microsoft Sentinel
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Varonis Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
















