Try our new research platform with insights from 80,000+ expert users

IBM Security QRadar vs Microsoft Purview Insider Risk Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

IBM Security QRadar
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
210
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (4th), User Entity Behavior Analytics (UEBA) (1st), Endpoint Detection and Response (EDR) (17th), Security Orchestration Automation and Response (SOAR) (4th), Managed Detection and Response (MDR) (8th), Extended Detection and Response (XDR) (11th)
Microsoft Purview Insider R...
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
3
Ranking in other categories
Microsoft Security Suite (29th), Insider Risk Management (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. IBM Security QRadar is designed for Security Information and Event Management (SIEM) and holds a mindshare of 7.2%, down 9.6% compared to last year.
Microsoft Purview Insider Risk Management, on the other hand, focuses on Insider Risk Management, holds 20.1% mindshare, down 20.5% since last year.
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
IBM Security QRadar7.2%
Wazuh10.9%
Splunk Enterprise Security9.3%
Other72.6%
Security Information and Event Management (SIEM)
Insider Risk Management Market Share Distribution
ProductMarket Share (%)
Microsoft Purview Insider Risk Management20.1%
Proofpoint Insider Threat Management19.8%
Dtex Systems13.7%
Other46.39999999999999%
Insider Risk Management
 

Featured Reviews

Mahmoud Younes - PeerSpot reviewer
Reliable installation and diverse use cases provide strong value
IBM Security QRadar has some areas for improvement. We have missed some DSM components. We need to customize logs where there is no DSM or connector for certain products. We can integrate but we have missed the DSM, which is the connector to pass logs coming from different applications. For example, with a university customer, we tried onboarding Canvas service. IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
PR
Insightful detection and prevention of data loss mitigates legal risks and reduces potential lawsuits
Microsoft Purview Insider Risk Management was helpful in performing investigations after alerts were received. I was able to quickly identify the source of issues, which was valuable for data loss prevention. Additionally, it has saved us money on lawsuits and the loss of important confidential information that could lead to legal issues.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Overall a great solution."
"The solution can scale."
"My overall rating for this solution is nine out of ten."
"The visibility it gives you into your infrastructure has been great."
"The most valuable features are the AI assistant, which is good at detecting known types of behavior."
"Search capabilities are sufficient for most tasks."
"It helps us discover any threats with their alerts and tracking."
"There are more than 120 extensions in QRadar, which are easy to install and configure. These can improve your analysis of events."
"Insider Risk Management's graphing is highly specific and useful. You can see the last six months of data for the Microsoft tenant. You can easily find what you need. For example, you can filter for alerts about devices, emails, etc."
"Microsoft Purview Insider Risk Management was helpful in performing investigations after alerts were received."
"The best thing about Purview is that it's easy to integrate with our day-to-day environment. We have Active Directory, and Word and Excel. Using a third-party vendor and trying to integrate with our existing environment would be much more challenging."
 

Cons

"The user interface is a bit clunky, a bit hard to find what you need."
"They should introduce some automation into the product."
"The weak signal detection with QRadar needs improvement. You can detect what you know, but what is unknown to the rule engine can't be detected."
"While the interface is easy to use, it could be a little more responsive."
"There was some complexity in the initial setup due to bandwidth issues."
"It is not app based."
"The modularity could be improved."
"There is a shortage of skilled individuals with knowledge about the solution. There is training required."
"For certain things, you need to install an agent. I understand it's for integrity, but if there could be a clientless solution for certain aspects, it would make life easier."
"The user interface also isn't user-friendly. When we introduce Insider Risk Management to our clients, they often find it difficult to understand. There is too much information, and the UI is not scalable. Also, entry-level IT technicians are not always interested in learning something new. It should be clearer and easier to understand."
"The reporting capabilities sometimes leave a little to be desired. It could be improved in terms of producing reports to provide information to the C-suite or others."
 

Pricing and Cost Advice

"A good approach would be to begin with an On Cloud subscription, then later on do a more exact sizing."
"It is overly expensive and overly complex in terms of licensing. They have many different appliances, which makes it extremely difficult to choose the technology. It is very difficult to choose the technology or QRadar components that you should be deploying. They have improved some of it in the last few years. They have made it slightly easy with the fact that you can now buy virtual versions of all the appliances, which is good, but it is still very fragmented. For instance, on some of the smaller appliances, there is no upgrade path. So, if you exceed the capacity of the appliance, you have to buy a bigger appliance, which is not helpful because it is quite a major cost. If you want to add more disks to the system, they'll say that you can't."
"I feel that the price is reasonable but compared to other products that are on the market, such as an offering by Microsoft, it is more expensive."
"IBM QRadar is a little bit expensive compared to other products."
"The maintenance costs are high."
"The price could be better. I bought a subscription for three years."
"IBM Security QRadar is a very expensive tool."
"Pricing is good."
Information not available
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
866,324 professionals have used our research since 2012.
 

Comparison Review

VS
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
11%
Manufacturing Company
7%
Government
7%
Computer Software Company
36%
Financial Services Firm
9%
Manufacturing Company
6%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise36
Large Enterprise102
No data available
 

Questions from the Community

What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendlier GUI and are not licensed based on capacity (amount of logs and information in...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for IBM Security QRadar?
When comparing with Splunk, IBM Security QRadar's cost is reasonable. Splunk is more expensive than IBM Security QRadar.
What needs improvement with Microsoft Purview Insider Risk Management?
The reporting capabilities sometimes leave a little to be desired. It could be improved in terms of producing reports to provide information to the C-suite or others.
What is your primary use case for Microsoft Purview Insider Risk Management?
The primary use case for Microsoft Purview Insider Risk Management was data loss prevention. This was my main objective.
What advice do you have for others considering Microsoft Purview Insider Risk Management?
I would recommend Microsoft Purview Insider Risk Management to others. I would rate the overall solution as a nine.
 

Also Known As

IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
Microsoft Insider Risk Management
 

Overview

 

Sample Customers

Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Information Not Available
Find out what your peers are saying about Splunk, Wazuh, Microsoft and others in Security Information and Event Management (SIEM). Updated: August 2025.
866,324 professionals have used our research since 2012.