No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Security QRadar vs ReliaQuest GreyMatter comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
IBM Security QRadar
Ranking in Extended Detection and Response (XDR)
8th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
218
Ranking in other categories
Log Management (5th), Security Information and Event Management (SIEM) (2nd), User Entity Behavior Analytics (UEBA) (3rd), Endpoint Detection and Response (EDR) (11th), Security Orchestration Automation and Response (SOAR) (5th), Managed Detection and Response (MDR) (8th)
ReliaQuest GreyMatter
Ranking in Extended Detection and Response (XDR)
30th
Average Rating
9.6
Reviews Sentiment
8.1
Number of Reviews
2
Ranking in other categories
Digital Risk Protection (11th), Managed Detection and Response (MDR) (16th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
HarshBhardiya - PeerSpot reviewer
SOC Engineer at a outsourcing company with 10,001+ employees
Have managed daily asset and alert monitoring effectively but have encountered limitations with manual processes and interface usability
It's still very manual and doesn't work on its own. It's still in an early stage and not on par where we can consider it a really successful detection system. The accuracy is not there. The UI could be better when compared to Sentinels where we can use flags and tagging. It could be much more user-friendly. IBM Security QRadar has all features and is fully competitive with other SIEM tools, but when it comes to user-friendliness, a new user takes time to get used to it. More intuitive, user-friendly interfaces and more helpful documentation would be beneficial. The query searching and data fetching could be faster. In large to very large organizations with around 5,000 or 6,000 assets or beyond, even with proper configurations and RAM and hardware backing up, the query is fairly slow.
MK
Senior Security Analyst at Tata Consultancy
Unified security monitoring has reduced alert fatigue and improves proactive threat hunting
I use real-time monitoring in ReliaQuest GreyMatter, which significantly improves my security posture. The unified interface helps reduce alert fatigue. I would estimate it saves around 20% in alert fatigue reduction. The automated threat hunting capabilities in ReliaQuest GreyMatter help me stay ahead of threats. The machine learning algorithm benefits my threat intelligence by providing deeper insights and predictions. I use various metrics to rate the success of the predictive threat intelligence in ReliaQuest GreyMatter.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about."
"Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features."
"We use it for malicious connections from malicious websites, to identify payloads that might be inside the traffic, to identify malicious processes or bugs that are running on the network, and any activities that tend to lead to data infiltration."
"The protection offered by this product is good, as is the endpoint reporting."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"Palo Alto is constantly adding new features."
"The solution is a new generation XDR that has a lot of artificial intelligence modules."
"There are many things I appreciate about IBM Security QRadar; I haven't used any other SIEM before IBM Security QRadar, so for me, it is perfect."
"We have the abilities to monitor each instance which originates on the process along with the performance of each department."
"It has the ability to summarize all the other security products and give us a one-stop-shop dashboard."
"The solution is flexible and easy to use."
"It can analyze event logs, event security, and give a good consult."
"It has a lot of good correlation rules. From a customer's point of view, it is one of the best solutions because you don't need to create correlation rules from scratch. You just review them and customize them as you want."
"It is a pretty solid product for the type that it is representing. It is a CM solution as compared to Splunk or ArcSight from HP. It is also user friendly. It comes with some internal AI as well, in which it automatically maps multiple lots from unrelated devices and makes a smart decision to link them back and create an offense based on that. It is a smart tool."
"The simple user access model, or the user interface, is something that is very helpful."
"ReliaQuest GreyMatter saves around 60% of time or resources."
"ReliaQuest GreyMatter has helped us to reduce security incidents by 89%, which is a significant amount of incidents we have seen."
 

Cons

"The downside to the solution is that there are a large number of false positives."
"Impact on system performance is horrible, adding a lot of delays for users."
"I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities."
"Cortex XDR by Palo Alto Networks could improve by offering remote management. It would be useful to look at the client's issue to fix it."
"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"The product's pricing needs improvement. They could provide more discounts. Additionally, the dashboard and control panel could be enhanced."
"The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
"For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
"In terms of what could be improved, I would say the script which we have to create for custom actions. QRadar needs to improve that feature. Additionally, QRadar has to provide the playbooks designing features."
"Maybe there should be more custom rules in the exchange. Basically, we are using a lot of threat rules, so maybe they'll develop something like that."
"QRadar's performance has room for improvement because it cannot handle the volume."
"Their technical support is also good. During weekends they are only looking at the priority issues. That is difficult, because sometimes the critical log sources stop sending events to QRadar and in those cases we need support on an urgent basis, but they're not going to support it during weekend."
"The user interface is a bit difficult to get used to."
"QRadar log integration of various applications can be a tough job at times. There may be occasions when you will not find any QRadar guide on adding logs of a particular application. Even if you come across one, adding a log process is not an easy one."
"I think that the search speed of this solution could be improved."
"There could be better integration with the solution."
"Areas that have room for improvement include user interface and integration."
 

Pricing and Cost Advice

"I don't recall what the cost was, but it wasn't really that expensive."
"Its pricing is kind of in line with its competitors and everybody else out there."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"I am using the Community edition."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"The pricing is a little bit on the expensive side."
"The tool's price is moderate."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"IBM Security QRadar is a very expensive tool."
"The pricing is higher but cheaper than others and there are no additional costs."
"The solution has a licensing model that is based on events per second so it scales to need and budget."
"The price of this solution is reasonable."
"An X-Force feed is free with QRadar."
"The pricing needs to be such that they are more competitive with other vendors."
"Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you."
"The product is expensive. We have purchased the perpetual license, but we pay for the support."
Information not available
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Outsourcing Company
12%
Financial Services Firm
10%
Construction Company
9%
Manufacturing Company
7%
Financial Services Firm
10%
Manufacturing Company
9%
Construction Company
8%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business93
Midsize Enterprise39
Large Enterprise107
No data available
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for IBM Security QRadar?
I am overall satisfied with the licensing cost for IBM Security QRadar.
What needs improvement with ReliaQuest GreyMatter?
Areas that have room for improvement include user interface and integration.
What is your primary use case for ReliaQuest GreyMatter?
I use ReliaQuest GreyMatter for detection and response, XDR, and SIEM. The best features I like about GreyMatter the ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Information Not Available
Find out what your peers are saying about IBM Security QRadar vs. ReliaQuest GreyMatter and other solutions. Updated: September 2026.
913,924 professionals have used our research since 2012.