No more typing reviews! Try our Samantha, our new voice AI agent.

IBM Security QRadar vs Tines comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.6
Torq users reported reduced alert management time with automation, enhancing productivity and showing potential for $600,000 annual ROI.
Sentiment score
6.4
IBM Security QRadar offers efficient data management, cost savings, competitive pricing, and long-term protection akin to security insurance.
Sentiment score
6.5
Tines automation reduced analyst needs by 30%, enhancing response time and productivity, with a 20% improved efficiency.
Since we started working with Torq, I am handling much fewer alerts. It is becoming really easy for me to handle an alert.
SOC Analyst at AppsFlyer
We have seen a return on investment, targeting a $600,000 ROI for the year.
Cyber Security Engineer at a real estate/law firm with 5,001-10,000 employees
By the time we officially bought Torq, we already had two workflows that were very helpful to us.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
With SOAR, the workflow takes one minute or less to complete the analysis.
Cyber Security Architects at VaporVM
AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar.
Strategic Account Executive at a computer software company with 51-200 employees
Investing this amount was very much worth it for my organization.
Information Security Analyst at Banglalink
I can speak for fewer employees needed because we used to require many analysts to deal with all the alerts that we were generating, but now we have about 90 to 95% of the alerts already automated through Tines, which requires tremendous time saved and a ton of reduction in the number of analysts required.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
In some domains, we were in a position to actually let go of people, meaning at least two people have been reduced from one team, which saves a lot of cost for the organization.
Head of Cyber Defense Center
We did not see proper value in it, whereas other platforms would have given much higher value for us.
Automation Engineer at a educational organization with 11-50 employees
 

Customer Service

Sentiment score
7.3
Torq offers highly rated customer service, known for quick, effective responses and knowledgeable support, though feature requests may delay.
Sentiment score
6.0
IBM Security QRadar support is mixed, with varying response times and expertise, but users find online resources helpful.
Sentiment score
7.4
Tines' customer service is highly rated for swift AI-powered support and accessible communication, despite not being available 24/7.
My impression of their technical support during the initial setup was that they were helpful, responded within a reasonable timeframe, and provided exactly what we needed.
Security Consultant at Integrity360
The speed and quality of their answers have been pretty good, as I usually get a response within 24 hours, and they follow up well.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
We can always get an answer, and the support team are experts in their own system.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
They assist with advanced issues, such as hardware or other problems, that are not part of standard operations.
Network and Security Architect at Deutsche Telekom
Support needs to understand the issue first, then escalate it to the engineering team.
Cyber Security Architects at VaporVM
The support is really good; for instance, if a critical ticket is submitted, you will get paged right away as it gets logged, and their analyst will look into it, letting you know as soon as possible so you can work on it.
Cyber Security Intern at a retailer with 1,001-5,000 employees
Whenever we hit roadblocks or issues with the platform or story, even if it was our mistake, the people from the most senior engineering team of Tines immediately were willing to get on call with us.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
I would rate the customer support a ten on a scale of one to ten.
Head of Cyber Defense Center
The support and engineering team is quick to resolve bugs and respond promptly.
Security Delivery Manager at Accenture
 

Scalability Issues

Sentiment score
6.4
Torq is praised for impressive scalability, adaptability, and effective workflow management, though requires careful management with large workflows.
Sentiment score
7.2
IBM Security QRadar is praised for scalability, though challenges in larger setups and specific hardware requirements are noted.
Sentiment score
8.2
Tines scales efficiently, managing complex workflows and diverse environments, seamlessly supporting enterprise applications without performance concerns.
Our case management is super scalable.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
In terms of scalability, you can do as long as you can build it, and they can support it.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Regarding the ability of the solution to grow in your work environment, if it is scalable, if it fits your business requirements, and if there is room to scale up, the answer is yes, for sure.
Global IT Director at OpenWeb
For EPS license, if you increase or exceed the EPS license, you cannot receive events.
Cyber Security Architects at VaporVM
It is built for growing teams and has more complex automation capacity.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Whenever this became insufficient, we could easily reach out to the Tines team where they immediately gave us a remedy or fixed the issue.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
From the workloads we have, it can scale for different workflows and add more workflows.
Head of Cyber Defense Center
 

Stability Issues

Sentiment score
6.7
Torq offers high stability and reliability with minimal downtime, quickly resolved issues, and significant improvements over other solutions.
Sentiment score
7.5
IBM Security QRadar offers robust stability and reliability, though some users report issues with patches and high-demand scenarios.
Sentiment score
8.6
Tines is highly reliable with minimal downtime, high accuracy, seamless updates, and consistently supports uninterrupted workflows effectively.
We have been using Torq for one and a half years, but we have experienced no downtime.
Angular Developer at Flourish Software
Most of the time, the system is stable as long as the components that they integrate with are stable.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
I have never faced any downtime or issues.
Senior Information Technology Security Consultant at Mideast Data Systems
On cloud, you don't see any disconnections or instability.
SOC Engineer at a outsourcing company with 10,001+ employees
I think QRadar is stable and currently satisfies my needs.
Architect of Cybersecurity at ASSIST - Software Services
The product has been stable so far.
Information Security Analyst at Banglalink
The tool is stable up to ninety-nine point nine percent.
Security Delivery Manager at Accenture
Tines is very stable.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
 

Room For Improvement

Torq users request improved AI integration, search functionalities, dashboards, transparency, templates, data manipulation, bulk editing, and playbooks.
IBM Security QRadar users seek improved upgrades, integrations, user interface, cost efficiency, AI features, and better threat detection.
Tines faces UI challenges, insufficient documentation, and compliance issues, requiring enhanced customization, onboarding, and expansion beyond security applications.
Torq should offer default templates that can directly scan firewall data and automate actions.
Senior Information Technology Security Consultant at Mideast Data Systems
The AI value depends on maturity. Real value depends heavily on telemetry, integration depth, and workflow design, all of which rely on how mature customers are in their SOC department.
Security Consultant at Integrity360
It was able to capture data but was unable to differentiate between the agent hostname we are using and the hostname that resides on the back end of the Internet.
Senior Consultant at a university with 10,001+ employees
We receive logs from different types of devices and need a way to correlate them effectively.
Network and Security Architect at Deutsche Telekom
If AI-related support can suggest rules and integrate with existing security devices like MD, IPS, this SIM can create more relevant rules.
Information Security Analyst at Banglalink
IBM Security QRadar does not support Canvas, so we had to create custom scripts and workarounds to pull logs from Canvas.
Cyber Security Architects at VaporVM
Reporting and dashboards could be more advanced for deeper analysis.
Security Delivery Manager at Accenture
The issue with the Implode action is that once we get a certain number of events into the Implode action, we lose context of all the events except the last one that came in, so it is a bit difficult to send data back once it goes through the Implode action.
Cyber Security Engineer at a tech vendor with 1,001-5,000 employees
I think they need to add more intelligence to the workflow layer because, depending upon what they have right now, it could be possible for Claude or Copilot or ChatGPT to have that feature quickly.
Head of Cyber Defense Center
 

Setup Cost

Torq's pricing is seen as affordable by some, costly by others, but enterprises value its modern features.
IBM Security QRadar is costly but valuable, priced per EPS/FPS, and cheaper than Splunk yet pricier than other SIEMs.
Tines is praised for cost-effective integration, ease of use, helpful support, dedicated account managers, and favorable licensing.
When they bring more and more value into the platform, it makes more sense to pay that price, but still, it is expensive.
Senior Cyber Architect at a manufacturing company with 10,001+ employees
Before deciding to implement Torq, I considered that compared to our old case management platform, Torq was a much better price and had a lot better value for what you get out of the platform, which was a key consideration for the company.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
It is an expensive solution, not an inexpensive solution, but we get through the flexibility.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
Splunk is more expensive than IBM Security QRadar.
Cyber Security Architects at VaporVM
It was costly mainly because of the value you can get right now compared to other solutions.
CTO at Sabyk
It depends on how much you want to spend.
Strategic Account Executive at a computer software company with 51-200 employees
Tines required no setup cost since we just used their cloud tier and built everything with internal engineering resources.
Automation Engineer at a educational organization with 11-50 employees
My experience with pricing, setup cost, and licensing is very good.
Head of Cyber Defense Center
I did not handle the purchasing side, so I did not actually know the exact pricing or the licensing details.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
 

Valuable Features

Torq enhances efficiency by streamlining workflows with AI, automation, and seamless integrations, offering user-friendly customization and scalability.
IBM Security QRadar is valued for real-time alerts, scalability, integration, AI features, user-friendly interface, and threat detection.
Tines' API integration offers no-code ease, flexibility, real-time automation, excellent support, and robust app integrations for efficiency.
Torq's unified platform approach to AI SOC automation and case management has significantly benefited us by integrating the case management platform with the automation, which saves time compared to managing multiple point solutions across our security stack.
CyberSecurity Engineer at a real estate/law firm with 10,001+ employees
The fact that I can build whatever I want within my own imagination and skills without relying on code is the best thing about Torq.
Director Of Cyber Security at a tech vendor with 501-1,000 employees
You can copy and paste a cURL command. If you have documentation or APIs, you usually have an example on the side. You basically have all the information on how the API call should be. You can just copy that and paste it into a step, and it will just build the step for you.
Global IT Director at OpenWeb
Recently, I faced an incident, a cyber incident, and it was detected in real time.
Information Security Analyst at Banglalink
IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches.
Strategic Account Executive at a computer software company with 51-200 employees
Compared to ArcSight, Splunk, or any other SIEM tools where you need their processing language such as structured query language, SPL, and in Sentinel there is KQL query languages, IBM Security QRadar doesn't require reliance on query languages.
SOC Engineer at a outsourcing company with 10,001+ employees
It helps in streamlining our security operations effectively and efficiently without requiring coding knowledge.
Security Delivery Manager at Accenture
What stands out mostly about Tines's features is the integrations. It connects easily with tools such as Slack, emails, and spreadsheets, and it makes data moves automatically without much work.
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Tines caught the failure and queued them automatically. We did not lose a single student log.
Automation Engineer at a educational organization with 11-50 employees
 

Categories and Ranking

Torq
Sponsored
Ranking in Security Orchestration Automation and Response (SOAR)
4th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
12
Ranking in other categories
AI-SOC (1st), AI-Powered Security Automation (1st)
IBM Security QRadar
Ranking in Security Orchestration Automation and Response (SOAR)
5th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
218
Ranking in other categories
Log Management (6th), Security Information and Event Management (SIEM) (2nd), User Entity Behavior Analytics (UEBA) (3rd), Endpoint Detection and Response (EDR) (10th), Managed Detection and Response (MDR) (7th), Extended Detection and Response (XDR) (10th)
Tines
Ranking in Security Orchestration Automation and Response (SOAR)
6th
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
8
Ranking in other categories
Threat Intelligence Platforms (TIP) (11th), AI-Powered Security Automation (2nd), AI IT Support (9th)
 

Mindshare comparison

As of June 2026, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Torq is 3.8%, down from 5.5% compared to the previous year. The mindshare of IBM Security QRadar is 5.8%, down from 7.6% compared to the previous year. The mindshare of Tines is 4.5%, down from 6.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Torq3.8%
IBM Security QRadar5.8%
Tines4.5%
Other85.9%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

AD
Solutions Architect at Swimlane
Automation has streamlined multi-tenant SOC workflows and improves alert handling efficiency
Although the reporting within Torq is not that great, we did ask for many features regarding reporting in Torq, but due to some platform constraints, they could not make the whole dataset available for us to be used in reporting. Except for that, we used some basic reporting. When I used Torq, it was indeed in the early stages of AI capabilities. Only a few customers were allowed to use it, and we were among them. It functioned well as long as we summarized the data properly. If you input garbage, you would get garbage out. Thus, we had to do significant fine-tuning regarding what data context we provided to the AI orchestrator to get meaningful results. In terms of Torq's unified platform approach to AI SOC automation and case management compared to managing multiple point solutions across my security stack, I find it case-centric. The unified view in case management is good since it provides clarity, although there are limitations regarding how many items in case management can be modified at once. Bulk operations are very limited, potentially due to their back-end database or data retrieval processes that can be improved. Regarding improvements for Torq, when we were onboarded, there were aspects we were uncertain about, such as the number of cases that could be generated, what data we could bring in, how many clients we could onboard, and similar concerns. Initially, we also lacked clarity about the number of playbooks or workflows we could build. Different triggers like system triggers, case-based triggers, and others can be employed without restrictions, but when it comes to on-demand and scheduled jobs, there is a limitation based on the subscription and pricing tier that notably caps the number of workflows we can create. No bulk editing across cases was one issue, along with limited filtering related to single grouping constraints. Additionally, the out-of-the-box case templates provided require substantial modifications before they become usable. There is also a feature in the cases for notes that cannot be searched. They are only visible through the UI, which is another area for improvement. The workflow and execution-based charges seem misleading as this was not discussed initially. I am not sure if new customers are made aware of this. It seems that workflows revolving around cases hinder functionality outside of case management, as we have many use cases needing on-demand triggers and schedules for functions like reporting or polling devices. Creating additional workflows to achieve basic functionalities raises costs significantly, which disadvantages customers. While they facilitate optimization and scaling, the support received tends to be very basic. Improvements can be made in that area as well.
HarshBhardiya - PeerSpot reviewer
SOC Engineer at a outsourcing company with 10,001+ employees
Have managed daily asset and alert monitoring effectively but have encountered limitations with manual processes and interface usability
It's still very manual and doesn't work on its own. It's still in an early stage and not on par where we can consider it a really successful detection system. The accuracy is not there. The UI could be better when compared to Sentinels where we can use flags and tagging. It could be much more user-friendly. IBM Security QRadar has all features and is fully competitive with other SIEM tools, but when it comes to user-friendliness, a new user takes time to get used to it. More intuitive, user-friendly interfaces and more helpful documentation would be beneficial. The query searching and data fetching could be faster. In large to very large organizations with around 5,000 or 6,000 assets or beyond, even with proper configurations and RAM and hardware backing up, the query is fairly slow.
Shadrach Godwish Chukwu - PeerSpot reviewer
SDR and Workflow Automation Specialist at a tech services company with 11-50 employees
Automation has replaced repetitive tasks and helps my team organize workflows in real time
Tines is overall good, but the setup can feel a bit technical at first. More templates for common workflows would make it much easier to start quickly without building everything from scratch. I can say that the documentation could be much simpler and mainly example-based, showing real workflows. Faster support responses would also help, especially when someone is building a very complex workflow so they can easily get support responses at any point. The setup time is considerable. It takes time to set it up, and the learning curve is steep. It is not hard once you know it, but getting started takes a whole lot of time and effort and slows new users down considerably. I will heavily dwell on a few things. More ready-made templates would help so you do not always start from scratch. A simpler onboarding flow for new users would also make it much easier to get started very quickly. Better in-app guidance when building workflows would also be helpful.
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Comparison Review

VS
Manager, Enterprise Risk Consulting at a tech company with 1,001-5,000 employees
Jun 28, 2015
Qradar vs. ArcSight
Continuing with the SIEM posts we have done at Infosecnirvana, this post is a Head to head comparison of the two Industry leading SIEM products in the market – HP ArcSight and IBM QRadar Both the products have consistently been in the Gartner Leaders Quadrant. Both HP and IBM took over niche SIEM…
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
10%
Manufacturing Company
10%
Construction Company
9%
Financial Services Firm
12%
Computer Software Company
10%
Construction Company
8%
Manufacturing Company
8%
Financial Services Firm
13%
Manufacturing Company
10%
Insurance Company
7%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise5
Large Enterprise5
By reviewers
Company SizeCount
Small Business92
Midsize Enterprise39
Large Enterprise107
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise4
 

Questions from the Community

What needs improvement with Torq?
I do not dislike anything about Torq because it has satisfied all of our use cases and requirements. We contacted sup...
What is your primary use case for Torq?
Initially, we were using Slack for small automations, such as creating pipelines or shutting down servers. For exampl...
What advice do you have for others considering Torq?
I have been working for five years with experience in the IT field. Torq is very good. It manages everything. I would...
What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
It mostly depends on your use-cases and environment. Exabeam and Securonix have a stronger UEBA feature set, friendli...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for IBM Security QRadar?
Pricing and the license of EPS were managed by the governance team. I was not responsible for managing those. I was s...
What needs improvement with Tines?
Tines is overall good, but the setup can feel a bit technical at first. More templates for common workflows would mak...
What is your primary use case for Tines?
My main use case for Tines has been automation. My main use has been automating simple workflows, such as moving data...
What advice do you have for others considering Tines?
My advice would be to start simple. The main thing is that you need to build small workflows first. When you build sm...
 

Comparisons

 

Also Known As

No data available
IBM QRadar, QRadar SIEM, QRadar UBA, QRadar on Cloud, IBM QRadar Advisor with Watson
No data available
 

Overview

 

Sample Customers

Information Not Available
Clients across multiple industries, such as energy, financial, retail, healthcare, government, communications, and education use QRadar.
Information Not Available
Find out what your peers are saying about IBM Security QRadar vs. Tines and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.