Our clients who are implementing or trying to implement a Security Operations Center use the IBM QRadar SIEM solution. This solution helps automate incident processing and provides visibility into the incident management process.
IT Specialist​ at a tech services company with 201-500 employees
Easy to deploy, and scalable, but the stability has room for improvement
Pros and Cons
- "The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing."
- "The solution is difficult to understand in the beginning and has complex management configurations that can be improved."
What is our primary use case?
What is most valuable?
The playbook engine is flexible and allows for the graphical visualization of processes, enabling the implementation of dynamic playbooks for incident response or testing.
The integration of our customer's infrastructure with other security management systems, such as Active Directory, firewalls, and vulnerability management systems, is effective.
What needs improvement?
The solution is difficult to understand in the beginning and has complex management configurations that can be improved.
The stability has room for improvement.
The cost has room for improvement.
For how long have I used the solution?
I have been using the solution for two years.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
What do I think about the stability of the solution?
I give the stability a seven out of ten. There is sometimes unexpected behavior within the logic of the playbook engine and features.
What do I think about the scalability of the solution?
I give the scalability an eight out of ten.
How are customer service and support?
We have had issues that were not resolved by technical support.
How would you rate customer service and support?
Neutral
How was the initial setup?
For the most part, the initial setup is straightforward and I give it a seven out of ten. The initial deployment and configuration require one month, followed by an additional 11 months of implementing various use cases and processes that need to be automated.
What's my experience with pricing, setup cost, and licensing?
I give the price of the solution a four out of ten. The solution comes with a high price tag, while some of the competitors provide identical functionality in their offerings at no extra cost.
What other advice do I have?
I give the solution a seven out of ten.
We have around 20 users.
The solution is of good quality and can be implemented successfully. However, in order to fully utilize its benefits, one must possess expertise in Python programming.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Cyber Security Consultant at a tech services company with 51-200 employees
Reliable with good technical support but needs better visualization
Pros and Cons
- "The product can scale."
- "The product can be a bit complex."
What is our primary use case?
We are implementors and implement this solution for our clients, who use it for analytics.
What is most valuable?
It offers good machine learning. The analysis is very helpful.
The user activity is effectively flagged. It can pinpoint strange activity.
It is stable and reliable.
The product can scale.
Technical support is good.
What needs improvement?
The product can be a bit complex. A lot of things, like visualization, could be better. It would help the customer gain a better understanding.
For how long have I used the solution?
I've used the solution for five to six years. I've used it for a while now at this point.
What do I think about the stability of the solution?
It is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. I'd rate the stability eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. It can handle thousands of users or maybe even more. I'd rate the scalability nine out of ten.
We mostly deal with small or medium enterprises.
How are customer service and support?
Most of the time, technical support is helpful. I am satisfied with the level of service we receive.
How would you rate customer service and support?
Positive
How was the initial setup?
It is easy to implement. I'd rate the ease of implementation seven out of ten.
The deployment only takes no more than a few hours. There are configurations and fine-tuning that have to happen after that, and everything could take about a week.
What about the implementation team?
As implementors, we can implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. It's not expensive compared to other solutions. If you get the console and other licenses, you can easily use it with other QRadar solutions.
What other advice do I have?
New clients should know that it does give good analytics and it will help them save time.
I'd rate the solution seven out of ten. It's a good product.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
Vice President - Technology & Managed Security Services at a computer software company with 1,001-5,000 employees
A simple and stable solution but the dashboards are old
Pros and Cons
- "The simplicity of the solution is the best feature."
- "The dashboards are all legacy and old."
What is most valuable?
The simplicity of the solution is the best feature.
What needs improvement?
The dashboards are all legacy and old. Their cloud support and the content available for cloud and containers are also minimal.
For how long have I used the solution?
We have been using this solution since 2019.
What do I think about the stability of the solution?
I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
I rate the scalability an eight out of ten, and we have about 35 people using it.
How are customer service and support?
I rate the technical support a five out of ten. They need to improve their availability. They have global support, which means we need to wait longer for a response.
How would you rate customer service and support?
Neutral
How was the initial setup?
I rate the initial setup a seven out of ten, and it is deployed on-premises. The deployment took about four to six weeks, and we did it in-house.
What was our ROI?
We have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
I rate the price a six out of ten, with ten being affordable and one being expensive. They recently changed their licensing model, and it's more complex.
What other advice do I have?
I rate this solution a six out of ten. Regarding advice, using this solution purely depends on the use case. If it meets your use case, then IBM QRadar is good, but other solutions like Securonix are much better.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cyber Security Student at a tech services company with 201-500 employees
Scalable, easy to use, and has a visualization feature that shows spikes in the system
Pros and Cons
- "The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log."
- "IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others."
What is our primary use case?
We are using IBM QRadar for log reviews, particularly logs that come and go from the IPS, firewall, etc.
We have different dashboards for different technologies such as our firewall, IPS, and domains for our main website, so we use IBM QRadar to observe the logs from our website, and we try to make internal and external connections for better domain security.
What is most valuable?
The best feature of IBM QRadar is visualization which shows you when there's a spike in the system, and this makes you realize that there's something wrong with the log.
What needs improvement?
IBM QRadar has outdated technology, and this is its area for improvement. When you try to implement an analytic expression, it's not updated. The solution doesn't support newer technologies, and it doesn't update regularly. For example, around the world, others implement new technologies, while IBM updates later than others.
There isn't any additional feature I'd like added to IBM QRadar at this point because it's sufficient for visualizing the logs.
For how long have I used the solution?
I've been with the company for one and a half months, and I've been using IBM QRadar almost daily, but the solution was deployed five or six months ago.
What do I think about the stability of the solution?
IBM QRadar is a stable solution.
What do I think about the scalability of the solution?
IBM QRadar is a scalable solution. My company currently has seven to eight different accounts on IBM QRadar, so it's a scalable technology. It has no problems with scalability.
How are customer service and support?
I didn't have any problems with IBM QRadar, so I never contacted the technical support team.
Which solution did I use previously and why did I switch?
I'm assuming that the main reason my company chose IBM QRadar is that IBM is one of the biggest tech companies in the world, so IBM products would be more secure and more reliable than other solutions.
How was the initial setup?
As I didn't set up or deploy IBM QRadar, I have no information on whether it was easy or complex to set up.
What's my experience with pricing, setup cost, and licensing?
I have no information about the licensing costs of IBM QRadar, and whether or not it requires a license.
What other advice do I have?
I'm an intern at one of the biggest telecommunication companies, and my company uses IBM QRadar.
My advice if you want to use IBM QRadar is that you should use it because it's very scalable and it's easy to use. The solution also has many dashboards, and you don't have to write any code or write different scripts to get the information you need. You can do it from the UI of IBM QRadar. The only room for improvement in the solution is that it doesn't support newer technologies, and it's late when it comes to updates.
I'm rating IBM QRadar nine out of ten because my experience with it has been excellent. The only downside to it is that IBM is late with adding new features or supporting new technologies compared to its competitors.
My company is an IBM QRadar customer.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at a tech services company with 51-200 employees
Excellent visibility, good notifications, and helpful support
Pros and Cons
- "The visibility it gives you into your infrastructure has been great."
- "The AI engine could be smarter."
What is our primary use case?
We are using it for visibility and compliance.
What is most valuable?
The visibility it gives you into your infrastructure has been great.
The notifications it provides offer valuable information when something is happening in your blind spot.
What needs improvement?
The AI engine could be smarter.
It is a bit expensive.
For how long have I used the solution?
I've used the solution for about three years.
What do I think about the stability of the solution?
The solution is stable. I'd rate it five out of five. It's very reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution scales well, and it's easy to do. I'd rate it five out of five in terms of the ease of scalability.
We have a lot of users on the solution currently. We have customers on the product as well. There are likely more than 500 users inside and outside the organization.
How are customer service and support?
Support has been helpful and responsive. There may sometimes be a delay. However, they do get you the information you need.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've only ever used IBM.
How was the initial setup?
The setup is a bit complex. I'd rate it two out of five in terms of ease of deployment. It took us a week to get everything up and running.
We had two engineers working on deployment and maintenance.
What about the implementation team?
We handled the solution in-house. We did not need outside assistance.
What was our ROI?
We've seen a good ROI. I'd give it a five out of five.
What's my experience with pricing, setup cost, and licensing?
It's a bit pricey as a product. I'd rate it a two out of five, with five being the most affordable. It depends on what you buy; the longer you use it, the better the cost. It's an all-inclusive license. You don't need to pay for extra features.
Which other solutions did I evaluate?
We did look at a few other options.
What other advice do I have?
We use the solution inside our organization. Our clients use it too. We are a premium partner in our region.
We're using the latest version of the solution.
I'd rate the solution nine out of ten. It really provides good visibility.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Premium Partners
Vice President & Country Head at a tech services company with 51-200 employees
Excellent risk rating but could keep data longer
Pros and Cons
- "QRadar UBA's most valuable feature is the risk rating of users depending on their behavior."
- "QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month."
What is most valuable?
QRadar UBA's most valuable feature is the risk rating of users depending on their behavior.
What needs improvement?
QRadar UBA only keeps the data for a short while (it's refreshed every five minutes) and would be improved if this were extended to a week or month. In the next release, I would like to be able to do a historical search of user scores.
For how long have I used the solution?
I've been using QRadar UBA for two and a half years.
What do I think about the stability of the solution?
QRadar UBA is quite stable.
Which other solutions did I evaluate?
QRadar UBA's price is a little more than street price and could be reduced.
What other advice do I have?
I would rate QRadar UBA seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
SOC Analyst Tier 2 at a security firm with 51-200 employees
An AI-powered incident and risk analysis, triage and response tool with a user-friendly graphical interface
Pros and Cons
- "I like the graphical interface. It's so good and easy."
- "Integration could be better. They should make it easy to integrate with other solutions."
What is our primary use case?
First, I used the manual to learn, then I tried to merge it with my company's needs, and there weren't any problems.
What is most valuable?
I like the graphical interface. It's so good and easy.
What needs improvement?
Integration could be better. They should make it easy to integrate with other solutions.
For how long have I used the solution?
I have been using IBM QRadar Advisor with Watson for three or four years.
What do I think about the stability of the solution?
IBM QRadar Advisor with Watson is a stable solution.
What do I think about the scalability of the solution?
I think IBM QRadar Advisor with Watson is scalable.
How are customer service and support?
We didn't use technical support as the community was very helpful.
How was the initial setup?
The initial setup was difficult the first time, but it got easier after that.
What's my experience with pricing, setup cost, and licensing?
I think my company pays for the license yearly.
What other advice do I have?
I would advise potential users to read the manual or the workbook before going forward with the deployment. Try to match the requirements with the company's needs to avoid facing issues in the future. But if you get stuck, you can always ask the community for help.
On a scale from one to ten, I would give IBM QRadar Advisor with Watson a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
IM Operations Manager at a tech services company with 1,001-5,000 employees
Simplified event quantity, scalable, but source data reports needed
Pros and Cons
- "IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through."
- "IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features."
What is most valuable?
IBM Qradar's ability to simplify the number of events, not only on a technical level but by making that information easy to pan through the orchestration deduplication. It is very impressive given that we have hundreds of devices that send event logs through.
What needs improvement?
IBM Qradar could improve the reporting. The tool is not designed to report. It's a great operational monitoring tool. You put it on a screen and you watch it. If you want to have analytics out of it, that's a whole different story. You're going to need more people and tools. What should be added is reporting and integration into Power BI, into some capability that produces analytical reports from the source data. IBM does not seem to care to add these features.
For how long have I used the solution?
I have been using IBM QRadar for approximately 10 years.
What do I think about the stability of the solution?
The stability of IBM Qradar is good.
What do I think about the scalability of the solution?
IBM Qradar is a scalable solution.
How are customer service and support?
The technical support from IBM Qradar could improve.
I rate the support from IBM Qradar a two out of ten.
How was the initial setup?
The initial setup of IBM Qradar is difficult, you need to know what you are doing to be able to complete the task. It is not easy.
We used three to four specialists to do the implementation depending on how many integration levels you're going to have. If you're managing the flows and going to be managing applications, logical access, patch management, vulnerability management then it can take more time and more people. It depends on the scale that you want to integrate.
IBM Qradar doesn't come ready for plug and play, for your APIs, integration, and all the other elements you will need a person that knows how to do the IBM QRadar setup. From that perspective, you need to make sure that integration points to the license keys, for validation, and that can be a different challenge if it doesn't work.
What other advice do I have?
My advice to others is they have to have IBM Qradar set for purpose and it depends on the role that you see your SIEM solution playing in the company. If you're offering it as a service to other companies, or you're an IT service provider or security solution provider, then yes, you probably need an enterprise base that is scalable but not with smaller enterprises.
I do think the IoT component of IBM Qradar is lacking. IBM tried and IoT is not specifically aimed at only cameras or what I call physical access points, integration into what I call scale technology. They are areas that would depend on each business to map out what the requirements are. This is not a McAfee endpoint or a Symantec endpoint device that gives you an alert.
There is more competition and innovative application development in this area we've seen in the last few years.
I rate IBM Qradar a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Dynatrace
Splunk Enterprise Security
Darktrace
Fortinet FortiEDR
SentinelOne Singularity Complete
Microsoft Sentinel
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Varonis Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?



















