The use cases that are widely used across the globe are related to ransomware phishing, lateral movement, et cetera.
Team Lead - Information Security at a computer software company with 10,001+ employees
Easy to set up and reliable, with a simple user-interface
Pros and Cons
- "We've found the solution to be scalable."
- "The IBM support can be better."
What is our primary use case?
What is most valuable?
The simple user access model, or the user interface, is something that is very helpful.
The initial setup is not too difficult.
So far, we have found the product to be stable.
We've found the solution to be scalable.
What needs improvement?
The IBM support can be better. It's an aspect that needs improvement.
In future iterations, I'd like to see an advance in office management, the out-of-the-box use cases that are provided. That needs to be part of the requirement.
What do I think about the stability of the solution?
It's a stable solution. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
Buyer's Guide
IBM Security QRadar
March 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution scales well.
We have 45,000 users on the solution right now.
We do plan to increase usage soon.
How are customer service and support?
We've dealt with technical support in the past and it was lacking.
They have provided dedicated time to us, to work on the issue that we are observing right now.
Which solution did I use previously and why did I switch?
We did not use a different solution. We chose this due to the fact that it's an industry-accepted solution. The use cases are easy to configure in multiple things that we considered important while taking the solution.
How was the initial setup?
The deployment was easy. It wasn't overly complex.
It took me around six months to do the implementation.
What about the implementation team?
We handled the deployment with the assistance of a vendor partner.
What's my experience with pricing, setup cost, and licensing?
I can't speak to the exact pricing. I've never looked at its commercial costs.
Which other solutions did I evaluate?
We did consider other options before choosing this product.
What other advice do I have?
We are a preferred partner of IBM.
I'd rate the solution at a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Good logging, reporting, support, and integration with GRD
Pros and Cons
- "The most valuable feature is the integration with the GRD, for banking."
- "The advanced planning management (APM) features should be included."
What is our primary use case?
We are a solution provider and QRadar is one of the products that we implement for our customers.
The majority of our clients for IBM products are financial institutions. By law, to be compliant, they are only allowed to run the current version of any solutions that have been procured. Specifically for our area, all of the financial institutions such as banks are mandated to use the latest version.
The use cases include the logging and reporting of servers. These are typically operations servers and critical servers. You can also use it to monitor network devices such as switches, routers, and firewalls.
Endpoints are not included for most of the clients.
What is most valuable?
The most valuable feature is the integration with the GRD, for banking.
What needs improvement?
The advanced planning management (APM) features should be included. We are facing an issue where many of the software houses in Pakistan have developed their own in-house. They have integrated the APM tool with their monitoring solution. This feature is attracting clients and I think that it should be included.
What do I think about the stability of the solution?
We have not faced any issues in terms of stability.
What do I think about the scalability of the solution?
This is a scalable product.
How are customer service and support?
The support from IBM is okay. I would rate them a four out of five.
How was the initial setup?
The initial setup is not very complex. My team has hands-on experience with the product, which is perhaps why they do not complain about its complexity.
The distributor helped us a lot, which is something that we appreciate.
What about the implementation team?
We implement this product for our clients.
Which other solutions did I evaluate?
There are competing products but IBM is a well-known brand so for the most part, we offer IBM QRadar to our clients.
What other advice do I have?
Overall, IBM QRadar is very good but no product is perfect.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
Buyer's Guide
IBM Security QRadar
March 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
Team Lead & Principal Software Engineer at a tech services company with 51-200 employees
Stable SIEM that offers strong visibility
Pros and Cons
- "It is a very good SIEM."
- "I think it's a very stable product that provides much more visibility than the other product."
- "I would like for Yara to be supported by all components."
What is our primary use case?
I deploy the IBM QRadar for many organizations, and I've been performing analyses for those organizations as well.
These organizations use the tool for monitoring of their environment. It's a basic SIEM product. So we just log each and every data source, perform an analysis, and create rules. We also create advanced use cases to cater the advanced threat(s).
What is most valuable?
I am unable to pick one, every component is valuable. It is a very good SIEM.
What needs improvement?
I would like for Yara to be supported by all components.
For how long have I used the solution?
I have been working with this product for the last five years.
What do I think about the stability of the solution?
I think it's a very stable product that provides much more visibility than the other product.
What do I think about the scalability of the solution?
You can scale the architecture of the QRadar easily by adding licenses.
Small to medium-sized organizations would require one to two people for maintenance while man power for large organizations would be determined by the architecture.
How are customer service and support?
Customer support needs some improvement as there have been a few cases where we were unable to reach them in time.
How was the initial setup?
I didn't find it to be complex. I think IBM QRadar has a more user-friendly GUI that helps your team work easily within it. Deployment for an all in one will take four to five hours but can vary depending on environment size.
What about the implementation team?
Our in-house team assists our customers with deployment. Our customers are the main POC and we are able to deploy into their environment, make necessary integrations, and create the rules.
What's my experience with pricing, setup cost, and licensing?
Licensing can be costly depending on your architecture.
What other advice do I have?
You receive alerts for misconfigurations which allows your administer to easily reconfigure any issues.
The organizations themselves are able to monitor all of their information regarding their team including what attacks they are facing on a daily bases.
I would rate this an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SOC Manager at Nais Srl
Feature - rich, well priced and has good support
Pros and Cons
- "The interface is good."
- "I would like to see the update process simplified."
What is our primary use case?
IBM QRadar is used to help our customers collect information. It collects the information from other tools on the firewall, network devices, cyber tools with both Carbon Black, Cortex, Cynet, and Darktrace.
What is most valuable?
It's a complete platform.
The interface is good.
They have more than 100 features.
What needs improvement?
It is not easy to use.
The updates are not very easy. It is very complex. I would like to see the update process simplified.
When I said "it is not easy to use", I mean that QRadar is not for beginners.
Needs high competence and skyll to use it in a satisfactory way to really help customers.
The complexity is not a flaw, but it si a necessary quality for QRadar to be a truly effective tool in a Cyber environement.
For how long have I used the solution?
We have used IBM QRadar within the last twelve months.
What do I think about the stability of the solution?
IBM QRadar is a stable solution.
What do I think about the scalability of the solution?
It's a scalable platform.
How are customer service and support?
Technical support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
What's my experience with pricing, setup cost, and licensing?
Pricing is good.
What other advice do I have?
I would rate IBM QRadar an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. As a SOC we are real user of QRadar platform for more then one customers.
Certified AIX I.T Manager at a financial services firm with 10,001+ employees
Easy to use and useful for preparing use cases
What is our primary use case?
We primarily use QRadar for monitoring and preparing use cases.
This solution is deployed on-prem.
What is most valuable?
The most important and valuable feature of QRadar is how useful it is for preparing use cases. It's also easy to use.
What needs improvement?
The GUI of QRadar should be improved.
For how long have I used the solution?
I have been using IBM QRadar for one year.
What do I think about the stability of the solution?
QRadar is stable.
What do I think about the scalability of the solution?
This solution is scalable.
How are customer service and support?
I have contacted IBM's technical support—it was great. They are very knowledgeable.
How was the initial setup?
QRadar is very easy to install, and I can do it myself. The time period will depend on the organization itself, since it depends on the environment and the number of servers and endpoints.
What about the implementation team?
I implemented this solution myself.
What's my experience with pricing, setup cost, and licensing?
I pay for licensing yearly.
Which other solutions did I evaluate?
What other advice do I have?
I rate QRadar an eight out of ten. I would recommend QRadar, as well as LogRhythm, to others considering implementation.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Leader at a computer software company with 1,001-5,000 employees
Manage and review incidents easily
Pros and Cons
- "The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents."
- "The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity."
What is our primary use case?
We use IBM QRadar for user behavior analytics and incident handling.
What is most valuable?
The features that I have found most valuable are that it is very stable, easy to get going, and easy to manage. It is also easy to review all incidents.
What needs improvement?
The only problem is that if you have too many events that occur, then the storage capacity becomes a problem. We would need to increase the storage capacity.
For how long have I used the solution?
I have been using IBM QRadar for four years.
What do I think about the scalability of the solution?
We have three customers using it and these customers have 100 to 300 users.
How are customer service and support?
Getting support sometimes takes time.
How was the initial setup?
The initial setup was quite straightforward.
We had the complete deployment and it was up and running in half a day.
What about the implementation team?
You can implement it by yourself.
What other advice do I have?
I would recommend IBM QRadar to other people who want to start using it.
On a scale of one to ten, I would give QRadar a nine.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Engineer at Harel Mallac Technologies Ltd
Simple to manage, reliable, and straightforward installation
Pros and Cons
- "The solution is easy to use, manage, and review all incidents."
- "If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage."
What is our primary use case?
I use IBM QRadar for user behavior analytics, and mostly incident handling.
What is most valuable?
The solution is easy to use, manage, and review all incidents.
What needs improvement?
If you have too many events that occur, then the storage capacity becomes a problem. You need to have more storage.
For how long have I used the solution?
I have been using IBM QRadar for approximately four years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
We have approximately three customers and the total users that are using it would be approximately 200.
How was the initial setup?
The initial installation was straightforward, we were able to have it running in half a day.
What about the implementation team?
I do the implementation and maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
There are different types of subscriptions available. We were on an annual subscription, but our customers typically choose the two years subscription option.
What other advice do I have?
I would recommend this solution to others.
I rate IBM QRadar a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Country Manager at a tech services company with 11-50 employees
Stable, scalable, and helpful support
Pros and Cons
- "I have found IBM QRadar to be stable."
- "IBM QRadar has a margin for development, for out-of-the-box use cases. It can be enhanced with better support and automate the use cases for that."
What is our primary use case?
The main tool for this operation center for collectings events from different devices, whatever server or network devices, such as switches and routers. It handles anything related to data that can be harmful related to security. Those events can be mapped to promote the threat, it creates another event for promoted threats.
We are a service provider and we provide services to our customers. We use IBM QRadar for many types of businesses, such as banks and telecom. It has a good reputation.
What needs improvement?
IBM QRadar has a margin for development, for out-of-the-box use cases. It can be enhanced with better support and automate the use cases for that.
For how long have I used the solution?
I have been using IBM QRadar for approximately two years.
What do I think about the stability of the solution?
I have found IBM QRadar to be stable.
What do I think about the scalability of the solution?
IBM QRadar is scalable.
How are customer service and support?
The technical support of IBM QRadar is good.
Which solution did I use previously and why did I switch?
IBM QRadar is the best SAN solution we have used compared to the others.
How was the initial setup?
We manage the installation of the solution. It is not something difficult, it is reasonable. It is not that easy for anyone to do, it needs a technical team.
What about the implementation team?
The implementation needs a technical team and we have two engineers for the implementation and maintenance.
What's my experience with pricing, setup cost, and licensing?
There is a license to use this solution, which is paid annually. However, there are subscription options available.
What other advice do I have?
I recommend this solution to others.
I rate IBM QRadar an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Splunk Enterprise Security
Dynatrace
Cortex XDR by Palo Alto Networks
Darktrace
SentinelOne Singularity Complete
Microsoft Sentinel
Fortinet FortiEDR
HP Wolf Security
Huntress Managed EDR
Varonis Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?

















