No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer993816 - PeerSpot reviewer
Senior Security Engineer at a tech services company with 1,001-5,000 employees
Real User
Jun 10, 2021
Feature rich solution recommended for every customer
Pros and Cons
  • "The features that I have found most valuable in QRadar are its data enrichment, use case creations, and adding references - those kinds of features are very good. Also QRadar's event filtration and device integration are perfect."
  • "We recommend QRadar; it is a good product, a good solution, and every customer should go with IBM QRadar."
  • "In terms of what could be improved, I would say the script which we have to create for custom actions. QRadar needs to improve that feature. Additionally, QRadar has to provide the playbooks designing features."
  • "Their technical support is also good. During weekends they are only looking at the priority issues. That is difficult, because sometimes the critical log sources stop sending events to QRadar and in those cases we need support on an urgent basis, but they're not going to support it during weekend."

What is most valuable?

The features that I have found most valuable in QRadar are its data enrichment, use case creations, and adding references - those kinds of features are very good. Also, QRadar's event filtration and device integration are perfect. 

Actually, we are looking for another product because a customer is demanding different products and they're not going with QRadar, hence we are trying to compare QRadar with other solutions like Securonix, Splunk, Exabeam, LogRhythm. Otherwise, all our customers are happy with QRadar.

I'm doing integrations and deployments for QRadar. So, in regards to integration and deployment, QRadar is very easy as compared to other products.

What needs improvement?

In terms of what could be improved, I would say the script which we have to create for custom actions. QRadar needs to improve that feature.  Additionally, QRadar has to provide the playbooks designing features.

For how long have I used the solution?

I have been working with IBM QRadar for the last four years.

What do I think about the stability of the solution?

QRadar is very stable in our deployment. I'm not aware of other customer deployments.

Buyer's Guide
IBM Security QRadar
June 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.

What do I think about the scalability of the solution?

IBM QRadar is scalable. We can scale it according to our requirements. We can scale it up, as per our requirement. We can increase the resources, we can increase the storage. We can do everything with QRadar.

How are customer service and support?

Their technical support is also good. During weekends they are only looking at the priority issues. That is difficult, because sometimes the critical log sources stop sending events to QRadar and in those cases we need support on an urgent basis, but they're not going to support it during weekend.

Which solution did I use previously and why did I switch?

We work with LogRhythm as well as QRadar, as well as NetIQ Sentinel, Azure Sentinel and others.

How was the initial setup?

The initial setup for QRadar is easy. It is easy to understand and easy to implement.

What's my experience with pricing, setup cost, and licensing?

As compared to LogRhythm, IBM QRadar's pricing is moderate.

What other advice do I have?

We recommend QRadar. It is a good product, a good solution.

Every customer should go with IBM QRadar.

On a scale of one to ten, I would give IBM QRadar a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
reviewer1593615 - PeerSpot reviewer
AVP - Security at a tech services company with 501-1,000 employees
Real User
Jun 6, 2021
Scalable, high visibility, and good technical support
Pros and Cons
  • "I have found visibility very helpful for analytics."
  • "The technical support is very good."
  • "This solution is on-premise and many customers are moving to the cloud base solution."

What is our primary use case?

IBM QRadar is typically deployed in a SOC environment for security monitoring. It is used for log and packet capturing. It has some supporting technology, such as data leakage prevention and data encryption.

What is most valuable?

I have found visibility very helpful for analytics.

What needs improvement?

This solution is on-premise and many customers are moving to the cloud base solution.

For how long have I used the solution?

I have been using this solution for approximately one year.

What do I think about the stability of the solution?

I have not had any complaints from my clients about the stability of the solution.

What do I think about the scalability of the solution?

The solution is scalable. Our customers that are using this solution are mainly large-sized companies, such as the government.

How are customer service and technical support?

The technical support is very good.

What other advice do I have?

Nowadays cloud stack security is very good. Some of my customers are planning to build their data center over the cloud, or implement cloud-based services using some of the beneficial services, such as threat intelligence services.

I rate IBM QRadar a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Buyer's Guide
IBM Security QRadar
June 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
reviewer1584831 - PeerSpot reviewer
Solution Architect Cybersecurity at a tech services company with 501-1,000 employees
Real User
May 26, 2021
Protects our network from various threats
Pros and Cons
  • "The threat hunting capabilities in general are great."
  • "In short, it provides us with real-time visibility so we can identify who the insider threats and what malicious activities are occurring inside of our own network."

    What is our primary use case?

    We use this solution for advanced threat detection, insider threat monitoring, risk and vulnerability management, and unauthorized traffic detection regarding our network. We can monitor and detect web attacks with it as well. 

    Within our organization, there are roughly 2,000 to 3,000 employees using this solution. As of now, we don't have any plans to increase our usage of IBM QRadar.

    How has it helped my organization?

    The basic use case of this solution is to identify insider threats. Insider threats are the most dangerous kind of threat for any type of organization to secure. This solution identifies who the insider threats are, and also determines if there are any malicious activities taking place inside of an organization itself. In short, it provides us with real-time visibility so we can identify who the insider threats and what malicious activities are occurring inside of our own network. It also protects our web applications from DNS attacks.

    What is most valuable?

    The threat hunting capabilities in general are great. 

    What needs improvement?

    I was going to say that the reporting could be improved, but IBM recently introduced a new cloud-based security service that integrates with QRadar. Now, reporting is much easier than before. I personally can't think of an area for improvement.

    For how long have I used the solution?

    I have been using this solution for two and a half years. 

    What do I think about the stability of the solution?

    This solution is quite stable. 

    How are customer service and technical support?

    We receive 24/7 support via email; however, we don't have to contact support often because we have our own trained team. They handle most issues.

    Which solution did I use previously and why did I switch?

    We used to use Splunk.

    How was the initial setup?

    How complex the initial setup is completely depends on the customer's infrastructure. If there are lots of tools that need to be integrated, then the setup is going to be really complex. I wouldn't say that the initial setup is complex, it's more moderate than anything. 

    Deployment took two to three weeks from beginning to end.

    What's my experience with pricing, setup cost, and licensing?

    The price of this solution is a little high.

    What other advice do I have?

    Before implementing a new solution, you need to understand your network infrastructure completely. You need to determine if third-party integration is supported or not. IBM Qradar supports a lot of third-party integration because third-party tool integration is often required. 

    Storage also needs to be defined properly as logs need to be kept for a certain amount of time. If you have to store logs for three to six months, then you'll need to ensure that you've evaluated the storage capacity properly.

    Overall, on a scale from one to ten, I would give this solution a rating of eight. We're very satisfied with it. 

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Real User
    May 24, 2021
    Stable, functional out of the box, and offers good integration capabilities
    Pros and Cons
    • "Technical support is good overall."
    • "The solution is functional right out of the box and it's a pretty simple system with different kinds of solutions that address different types of problems."
    • "The reporting system could use some upgrading."

    What is our primary use case?

    We make some special demos that we sell to our customers. We work as a technical support L1/L2 for our customers in these cases as well.

    The solution allows organizations to check people who work from home or in the office. It can help a company understand who is connected from home. 

    Sometimes people give a login and password to colleagues. The security can see the situation when someone logs in locally, and they can see a remote connection. They can see this is from the login and password. They'd be able to tell if something was shared and could dig deep to figure out if it is a breach or if it is something that has been properly shared. 

    What is most valuable?

    The SOAR features are very good.

    The product is able to handle special requests.

    It can effectively search local files.

    We are able to deploy in two or more different locations.

    The solution is functional right out of the box and it's a pretty simple system with different kinds of solutions that address different types of problems. 

    The initial setup is pretty straightforward.  

    The solution is stable.

    The product can scale.

    Technical support is good overall.

    Qradar has a lot of integration capabilities with different security products.

    If we talk about functionality in general for SIEM systems, it's good.

    What needs improvement?

    In terms of the government sector, sometimes they do not have enough money to buy a full SIEM. That's why they ask about some parts of the SIEM system or core. It can be expensive.

    It would be ideal if they offered a barebone setup alongside an appliance. It's very interesting for different kinds of customers. Most of them prefer the core appliance, yet some of them prefer barebone.

    It would be ideal if the solution offered new connectors to other systems.

    The reporting system could use some upgrading.

    For how long have I used the solution?

    We've been using the solution for at least the last 12 months or so.

    What do I think about the stability of the solution?

    The stability is good. there are no bugs or glitches. It doesn't crash or freeze.

    What do I think about the scalability of the solution?

    The scalability of the product is very good. Sometimes we get requests for specific functionality and usually, we can accommodate that.

    How are customer service and technical support?

    Generally, we are happy with technical support. They are helpful and responsive.

    How was the initial setup?

    The initial setup is very simple for our customers due to the fact that the first step is a demo for a customer. We need about 5 to 15 working days to make this demo. We talk about making a core system. It's not difficult to make over the Qradar SIEM. After that, if the customer needs some special function for, for example, different parts of the organization, we can propose some separate parts of SIEM. That's about two or eight weeks away. 

    In general, for a SIEM project, you are looking at a deployment time of about two til eight months. 

    What about the implementation team?

    As integrators, we can help advise clients and assist in the deployment process.

    What's my experience with pricing, setup cost, and licensing?

    IBM Qradar has an interesting scheme for payments. They have annual payments for customers who use subscriptions for some services. I can't see any problem with the current financial scheme for this product generally. It's okay.

    What other advice do I have?

    We are implementors. Our customers are the ones that use IBM Qradar.

    We are an IBM partner.

    We strongly recommend to our customers use the latest version of Qradar. It's important for security. We tend to use the latest in general.

    Our customer is a government organization, including some ministries. Therefore, they use on-premise deployments only. However, they have some plans for hybrid clouds or private clouds in the next three or four years. That said, it's very hard to say exactly as the work at the ministry is about security. On-premise is deemed to be more secure.

    I'd rate the solution at a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1518060 - PeerSpot reviewer
    SOC Team Lead at a financial services firm with 1,001-5,000 employees
    Real User
    Apr 19, 2021
    Flexible, easy to learn, and price fairly
    Pros and Cons
    • "I have found the most important features to be the flexibility, tech framework, and disk manager."
    • "The solution has great support; whenever we had an issue they were able to give us support within 15 minutes."
    • "There could be better integration with the solution."

    What is our primary use case?

    Depending on the organization's needs the solution can monitor different types of security through logs.

    What is most valuable?

    I have found the most important features to be the flexibility, tech framework, and disk manager. Additionally, the solution is easy to learn how to use it.

    What needs improvement?

    There could be better integration with the solution.

    For how long have I used the solution?

    I have been using the solution for approximately three years.

    What do I think about the stability of the solution?

    Every solution has some bugs and other issues but for the most part, this solution is stable.

    What do I think about the scalability of the solution?

    The solution is scalable. The amount of users is dependant on what your needs are. You can have many users having access to the solution. For example, out of a 5,000 person network, you could have five with access to it for security. 

    How are customer service and technical support?

    The solution has great support. Whenever we had an issue they were able to give us support within 15 minutes.

    How was the initial setup?

    The installation was easy but this can depend on what appliances you want to install it on. If it is VMware, then the installation is easy, it took me 30 minutes.

    What about the implementation team?

    We did use a consultant to do the deployment and we only needed one technician.

    What's my experience with pricing, setup cost, and licensing?

    The solution is priced fairly, there is a license for the solution, and we pay annually.

    What other advice do I have?

    I would recommend the solution to others and we plan to continue using it in the future.

    I rate IBM QRadar a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1520922 - PeerSpot reviewer
    Regional Director, Customer Success (GTM Solutions & Services) at a tech services company with 51-200 employees
    MSP
    Apr 17, 2021
    Flexible, easy to use, and scalable
    Pros and Cons
    • "The solution is flexible and easy to use."
    • "We have evaluated Secureonix and this solution is far superior."
    • "IBM is going through some problems with its resources currently making its support response time slow."

    What is our primary use case?

    We are a service provider and we are providing the solution as a managed service for multitenancy security.

    What is most valuable?

    The solution is flexible and easy to use.

    What needs improvement?

    IBM is going through some problems with its resources currently making its support response time slow.

    For how long have I used the solution?

    I have been using the solution for a couple of months.

    What do I think about the stability of the solution?

    I find the solution reliable. 

    What do I think about the scalability of the solution?

    The solution is scalable. We have 15 customers using it at the moment.

    How are customer service and technical support?

    The support could be a lot better by being faster.

    Which solution did I use previously and why did I switch?

    We recently switched to this solution from LogRhythm cloud. One of the main reasons we switched solutions was because it is more scalable.

    How was the initial setup?

    The installation was a little difficult and could be made easier.

    Which other solutions did I evaluate?

    We have evaluated Secureonix and this solution is far superior. We did the implementation of Securonix for two customers and we canceled it. We rolled back those clients onto this solution because Securonix failed on both implementations.

    What other advice do I have?

    I would recommend this solution to others. We have invested in it and we plan on using it in the future.

    I rate IBM QRadar an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
    PeerSpot user
    Security Operations Manager at a comms service provider with 501-1,000 employees
    Real User
    Mar 20, 2021
    Flexible and very scalable with a straightforward setup
    Pros and Cons
    • "The solution is quite flexible."
    • "We pay a little bit extra for Watson, and the Watson feature enables the analyst to go through and triage things much faster."
    • "Technical support really needs to be improved. Right now, they aren't where they need to be at all."
    • "Trying to get answers out of IBM is like trying to get blood out of a stone. They need to be more helpful and responsive."

    What is our primary use case?

    We mostly use the product for PCI compliance.

    What is most valuable?

    We pay a little bit extra for Watson, and the Watson feature enables the analyst to go through and triage things much faster. It's quite useful for us and worth the smaller extra bit of money.

    The solution is quite flexible.

    We enjoy the fact that it is cloud-based.

    The initial setup was very straightforward.

    The solution is very scalable.

    We've found the stability to be mostly very good.

    What needs improvement?

    Technical support really needs to be improved. Right now, they aren't where they need to be at all.

    The solution is very expensive. We'd appreciate the product more if it came at a lower price point.

    What do I think about the stability of the solution?

    It is generally very stable. We've had odd little breakages, however, generally, nothing major has gone wrong. The performance is good. It's a reliable product.

    What do I think about the scalability of the solution?

    The scalability aspect of the product is very good. That was one of the reasons that we bought it. If a company needs to expand it, it can do so with relative ease. It's not hard.

    Currently, all the members of the tech ops team use the product, and there are five of them.

    We may not increase usage; we may switch to something else. That has yet to be determined. It's not set in stone.

    How are customer service and technical support?

    We've used technical support in the past and we haven't been satisfied with the level of service on offer.

    Trying to get answers out of IBM is like trying to get blood out of a stone. They need to be more helpful and responsive. Right now, they aren't either of those things.

    How was the initial setup?

    The initial setup was not difficult or complex. It was very straightforward. A company should have too much trouble with the process.

    The deployment process was very, very quick as well. There is a collector deployed on our network. We spun that out. You point your log sources at it, you point it at some IP addresses that IBM gives you, and it just works.

    What about the implementation team?

    We did not use an integrator or consultant for the deployment. We handled it ourselves, with our own staff. Everything was done in-house.

    What's my experience with pricing, setup cost, and licensing?

    The product is not a cheap solution. it's quite expensive.

    We do also pay more in order to use Watson.

    Which other solutions did I evaluate?

    We're currently evaluating other options to see if we want to switch off of this product in the future. Nothing has been decided. I'm currently doing some preliminary research. We're always looking for solutions that are better or cheaper.

    What other advice do I have?

    We are just a customer and end-users. We don't have a business relationship with IBM.

    We are using the latest version of the solution, as we have the cloud version of the product. Whatever the latest version is, IBM upgrades it automatically. We don't need to worry about that on our end.

    In general, I would rate the solution at a seven out of ten. If it were cheaper it might rate a bit higher, however, for the most part, it does what we need it to do.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1421823 - PeerSpot reviewer
    Deputy General Manager at a comms service provider with 5,001-10,000 employees
    Real User
    Mar 12, 2021
    Correlation done well, fair pricing, and knowledgeable technical team
    Pros and Cons
    • "When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed."
    • "I have noticed the interface has room for improvement."

    What is most valuable?

    We are looking for the entire QRadar spectrum but it has many products. QRadar is a kind of program, we are looking for system modelling, point modelling, network side modelling similar to QRadar network inside, and the capability to correlate between the network and endpoint. Most of the SIEM's have to rely on when it comes to network side third party or separate network traffic analysis. When it comes to QRadar, they can do the correlation and not only in networks but also endpoints. This is one of the good features that we have noticed.

    What needs improvement?

    Since we have not used the solution very long my information is limited when it comes to improvements. I have noticed the interface has room for improvement.

    For how long have I used the solution?

    I have been using the solution for two years. However, my company has not deployed the solution yet and we are in the early stages of testng.

    How are customer service and technical support?

    The solution has a good technical team.

    How was the initial setup?

    The installation is complex. There is some overloading that happens, this could be simplified and made easier by allowing all key features on the first level dashboard to be viewed.

    What's my experience with pricing, setup cost, and licensing?

    When it comes to the initial pricing there can be a huge discount from there side and also I think they are open to competing with other products. Even though the price can be a little high sometimes there product is number one. They have a wide range of products.

    Which other solutions did I evaluate?

    We have compared Securonix and many other solutions to this one.

    What other advice do I have?

    I rate IBM QRadar a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    reviewer1216545 - PeerSpot reviewer
    Cybersecurity Business Development Manager at a comms service provider with 10,001+ employees
    Real User
    Mar 1, 2021
    Helpful customer support, overall good functionality, and reliable
    Pros and Cons
    • "Overall a great solution."
    • "There needs to be better integration with other applications."

    What is our primary use case?

    I am currently working in the Brazilian operation of my company. I have a project in the airline industry in Brazil. This project improves the correlation of logs. There is another company I ticket to improve the solution, they have chosen to correlate the logs. We have SOC, Security Operation Center in Brazil, with 53 employees. We developed all these solutions in Brazil and it is in operation in 34 countries. 

    What is most valuable?

    Overall a great solution.

    What needs improvement?

    There needs to be better integration with other applications.

    What do I think about the scalability of the solution?

    We have approximately 40 users using the solution.

    How are customer service and technical support?

    The technical support is good.

    How was the initial setup?

    The installation is complex.

    What about the implementation team?

    We do the deployment for the solution.

    What other advice do I have?

    I rate IBM QRadar a ten out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Cyber Security Consultant at Gulf Business Machines
    Reseller
    Feb 11, 2021
    Great integration capabilities with excellent scalability potential and an easy setup
    Pros and Cons
    • "The most valuable aspect of the solution is the integration capabilities on offer."
    • "In general, the product is awesome."
    • "Technical support could be improved by a bit."
    • "The performance of the solution could be improved."

    What is our primary use case?

    We primarily use the solution for log collection and security incidents as well as event management.

    How has it helped my organization?

    We benefit the most from the integration on offer. IBM QRadar offers a solution to our enterprise customers, and certainly, the admin has been benefiting from it, in terms of having more visibility on what's happening on the network in terms of events, flows, et cetera, and all in real-time. 

    What is most valuable?

    In general, the product is awesome. It's almost perfect.

    The most valuable aspect of the solution is the integration capabilities on offer. It's very helpful to have so many options.

    The initial setup is pretty straightforward.

    The stability is good.

    We've found the scalability to be excellent.

    It offers all of the specifications of the hardware that we need.

    What needs improvement?

    The performance of the solution could be improved. Right now, it's the weakest aspect. I wish it was better.

    Technical support could be improved by a bit.

    For how long have I used the solution?

    I've been dealing with the solution for five years at this point.

    What do I think about the stability of the solution?

    The stability of the solution is very good. It's reliable. There aren't bugs or glitches. It doesn't crash or freeze. It's been good.

    What do I think about the scalability of the solution?

    There's nothing better than QRadar when it comes to scalability. You can scale it to 100,000s of events per second. It can be scaled as much as you want. It has no limitations to it.

    How are customer service and technical support?

    Technical support is okay. On a scale from one to ten, I would give them an eight. They could do better, however, we are mostly happy with their level of support.

    How was the initial setup?

    The initial setup is not complex at all. It's quite straightforward. If a company implements this solution, they shouldn't have any issues with the setup process at the outset.

    How long it takes to deploy depends on the size of the environment and the company. If it's a small enterprise, it can be done basically in a week or so. It's all about not just the department, however. It's all about collecting the log sources to integrate into it. That is where the process takes time. If the log sources are put together, things become much easier to handle. It's quicker and easier to define the rules, correlations, and reporting. The most time spent at the outset is in collecting the log sources and getting the log sources to send the data to.

    The deployment process doesn't need many people. It depends on the deployment structure at first. If it treats a distributed architecture, of course, you need a couple of guys to be on board. However, then it's not only about deploying the solution, it's all about integrating the solution with different products or different platforms. That is where the time goes in. It's not a one-person job. Right from the application database, metro securities, and different controls that are in place, they all need to be integrated into the center. If we're talking about an enterprise, the team in an enterprise is equally responsible for waiting for those things to integrate.

    What's my experience with pricing, setup cost, and licensing?

    The NEMA licensing structure is very easy. It's far better than the previous licensing structure they had. They charge you based on the number of events per second and flows per second, and that's the beauty of it. The rest of the components are complimentary. That's it. It's not a complex process of licensing anymore. It's very simple and straightforward.

    What other advice do I have?

    We are resleers of QRadar.

    In general, we have been quite happy with the solution. I would rate it nine out of ten.

    We get excellent visibility in every aspect. It's easy to handle incidents when you really have everything in one place. You begin to know exactly what's happening on a network, and how the systems are performing and behaving.

    When you compare it to other products, what I would advise is you look at how long they have been in business. This product has been in business for a very long time. You also need to look at the other integration factors, such as forensic, as they're very important. When it comes to forensic, nobody does better than what IBM Qradar Forensic does. There are other factors too - like its Watson integration, and all those things really play an equally important role.

    It's not only about just the SIM, or your goals towards is going to be in building the SOC, Security Operation Center. It's all about automation as well. The integration should also look into automation capabilities. That way, you will be able to scale it up to build up a proper SOC.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
    PeerSpot user
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2026
    Buyer's Guide
    Download our free IBM Security QRadar Report and get advice and tips from experienced pros sharing their opinions.