We use this solution both in our company and those of our clients. We are resellers of QRadar.
CEO at a tech services company with 11-50 employees
Very powerful with plenty of features and capabilities
Pros and Cons
- "The product has plenty of features and capabilities."
- "The usability of interfaces could be improved."
What is our primary use case?
What is most valuable?
Curator is the leader of teams in the market. It's a product with plenty of features and capabilities. It's a very powerful solution.
What needs improvement?
The usability of interfaces could be improved and the solution could have better correlation services, as well as faster and updated intelligence interfaces.
For how long have I used the solution?
I've been using this solution for five years.
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Technical support has room for improvement.
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are reasonable.
What other advice do I have?
I rate the solution nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer.

Solution Security Architect at PT. Sinergy Informasi Pratama
Provides great analysis of event logs, event security; easily manageable with one monitor
Pros and Cons
- "It can analyze event logs, event security, and give a good consult."
- "Solution has too many menus that require going to two or three sub-monitors to enter the QRadar."
What is our primary use case?
This is a solution you use when you have many security products that you want to manage in one monitor, one analytic. We are partners with IBM and provide implementation services to our customers. I'm a solution security architect.
What is most valuable?
The most valuable feature is that it can analyze event logs, event security, and give a good consult. When you have SIEM, you can easily manage with one single monitor. QRadar can do a lot of analyses of every security product and will let us know what needs to be done to the log. Sometimes we need security orchestration automated response to support the SOC team.
What needs improvement?
The concern with QRadar is that there are so many features in the dashboard, too many menus that require going to two or three sub-monitors to enter the QRadar. The user interface is good but there are so many features that can be confusing for the administrator. It could be simplified.
For how long have I used the solution?
I've been using this solution for a year.
What do I think about the stability of the solution?
I think that QRadar is stable, but I've never worked with other solutions in this area and I have nothing to compare it to. It has dedicated machines and offers great performance.
What do I think about the scalability of the solution?
The scalability is easy but it comes at a high price.
How are customer service and support?
IBM in Indonesia provides great support.
How was the initial setup?
The initial setup is complex if the data set is large. It really depends on that. We provide maintenance services to our clients so that if they have any trouble, we assist with troubleshooting.
What's my experience with pricing, setup cost, and licensing?
SIEM is quite a pricey solution so we only offer it to enterprise companies that can pay the fees. For smaller companies, it's an extremely expensive product.
What other advice do I have?
I recommend this solution because I think they provide great support from the sales and technical perspective.
I rate the solution nine out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Assistant IT Manager at a insurance company with 1,001-5,000 employees
A SIEM solution that's easy to use, but the price could be better
Pros and Cons
- "I like that it's easy to use and the performance is good."
- "It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation."
What is our primary use case?
I use QRadar for cybersecurity defense, operation, and to improve performances.
What is most valuable?
I like that it's easy to use and the performance is good.
What needs improvement?
It would be better if it were more stable and more secure. The price for maintenance could be better. It's too high. In the next release, I think they should focus on the price and the operation.
For how long have I used the solution?
I have been using IBM QRadar for four years.
What do I think about the stability of the solution?
IBM QRadar is a stable solution, but it could be more stable.
What do I think about the scalability of the solution?
IBM QRadar is a scalable solution. We have about 100 users at the moment.
How are customer service and technical support?
I remember that I opened ten or 20 cases to receive support from IBM over three years.
How was the initial setup?
The initial setup and deployment are very easy. I think it took us about a month to implement this solution. We have a team of two, one manager and one technical, to deploy, manage, and maintain this solution.
What about the implementation team?
We installed this solution with the help of a consultant.
What's my experience with pricing, setup cost, and licensing?
The price could be better. I bought a subscription for three years.
What other advice do I have?
On a scale from one to ten, I would give IBM QRadar a seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a tech services company with 201-500 employees
Excellent network monitoring but needs better compatibility
Pros and Cons
- "The feature that I have found most valuable is how it monitors the real network. That is its leading security feature."
- "The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good."
What is our primary use case?
Our primary use case is for monitoring global infrastructure.
What is most valuable?
The feature that I have found most valuable is how it monitors the real network. That is its leading security feature.
What needs improvement?
In terms of what could be improved, I'd say do nothing, in its current state it does quite okay for now.
The biggest problem was built on top of the QRadar in the executive operations center network. The integration was not using the network security specialist properly, and all the incidents were inferior with QRadar. Its compatibility is not really good
For how long have I used the solution?
I have been using IBM QRadar for more than five years.
I'm using the latest version of QRadar.
What do I think about the stability of the solution?
The stability is very good. Its operation is very good.
What do I think about the scalability of the solution?
We have less than five people using it.
For us, as a small security company, it is covering our needs and our growth.
How are customer service and technical support?
Customer support is good. When an incident gets raised there is a 10 day response.
How was the initial setup?
The initial setup was complex.
What about the implementation team?
We use the vendor for everything. That is the style of the corporation. For these jobs the responsibility and knowledge is on the vendor's side.
What's my experience with pricing, setup cost, and licensing?
Implementation is over time and the maintenance price for QRadar is competitive.
What other advice do I have?
On a scale of one to ten, I would give IBM QRadar a seven.
Overall, I would of course recommend this product to others because of all its functionalities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Management Executive at a security firm with 11-50 employees
User-friendly, easy to deploy with proper training and offers good coverage
Pros and Cons
- "What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value."
- "The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue."
What is our primary use case?
We primarily use the solution for breach management. We use it for identifying rogue IPs and picking up anomalies in terms of the network traffic coming in. We've seen a year of use cases in terms of breach management and incident management. We find IBM QRadar quite relevant in terms of protecting against potential malicious traffic coming into your organization.
Obviously, it is evolved, and where we're utilizing IBM QRadar is to do other analytical capabilities, which include identity and access management. We've got a unique way where we use the platform to generate a view of all your identities and access that is granted within your environment and so forth. We are able to map that using IBM QRadar, which is not a use case that is normally thought about, however, we found from an analytical point of view, this is what we can do because we get all the information we need here.
What is most valuable?
IBM QRadar is phenomenal as a SIEM SOC solution. In terms of its capability, in terms of its usability, in terms of the SOC solutions or SIEM solutions out there, we find QRadar the most user-friendly.
It gives you the right coverage as the analytical platform that's coupled with Watson is phenomenal.
From a deployment perspective, we found it very, very good.
What we like about QRadar and the models that IBM has, is it can go from a small-to-medium enterprise to a larger organization, and it gives you the same value.
It's easy to use if you go through the proper training. We find that the current IBM team in South Africa is not as good as the teams abroad, however, if you get the right support and the right training, which we have got, we find it very, very, very customizable and user-friendly.
What we have done is we do not use a lot of level-one analysts. We use a lot of developers, so we constantly evolve the rule-set. Most of the organizations that have employed QRadar, what they do is they stack it up with level-one and level-two analysts, as opposed to having more security developers who enhance the rule-set, due to the fact that all of the same technologies work on rule-sets. If you can dynamically change the rule-set on the fly, you're good. We have got a different model in terms of the way we operate a SOC, where we have more developers amending the rules, you will lessen the number of false positives that you encounter. The biggest problem with most of the SIEM technologies out there is that you get too many false positives, and again, it impacts your operational SOC. We don't have that issue here.
What needs improvement?
The only challenge with products like IBM is the EPS. You just have to be really on the events per second, as that's where the cost factor becomes a huge issue.
You do need proper training. Better training leads to better implementation. South Africa does not have the most knowledgeable technical support team. One challenge that you have in South Africa is the quality of the IBM resources. They're not up to the level companies need. I have to criticize IBM on that point - the skill level in South Africa and the South African franchise of IBM doesn't necessarily meet the quality of the product.
They can improve on the architecture. It's the way you deploy it. It's your enterprise architecture team that needs to understand it well. Again, due to our unique skillset on it, we deploy it in a very different way where we reduce the consumption of events per second, which reduces the overall cost of it. However, with the architecture, you need to get better guidance from IBM in terms of the way which the architecture is done.
What I will say about IBM is that if you deploy it stock standard, it can be a very expensive tool, especially with your events per second, and where the way you deploy it architecturally will determine how much it costs you to manage it, as your events per second can be reduced through proper architecture. It's critical to an IBM install that a user understands the architecture and the deployment strategy.
For how long have I used the solution?
I've been dealing with the solution for a very long time. It's likely been about six years or so at this point. I've used it for a while.
What do I think about the scalability of the solution?
We've got three customers on the solution currently.
How are customer service and technical support?
Technical support is lacking in South Africa and it doesn't meet the quality of the product. We're not quite satisfied with the level of service of knowledgeability on offer here.
They need to be faster and more knowledgeable. If you log a ticket to South Africa, they can be quicker and more knowledgeable about issues. It's a problem within South Africa where the skill level of the IBM local team is not to the level it should be. Whether it's training or support, there's a problem. It's not the greatest.
How was the initial setup?
The initial setup can be difficult if you don't have a good understanding of the product, for us, it's not too difficult.
To do a small deployment takes us about two weeks.
When we did the deployment for one of our clients recently it took us four engineers from our side and four engineers from the outside to deploy it within two weeks.
What about the implementation team?
We handle deployments for our clients. Occasionally we need outside assistance.
What was our ROI?
From a return on investment, the client sees in terms of its value from an IBM perspective, is a massive value from the deployment of QRadar.
What's my experience with pricing, setup cost, and licensing?
On-premises is pretty expensive as opposed to the cloud.
You do need to pay for a year subscription. You are charged at events per second as well.
What other advice do I have?
On QRadar, we look at the cloud-based uses as opposed to on-premise due to the cost factor.
In terms of SIEM technologies, in terms of what you can get, I would rate it an eight out of ten. The QRadar platform is phenomenal in terms of what it does.
If you want to get the best out of IBM, spend more time on the rules generation and the modification of the rules.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Network Security Engineer at a computer software company with 51-200 employees
Priced well, scalable, but better threat detection needed
Pros and Cons
- "I have found IBM QRadar to be scalable."
- "IBM QRadar could improve the plugins and threat detection."
What is our primary use case?
We are using IBM QRadar for threat protection and management.
What needs improvement?
IBM QRadar could improve the plugins and threat detection.
For how long have I used the solution?
I have been using IBM QRadar for approximately seven years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I have found IBM QRadar to be scalable.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is reasonable.
What other advice do I have?
I rate IBM QRadar a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Analyst at a tech services company with 501-1,000 employees
Easily monitors your environment with good user interface and plug-in integrations
Pros and Cons
- "One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like Scout, Carbon Black, and the rest."
- "I would like the rule creation interface to be much more user-friendly in the next release."
What is our primary use case?
We use IBM QRadar to monitor security logs across the network.
What is most valuable?
One very useful feature is the plug-in offering that allows you to integrate it with other solutions, such as integrating it with plug-ins like ForeScout, Carbon Black, and the rest. Additionally, the ability of the agents to filter using XPath query to filter out the specific events you want to pick from, especially Windows log sources, is also very useful. That goes a long way in managing the EPS of the solution.
What needs improvement?
There are two ways you can pull logs: one way is where you can receive logs or send logs using the agents and previous transformation and the other way is where QRadar logs onto the servers using the admin account and then pulls the logs itself. The functionality that I would love to see with that remote pulling is to have the ability to also select what logs its pulling because when you use MSRPC now to receive loads from your log surface, it basically pulls all the events from that server. So even the noisy events that would overshoot your EPS, would also be pulled. So for particularly active or high servers that generate a whole lot of security events, let's say like your SFTP server that has a lot of devices on your network connecting to it, if you try to pull the logs remotely it would overshoot your EPS really quickly.
So if they could improve the functionality of the remote pull to also be able to select the logs that it is pulling from the log sources, that would be very, very effective. The reason for the pull is because the agents are not tamper-proof and any administrator can help shut down the service and uninstall the application and a whole lot of other things. Basically, your listening agent is at the mercy of the administrators, and for a security device or security software, that is a big vulnerability, because anybody can then go into the server, stop the agent, and then run any command or make any change they want to do, which would make your monitoring null and void. It would be good if the agent itself could be tamper-proof. And back to the first point, the reason why I prefer the remote pull is if there's no agent on the server and it's the console logging onto the server, your monitoring is much more secure. Regardless of what changes are being made on the server or what's going on the server, if the server is shut down and then a newer version is brought up with the same hostname and IP address, you would not need to go back in and re-install the agent. The console would just automatically connect back to that server once the IP address and the host are back up.
Additionally, I would like the rule creation interface to be much more user-friendly in the next release.
For how long have I used the solution?
I have been using IBM QRadar every day for the last 12 months.
What do I think about the stability of the solution?
In terms of stability, it is very stable. In the almost two years in the environment, there has been only one issue. It was a disc failure and that was replaced within a week by the OEM.
What do I think about the scalability of the solution?
Scalability might be an issue, but maybe it's because in our environment we do not use the application host. Since we use on-premise appliances we did notice that performance degraded a little when we added some plugins. So the recommendation was that we should have a separate application server that would host the application and then interface with the plugins and interface with the management console. But we do not have that within our environment so I can't speak to whether that would improve performance.
How are customer service and technical support?
IBM tech support has been responsive.
How was the initial setup?
I believe the initial setup was straightforward but I was not here for the setup, although I did not get any complaints.
What's my experience with pricing, setup cost, and licensing?
The license is a yearly one.
What other advice do I have?
I would recommend IBM QRadar. The user interface is really great and it simplifies the task of monitoring your environment.
On a scale of one to ten, I would give IBM QRadar an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber threat Intelligence Manager at CyberLab Africa
Beneficial log reporting, excellent technical support, but stability needs improvement
Pros and Cons
- "The most valuable features are log monitoring, easy-to-fix issues, and problem-solving."
- "There is a shortage of skilled individuals with knowledge about the solution. There is training required."
What is our primary use case?
We use IBM QRadar for threat protection.
What is most valuable?
The most valuable features are log monitoring, easy-to-fix issues, and problem-solving.
What needs improvement?
There is a shortage of skilled individuals with knowledge about the solution. There should be more training programs to teach and enable users get familiar.
For how long have I used the solution?
I have been using this solution for approximately one year.
What do I think about the stability of the solution?
The stability of the solution could improve.
What do I think about the scalability of the solution?
We have approximately 20 people using this solution in my organization.
How are customer service and technical support?
The technical support is great. Additionally, there are plenty of resources available to increase knowledge about the solution.
Which solution did I use previously and why did I switch?
We have used other solutions in the past.
How was the initial setup?
The installation is not very difficult, I did not have any problems.
What about the implementation team?
We used consultants for the implementation. We have five engineers that do the maintenance of this solution.
What's my experience with pricing, setup cost, and licensing?
There is a license required for this solution.
What other advice do I have?
I would recommend this solution to others.
I rate IBM QRadar a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Splunk Enterprise Security
Microsoft Sentinel
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Grafana Loki
Trellix Endpoint Security Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?