Our primary use case is to get logs mainly from firewalls, although you can also get logs from anything that can forward syslogs. We use it to sort events.
Vulnerability Manager at a tech services company with 51-200 employees
Scanning by the Vulnerability Manager and alert-generation are key features for us
Pros and Cons
- "The most valuable feature is the QRadar Vulnerability Manager which provides vulnerability scans. In addition, I like the way QRadar generates alerts."
- "It would be good if the program allowed certain profiles to only see certain customer information."
What is our primary use case?
How has it helped my organization?
Instead of logging in to multiple devices and checking the logs, QRadar gives us one centralized point for comparing data against each other and rules to make sure that you don't miss anything. It tells you where all the detections happened. It provides easier access and we pick up things way quicker than in the past.
What is most valuable?
The most valuable feature is the QRadar Vulnerability Manager which provides vulnerability scans. In addition, I like the way QRadar generates alerts.
What needs improvement?
It would be good if the program allowed certain profiles to only see certain customer information.
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
If you're running the latest version under recommended specifications, it is very stable thus far.
What do I think about the scalability of the solution?
It's scalable.
How are customer service and support?
The technical support has definitely improved. In 2016-17 it took me about ten hours to get a reply from IBM. It now takes an hour to two hours for them to reply to me.
Which solution did I use previously and why did I switch?
We went with QRadar because it's a more well-known product. I was only using the AlienVault Community Edition, a free version. It wasn't a fully-paid version I was using at the time. IBM QRadar was just the product the company was using.
How was the initial setup?
The setup is straightforward. The last one I did took me about three days. It only takes half an hour to set up QRadar, but getting the other systems to talk with QRadar, to forward syslogs, is what took the additional time, because I didn't have all the login information. If you've got all the relevant information, it shouldn't take you more than a day to set it up.
What's my experience with pricing, setup cost, and licensing?
QRadar is quite expensive. It wouldn't be worth it for a small business unless, through a third-party company, they used it in a software-as-a-service type of arrangement, rather than buying the licenses outright.
There are additional costs beyond the standard licensing fees. For example, there are add-ons like the QRadar Vulnerability Manager.
What other advice do I have?
QRadar, as a product, might be very straightforward, but to fully understand the product you would need to go for the QRadar training. IBM's training for QRadar is very expensive but it really helps you use the product to its full potential. Before I went to the training, I only used about ten percent of its capability. I would recommend going for the training on the product.
In terms of the number of users, it's not users logging in every day and doing stuff on QRadar. It's a handful of people from the team monitoring QRadar. We could be managing, for example, 50 or 70 customers through one dashboard and about ten people would be monitoring it. The users have a specific role.
The amount of staff required for deployment or maintenance depends on the type of update or patch that's being deployed. For deployment of a new patch it, it could take anything from an hour to about ten hours. It depends on the patch, how big the patch is, and if you've gone through a testing phase or not. So there are multiple dependencies on how long it would take. An average, for me, would be three hours to do certain deployments.
Currently it's being used quite widely. The only downfall of this product would be its price. I wouldn't recommend it for a small company. For larger companies I know it's being widely used.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.

Senior Analyst at a tech services company with 201-500 employees
We can add anything to it, as it is a good companion to other tools
Pros and Cons
- "It integrates very easily with other solutions. The solution is flexible. We can add anything to it, as it is a good companion to other tools."
- "It's user-friendly when compared to other products."
- "They should introduce some automation into the product."
- "There was some complexity in the initial setup due to bandwidth issues."
What is our primary use case?
The primary use case is for insurance and product manufacturing. We use it to create rules and Windows firewalls.
How has it helped my organization?
Before implementing this solution, we had no security. After integrating many thing, we received reports letting us know what is compromised.
What is most valuable?
It's user-friendly when compared to other products. New users can easily understand the product.
It integrates very easily with other solutions. The solution is flexible. We can add anything to it, as it is a good companion to other tools.
What needs improvement?
They should introduce some automation into the product.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It has good stability. If there is an issue, we restart the box.
What do I think about the scalability of the solution?
It is easily scalable.
Our team has nine people.
How are customer service and technical support?
The technical support is good.
Which solution did I use previously and why did I switch?
Previously, I was using McAfee Nitro. Comparing with McAfee, QRadar is user-friendly and easy to use.
How was the initial setup?
There was some complexity in the initial setup due to bandwidth issues.
The implementation took two to three days.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
September 2025

Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Senior Information Security Analyst at a financial services firm with 501-1,000 employees
Helps us to discover any threats with their alerts and tracking
Pros and Cons
- "It helps us discover any threats with their alerts and tracking."
- "The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not way straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference."
How has it helped my organization?
It helps us discover any threats with their alerts and tracking.
What is most valuable?
QNI is the most valuable feature.
What needs improvement?
I would like for them to lower the price.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
The system is quite stable, so far we haven't had any problems. Although the initial supply of the appliance was a bit faulty, the processor kept on failing. We were within the warranty so they supplied new ones. After loading logs, the system is very stable and nothing to worry about.
What do I think about the scalability of the solution?
It's very scalable. There are currently five users. We may still onboard more users depending on the requirements and their departmental level.
We do plan to increase usage.
How are customer service and technical support?
Their support is excellent, they are available when we need them. I'm satisfied so far.
How was the initial setup?
The initial setup wasn't exactly straightforward but the vendor who set it up for was helpful. It was very straightforward with their help. The deployment took two months.
We require two admins for maintenance.
What about the implementation team?
We used our own people and the certified IBM vendor for the implementation. We had a very good experience with them.
What's my experience with pricing, setup cost, and licensing?
We do licenses once a year.
Which other solutions did I evaluate?
We also looked at LogRhythm.
What other advice do I have?
I would advise someone considering this solution to write down your use cases and evaluate them with the vendor. Evaluate the best solution based on your use cases because you are the ones who are going to use it. The vendor will try and implement and leave you with your problems.
If the solution meets your requirements and solves most of your problems, you're good to go. QRadar is the best solution we have. The only challenge is that IBM has been a closed enterprise. It should be more open to integrating with other providers at an enterprise level. We're a bank and the core banking system integration is not always straightforward and there is no integration between IBM and these products. If IBM could open up and provide a way of integrating it seamlessly, without charging more for it, that would make a big difference.
I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security and Business Development Manager at a computer software company with 51-200 employees
Enables us to ensure that the data being transferred from one company to another is done securely but it needs better cloud security
Pros and Cons
- "The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two."
- "Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them."
What is our primary use case?
Our primary use case is for the security. We use it to make sure that the data that is being transferred from one company to the other is being done securely.
How has it helped my organization?
The security has improved my organization.
What is most valuable?
The securing of data is the most important feature because nowadays as cloud has come in, it is especially challenging to secure. We are actually planning for Palo Alto to be a better option because IBM needs better security for their cloud.
What needs improvement?
If IBM provides me with a better service or better options than Palo Alto, I would remain with IBM. As for my knowledge, I recently evaluated Palo Alto that has better security features, especially for a client's email.
Before we didn't have any security issues but recently a few of the user emails were hacked. We had to actually recreate their emails for them.
If IBM could give us a complete package of on-cloud solutions, firewall, antivirus, and also mobile security, that would make it a lot better. Nowadays people are using mobile and tablets, rather than laptops or computers.
We get updates from IBM directly but then the users have to update. There are challenges where sometimes if we update the client's system, it takes a lot of time to update.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
Stability is very good. It's better than it used to be.
What do I think about the scalability of the solution?
Scalability is very good.
Everyone has used this solution for security purposes. We use it daily.
How are customer service and technical support?
The support is very good. We get support whenever we need it. Sometimes they respond immediately and sometimes it will be within 24 hours. We can ask them to please do it right away and they can get a request done within an hour or two.
How was the initial setup?
The initial setup is fine. The moment we send the packets for an update it's easy but then there are challenges for the users. We have actually changed the hardware, so it got updated. We have to check if the problems are due to the hardware or due to the software.
The initial setup normally will take a day. it depends on the number of users. We have 300 users on the system which took around ten days.
We require five to ten staff members for deployment and maintenance.
Which other solutions did I evaluate?
Before we went with IBM, we didn't look at other solutions but recently I looked into switching to Palo Alto and also evaluated Fortinet.
What other advice do I have?
I would advise someone considering this solution to evaluate several solutions, compare them, and if there is an option for customization check with the solution provider, and then go for it.
I would rate it a seven out of ten. It's a good solution, we've used it for a long time, but then there are a few issues with security.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cybersecurity Consultant at CIA Botswana
Enables our clients to detect threats and vulnerabilities in real time
Pros and Cons
- "Most of our clients are interested in automation. The automation part is good because they are able to detect threats and vulnerabilities in real time. It's very fast."
- "The API integration for AD is a problem when it comes to vulnerability management. If you want to incorporate multiple factor authentication it becomes a problem with the AD. It doesn't integrate well. That needs to be improved."
What is our primary use case?
Our primary use case if for security analytics. We do investigation and security analytics, so we collect events and after collecting events we give positive security analytics to clients.
How has it helped my organization?
Most of our clients are interested in automation. The automation part is good because they are able to detect threats and vulnerabilities in real time. It's very fast.
What is most valuable?
The vulnerability management aspect is the most valuable feature. IBM QRadar is the only SIEM solution with integrated vulnerability management. That's why most clients are flocking to it. API integration is very easy.
What needs improvement?
The API integration for AD is a problem when it comes to vulnerability management. If you want to incorporate multiple factor authentication it becomes a problem with the AD. It doesn't integrate well. That needs to be improved.
The configuration steps are not easy to follow compared to NetWitness.
What do I think about the scalability of the solution?
Scalability is good. I have plans to increase usage it just depends on the contracts. If I get more contracts I get more people. Most clients want to manage security and so they would want to outsource their expertise. If they outsource their expertise that means I have to recruit more people.
How are customer service and technical support?
Their technical support is pretty good.
How was the initial setup?
The initial setup was easy. It usually takes around three months or so. In terms of the implementation strategy, once we get the correct events sorted, the strategy is to connect enough events sources so that they give you an efficient solution.
We require five to ten people for setup and maintenance.
What about the implementation team?
I'm the consultant so we do the implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
The licensing depends on the customer. The pricing is good.
What other advice do I have?
I would rate it an eight out of ten. Not a ten because the configuration part of it should be easier. They tried to integrate everything together to be all in one, but it's not easy to configure.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
Security Consultant at Varutra Consulting
The product is easy to use, but it needs a comprehensive PDF user guide
Pros and Cons
- "The stability is good."
- "The scalability is good."
- "I would suggest QRadar release any documentation or give an online demo, like videos on YouTube. It would increase publicity and public appeal."
What is our primary use case?
We use it to detect security incidents.
What is most valuable?
- IBM Resilient Incident
- IBM Threat Intelligence
- IBM QRadar is easy to use.
What needs improvement?
The user guide is not readily available. I would suggest the support or technical team release a PDF guide, like Splunk, SolarWinds, or ArcSight. This will be good for consultants or whomever is using QRadar. This would be really helpful. I have searched on a lot on sites, but I have not found a single PDF containing everything. Our consultants are taking too much time understanding the product's technical aspects.
They could arrange a demo on their website so user who register may use WebEx or any type of meeting invitation, and the support team could give a demo. Having hands-on technology is important. We lost a few clients, because they asked us, "Do you have hands-on QRadar?" At that time, we said, "No, but we will cover it." Due to this, we didn't get the project. Clients wants consultants who are certified in QRadar. Even after completing the certification as a QRadar deployment professional, I would suggest QRadar release any documentation or give an online demo, like videos on YouTube. It would increase publicity and public appeal.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
The stability is good.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and technical support?
I haven't contact the technical support yet.
What about the implementation team?
We have a security consultant for our deployments.
We haven't deployed yet, but our client has deployed IBM QRadar. We have been monitoring it, creating rules, and fine tuning it. These are my responsibility with respect to QRadar.
I did not get opportunity or experience to deploy the QRadar into the client's environment.
Which other solutions did I evaluate?
We are recommending IBM QRadar, SolarWinds, and ArcSight to our clients.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Engineer at dig8labs
Custom parsing tool makes customization easy, and UI is friendly
Pros and Cons
- "The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding."
- "The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria."
How has it helped my organization?
The features make my work easier.
What is most valuable?
The most valuable feature is the DSM Editor. The custom parsing tool is very nice, outstanding. I have used McAfee's SIEM and LogRhythm as well, but because of this feature of QRadar, I don't think their solutions are good.
Customizing it is very easy and it has a user-friendly interface.
What needs improvement?
The product is good, but one feature they should have is an Elasticsearch. Currently, in QRadar, there are no Elasticsearch criteria. Elasticsearch is a very fast search engine. IBM should consider it as part of QRadar. Currently, QRadar has a very slow search. If I search previous months' data it stops.
For how long have I used the solution?
More than five years.
What do I think about the scalability of the solution?
The scalability is good. I'm quite satisfied with it.
How are customer service and technical support?
Technical support is the area IBM should work on. Support is not that responsive. If I open a support ticket, it takes three to four days for them to respond. They take that much time.
Which solution did I use previously and why did I switch?
I have used different solutions in the organization, but the main reason for switching is the customization. QRadar very much supports customization. Another reason is that, in the market, we can easily get QRadar resources, like an analyst or engineer, as compared to other products. This is a reason that organizations move towards QRadar.
How was the initial setup?
The initial setup was very straightforward. I didn't have to do anything once I installed it and configured it. It was very simple. Other solutions I have worked on, such as McAfee and LogRhythm, are a bit complex. This one is very easy to install and configure.
The deployment takes one to two months, max. The implementation strategy is totally dependent on the number of EPS, the requirements, and the types of log sources. We collect this information and then create our strategy.
I have been an engineer in many firms. I have deployed it by myself. One expert can deploy it. If there are 100,000 EPS you'll need more resources. If you have 5,000 to 10,000 EPS, one person can do it.
What's my experience with pricing, setup cost, and licensing?
IBM has subscriptions plans that run for one year.
What other advice do I have?
Overall, it's much better than other products.
In terms of increasing its usage, I have suggested to my organization that it tell customers to use it, its capacity and capabilities, with other tools like Watson.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner.
Senior Server Security Engineer at a consultancy with 11-50 employees
Has great scalablity, if you use APS 25 GPS license you can change to 3000 EPS anytime
Pros and Cons
- "IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution."
- "I think QRadar is very complex. It's a distributed system and IBM QRadar has an all-in-one solution which is not like that distributed solution but it's a good product. IBM needs to consider the user interface because if we compare it with AlienVault, the AlienVault user interface is fantastic but the IBM QRadar user interface is very complex. They should focus on how to make it easier for the client."
What is our primary use case?
Our primary use case of this solution is to identify threats.
How has it helped my organization?
We do R&D for IBM QRadar and we are also a cybersecurity solution based company. We provide solutions for our clients like banking, government agencies, and other non-government organizations. Our clients test in our labs and we try to understand how a product works and how a product will help our clients. I have more than three years experience with AlienVault and I use AlienVault a lot and I have already deployed it in a few banks. I am now trying to understand how IBM QRadar works and what the difference between IBM QRadar and AlienVault is.
What is most valuable?
This solution has many valuable features but I especially like the Log Manager feature.
What needs improvement?
I think QRadar is very complex. It's a distributed system and IBM QRadar has an all-in-one solution which is not like that distributed solution but it's a good product. IBM needs to consider the user interface because if we compare it with AlienVault, the AlienVault user interface is fantastic but the IBM QRadar user interface is very complex. They should focus on how to make it easier for the client.
IBM has everything you need in a cybersecurity solution. If you want to build a cybersecurity operation center version then I think QRadar is a perfect solution.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
IBM QRadar is stable and scalable.
What do I think about the scalability of the solution?
Scalability is good. If you use APS 25 GPS license you can change to 3000 EPS anytime. Also, you can integrate a distributed solution with the all-in-one deployment. If you have a very small organization, you don't need model 5000 EPS license so you can deploy all-in-one and then one day if your organization grows bigger, you can deploy a distributed system.
How are customer service and technical support?
We have our own system and network experts, forensic experts, and database expert so until now, we haven't had any issues that required us to contact their support.
How was the initial setup?
The initial setup was complex. When it comes to the deployment, you can get it done in a day but if you want to fine-tune it can take a very long time. This isn't only for QRadar, but this applies to most solutions.
It takes two or three people to deploy this product but if you want to do custom configuration then you need each and every part's expert. You need a network expert, forensic expert, and system expert. If you want an advanced system configuration you need many more people. If you only want to integrate this solution in your organization then two or three people is more than enough for the deployment.
What about the implementation team?
We deploy it for our clients.
What's my experience with pricing, setup cost, and licensing?
Licensing is very expensive, IBM QRadar is a very expensive solution. If you want to minimize costs then IBM QRadar is not for you.
What other advice do I have?
I would rate it an eight out of ten. Not a ten because of the complex interface.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.

Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Fortinet FortiEDR
Dynatrace
Splunk Enterprise Security
Microsoft Sentinel
Darktrace
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Grafana Loki
Trellix Endpoint Security Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?