We use IBM Security QRadar for storage. These tools are setting high tools on the usage of the logs from multiple devices. It manages millions of logs from multiple devices, such as firewalls, routers, switches, etc. The solution is stable and has better support than LogRhythm. It doesn't have multiple components or servers, troubleshooting, or remote servers. It is based on a CentOS platform, and implementation is difficult.
Cyber Security Engineer at Diyar United Company
A security solution to manage logs from multiple devices
Pros and Cons
- "It protect us from multiple authentication values, unauthorized access and antivirus threats."
- "IBM Security QRadar lacks automated response. With this feature, there's no need to visit VirusTotal or other sites for IP reputation. There should be a small plug-in where users can click to retrieve details about the reputation and organization of public IP."
What is our primary use case?
How has it helped my organization?
We make use of the tool to ensure company security. We have the firewall services and switches integrated. We use the solution for attack-related loss, firewall and blacklist IP. There are multiple use cases, like, internal firewalls, internal Windows servers and Internet controllers. It protect us from multiple authentication values, unauthorized access and antivirus threats. We don't open and see the console all the time, so we need automated alert access to all Windows. There's a malware incident and wireless incident. The QRadar has antivirus which detect cache files, etc.
What is most valuable?
IBM Security QRadar is stable. The tool exhibits minimal vulnerabilities and does not encounter multiple issues. It is not easy to operate, it ensures minimal downtime. Its usability, synchronization with systems, user interface, and storage capabilities are crucial. Storage is essential for research and hunting, as it involves delving into logs. The response time of IBM QRadar is commendable, and even when processing large amounts of data, it maintains a consistently high level of performance. The tool utilise RAM efficiently.
What needs improvement?
IBM Security QRadar lacks automated response. With this feature, there's no need to visit VirusTotal or other sites for IP reputation. There should be a small plug-in where users can click to retrieve details about the reputation and organization of public IP.
Buyer's Guide
IBM Security QRadar
June 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
For how long have I used the solution?
I have been using IBM Security QRadar for 4 years. We are using V7.5 of the solution.
What do I think about the stability of the solution?
The solution is stable. It's crucial for maintaining the company's security.
I rate its stability as nine out of ten.
What do I think about the scalability of the solution?
The solution’s scalability is excellent.
25 users are using this solution.
I rate the solution’s scalability a nine out of ten.
How are customer service and support?
IBM provides good support.We have paid licenses, which come with special performance enhancements.
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup is straightforward and can be done within a day. It is based on Linux. If there is any issue, you need to bang your head to solve the issue.
IBM Security QRadar requires a specific server with a minimum of 128 GB RAM and can support up to 2,000 endpoints. The installation process involves obtaining the ISO and setting up the necessary configurations. Once installed, we must ensure the components are properly located and configured.
One person is required for maintenance and deployment each.
I rate the solution's setup as a seven out of ten.
Which other solutions did I evaluate?
We opted for IBM Security QRadar based on its market rating and recommendations from previous alumni who have experience with it at our company. QRadar is a software solution provided by IBM for security purposes.
What other advice do I have?
QRadar supports connectivity with a 2800 vendors, including Cisco and Fortinet FortiGate. These integrations encompass various platforms such as VMs, Linux distributions like Red Hat and CentOS, and Symantec and Microsoft Windows for CRM databases and other server functionalities. Cloud technologies such as Office 365 are also supported.
The tool is flexible and I recommend it.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy Director at Board Of Revenue
Saves time and enhances our detection and response capabilities
Pros and Cons
- "IBM Security QRadar has significantly improved our incident response procedures."
- "There is room for improvement in IBM QRadar in integrating features for SOC maturity and security levels directly into QRadar."
What is our primary use case?
As a security professional, I rely on IBM Security QRadar for a variety of use cases tailored to our security needs. With over 200 implemented, these range from real-time threat detection and incident response to compliance reporting and user behavior analytics.
What is most valuable?
IBM Security QRadar has significantly improved our incident response procedures. We have implemented a structured plan within the system, ensuring adherence and minimizing human error.
What needs improvement?
There is room for improvement in IBM QRadar in integrating features for SOC maturity and security levels directly into QRadar. That would enhance its effectiveness. Additionally, incorporating features for assessing and improving SOC maturity within QRadar itself would be beneficial, eliminating the need to rely on separate tools for this purpose.
For how long have I used the solution?
I have been working with IBM Security QRadar for over two years.
What do I think about the stability of the solution?
We have not had any stability issues with QRadar.
What do I think about the scalability of the solution?
IBM QRadar is scalable to meet the growing needs of our business. As our network expands with additional devices and log sources, QRadar can easily accommodate them. We can also create specific use cases tailored to the nature of each log source.
How was the initial setup?
Our experience with the initial setup of QRadar was smooth because we opted for a managed security solution through our service providers. The installation itself took about one to two hours but integrating various sources, creating use cases, fine-tuning, and enabling logs could take up to two to three months. However, in our enterprise network deployment, we managed to accomplish it within six months.
What was our ROI?
Implementing IBM QRadar is similar to investing in insurance for our organization's security. While the return on investment may not be immediately tangible, it is crucial for mitigating potential disasters and ensuring our organization's resilience against security threats in the long run.
What's my experience with pricing, setup cost, and licensing?
Overall, I'm satisfied with the value IBM QRadar provides for its price. However, there is room for improvement in terms of including more features with the base license instead of requiring additional licensing fees for each feature or application.
What other advice do I have?
We chose to work with IBM QRadar mainly because it was widely deployed in our country, Pakistan, with no significant presence of alternatives like Splunk or LogRhythm.
IBM Security QRadar has enhanced our threat detection and management processes by providing comprehensive visibility into network traffic and events. With QRadar, we have end-to-end visibility across our network, enabling us to monitor traffic from origin to destination and analyze all relevant logs and events.
IBM Security QRadar stands out with features like advanced analytics and customizable dashboards, making it effective for our security needs. While it shares common features with other SIEM solutions, these unique capabilities have been instrumental in improving our security.
Integration capabilities play a crucial role in enhancing the overall security posture of IBM QRadar. By integrating with various tools like Active Directory, privilege access management, firewalls, and email security appliances, QRadar aggregates logs from different sources. It then utilizes machine learning, artificial intelligence, and custom rules to analyze this data, helping our security operations center make informed decisions and respond effectively to potential threats.
Overall, I would rate IBM QRadar as a seven out of ten. It is a great tool but operating IBM QRadar requires a higher level of technical expertise.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
IBM Security QRadar
June 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,838 professionals have used our research since 2012.
Information Security Engineer at Glasshouse Systems
A highly stable and scalable solution that provides good technical support
Pros and Cons
- "The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability."
- "IBM Security QRadar’s GUI could be improved."
What is our primary use case?
I've got use cases where we monitor positive controls wherein something doesn't allow something to happen. It alarms when somebody changes the control.
What is most valuable?
The most valuable features of IBM Security QRadar are flexibility, IBM support, and scalability.
What needs improvement?
IBM Security QRadar’s GUI could be improved.
For how long have I used the solution?
I have been using IBM Security QRadar for 12 years.
What do I think about the stability of the solution?
I rate IBM Security QRadar ten out of ten for stability.
What do I think about the scalability of the solution?
Around five to ten users are using the solution in our organization.
I rate IBM Security QRadar ten out of ten for scalability.
How was the initial setup?
The solution's initial setup is pretty difficult. I rate IBM Security QRadar a four or five out of ten for the ease of its initial setup.
What about the implementation team?
Based on the size and the number of use cases, the solution's deployment can take three or four days to a few months.
What's my experience with pricing, setup cost, and licensing?
IBM Security QRadar is about 50% less expensive than Splunk. SIEM solutions charge by the amount of data, whether EPS or gigabytes. They directly incentivize you not to put things in it, which doesn't make sense since the goal is to put everything in it. They'd make it where you can't afford to do it.
On a scale from one to ten, where one is cheap and ten is expensive, I rate IBM Security QRadar's pricing a five out of ten.
What other advice do I have?
Overall, I rate IBM Security QRadar a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner/customer
Analyst at a hospitality company with 10,001+ employees
Has real-time detection feature but is not as flexible as Splunk
Pros and Cons
- "The tool's most valuable feature is real-time detection."
- "The solution is not as flexible as Splunk."
What is our primary use case?
We use the product to customize rules and detect malicious behavior.
What is most valuable?
The tool's most valuable feature is real-time detection.
What needs improvement?
The solution is not as flexible as Splunk.
For how long have I used the solution?
I have been working with the product since 2016.
How are customer service and support?
I haven't contacted technical support yet.
Which solution did I use previously and why did I switch?
I worked with Splunk before IBM Security QRadar.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing is based on the EPS model.
What other advice do I have?
I prefer Splunk since it gives a lot more freedom and flexibility. I rate the overall solution a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architectv at Smarttech247
Useful for threat hunting, investigation, and triage analysis
Pros and Cons
- "The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons."
- "Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances."
What is our primary use case?
We utilize the product for our Security Operations Center operations. Additionally, we extend its use to our customers, employing it for tasks such as threat hunting, investigation, and triage analysis.
What is most valuable?
The tool's most valuable feature is log source management. It enables us to connect to various log sources, including content, authentications, or other customized integrations. These integrations can be tailored for use with other platforms that don’t already have built-in IBM add-ons.
Its scalability is also important. It is also compatible with ISO 27001, DSS API, and various certifications.
As part of our security infrastructure, this tool excels in detecting a wide range of attacks. Its responsiveness surpasses that of alternative solutions. Moreover, the user-friendly interface greatly benefits our analysts. The product is helpful in anomaly detection scenarios.
Additionally, we leverage out-of-the-box content and libraries within the IBM ecosystem. Its user behavior analysis helps us to ensure that our customers are protected.
Correlation plays a pivotal role in our security strategy. It helps us to analyze logs from different sources. This process helps to correlate logs from endpoints.
What needs improvement?
Certain updates—especially when using Azure—don't apply directly. Our engineering team must invest additional effort to implement these updates. However, the tool's cloud-based version poses no issues. However, upgrading the product can sometimes be challenging for on-premises instances.
Our current query language (KQL) serves its purpose, but there's room for improvement. Consider introducing a more human-friendly language to streamline analyst training. Analysts could then express queries in a manner akin to human language. This change would expedite processes, making it easier for new analysts to adapt.
For how long have I used the solution?
I have been working with the product for five years.
What do I think about the scalability of the solution?
I rate the tool's scalability an eight to nine out of ten.
How are customer service and support?
Troubleshooting delays have been a recurring challenge. Occasionally, responses take two to three days, leading to escalations. While their website’s knowledge base is commendable, troubleshooting scenarios demand more time. My observation is that they may be understaffed.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
My company has customers using Splunk and Chronicle SIEM. When comparing Splunk and IBM Security QRadar, they indeed offer similar features, but their business models differ. Chronicle SIEM predominantly operates in the cloud. However, we cannot offer the cloud model if a customer prefers an on-premises solution.
Splunk and IBM Security QRadar both cater to diverse deployment preferences. Splunk boasts a slightly more robust correlation engine than IBM Security QRadar. Splunk tends to be marginally more expensive than IBM Security QRadar.
How was the initial setup?
The number of log sources significantly impacts deployment complexity. The process becomes more complicated for environments with 50 log sources compared to those with fewer sources (e.g., 20 or 10).
Each log source requires a connection to IBM, a task that can take several days or hours, depending on its complexity.
On average, the entire deployment process spans six to eight weeks.
What's my experience with pricing, setup cost, and licensing?
The tool's on-premise version is expensive. However, it is cheaper than Splunk. The hybrid model offers shared instances for customers, which is not expensive. Customers with a limited budget can opt for it. You can get premium support with licenses. However, if you need customized integration, you need to buy it.
What other advice do I have?
I rate the overall product an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Director of Incident Response at a retailer with 10,001+ employees
Robust and reliable but needs some fine-tuning
Pros and Cons
- "It'll get you from point A to B."
- "I equate QRadar to a robust solution."
- "There should be more opportunity for community kind of distribution where, for example, if there was a zero-day threat targeting companies."
- "Out of the box, it's just not one of those things that I leverage as a single source of truth regarding the user behavior analytics aspect of it."
What is our primary use case?
The UBA component is something that is there. However, it's something that honestly hasn't been leveraged as much. It's probably not a UBA feature like the ones we’ve used in the past. In any case, the UBA feature is there. You can look at the users and look at any risky activity or use cases. I tend to look at it. However, it's not my main source in terms of leveraging it as a UBA.
What is most valuable?
I equate QRadar to a robust solution. You get all the live sources. If you have someone there fine-tuning the solution and creating rules for the team to ensure the fence is alert. It's a robust solution.
In the past, I've heard the term that it's like a Cadillac, a trusted Cadillac. It'll get you from point A to B. It does what integration is supposed to do.
What needs improvement?
It needs a little bit perhaps more fine-tuning on the SIM aspect of it. Out of the box, it's just not one of those things that I leverage as a single source of truth regarding the user behavior analytics aspect of it.
With QRadar, IBM has had ample time to innovate, make changes to the interface, and keep up with some of the competitors. Yet, IBM delays innovating QRadar, since, once people are tied into it, they stick to the SIM as that's what they're used to. Right now, you have many other players in the market, like Datadog, Sumo Logic, and Splunk. Splunk has a ton of connectors as well, which is making it more appealing for other people to look at other solutions, especially when they're trying to look at a cloud-native solution.
There should be more opportunity for community kind of distribution where, for example, if there was a zero-day threat targeting companies. I know that many other solutions now provide ease of use in terms of sharing rules and for identifying and tracking some of these zero-day vulnerabilities out there. Radar needs to do the same.
For how long have I used the solution?
I’ve been using the solution for about four years or so.
What do I think about the stability of the solution?
The stability's great. The solution is robust. It's trusted. Depending on how you have it deployed if it's a standalone appliance or it's high availability paired so that you have redundancy, the solution is reliable.
What do I think about the scalability of the solution?
Anywhere from 25 to 50 users are using it. The primary users are security operations. However, then you do have some folks on the infrastructure side that also leverage QRadar. It wasn't always the case. That said, once we provided access to the infrastructure team, they enjoy using QRadar for looking at logs, and troubleshooting. That would involve the networking team and the server team. They also leverage it as well.
How are customer service and support?
Overall, the IBM team is responsive in regards to ticketing. Obviously, you have to create a ticket with IBM and they will get someone to get on a WebEx with you within a reasonable amount of time depending on the urgency.
They will help resolve issues and create cases. The support is there in terms of having any issues or QRadar is generating errors. Support will guide you and record the session and help remove any issues or obstacles that you have, so I definitely would rate them high on the support aspect of it.
How was the initial setup?
I didn't set it up. Probably part of the engineering team set it up.
What's my experience with pricing, setup cost, and licensing?
I do not know the exact cost. It's a bit tricky as some of it is tied into pre-contracts that we have. Some parts of the company do prepaid funds for certain solutions. It's different. It varies.
What other advice do I have?
While I use QRadar, I'm in a managerial role, so I'm not living in it every single day as my team members are.
Every situation is different. I know a lot of organizations or a lot of C-suite executives all go to the same kind of conferences each year. Then they all come back singing the same song: "We all have to go to the Cloud."
I’d rate the solution six out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head of Cyber security analysis at DNV Poland Sp. z o.o.
It has good support and works with Linux platforms
Pros and Cons
- "It's hard for me to pinpoint any one feature that's most valuable because it is all about consuming logs and analyzing them. We started using QRadar UBA because we needed something that could analyze Linux authentication information. Other products take care of the Windows platform."
- "IBM technical support is excellent."
- "I don't give it a 10 because it is something we have to request. I would love it if UBA was included out of the box like Microsoft."
What is our primary use case?
We analyze all our authentication traffic in QRadar UBA using the solution's AI module to detect and understand uncommon authentication patterns. There is also the rule logic, but we don't use that much. Instead, we mostly rely on AI to do that. In that respect, I wouldn't say we are using the product to the fullest extent because we only have the AI and what the CM is providing. We have a suite of security products, and QRadar UBA is only one source of information that we rely on.
QRadar UBA collects information on 16,000 employees in the company, including when they log in and out or when they launch applications. We have a team of 10 security analysts who go into the solution to check the alarms. IBM has set the solution up so that we only need to react to the alarms. The UBA will flag it if someone does something weird, and our security team will investigate the anomaly to see if that was valid or malicious.
We are currently on QRoC — short for QRadar for Cloud — so it's the latest and greatest solution. It was originally on a private cloud, but we moved to the public cloud three years ago.
What is most valuable?
It's hard for me to pinpoint any one feature that's most valuable because it is all about consuming logs and analyzing them. We started using QRadar UBA because we needed something that could analyze Linux authentication information. Other products take care of the Windows platform.
What needs improvement?
Better algorithms or AI would always be appreciated, but this product does what it's supposed to do. And maybe there is something behind the scenes that could be improved, but I don't know.
UBA is a plugin for QRadar SIEM. If we're talking about the SIEM solution as a whole, there is a lot I can talk about, but there isn't much to say about UBA as a standalone. I'm not in a position to criticize or comment on the underlying code.
For how long have I used the solution?
I have been using QRadar UBA for six years.
What do I think about the scalability of the solution?
I haven't had any problems. We have never needed to add more memory or CPU.
How are customer service and support?
IBM technical support is excellent. 10 out of 10. IBM is highly professional when it comes to security support. IBM's support for other types of solutions isn't quite as good, but the security domain is a different world. I've worked with IBM in other areas, and it's different. Security support is on a tier by itself inside IBM.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are also using a Microsoft solution called Azure Advanced Threat Protection. It provides similar UBA features but only for a Microsoft environment. Most UBA products do exactly the same thing. I haven't tried many other solutions besides QRadar, Microsoft, and Splunk.
Splunk is brilliant. It does the same thing, but it's slightly more expensive, so we selected IBM. Microsoft's solution is a little cheaper, but it lacks Linux support currently. There are minor differences, but we went with IBM in this case because it has the best support.
How was the initial setup?
IBM did the setup. I called them to ask for UBA, and it was available the next day. They handled all the deployment and maintenance.
What about the implementation team?
What was our ROI?
I have not calculated ROI for this product. QRadar UBA is a tiny part of the entire security portfolio. In the context of the SIEM as a whole, the cost is so low that it's hard to defend not doing it.
What's my experience with pricing, setup cost, and licensing?
I have no idea what QRadar UBA costs as a standalone solution because it is bundled with the QRoC security operation center and several other modules that we pay for in a big lump sum. However, I don't think that part is too expensive. It's a plugin to the QRadar SIEM that feeds off the same data. We have X-Force Threat Exchange, so IBM is operating the SIEM for us. I say to them, "I want UBA," and there it is.
What other advice do I have?
I rate QRadar UBA eight out of 10. It's a small product doing exactly what it's supposed to do as an integrated part of our SIEM. It looks good and works well. I don't give it a 10 because it is something we have to request. I would love it if UBA was included out of the box like Microsoft.
Regardless of which solution you use, I recommend user behavior analytics. It provides valuable information to the security team. It doesn't matter whether you use Splunk or Microsoft— you should use a UBA solution.
We will probably stick with QRadar for the foreseeable future. It depends on the developments in the SIEM market. We will probably continue with IBM because changing SIEM is not something you do lightly. As long as we keep the IBM SIEM, we will continue to use QRadar UBA.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cybersecurity at a computer software company with 51-200 employees
A highly scalable and stable tool with a responsive support team
Pros and Cons
- "Stability-wise, I rate the solution a ten out of ten."
- "The price of IBM Security QRadar is an area of concern where improvements are required."
What is our primary use case?
I use IBM Security QRadar in my company as it provides features like SIEM, SOAR, and QNI.
What is most valuable?
The most valuable feature of IBM Security QRadar stems from the fact that it is a product that is like a complete suite.
What needs improvement?
The price of IBM Security QRadar is an area of concern where improvements are required. IBM is never known to provide products at a cheap price.
IBM Security QRadar's UI is an area with certain shortcomings where improvements are needed.
In the future, I would like IBM Security QRadar to have a library of adapters or APIs.
The area around recovery time is an aspect of IBM's technical support where improvements are required.
For how long have I used the solution?
I have been using IBM Security QRadar for more than a year. I use the solution's latest version. My company is in the process of being declared as a golden partner of IBM.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. Scalability-wise, I rate the solution a ten out of ten.
My company currently deals with around four to five organizations comprising medium to large companies where IBM Security QRadar is used.
How are customer service and support?
The solution's technical support is responsive. The only area where I don't agree with IBM Security QRadar's technical support stems from the lack of proper or defined recovery time, even though their response time is good.
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have experience with Splunk. My company deals with Splunk since we had no choice owing to the fact that one or two customers wanted it.
In the past, I was using open-source products, including solutions like Elastic Security and Wazuh.
My company decided to switch from Wazuh to IBM Security QRadar.
How was the initial setup?
The product's deployment phase can be described as an average one.
I rate the deployment process of IBM Security QRadar a seven on a scale of one to ten, where one is difficult, and ten is easy.
The solution is deployed on an on-premises model.
What's my experience with pricing, setup cost, and licensing?
On a scale of one to ten, I rate the price a one, where one is an extremely expensive product, and ten is a cheap product. IBM Security QRadar is an expensive product. A customer gets discounts only when they ask for them from IBM.
The challenge is that if someone submits a request or proposal and finds that the prices of the products our company deals with are too high, we may not even be shortlisted for negotiations. If my company gets shortlisted for the next round, then we get questioned over the high prices.
What other advice do I have?
My company takes care of the maintenance part of the solution for our clients who use IBM Security QRadar in their environments. Nine engineers and one manager take care of the maintenance process of IBM Security QRadar. My company has a lot of certified employees to take care of IBM Security QRadar's maintenance. My company can be considered a powerhouse when it comes to products from IBM.
I recommend the solution to those who plan to use it.
Splunk and IBM are leaders as per Gartner Magic Quadrant. I believe that IBM Security QRadar should be fairly priced for SMEs.
I rate the overall tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
IT Security Administrator at Zitouna Bank
A scalable tool useful for authentication purposes but needs to provide more product training to its users
Pros and Cons
- "It is a scalable solution."
- "With IBM Security QRadar, my company faced issues with the support we received for the product."
What is our primary use case?
I use IBM Security QRadar in my company for authentication of users and to block the access of a user to the internet. In my company, we have only used the basic version of the solution, and currently, we don't have a license for the product since we didn't renew it. The basic version of the solution fits my company's basic requirements.
What needs improvement?
IBM Security QRadar is not hard to implement and administrate. To serve new use cases or do the tuning and allow correlation rules, you may need training since it is necessary to know the solution. With IBM solutions, you need training to know how to use the different features of the solution. IBM needs to provide training to its users to teach them how to use the case manager and how to tune rules.
For how long have I used the solution?
I have been using IBM Security QRadar since 2020, so I have experience with it for three years. I am a customer of IBM.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
With IBM Security QRadar, my company faced issues with the support we received for the product. Basically, my company faced problems due to the delays or mistakes made by IBM's support team.
I rate the technical support a six out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The solution is deployed on an on-premises model.
For the product's implementation, my company took two months. To implement all log sources, my company took somewhere between three to five months.
What's my experience with pricing, setup cost, and licensing?
IBM Security QRadar is a very expensive tool.
What other advice do I have?
In the future, my company would want the cloud version of the solution and not its on-prem version.
I rate the overall tool a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SOC Manager at ALEXBANK
Highly scalable, excellent learning modules, but would like to see a better user interface
Pros and Cons
- "The most valuable feature is the machine learning module."
- "I would like to see some artificial intelligence and alternative solutions."
What is our primary use case?
Our primary use case is in the banking industry in two banks here in Egypt. We generally are monitoring the user behavior of the employees, For example, working after working hours, and signing into the machines after working hours.
What is most valuable?
The most valuable feature is the machine learning module.
What needs improvement?
I would like to see the interface improved along with the tuning and any adjustments when it comes to maintenance. It is not straightforward. I would also like to see some artificial intelligence and alternative solutions.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for almost five years now.
What do I think about the stability of the solution?
I would give stability an eight on a scale of one to ten.
What do I think about the scalability of the solution?
The scalability is not a problem and we have above three thousand in our organization.
How was the initial setup?
The initial setup is extremely easy and straightforward.
What about the implementation team?
The deployment took around two to three days and we did it ourselves in-house. We simply downloaded the application and went from there following the deployment process.
What was our ROI?
We are seeing a return on investment when it comes to profiling the employees.
What's my experience with pricing, setup cost, and licensing?
The pricing is higher but cheaper than others and there are no additional costs.
Which other solutions did I evaluate?
We looked at ArcSight but the cost is more expensive than IBM. ArcSight did have the artificial intelligence model.
What other advice do I have?
I would recommend tuning it to the maximum before going live. I would rate IBM QRadar User Behavior Analytics a seven on a scale of one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
Splunk Enterprise Security
Dynatrace
SentinelOne Singularity Endpoint
Darktrace
Microsoft Sentinel
Varonis Platform
Elastic Security
Huntress Managed EDR
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?



















