We are mainly using predefined rules on IBM QRadar User Behavior Analytics
Manager at a computer software company with 11-50 employees
Scalable, easy to use, but lacking features and modern user interface
Pros and Cons
- "IBM QRadar User Behavior Analytics's most important feature is its ease of use."
- "IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms."
What is our primary use case?
How has it helped my organization?
When we started using IBM QRadar User Behavior Analytics's add-on or extension, we received more than 17 new use cases. Our organization has benefited from using IBM QRadar User Behavior Analytics.
What is most valuable?
IBM QRadar User Behavior Analytics's most important feature is its ease of use.
What needs improvement?
IBM QRadar User Behavior Analytics could improve machine learning use cases because they are limited and most of the use cases are rule-based. They should develop more use cases, such as in Securonix or Exabeam because they will detect a threat. Using machine learning is mainly on the correlation rules, but if you think about Exabeam or Securonix, they detect using machine learning or machine learning-based algorithms.
Using the interface of IBM QRadar User Behavior Analytics is the same for years, they should redesign the interface to make it more modern. Some historical queries take a long time, they should improve or change their database. There are some missing operators on the correlation side. For example, some before operated.
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
For how long have I used the solution?
I have been using IBM QRadar User Behavior Analytics for approximately three years.
What do I think about the stability of the solution?
IBM QRadar User Behavior Analytics is stable most of the time. However, it works on the client-side which requires a lot of system resources, such as RAM. In some cases, if the work is high, the stability deteriorates, but mainly it is stable.
What do I think about the scalability of the solution?
The scalability of IBM QRadar User Behavior Analytics is good.
We have two people using this solution. We do not have plans to increase usage.
How are customer service and support?
We use a consultancy company for support and are not directly connected to IBM support.
How was the initial setup?
The deployment of IBM QRadar User Behavior Analytics is very easy when compared to other machine learning solutions. The full deployment took approximately three weeks with less than 5,000 EPAs.
What about the implementation team?
We used a consultant that help us deploy and do maintenance for IBM QRadar User Behavior Analytics.
What was our ROI?
I rate the return on investment of IBM QRadar User Behavior Analytics a four out of five.
What's my experience with pricing, setup cost, and licensing?
IBM QRadar User Behavior Analytics is an application framework and you can install many applications without any additional costs.
I rate the price of IBM QRadar User Behavior Analytics a four out of five.
What other advice do I have?
IBM QRadar User Behavior Analytics is a good solution. If there is a big enough budget they might be able to afford the solution since it is expensive. If the conditions are okay, then they should select the solution.
I rate IBM QRadar User Behavior Analytics a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer at a tech services company with 11-50 employees
Incredible capacity for creating machine models; falls short on documentation
Pros and Cons
- "The timeline and machine learning features are great."
- "The solution lacks vendor support."
What is our primary use case?
Our primary use case is logging for any anomalous traffic in terms of access times and deviations when users are in different groups within the AD. When a user deviates from their functionality, it's flagged in the UBA and for VPN traffic. I also use it for geolocation functionality. We are partners of IBM and I'm a system engineer.
What is most valuable?
The timeline and the machine learning features are great at quickly flagging users who have either left the organization or have dormant accounts. The way that the app has transformed over time is quite phenomenal. One of the major improvements is its capacity for creating machine models. It comes with 16 default machine learning models, where it tracks user activity and changes in profiles and authentications. There are various default machine learning models and I'm able to model those to parameters that suit my needs. It's great that I'm able to implement an unlimited number of use cases on the UBA, putting in as many different kinds of logic as I want. It's a big advantage.
What needs improvement?
I'd like to see improved support from the vendor. In addition there are things that are not documented on the IBM site. If you'd like to do something at a high level, the information is not available in the documentation and you have to find it elsewhere.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
The solution has never crashed or failed, it's stable.
What do I think about the scalability of the solution?
We haven't tested scalability and currently have around 100 users. I'm responsible for maintenance.
How are customer service and support?
The customer support is helpful but that's more about it being a good solution.
How was the initial setup?
The initial setup is straightforward, it's just a download and it installs. It's a matter of configuring a few parameters in terms of tweaking the thresholds that you want the app to fire in on. Installing takes a few seconds, but in terms of letting it land so that you can tweak it and tune the various metrics, takes about a week.
What's my experience with pricing, setup cost, and licensing?
This is a free solution which is one of the main reasons we chose it. It's just a matter of getting a license for the curator as a platform.
What other advice do I have?
I recommend this solution and rate it seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
IBM Security QRadar
January 2026
Learn what your peers think about IBM Security QRadar. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Archtect at a financial services firm with 1,001-5,000 employees
Easy to set up and expand but has too many false positives
Pros and Cons
- "The scalability is very good. It's not a problem."
- "I'm not sure about the stability just yet. We've observed a few issues and we raised a supporting ticket for it."
What is most valuable?
To be very frank, it's not that much help as of now. We are not getting that many insights from UVA, which we wanted, actually. As of now, we are exploring that UVA, and we have installed it. It's still quite new.
The initial setup is straightforward.
What needs improvement?
The solution is still new to us. Currently, it's a work in progress with this. I'm not in any particular condition to tell what exact improvements are required. I will let a few more months go by before analyzing the overall UBS solution QRadar to get to know and final understanding of this particular application.
There are a lot of things that require modification. That's my initial observation, however, I need more time and a few more months to get to know it and get a final understanding of the solution as a whole.
I want a reduction of false positives. I want crisp true positive incidents out of it. I want to see proper user behavior. Whatever algorithm is working in the background, that algorithm should produce accurate, true positive incidents and not false positives.
For how long have I used the solution?
We are using QRadar as an appliance for the last four years, however, we recently, for the last six months, started using UBS.
What do I think about the stability of the solution?
I'm not sure about the stability just yet. We've observed a few issues and we raised a supporting ticket for it.
What do I think about the scalability of the solution?
The scalability is very good. It's not a problem.
How are customer service and support?
Technical support has been very supportive. We're largely satisfied with them.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward and simple. It's not very complex.
We are using multiple features in QRadar. UVA is just one feature. We have overall 14 data nodes and we are almost 2,500 GB of data integrated with it and we are using multiple applications in QRadar. We have a nine-member team that manages the overall QRadar architecture, not only UBA.
What about the implementation team?
We did a direct integration.
What's my experience with pricing, setup cost, and licensing?
I'm an architect. Normally costs and licensing are handled by senior management.
For UBA, they haven't asked for any extra charges or anything. It's included in the licensing.
What other advice do I have?
We're an IBM partner. We have platinum support with IBM.
We have segregated our data between on-prem and the cloud. All the on-prem data we have integrated with the QRadar. QRadar itself is an on-prem solution. We have QRadar hardware with us.
At this point, I would not recommend the solution to others.
I'd rate the solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Business General Manager at a tech consulting company with 11-50 employees
Good logging, reporting, support, and integration with GRD
Pros and Cons
- "The most valuable feature is the integration with the GRD, for banking."
- "The advanced planning management (APM) features should be included."
What is our primary use case?
We are a solution provider and QRadar is one of the products that we implement for our customers.
The majority of our clients for IBM products are financial institutions. By law, to be compliant, they are only allowed to run the current version of any solutions that have been procured. Specifically for our area, all of the financial institutions such as banks are mandated to use the latest version.
The use cases include the logging and reporting of servers. These are typically operations servers and critical servers. You can also use it to monitor network devices such as switches, routers, and firewalls.
Endpoints are not included for most of the clients.
What is most valuable?
The most valuable feature is the integration with the GRD, for banking.
What needs improvement?
The advanced planning management (APM) features should be included. We are facing an issue where many of the software houses in Pakistan have developed their own in-house. They have integrated the APM tool with their monitoring solution. This feature is attracting clients and I think that it should be included.
What do I think about the stability of the solution?
We have not faced any issues in terms of stability.
What do I think about the scalability of the solution?
This is a scalable product.
How are customer service and support?
The support from IBM is okay. I would rate them a four out of five.
How was the initial setup?
The initial setup is not very complex. My team has hands-on experience with the product, which is perhaps why they do not complain about its complexity.
The distributor helped us a lot, which is something that we appreciate.
What about the implementation team?
We implement this product for our clients.
Which other solutions did I evaluate?
There are competing products but IBM is a well-known brand so for the most part, we offer IBM QRadar to our clients.
What other advice do I have?
Overall, IBM QRadar is very good but no product is perfect.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
IT Solutions Product Manager at a computer software company with 11-50 employees
It is very easy to install and configure, but after restarting the server, you need to manually start some of the services
Pros and Cons
- "What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own."
- "I have noticed a few things while working on this. After the restart of the server, sometimes, the services misbehave, and you need to manually start or restart the service. I have seen that specifically with the Tomcat service. Sometimes, when you click on log sources, instead of opening the log source extension, it redirects you over the internet."
What is our primary use case?
I am a Product Manager. I am managing the inventory and the logs. For R&D purposes, we downloaded various SIEM solutions from the internet to analyze their performance, and QRadar was one of them. I downloaded the Community Edition of QRadar to check its capabilities and see how to integrate various log sources in our network. It is in my lab, and I have tested it with a few hardware devices and a few computers and servers.
What is most valuable?
What I like the most about it is that you can very easily install and configure it. As compared to other SIEM solutions, for which you need to know and do a lot more to prepare your SIEM environment, QRadar is much simpler to install and configure. There are various options in the Admin console. In the Admin tab, you can design dashboards and view various graphs. It has a lot of attractive features, and you don't need to configure everything on your own.
What needs improvement?
I have noticed a few things while working on this. After the restart of the server, sometimes, the services misbehave, and you need to manually start or restart the service. I have seen that specifically with the Tomcat service.
Sometimes, when you click on log sources, instead of opening the log source extension, it redirects you over the internet.
There are two types of dashboards in QRadar. One is the conventional or old one, and the other one is Pulse. The Pulse dashboard is better, but we would like to have more options in the dashboard.
Additionally, if possible, there should be a single product for SIEM and SOAR. Instead of having QRadar and Resilient separately, there should be a combined solution to benefit from both. Furthermore, there should be a built-in mechanism to configure it in the cluster mode and high availability mode.
For how long have I used the solution?
I tested this product in the last two, three months. It is not implemented in our company.
How was the initial setup?
Its installation is very simple. You can install it and configure it very easily.
Which other solutions did I evaluate?
We are looking at implementing a SIEM solution, and currently, we're comparing various commercial and open-source SIEM solutions. We have tested Wazuh, which is an open-source SIEM solution, but we have not finalized anything.
What other advice do I have?
I would rate it a seven out of 10. It is good, but when a product doesn't behave in a good manner, it creates confusion. Its behavior isn't consistent.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head Of Sales at a tech services company with 11-50 employees
Modular product that sets up a clear roadmap
Pros and Cons
- "Flexible and valuable product that is modular, so you can easily set up a roadmap for your clients."
- "Each module requires a separate license and a separate cost."
What is most valuable?
From a sales perspective, IBM QRadar is very competitive when it comes to prices. It's a flexible and valuable product. It has a good edge in the region and good references as well. You can easily capitalize and upsell on whatever you sold previously. It's a modular product, so you can set up a roadmap and plan for your customers. This is one of the main advantages of QRadar.
What needs improvement?
Right now, there are a lot of solutions in the market that consider themselves next-gen SIEM solutions, like AzureVM. IBM QRadar can be revised considering the competition, market segment, references, and the maintenance of the landscape.
Some modules can be shared as embedded within the same solution because this would be a compelling edge versus others. When it comes to other products, like LogRhythm for example, they can consider the SOAR and the threat Intel embedded with the SIEM Solution licenses. However, when it comes to IBM, they consider each module as a separate license with a separate cost. So it doesn't make sense to compete if the customer isn't convinced with IBM, because you'd have tough competition when it comes to financials.
For how long have I used the solution?
I have been using QRadar for more than five to six years.
What do I think about the stability of the solution?
IBM QRadar is a stable product.
What other advice do I have?
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technology Officer at a tech services company with 51-200 employees
Great dashboards and visibility; lacks decent support and some maturity
Pros and Cons
- "Improves visibility and has a great new dashboard."
- "The solution lacks some maturity."
What is our primary use case?
We are users and implementers of this solution.
What is most valuable?
I like the new dashboard which enables us to understand how many real threat attempts are made in a day. I also like the QRadar incident response, we installed the QIF last week. The solution has improved visibility so that we've been able to discover that some of our customers have not had any protection and were very vulnerable. It's an important area. I also find that the user behavior analysis is relatively simple. We are customers of QRadar.
What needs improvement?
I think the user management model is very detailed but you really have to know what you're doing just to be able to manage things. I think the solution lacks some maturity. When you put it in a large organization as a security system or a cybersecurity system and you want to enable automation, it's difficult to get that level of maturity.
For how long have I used the solution?
We've been using this solution for about 18 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable. We have a total of 19 users in the company. The solution is used extensively and we plan to increase the number of users.
How are customer service and support?
The technical support could be better. I'd rather work with my implementing expert and not the OEM. Although they have the expertise, the development guys are very slow.
Which solution did I use previously and why did I switch?
We tested a few other solutions including AlienVault, Splunk, Micro Focus, and Outside. QRadar was the best of the breed for our needs and for a big system like ours, it's less complex than Splunk or Outside.
How was the initial setup?
The initial setup is complex. Theory is one thing and practice is another. We had to go back and forth with IBM just to find the relevant versions with the relevant operating system to sit on the relevant virtual environment. Then we found a few bugs. We are in a production system in a very big organization so deployment was carried out in stages. It took about a month in total to get things working and to start collecting logs. We had help from IBM Azure.
Maintenance is required, you have to watch it, and work on it on a daily basis.
What's my experience with pricing, setup cost, and licensing?
We pay an annual license fee. On top of that, every model adds to the cost. It's not just the license; the sales people want you to think you're only paying for certain things but we know how it works.
What other advice do I have?
The pre-design and the low-level design should be very, very, specific. It's important to check that the compatibility is there. If not, neither IBM nor OEM will support you.
I would rate the solution more highly but it's very expensive and given the high cost, I would expect quicker and better service from the OEM so I rate the solution seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Sales Consultant at a computer software company with 10,001+ employees
Great detection capability; lacks features such as predictive identification of threads
Pros and Cons
- "Vulnerability data, network data and the like, are part of correlation and detection."
- "Pricing model could be more cost-effective."
What is our primary use case?
I was initially a reseller before selling the solution from within IBM. I'm currently a freelance security sales consultant.
What is most valuable?
A valuable feature is the detection capability. I like that the solution can use data other than log data which means that things like vulnerability data, network data and the like, are part of the correlation and detection.
What needs improvement?
I think they could change their pricing model to be more cost effective. It currently relies on data ingestion. I'd like to see IBM extend their capability with the solution to include more than just fault finding, features such as predictive identification of threads. Having better support for things like MITRE and the ATT&CK chain, and using all of the known attacks that are out there when they're actually spotting events and correlations.
For how long have I used the solution?
I've used this solution for 10 years.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and technical support?
Technical support is pretty good, but sometimes when the problems are complex they can be slow to respond.
How was the initial setup?
The initial setup is very easy. I think it's one of the easiest SIMs to use.
What other advice do I have?
IBM has recently come out with a new version called Cloud Pak for Security but I haven't used it yet. It contains not just QRadar, but also IBM's resilience incident response products.
I recommend the solution but because of the issues with pricing and technical support, I rate the solution seven out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Security Information and Event Management (SIEM) Log Management User Entity Behavior Analytics (UEBA) Endpoint Detection and Response (EDR) Security Orchestration Automation and Response (SOAR) Managed Detection and Response (MDR) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Dynatrace
Splunk Enterprise Security
Fortinet FortiEDR
Darktrace
Microsoft Sentinel
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Varonis Platform
Buyer's Guide
Download our free IBM Security QRadar Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, IBM QRadar or Splunk?
- What SOC product do you recommend?
- Has anyone got experience in deployment of a SIEM solution?
- IBM QRadar is rated above competitors (McAfee, Splunk, LogRhythm) in Gartner's 2020 Magic Quandrant. Agree/Disagree?
- What is your opinion of IBM QRadar?
- What are the biggest differences between Securonix UEBA, Exabeam, and IBM QRadar?
- Why do most companies prefer IBM QRadar?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?


















