Softwr
IBM QRadar logo

IBM QRadar

Enterprise SIEM licensed by events per second, whose cloud business IBM sold to Palo Alto Networks in 2024.

As of 30 August 2026, IBM QRadar's pricing is not published; the vendor quotes on request. A long-established SIEM with native network flow analysis alongside log correlation. Softwr lists it under Cybersecurity. IBM QRadar is made by IBM Corporation, launched in 1911, available on Web, API.

Overview

What IBM QRadar does

QRadar is a security information and event management platform. It ingests logs from across an estate, normalises them through Device Support Modules, and correlates the results with rules into what it calls offences, which chain related events into a single investigable item. Its distinguishing technical feature is that it also ingests network flow data natively through QFlow and QNI, so an analyst can pivot from a log event to the traffic that surrounded it without a separate network detection product. It has been sold as an on-premises appliance and virtual appliance, as QRadar on Cloud, and latterly as the QRadar Suite bundling EDR from the ReaQta acquisition and SOAR from Resilient. The fact that overrides everything else is commercial. In May 2024 IBM announced the sale of the QRadar SaaS assets to Palo Alto Networks, and the transaction closed that September. Palo Alto has been migrating those customers onto Cortex XSIAM, its own platform, with migration incentives. IBM has said it will continue supporting on-premises QRadar customers, but the strategic direction of the cloud product now belongs to a competitor and IBM's own security narrative has moved to consulting and to watsonx. A buyer evaluating QRadar in 2026 is therefore not choosing between SIEMs on features; they are choosing between an on-premises product with a support horizon and a migration onto a different vendor's platform. The existing customer base is large regulated enterprises, often with an IBM relationship, log residency requirements that rule out shared SaaS, and a SOC with staff assigned to the platform. The trade-off has always been operational cost rather than licence cost. QRadar is licensed by events per second and flows per minute, which means every log source you add raises the meter, and it needs an engineer who knows it. Organisations that deploy it without that person accumulate unreviewed offences and unparsed log sources until the platform becomes a compliance artefact rather than a detection capability.

What people use it for

  • A regulated enterprise that must keep log data on premises or in a specific jurisdiction and cannot use a shared SaaS SIEM
  • A SOC that wants log correlation and network flow analysis in one platform rather than buying an NDR product separately
  • An existing QRadar estate deciding whether to stay on premises or accept the migration path to a different vendor's platform
  • Compliance-driven log retention and reporting where the audit requirement is specific about collection, retention and reporting

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about IBM QRadar.

  • IBM sold the QRadar SaaS business to Palo Alto Networks in 2024 and those customers are being moved to Cortex XSIAM, so anyone buying today is choosing an on-premises product whose vendor has publicly moved the cloud future to a competitor, and the support horizon becomes a contract negotiation rather than an assumption.
  • Licensing is by events per second and flows per minute, so every additional log source raises the cost directly and teams routinely exclude verbose sources such as DNS, proxy, endpoint and cloud audit logs to stay under the licence, which strips out exactly the data an investigation later needs.
  • It needs a dedicated operator: rule tuning, parser work and offence triage are continuous jobs, and an organisation that deploys QRadar without at least one named engineer accumulates thousands of unreviewed offences and a false sense of coverage.
  • A log source without a matching Device Support Module arrives unparsed, and writing a custom parser with regular expressions against an unfamiliar payload format is specialist work that can take days per source, which quietly determines which systems ever get monitored.
  • On-premises capacity is planned across consoles, processors, collectors and data nodes, so outgrowing the sizing means procuring and racking more appliances rather than changing a subscription tier, and growth becomes a purchasing cycle measured in months.

Cross-shopped

What people choose instead of IBM QRadar

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

Pricing

What IBM QRadar costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

QRadar SIEM

Free

  • Event and flow processing
  • Offense management
  • Threat intelligence
  • Contact sales

QRadar Cloud

Free

  • Cloud-native deployment
  • Elastic scaling
  • Managed infrastructure
  • Contact sales

QRadar Suite

Free

  • SIEM + SOAR + XDR
  • Unified analyst experience
  • Federated search
  • Contact sales

Capabilities

Features

  • Offence model

    Correlates related events and flows into a single investigable item rather than a stream of individual alerts

  • Network flow analysis

    Ingests NetFlow, IPFIX and packet-derived flow data natively alongside logs, including application-layer detail via QNI

  • Device Support Modules

    Prebuilt parsers for a large catalogue of log sources, with a framework for writing custom ones

  • Ariel query language

    Purpose-built search over event and flow stores for investigation and rule building

  • Rules and building blocks

    Layered correlation logic with reusable building blocks so tuning does not mean rewriting every rule

  • Deployment topology

    Console, event processors, event collectors, flow collectors and data nodes can be distributed for scale and data residency

  • App Exchange

    Vendor and community extensions for content packs, integrations and dashboards

  • Use Case Manager

    Maps deployed rules against MITRE ATT&CK to show detection coverage and gaps

  • QRadar SOAR integration

    Case management and playbooks from the Resilient acquisition, sold as part of the suite

  • Compliance content

    Prebuilt reports and rule packs aligned to PCI DSS, HIPAA and similar regimes

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Who owns QRadar now?

It is split. IBM sold the QRadar SaaS assets to Palo Alto Networks in a deal announced in May 2024 and closed that September, and those customers are being migrated to Cortex XSIAM. IBM retains and supports the on-premises product.

Is QRadar being discontinued?

IBM has committed to continuing support for on-premises customers, including security updates, while offering migration assistance. The cloud product's future belongs to Palo Alto. If you are signing a multi-year term, get the support horizon written into the contract.

How is it licensed?

By events per second for logs and flows per minute for network data, with the software or appliance sized to that rate. Add-on modules in the suite are licensed separately.

What is an offence?

QRadar's term for a correlated case. Rules group related events and flows against a common indicator such as a host or user, so an analyst reviews one offence rather than the hundreds of events behind it.

Do I need a full-time engineer?

In practice yes for anything beyond a small deployment. Parser development, rule tuning and offence triage do not stop, and the most common failure mode is a well-installed QRadar that nobody has tuned since go-live.

Behind it

Who makes IBM QRadar

Company
IBM Corporation
Based in
Armonk, New York, USA
Share

Keep looking

Where to go from IBM QRadar

Best Cybersecurity software for

Compare IBM QRadar with

Other Cybersecurity software

  • The world's most-loved password manager

    From $2.99/mo10 researched notes
  • Powerful protection against evolving threats

    From $36/yr14 researched notes
  • Simplify online life with LastPass password manager

    Free plan12 researched notes
  • Cloud-native SIEM and SOAR solution

    Free, then $2.46/day12 researched notes
  • Stop breaches with AI-native cybersecurity

    Free, then $7.99/device/month12 researched notes
  • AI-powered SIEM platform for modern security operations

    8 researched notes
  • Intelligence-driven cybersecurity

    From $25,000/yr11 researched notes
  • Email security and data protection suite from a private company owned by Thoma Bravo, licensed per user with modules sold separately.

    From $6/mo14 researched notes
  • XDR platform correlating Trend Micro's endpoint, email, server, cloud and network sensors, licensed through a shared credit pool.

    From $75/yr14 researched notes
  • AI-native application security platform detecting and fixing vulnerabilities across the SDLC

    Free, then $300/yr11 researched notes
  • Open-source authentication and two-factor portal for reverse proxies

    Open source9 researched notes
  • Twilio's free authenticator app with encrypted cloud backup, mobile only since the desktop clients were withdrawn in 2024.

    Free plan14 researched notes
  • Transparent proxy that encrypts, tokenises and masks database fields without application code changes

    Pricing on request13 researched notes
  • Phishing-resistant passwordless authentication with device trust enforced at every login

    Pricing on request11 researched notes
  • Privileged access management, endpoint privilege management and secure remote access

    Pricing on request11 researched notes

Softwr does not host reviews and shows no star rating for IBM QRadar, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on IBM QRadar

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare IBM QRadar with alternatives