
Overview
Threats are increasing in volume and sophistication at a staggering pace. Real-time monitoring and visibility are required to detect threats like ransomware, insider threats, and cloud attacks before they cause disruption.
IBM Security® QRadar® Suite is a modernized threat detection and response solution designed to unify the security analyst experience and accelerate their speed across the full incident lifecycle. The portfolio is embedded with enterprise-grade AI and automation to dramatically increase analyst productivity, helping resource-strained security teams work more effectively across core technologies.
IBM Security QRadar SIEM (Classic): Market-leading Security Information and Event Management (SIEM) solution enables you to run your business in the cloud and on premises with visibility and security analytics built to rapidly investigate and prioritize critical threats.
IBM Security QRadar SOAR: Recent winner of a Red Dot Design Award for interface and user experience, QRadar SOAR helps organizations automate and orchestrate incident response workflows and ensure their specific processes are followed in a consistent, optimized and measurable way.
For more information, visit https://www.ibm.com/qradar
For customized QRadar SIEM (Classic) / QRadar SOAR pricing or if you are interested in additional product capabilities such as Threat Intelligence, Data Explorer, or EDR - contact your IBM Sales Representative or email us at SecurityOrdersAWS@wwpdl.vnet.ibm.com .
Highlights
- Find the right size for your solution and estimate your IBM QRadar SIEM (Classic Software) price: https://www.ibm.com/qradar/security-qradar-siem/pricing?mpid=aws
- Gain centralized visibility across AWS and hybrid cloud environments via a single pane of glass. Leverage deep integrations with AWS security services including AWS Security Hub, CloudTrail, GuardDuty, Network Firewall, WAF, Amazon Detective, CloudWatch, VPC Flow Logs and more.
- Correlate data across users, networks, and AWS native services to gain deep insights into key threats including cloud misconfigurations, policy changes and suspicious user activity. Connect related events to ensure teams only receive a single alert for an incident.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
QRadar SIEM | 500 Events Per Second, 10000 Flows Per Minute | $12,074.40 |
QRadar SOAR | 2 Authorized Users | $22,704.00 |
Vendor refund policy
All orders are non-cancellable and all fees and other amounts that you pay are non-refundable. If you have purchased a multi-year subscription, you agree to pay the annual fees due for each year of the multi-year subscription term.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
For Sales Inquiries Contact: SecurityOrdersAWS@wwpdl.vnet.ibm.com To contact IBM Security QRadar Suite Software support:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Security monitoring has improved and helps us detect threats faster while building our SOC
What is our primary use case?
My main use case for IBM Security QRadar is implementing it as a SIEM solution to collect logs and correlate events so we can have offenses inside our organization.
Acting as a SIEM solution, IBM Security QRadar helps us deep dive into what happened in our network by collecting network flows and network events, and correlating events to generate incidents or offenses so we can stop attacks.
What is most valuable?
The best features IBM Security QRadar offers include its stability.
What makes IBM Security QRadar's stability stand out for me is that I am currently using FortiSIEM , but implementing IBM Security QRadar is a more advanced and more stable product, making it reliable for me to use.
IBM Security QRadar helps my organization correlate events and gain insight into our network traffic and security events.
Since using IBM Security QRadar, it has helped reduce security risks as we have a risk manager module, which is really helpful for us, and the response to an incident is very quick, so we have reduced the mean time to detect attacks.
What needs improvement?
I think the support for IBM Security QRadar needs improvement as it is a big product and needs more support engineers to help customers.
The time to support and providing more engineers for support are the needed improvements.
For how long have I used the solution?
I have been working in my current field for about ten years.
What do I think about the stability of the solution?
IBM Security QRadar is stable.
What do I think about the scalability of the solution?
IBM Security QRadar's scalability is great.
How are customer service and support?
The customer support for IBM Security QRadar needs improvement.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
I have seen a return on investment in terms of time saved and money saved as we stopped attacks, which also means fewer employees are needed.
What's my experience with pricing, setup cost, and licensing?
Regarding the setup cost, it is great; the licensing module is very powerful and has a granular structure, so the licensing is great, but the price needs more focus to be compared to other vendors.
Which other solutions did I evaluate?
I did not evaluate other options before choosing IBM Security QRadar.
What other advice do I have?
I would advise others looking into using IBM Security QRadar that it can help your organization reduce the mean time to detect and mean time to respond, and also in building a SOC. I would rate this product a ten out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Improved phishing investigations and threat hunting have strengthened our security operations
What is our primary use case?
I use IBM Security QRadar to collect logs, analyze them, and share details. When I began investigating incidents and working with the SOC team, I was using IBM Security QRadar .
How has it helped my organization?
IBM Security QRadar has been a game-changer for our SOC at Kantar. It pulls everything together—logs from endpoints, networks, you name it—letting us spot threats faster and cut down response times by about 40% on stuff like phishing alerts and endpoint issues across our 6,000 machines.
What is most valuable?
IBM Security QRadar offers a wide range of powerful features. During phishing-related investigations, it greatly assists from an analyst’s investigation point of view. A core capability of IBM Security QRadar is visibility — it collects and normalizes logs and network flow events from multiple tools. It can ingest logs from almost any source. Its advanced, modular architecture supports real-time log collection from diverse systems, making it well-suited for environments using platforms such as CrowdStrike, Microsoft Defender, Trend Micro, and Symantec.
These features are highly beneficial in our environment because, from a security perspective, proper log collection and management are crucial. QRadar streamlines SOC operations by automating alert triggers and providing unified visibility across multiple environments, which enhances our team’s ability to handle phishing and EDR alerts effectively. The shift handover capability is another valuable feature of IBM Security QRadar. Real-time log normalization and its advanced analytics engine help reduce high-risk alerts and false positives by up to 50%.
From an analyst’s perspective, threat hunting and groundwork during rotational shifts, combined with SOAR playbook automation, enable efficient endpoint isolation and quarantine actions. IBM Security QRadar also features a custom rules engine that allows analysts to create dynamic rules using AQL, targeting niche threats such as suspicious domains, all without vendor lock-in. Unlike rigid EDR policies, its petabyte-scale indexing efficiently handles massive event-per-second (EPS) volumes without performance degradation, making it ideal for expanding enterprise environments compared to lighter SIEM solutions.
What needs improvement?
IBM Security QRadar needs improvement in several areas. It should be better integrated with AI, as L1 analysts often deal with noisy rules that require constant fine-tuning. Smarter, out-of-the-box analytics — comparable to CrowdStrike’s low false-positive performance — would significantly enhance efficiency. Additionally, a more intuitive and customizable dashboard would provide better visibility, making it easier to identify available options and streamline operations.
The QRadar mobile app also requires upgrades, as it currently lags behind with limited incident (offense) visibility and lacks push alerts for high-severity events. This becomes challenging during shift rotations. Adding an option for bulk offense closure with multi-select capabilities and predefined reason templates would save time, as manual tagging is currently cumbersome. These improvements are essential for optimizing the overall analyst experience.
For how long have I used the solution?
I have used IBM Security QRadar for more than two years.
What do I think about the stability of the solution?
QRadar scales like a champ for our setup—handles petabyte-scale data
How are customer service and support?
Good
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Yeah, before QRadar, we were piecing things together with a mix of Microsoft Defender for logs from endpoints and some basic syslog forwarding from Trend Micro Deep Security , but it wasn't a full SIEM —just siloed tools that made correlation a nightmare.
How was the initial setup?
complex
What about the implementation team?
consultant
What was our ROI?
I can say that almost 35% of time is reduced, specifically 30 to 35% time reduction.
Which other solutions did I evaluate?
We looked at Splunk and Azure Sentinel as main alternatives before landing on QRadar—Splunk for its search power and Sentinel since we're heavy on Azure .
What other advice do I have?
I recommend IBM Security QRadar because it is a trusted IBM product that many organizations and financial institutions use for its strong visibility and analytical capabilities. I have had a great experience working with IBM Security QRadar. From what I know, most SOC professionals agree that once you gain experience with QRadar, adapting to any other SIEM tool becomes much easier. Overall, I would rate my experience with IBM Security QRadar highly due to its robust features and wide industry adoption.
Building a proactive soc has improved threat correlation and deep log investigation
What is our primary use case?
My main use case for IBM Security QRadar is building a SOC with IBM Security QRadar as a SIEM.
I use IBM Security QRadar in my SOC operations as an information security management, security and event management tool, to correlate events and build use cases for incident response.
My main use case helps us to deep dive into the logs and correlate events from many other products like firewalls, endpoints, and also a lot of products.
What is most valuable?
The best features IBM Security QRadar offers include vulnerability management, a powerful integration, and being a stable product. The vulnerability management feature helps to build an asset library for our organization, and with integrations, we can integrate this vulnerability with other ticketing systems to discover new vulnerabilities and build a patch management for it.
IBM Security QRadar has positively impacted my organization by allowing me to get offenses and threats into our organization, helping me to discover the real threats attacking our organization. The real threats that IBM Security QRadar helps us with are provided as offenses, real offenses with real examples that allow us to discover new offenses and assist in closing these offenses.
What needs improvement?
IBM Security QRadar can be improved; perhaps IBM support needs improvement in fast response and also the team response.
For how long have I used the solution?
I have been using IBM Security QRadar for about nine years.
What do I think about the stability of the solution?
IBM Security QRadar is stable.
What do I think about the scalability of the solution?
IBM Security QRadar's scalability is great; you can have a new collector to deploy if you have increased EPS per second.
How are customer service and support?
Customer support for IBM Security QRadar needs improvement.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have not used a different solution before IBM Security QRadar; this is my first use.
What was our ROI?
I have seen a return on investment; I can share that it includes time saved, money saved, and fewer employees needed.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is great compared to the other vendor.
Which other solutions did I evaluate?
I did not evaluate other options before choosing IBM Security QRadar.
What other advice do I have?
IBM Security QRadar is stable and has great support.
I advise others looking into using IBM Security QRadar that it is really helpful for building a SOC and to get a deep dive into your real threats at the earliest time. I have given this product a review rating of 10.
Have managed daily asset and alert monitoring effectively but have encountered limitations with manual processes and interface usability
What is our primary use case?
The use cases are daily monitoring, asset management, asset monitoring, asset health status monitoring, and alert monitoring. That is the current use case of what SIEM is being used for.
What is most valuable?
The query search and log fetching are really helpful in IBM Security QRadar when compared to other tools.
Compared to ArcSight, Splunk, or any other SIEM tools where you need their processing language such as structured query language, SPL, and in Sentinel there is KQL query languages, IBM Security QRadar doesn't require reliance on query languages. There are filters which you can use directly and apply to get the data you want fairly easily.
What needs improvement?
It's still very manual and doesn't work on its own. It's still in an early stage and not on par where we can consider it a really successful detection system. The accuracy is not there.
The UI could be better when compared to Sentinels where we can use flags and tagging. It could be much more user-friendly. IBM Security QRadar has all features and is fully competitive with other SIEM tools, but when it comes to user-friendliness, a new user takes time to get used to it. More intuitive, user-friendly interfaces and more helpful documentation would be beneficial.
The query searching and data fetching could be faster. In large to very large organizations with around 5,000 or 6,000 assets or beyond, even with proper configurations and RAM and hardware backing up, the query is fairly slow.
For how long have I used the solution?
I have been using it for almost nine months.
What do I think about the stability of the solution?
The solution is extremely stable because it's on cloud. On cloud, you don't see any disconnections or instability. Any solution that is on cloud works really stably.
What do I think about the scalability of the solution?
I am both a customer and we provide service to that.
How are customer service and support?
I never needed to reach out to support because most of the expertise was already available.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
How was the initial setup?
There are analytical workspaces where we create automatic ticket creations and automatic email notifications.
What about the implementation team?
I have worked on technologies including Qualys, Group-IB, and QRadar. I have experience with CrowdStrike EDR and Bitdefender. On the EDR front, I have worked on CrowdStrike and Bitdefender. For SIEMs, I work with IBM Security QRadar and Sentinel. For vulnerability assessments, I work with Qualys.
What was our ROI?
There are no observable benefits on ROI process-wise, workability-wise, or usability-wise.
Which other solutions did I evaluate?
We chose IBM Security QRadar because we were moving to cloud. Previously it was an on-prem solution. Compared to Splunk and Sentinel, it's much more cost-effective.
What other advice do I have?
IBM Security QRadar is capable of handling much of the market requirements. It's comparable to any other SIEM tool without standing out significantly.
It's fairly open for custom integrations, but it depends on what type of logs we are receiving and what kind of parsing we are getting done. The integrations are totally based on the skill sets if third-party or custom integrations are required.
When it comes to log management, it's fairly easy to manage and the log rotate is really good compared to any standard SIEM tool. It just gets the work done.
I rate IBM Security QRadar an 8 out of 10.
Has provided fast deployment with out-of-the-box use cases and improved threat detection through integrated AI tools
What is our primary use case?
In IBM Security QRadar , I used to work for a company that wanted to implement AI, generative AI, to help financials and banks improve their process of software development, including testing for their tools and all the releases they are doing for the improvements of the applications of software on the cloud.
What is most valuable?
IBM Security QRadar 's AI and machine learning capabilities for threat detection and response are exceptional, and Q Site is used to create panels and visualizations of software development processes. It's really fast and impressive compared to QuickSight . The detector library contributes significantly to its functionality. The main importance is the releases without any kind of security breaches, and IBM Security QRadar gives the opportunity to improve the time to market of the releases with a great evaluation of cybersecurity breaches. It's currently the top solution in the industry.
What needs improvement?
I assess the integration of third-party technologies with IBM Security QRadar's open architecture as lacking compared with what is available, because there are more genesis and solutions, but nothing compares with AWS cloud solutions. The top integrations happen here. The only difficulty is when integrating with ServiceNow ; solutions from Microsoft, Google, Rackspace are really complex to integrate with ServiceNow , but Amazon is easier than other solutions.
I'm talking about IT Operation Management or hardware as management, DevOps or SecOps of ServiceNow, and those are really complex use cases to integrate with third parties, but Amazon does it better.
Overall, I would rate IBM Security QRadar an 8.5, because it depends on the use case, but there should be more focus on small and medium businesses, especially given the number of FinTechs and entrepreneurs in Mexico that require easier solutions with less budget. AWS Cloud is amazing for macro projects on software development, but it needs to be more accessible for SMBs, which is why I give it an 8.5; there's room for improvement in that area.
For how long have I used the solution?
With AWS as a cloud provider, I used to work for a company that implements solutions for AWS cloud solutions.
How are customer service and support?
I would rate their customer service or technical support as the best in Mexico. The only issue is the language barrier sometimes, because customer support services are used from India, and that can be challenging. While I speak English, it's difficult to understand some accents. However, besides that, local support in Mexico has people ready to provide level one, level two, and level three support. When something complex arises, the ticket gets transferred to India or to third parties not in Mexico, but it's very difficult to scale a ticket that far. The customer support located in Mexico speaks Spanish and they help to resolve issues, depending on the agent.
How would you rate customer service and support?
Neutral
How was the initial setup?
For the initial setup of IBM Security QRadar, you need to have the right people, but if you are a newbie to these kinds of solutions and want to do out-of-the-box implementations, Amazon provides out-of-the-box use cases that you can implement immediately, and the personalization is easy to accomplish.
What was our ROI?
In terms of return on investment, I have worked on exercises where the payback occurs within three or four months, which is very good for a cloud solution because implementation cycles can be really long. AWS gives the chance to implement a solution out of the box with use cases that are already in IBM Security QRadar. Solutions such as Q Business, Q Site, QuickSight are already out of the box, so implementing and configuring a use case takes about two to three months, with the payback being almost immediate.
What's my experience with pricing, setup cost, and licensing?
The pricing for IBM Security QRadar is not the best, but it's not the worst. It depends on how much you want to spend. The last time I worked with this technology was in 2023. The pricing reflects how much you want to spend for the results you want to have. If you want the best of the best, you go to AWS Cloud.
What other advice do I have?
I rate IBM Security QRadar 8.5 out of 10.