Talk to us
by IBMTechBag Intel Page

IBM QRadar SIEM

Your security logs must stay on hardware you control. The sale of QRadar’s cloud edition doesn’t change that — IBM QRadar SIEM collects log events and network flows on appliances you own and correlates them into alerts — still sold and developed by IBM on-premises; only the SaaS edition went to Palo Alto in 2024.

On-premises, still sold by IBMEPS and FPM, or per MVS7.6.0 GA on 30 June 2026

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
IBM describes two licence models on its pricing page but prints no figure for either
Quote
Release
Generally available on 30 June 2026 under announcement letter AD26-0341
7.6.0
Analysts
Gartner SIEM Magic Quadrant 2024; IBM’s 2025 placement is unverified, so no current claim
Leader (2024)
India
No IBM-run QRadar cloud remains; residency follows wherever you rack the appliances
Your hardware

Quick answer

IBM QRadar SIEM is IBM’s on-premises SIEM, run on hardware or virtual appliances you own, and IBM still sells and develops it: 7.6.0 went GA on 30 June 2026. Only the QRadar SaaS business went to Palo Alto Networks, divested on 5 September 2024. Licences count events per second and flows per minute, or Managed Virtual Servers with unlimited ingest; no price is published. Logs stay on your hardware in India. Read more ↓ Show less ↑
Part 01 · Orient

The IBM platform family

This page covers IBM QRadar SIEM — the on-premises SIEM; QRadar SOAR is sold separately. The rest:

Quick facts

30-second orientation
Product
On-premises SIEM on hardware or virtual appliances, taking in log events and network flows
Maker
IBM, Armonk, New York; CEO Arvind Krishna. The old “IBM Security” prefix is gone
Status
Version 7.6.0 generally available since 30 June 2026; 7.5.0 still gets update packages
The SaaS
Divested to Palo Alto Networks on 5 Sept 2024; Palo Alto announced its end of life on 14 April 2025
Price
Not published; IBM quotes subscription or perpetual licences
Licence
Usage Model by EPS and FPM, or Enterprise Model per Managed Virtual Server with unlimited ingest
Content
IBM claims 700 prebuilt integrations and partner extensions, plus thousands of Sigma rules
Support
7.6.0 sits on Support Cycle-5 (5+1+3), so standard support runs to about June 2031
India
Logs stay on appliances you rack, in your own Indian data centre or a colo you choose
In India via
TechBag — EPS and flow sizing, quote in INR with GST, upgrade planning
Part 02 · Learn

Understand on-premises SIEM before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is an on-premises SIEM?

A SIEM gathers logs and network flows in one place and correlates them into alerts; on-premises, it all runs on your hardware.

Logs left on every box vs one on-premises SIEM — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionLogs left on each boxIBM QRadar SIEM
Where security logs liveOn each server and firewall until rotatedOn QRadar appliances in your own data centre
Seeing network behaviourFlows ignored or kept in a separate toolFlows licensed and correlated beside logs
Writing detectionsEvery rule hand-built by the teamThousands of open Sigma rules to start from
Paying for volumeNo central tool, so no bill and no viewEPS and FPM, or per MVS with no ingest cap
Who runs the SOCWhoever is free when an alarm firesYour analysts, or IBM X-Force as a service
What it is NOT—SOAR, an IBM cloud service, or a price list

The cheapest first step is a week of EPS and flow counts at peak: it decides the licence model, the appliance size and the quote.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where QRadar runs

Appliances

Hardware or virtual appliances

QRadar SIEM ships as hardware appliances or as virtual appliances on your hypervisor, inside your own data centre; IBM no longer operates a cloud edition of it for customers.

02
How capacity is licensed

Meters

Usage Model and Enterprise Model

The Usage Model counts events per second and flows per minute; the Enterprise Model counts Managed Virtual Servers and drops the ingest ceiling. Both come as subscription or perpetual.

03
What it can read and detect

Content

Integrations and Sigma rules

IBM claims 700 prebuilt integrations and partner extensions for sources, and native support for thousands of open-source Sigma rules, a detection format shared across SIEM vendors.

04
What happens after an alert

Response

QRadar SOAR and X-Force services

Playbooks and case management are a separate on-prem product, QRadar SOAR; teams without a SOC of their own can have IBM X-Force Threat Management Services run QRadar for them.

Appliances on your premises — events and flows licensed by EPS and FPM or per MVS, with Sigma rules and SOAR alongside.

Part 03 · Evaluate

Six capabilities. Collect, detect, operate.

IBM QRadar SIEM correlates your logs and network flows on appliances that never leave your data centre.

Collect
Integrations

Sources ready to plug in

IBM claims 700 prebuilt integrations and partner extensions, covering the firewalls, servers and apps a SOC typically ingests.

Collect
Events + flows

Logs and network traffic

The licence counts both log events per second and network flows per minute, so traffic records sit beside logs in one system.

Detect
Sigma

Open detection rules

Native support for thousands of open-source Sigma rules gives a small team a starting library instead of a blank rule editor.

Detect
On your hardware

Correlation stays in-house

Collection, storage and correlation all run on appliances you own, so no security telemetry has to leave your building.

Operate
Managed option

IBM can run it for you

IBM X-Force Threat Management Services offers QRadar as a managed service for teams that lack round-the-clock analysts.

Operate
Lifecycle

Dated support windows

7.6.0 runs on Support Cycle-5, five years standard plus extensions, and fix packs such as 7.6.0.2 close published CVEs.

See it, don’t just read it

Watch the SIEM concepts behind QRadar

IBM Technology explainers on what a SIEM does and on catching insiders with SIEM analytics, plus a 2023 news bulletin on QRadar SIEM.

IBM Technology (official IBM channel)·Topic explainer, December 2022

What Is SIEM?

A whiteboard explainer of what any SIEM collects and correlates; it covers the category, not a QRadar demo.

IBM Technology (official IBM channel)·Topic explainer, December 2023

Fight Insider Threats with AI-infused SIEM

How analytics inside a SIEM help spot insiders; a concept talk from before the 7.6 release.

IBM Technology (official IBM channel)·News bulletin, October 2023

IBM Tech Now: IBM and Equinix, the White House cybersecurity plan and an award for QRadar SIEM

A short news round-up recorded before the 2024 SaaS sale; only one of its items concerns QRadar SIEM.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why IBM QRadar SIEM

IBM sold the cloud edition, not the product. QRadar SIEM still runs on your hardware, on IBM’s roadmap.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Still IBM’s product, still on your premises

The 2024 deal moved only the cloud edition: IBM dates the QRadar SaaS divestiture to Palo Alto Networks at 5 September 2024 and says it still sells QRadar on-premises. Release 7.6.0 went GA on 30 June 2026 on Support Cycle-5, so standard support runs to about June 2031.

02

Two meters, so the estate picks the bill

The Usage Model licenses events per second and flows per minute, which suits a SOC with steady, measured volumes. The Enterprise Model licenses Managed Virtual Servers with unlimited log ingestion, so a chatty new source does not reopen the contract. Both come as subscription or perpetual.

03

Content you are not locked into

IBM claims 700 prebuilt integrations and partner extensions, and native support for thousands of Sigma rules. Sigma is an open rule format, so detections kept in it can move with you, a fair hedge for a product whose cloud sibling changed owner. Pilot the integrations for your own firewalls.

04

Where it stops

No public price and no IBM-hosted edition: the SaaS belongs to Palo Alto, which announced its end of life in April 2025. Playbooks need QRadar SOAR, sold apart. IBM was a Gartner SIEM Leader in 2024; its 2025 placement is unverified. You size, patch and store it all yourself.

The idea
Logs and flows correlated on your hardware
The residency
Wherever you rack it, India included
The price
Quoted on EPS and FPM, or per MVS
Proof, not promises

The numbers behind the platform

700 integrations
prebuilt integrations and partner extensions IBM claims for QRadar SIEM
— Vendor
~2031
roughly when 7.6.0 standard support ends under IBM’s Support Cycle-5 (5+1+3)
— Vendor
30 June 2026
general availability of QRadar 7.6.0, announced in letter AD26-0341
— Vendor
2 licence models
Usage Model on EPS and FPM, or Enterprise Model per MVS with unlimited ingest
— Vendor
5 Sept 2024
the date IBM gives for divesting the QRadar SaaS assets to Palo Alto Networks
— Vendor
2024
the latest year a Gartner SIEM Leader placement for IBM can be verified
— Analyst

What your IBM QRadar SIEM rollout looks like

Week 1Model

Measure events and flows

Count events per second and flows per minute at today’s peak, and list the sources that must stay on your own hardware.

Week 2Decide

Pick the licence model

Weigh the EPS and FPM Usage Model against per-MVS Enterprise licensing, then choose subscription or perpetual terms.

Week 4Pilot

Rack the appliances

Place hardware or virtual appliances in your Indian data centre, size disk for the retention you need, connect sources.

Month 2Prove

Import and tune Sigma rules

Load the Sigma rules that match your threats, tune them on a month of your own data, and switch off the noisy ones.

Month 3Commit

Patch and set the roadmap

Apply the current fix pack, such as 7.6.0.2, and decide whether QRadar SOAR or X-Force managed services come next.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
64+ reviews*
76% would recommend
Log and flow coverage4.3
Correlation rules4.1
On-premises control4.4
Ease of tuning3.4
Value for money3.5
5★
38%
4★
37%
3★
17%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our regulator wanted security logs on hardware we own. QRadar appliances in our Mumbai data centre settled it early.”
CISO
BFSI
Telecom
“A new firewall cluster doubled our EPS in a week. Moving to per-MVS licensing ended the true-up arguments for good.”
SOC Manager
Telecom
Manufacturing
“Flow records showed a file server talking to an unknown host at 3 a.m.; its logs looked perfectly normal that night.”
Security Analyst
Manufacturing
Healthcare
“Importing Sigma rules gave our three-person team a head start, though almost every rule needed tuning to our data.”
Detection Engineer
Healthcare
Insurance
“The SaaS sale worried our board. The 7.6 release and its Cycle-5 support dates in writing calmed the renewal debate.”
Head of IT Risk
Insurance
Government
“You own the patching. We slipped one update package and the CVE bulletin landed in the same week as our audit.”
Infrastructure Lead
Government
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag SIEM Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
IBM QRadar SIEMThis page

EPS and FPM, or per MVS; IBM publishes no price.

Grid 02 · The architecture

Deployment Control × Platform Breadth

The grid nobody publishes — how far you can keep the SIEM and its data on your own hardware vs how much of the SOC one licence covers.

Cloud-only platformsBroad and self-hostableCloud point SIEMsOn-prem SIEM cores
IBM QRadar SIEMThis page

Appliances you own; SOAR is a separate product.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

IBM QRadar SIEM vs the SIEM field

Against Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Securonix and ManageEngine Log360 — on deployment, meters, price, retention, automation and India.

DimensionIBM QRadar SIEMSplunk Enterprise SecurityMicrosoft SentinelPalo Alto Cortex XSIAMSecuronix Unified Defense SIEMManageEngine Log360
What it isIBM’s on-prem SIEMCisco-owned SIEMAzure-native SIEMAI-led SecOps platformCloud SIEM on SnowflakeZoho’s unified SIEM
DeploymentAppliances, on-premCloud or self-managedAzure SaaS onlyCloud onlyCloud; no self-hostOn-prem or cloud
Data it takes inEvents and flowsAny machine dataMicrosoft logs freeWhole security estateCloud to identityServers to cloud apps
Pricing modelEPS + FPM, or per MVSIngest or workloadPer GB ingestedData and scopeGB a day, in bandsPer log source
Published entry priceNot publishedQuote; ~$1,000 GB/day~$4.30 per GBQuote onlyNo rate card$300 a year (Basic)
Included vs add-onSOAR sold apartSOAR is extraLogic Apps extraSOAR, TI, ASM inUEBA and SOAR inUEBA, workflows in
RetentionYour disk decidesPriced by term90 days includedSet in the quote365 days hotYour storage on-prem
Detection contentSigma rules nativeESCU, risk alertsKQL rules, FusionAI incident stitchingUEBA plus retro-huntsRules, UEBA, Zia
AutomationNeeds QRadar SOARSplunk SOAR, extraLogic Apps playbooksNative automationSOAR in entitlementBuilt-in workflows
Analyst standingLeader in 202411× Leader (2025)Leader (2025)No SIEM MQ cited6× Leader (2025)None cited
India data locationYour Indian DCAWS Mumbai or yoursStored in IndiaNot documentedBYO-Snowflake in IndiaChennai, Mumbai, or own
Product status7.6.0, support to ~2031ES 8.x, Cisco-backedPortal move by 2027QRadar SaaS successorNew CEO, June 2026Active, AI added
Lock-in and exitSigma eases exitSPL to rewriteKQL, Azure-boundPlatform commitmentYour Snowflake helpsZoho estate pull
Best fitExisting QRadar estatesEngineering-heavy SOCsMicrosoft-shaped estatesSOC model rethinkCloud, year-long huntsMid-market, India-built
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose IBM QRadar SIEM if…

  • ✓Your regulator or board wants SIEM data on hardware you own and rack in India, not in anyone’s cloud
  • ✓You already run QRadar and want the 7.6 line, with standard support to about 2031, rather than a migration project
  • ✓Your volumes are steady enough to license by EPS and FPM, or large enough that per-MVS unlimited ingest pays off

Compare alternatives if…

  • ✓You want the SIEM delivered as a service — Sentinel, Securonix and Cortex XSIAM are cloud-native, and IBM no longer hosts one
  • ✓You want a number before the first call — Sentinel publishes per-GB rates and Log360 lists editions from $300 a year
  • ✓You want automation in the same licence — XSIAM and Securonix include SOAR, while QRadar needs QRadar SOAR

Do not expect…

  • ✓An IBM-hosted QRadar: the SaaS edition belongs to Palo Alto, which announced its end of life in April 2025
  • ✓A current Gartner Leader claim — 2024 is the latest IBM placement that could be verified
  • ✓Randori or QRadar EDR SaaS from IBM; both were divested to Palo Alto alongside QRadar SaaS

IBM QRadar SIEM is one of 35 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does reading logs box by box cost you?

Drag the sliders (log sources feeding the SIEM; analyst-hour cost). Estimates model analyst time spent reading logs box by box and assembling audit evidence at an assumed 1.5 hours per log source a year, with 70% of it removed by central collection and correlation. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual log-review cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: IBM licenses QRadar SIEM on a Usage Model (events per second plus flows per minute) or an Enterprise Model (per Managed Virtual Server, with unlimited log ingestion), each as a subscription or perpetual licence, and prints no figure for either. QRadar SOAR is licensed separately. TechBag measures your EPS and flows first, then quotes in INR with GST.

Usage Model

Best for steady, measured volumes

  • Licensed on EPS and FPM
  • Subscription or perpetual
  • Price on quote only

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Enterprise Model

Best for growing or noisy estates

  • Per Managed Virtual Server
  • Unlimited log ingestion
  • Subscription or perpetual

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Deployment

Must logs stay on hardware you own? QRadar SIEM is on-premises only; IBM no longer offers a SaaS edition.

2
Licence model

Are volumes steady enough for EPS and FPM, or growing fast enough that per-MVS unlimited ingest is safer?

3
Terms

Subscription or perpetual? Ask for both, itemised in INR with GST, with the support years written in.

4
Version

Will you deploy 7.6.0, on Support Cycle-5 to about 2031, or stay on 7.5.0 and schedule the upgrade?

5
Patching

Who applies fix packs? CVE-2026-13477 needed 7.6.0.2 or 7.5.0 UP15 IF05; CVE-2025-33141 needed UP16.

6
Integrations

Are your firewalls, servers and cloud apps among the 700 integrations IBM claims? Test the top five in a pilot.

7
Automation

Do you need playbooks? Budget QRadar SOAR separately, or ask about IBM X-Force Threat Management Services.

8
SaaS history

Were you a QRadar SaaS customer? That service now sits with Palo Alto, whose path is Cortex XSIAM, not IBM.

FAQ

Questions buyers ask

It is IBM’s security information and event management software for your own premises, delivered as hardware or virtual appliances that collect log events and network flows and correlate them into alerts. IBM still sells and develops it, and version 7.6.0 became generally available on 30 June 2026.

Ready to evaluate IBM QRadar SIEM?

Measure your events and flows first, or let a TechBag advisor compare the Usage and Enterprise models for your estate before IBM quotes.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.