Your security logs must stay on hardware you control. The sale of QRadar’s cloud edition doesn’t change that — IBM QRadar SIEM collects log events and network flows on appliances you own and correlates them into alerts — still sold and developed by IBM on-premises; only the SaaS edition went to Palo Alto in 2024.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers IBM QRadar SIEM — the on-premises SIEM; QRadar SOAR is sold separately. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A SIEM gathers logs and network flows in one place and correlates them into alerts; on-premises, it all runs on your hardware.
What consolidation actually replaces, dimension by dimension.
| Dimension | Logs left on each box | IBM QRadar SIEM |
|---|---|---|
| Where security logs live | On each server and firewall until rotated | On QRadar appliances in your own data centre |
| Seeing network behaviour | Flows ignored or kept in a separate tool | Flows licensed and correlated beside logs |
| Writing detections | Every rule hand-built by the team | Thousands of open Sigma rules to start from |
| Paying for volume | No central tool, so no bill and no view | EPS and FPM, or per MVS with no ingest cap |
| Who runs the SOC | Whoever is free when an alarm fires | Your analysts, or IBM X-Force as a service |
| What it is NOT | — | SOAR, an IBM cloud service, or a price list |
The cheapest first step is a week of EPS and flow counts at peak: it decides the licence model, the appliance size and the quote.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
QRadar SIEM ships as hardware appliances or as virtual appliances on your hypervisor, inside your own data centre; IBM no longer operates a cloud edition of it for customers.
The Usage Model counts events per second and flows per minute; the Enterprise Model counts Managed Virtual Servers and drops the ingest ceiling. Both come as subscription or perpetual.
IBM claims 700 prebuilt integrations and partner extensions for sources, and native support for thousands of open-source Sigma rules, a detection format shared across SIEM vendors.
Playbooks and case management are a separate on-prem product, QRadar SOAR; teams without a SOC of their own can have IBM X-Force Threat Management Services run QRadar for them.
Appliances on your premises — events and flows licensed by EPS and FPM or per MVS, with Sigma rules and SOAR alongside.
IBM QRadar SIEM correlates your logs and network flows on appliances that never leave your data centre.
IBM claims 700 prebuilt integrations and partner extensions, covering the firewalls, servers and apps a SOC typically ingests.
The licence counts both log events per second and network flows per minute, so traffic records sit beside logs in one system.
Native support for thousands of open-source Sigma rules gives a small team a starting library instead of a blank rule editor.
Collection, storage and correlation all run on appliances you own, so no security telemetry has to leave your building.
IBM X-Force Threat Management Services offers QRadar as a managed service for teams that lack round-the-clock analysts.
7.6.0 runs on Support Cycle-5, five years standard plus extensions, and fix packs such as 7.6.0.2 close published CVEs.
IBM Technology explainers on what a SIEM does and on catching insiders with SIEM analytics, plus a 2023 news bulletin on QRadar SIEM.
A whiteboard explainer of what any SIEM collects and correlates; it covers the category, not a QRadar demo.
How analytics inside a SIEM help spot insiders; a concept talk from before the 7.6 release.
A short news round-up recorded before the 2024 SaaS sale; only one of its items concerns QRadar SIEM.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
The 2024 deal moved only the cloud edition: IBM dates the QRadar SaaS divestiture to Palo Alto Networks at 5 September 2024 and says it still sells QRadar on-premises. Release 7.6.0 went GA on 30 June 2026 on Support Cycle-5, so standard support runs to about June 2031.
The Usage Model licenses events per second and flows per minute, which suits a SOC with steady, measured volumes. The Enterprise Model licenses Managed Virtual Servers with unlimited log ingestion, so a chatty new source does not reopen the contract. Both come as subscription or perpetual.
IBM claims 700 prebuilt integrations and partner extensions, and native support for thousands of Sigma rules. Sigma is an open rule format, so detections kept in it can move with you, a fair hedge for a product whose cloud sibling changed owner. Pilot the integrations for your own firewalls.
No public price and no IBM-hosted edition: the SaaS belongs to Palo Alto, which announced its end of life in April 2025. Playbooks need QRadar SOAR, sold apart. IBM was a Gartner SIEM Leader in 2024; its 2025 placement is unverified. You size, patch and store it all yourself.
Count events per second and flows per minute at today’s peak, and list the sources that must stay on your own hardware.
Weigh the EPS and FPM Usage Model against per-MVS Enterprise licensing, then choose subscription or perpetual terms.
Place hardware or virtual appliances in your Indian data centre, size disk for the retention you need, connect sources.
Load the Sigma rules that match your threats, tune them on a month of your own data, and switch off the noisy ones.
Apply the current fix pack, such as 7.6.0.2, and decide whether QRadar SOAR or X-Force managed services come next.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our regulator wanted security logs on hardware we own. QRadar appliances in our Mumbai data centre settled it early.”
“A new firewall cluster doubled our EPS in a week. Moving to per-MVS licensing ended the true-up arguments for good.”
“Flow records showed a file server talking to an unknown host at 3 a.m.; its logs looked perfectly normal that night.”
“Importing Sigma rules gave our three-person team a head start, though almost every rule needed tuning to our data.”
“The SaaS sale worried our board. The 7.6 release and its Cycle-5 support dates in writing calmed the renewal debate.”
“You own the patching. We slipped one update package and the CVE bulletin landed in the same week as our audit.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the SIEM market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
EPS and FPM, or per MVS; IBM publishes no price.
The grid nobody publishes — how far you can keep the SIEM and its data on your own hardware vs how much of the SOC one licence covers.
Appliances you own; SOAR is a separate product.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSIAM, Securonix and ManageEngine Log360 — on deployment, meters, price, retention, automation and India.
| Dimension | IBM QRadar SIEM | Splunk Enterprise Security | Microsoft Sentinel | Palo Alto Cortex XSIAM | Securonix Unified Defense SIEM | ManageEngine Log360 |
|---|---|---|---|---|---|---|
| What it is | IBM’s on-prem SIEM | Cisco-owned SIEM | Azure-native SIEM | AI-led SecOps platform | Cloud SIEM on Snowflake | Zoho’s unified SIEM |
| Deployment | Appliances, on-prem | Cloud or self-managed | Azure SaaS only | Cloud only | Cloud; no self-host | On-prem or cloud |
| Data it takes in | Events and flows | Any machine data | Microsoft logs free | Whole security estate | Cloud to identity | Servers to cloud apps |
| Pricing model | EPS + FPM, or per MVS | Ingest or workload | Per GB ingested | Data and scope | GB a day, in bands | Per log source |
| Published entry price | Not published | Quote; ~$1,000 GB/day | ~$4.30 per GB | Quote only | No rate card | $300 a year (Basic) |
| Included vs add-on | SOAR sold apart | SOAR is extra | Logic Apps extra | SOAR, TI, ASM in | UEBA and SOAR in | UEBA, workflows in |
| Retention | Your disk decides | Priced by term | 90 days included | Set in the quote | 365 days hot | Your storage on-prem |
| Detection content | Sigma rules native | ESCU, risk alerts | KQL rules, Fusion | AI incident stitching | UEBA plus retro-hunts | Rules, UEBA, Zia |
| Automation | Needs QRadar SOAR | Splunk SOAR, extra | Logic Apps playbooks | Native automation | SOAR in entitlement | Built-in workflows |
| Analyst standing | Leader in 2024 | 11× Leader (2025) | Leader (2025) | No SIEM MQ cited | 6× Leader (2025) | None cited |
| India data location | Your Indian DC | AWS Mumbai or yours | Stored in India | Not documented | BYO-Snowflake in India | Chennai, Mumbai, or own |
| Product status | 7.6.0, support to ~2031 | ES 8.x, Cisco-backed | Portal move by 2027 | QRadar SaaS successor | New CEO, June 2026 | Active, AI added |
| Lock-in and exit | Sigma eases exit | SPL to rewrite | KQL, Azure-bound | Platform commitment | Your Snowflake helps | Zoho estate pull |
| Best fit | Existing QRadar estates | Engineering-heavy SOCs | Microsoft-shaped estates | SOC model rethink | Cloud, year-long hunts | Mid-market, India-built |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
IBM QRadar SIEM is one of 35 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (log sources feeding the SIEM; analyst-hour cost). Estimates model analyst time spent reading logs box by box and assembling audit evidence at an assumed 1.5 hours per log source a year, with 70% of it removed by central collection and correlation. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: IBM licenses QRadar SIEM on a Usage Model (events per second plus flows per minute) or an Enterprise Model (per Managed Virtual Server, with unlimited log ingestion), each as a subscription or perpetual licence, and prints no figure for either. QRadar SOAR is licensed separately. TechBag measures your EPS and flows first, then quotes in INR with GST.
Best for steady, measured volumes
Best for a broader rollout
Best for growing or noisy estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Must logs stay on hardware you own? QRadar SIEM is on-premises only; IBM no longer offers a SaaS edition.
Are volumes steady enough for EPS and FPM, or growing fast enough that per-MVS unlimited ingest is safer?
Subscription or perpetual? Ask for both, itemised in INR with GST, with the support years written in.
Will you deploy 7.6.0, on Support Cycle-5 to about 2031, or stay on 7.5.0 and schedule the upgrade?
Who applies fix packs? CVE-2026-13477 needed 7.6.0.2 or 7.5.0 UP15 IF05; CVE-2025-33141 needed UP16.
Are your firewalls, servers and cloud apps among the 700 integrations IBM claims? Test the top five in a pilot.
Do you need playbooks? Budget QRadar SOAR separately, or ask about IBM X-Force Threat Management Services.
Were you a QRadar SaaS customer? That service now sits with Palo Alto, whose path is Cortex XSIAM, not IBM.
Measure your events and flows first, or let a TechBag advisor compare the Usage and Enterprise models for your estate before IBM quotes.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.