TrustRadius: an HG Insights company

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    IBM Security QRadar SIEM

    Score8.9 out of 10
    N/AIBM Security QRadar is security information and event management (SIEM) Software.N/A

    LevelBlue USM Anywhere

    Score8.4 out of 10
    N/AThe LevelBlue USM Anywhere XDR platform (replacing the former AlienVault USM) delivers threat detection, incident response, and compliance management.

    $1,075

    per month

    Pricing
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Editions & Modules
    No answers on this topic
    Essentials
    $1,075
    per month
    Standard
    $1,695
    per month
    Premium
    $2,595
    per month
    Offerings
    Pricing Offerings
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Free Trial
    YesYes
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    NoYes
    Entry-level Setup FeeNo setup feeOptional
    Additional Details
    More Pricing Information
    Community Pulse
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Considered Both Products
    IBM
    Chose IBM Security QRadar SIEM
    With IBM supplying this solution, you're inherently getting the globally recognized IBM support environment as well. As an enterprise solution, Qradar is among stiff competition but the reliability and availability make it a cut above the rest. While I also recommend …
    Incentivized
    LevelBlue
    Chose LevelBlue USM Anywhere
    AlienVault USM offers a user-friendly interface and comprehensive features at a lower cost compared to QRadar, making it our preferred choice for effective threat detection and response.
    Incentivized
    Chose LevelBlue USM Anywhere
    Easy to deploy and ease of use, good training by ATT
    Incentivized
    Chose LevelBlue USM Anywhere
    QRadar is one of the top SIEMs on the market. AlienVault USM is more suitable for companies or clients having a smaller budget, as AlienVault USM is cheaper than QRadar. Regarding features, QRadar trumps AlienVault USM, as it is a product with a vast array of features.
    Incentivized
    Chose LevelBlue USM Anywhere
    AlienVault USM is considerably more user-friendly, but it does fall short with the search functionality that a query language offers when looking for specific logs/statistics/data.
    Incentivized
    Chose LevelBlue USM Anywhere
    The price and the ease-of-use, and the support from AlienVault are better. I had a lot of trouble starting out, but they guided me very well. The training provided by AlienVault was fantastic, because I could play without the fear of breaking anything.
    Incentivized
    Chose LevelBlue USM Anywhere
    I didn't select either product but I have used both. I suspect IBM QRadar is more expensive, however, it is also more responsive, includes support for e-streamer, does parse the "blocked" field in source fire logs, and includes UEBA.
    Incentivized
    Chose LevelBlue USM Anywhere
    Compared to the main competitor's products, the AlienVault USM is particularly good in terms of cost effectiveness. Your company does not need to spend a huge amount of money in the first place just to test out the result. By using AlienVault USM, you can also get great support …
    Incentivized
    Chose LevelBlue USM Anywhere
    AlienVault USM is particularly outperforming the competitors in terms of security threats detection. However, like all the other tools, it does not automatically do the thing that you want to do. But with correctly setting up the rules and properly tuning the tool, it can …
    Incentivized
    Chose LevelBlue USM Anywhere
    The tool works well compared with the two others. As I said previously, AlienVault USM gives you a lot of visibility right out of the box and with very little configuration.

    However, I like the ability to customize pieces, such as log parsers and dashboards, as I see fit without …
    Incentivized
    Chose LevelBlue USM Anywhere
    Alienvault was the most aggressive in their pricing and marketing of ease of deployment. The ease of deployment was what really aided in their ability to win our business. The ROI was worth the investment for our security at the time. Also being a market leader aided in our …
    Incentivized
    Chose LevelBlue USM Anywhere
    AlienVault USM is more affordable than the other solutions and much easier to deploy and maintain.
    Incentivized
    Chose LevelBlue USM Anywhere
    We selected AlienVault USM because it was a lot less expensive than many other SIEM tools in the marketplace.
    Incentivized
    Chose LevelBlue USM Anywhere
    Honestly, pricing is the main reason. AlienVault was already purchased when I was hired as Director, and the company did not have enough budget for anything else. Implementation was subpar, very disappointing, and renewal was a nightmare.
    Incentivized
    Chose LevelBlue USM Anywhere
    With the exception of Solar Winds, AlienVault USM is far easier to administer and support, but far less extensible. LogRhythm and Splunk are going to offer far more advanced capabilities in the way of deployment models, features, and automation capabilities. Also, other …
    Incentivized
    Chose LevelBlue USM Anywhere
    AlienVault was the cheapest solution compared with the competition and had similar or better features. Also, the SaaS based solution made it easy to deploy the solution without the need to maintain additional servers on premise. It was very easy to use and had a great UI which …
    Incentivized
    Chose LevelBlue USM Anywhere
    SIEM vendors are having to adapt and thus it is difficult to perform a true apples-to-apples comparison between all the vendors. They offer different features and can even take different approaches to solving the logging and SIEM issue. Still, with that consideration in mind, …
    Incentivized
    Chose LevelBlue USM Anywhere
    Though IBM QRadar is a good product, it is not easy to manage and maintain. It's too bulky to understand and manage. The correlation rules are also not easy to work with. AlienVault has great support and knowledge. The community strength derived from being open source gives …
    Incentivized
    Chose LevelBlue USM Anywhere
    Both of the products I have used in the past were much more medium-large sized businesses. They both had functionalities which are helpful from a trending perspective, have better reporting, and a much more involved user base. The cost of these are prohibitive compared to …
    Incentivized
    Chose LevelBlue USM Anywhere
    While they have a comparable range of features and functionality as SIEM's, QRadar was built to be a SIEM first and foremost where AlienVault USM has amore rounded all-inclusive set of features. Despite having more elements, AlienVault USM Anywhere is the more intuitive and …
    Incentivized
    Chose LevelBlue USM Anywhere
    IBM QRadar - long and clunky installation process, after which we weren't blown away by the tired and over-complicated user interface - wasn't a good fit for us.
    InsightIDR - disappointing engagement with their sales team, who weren't able to answer surface-level questions about …
    Incentivized
    Chose LevelBlue USM Anywhere
    For us it came down to cost. AlienVault's competitors just could not compare on cost for a small organization like us. They are out of touch. Everyone needs a solid tool like AlienVault, but too often the industry only caters to big budgets. More often than not, that results in …
    Incentivized
    Chose LevelBlue USM Anywhere
    Being able to integrate multiple uses into a single appliance is a great win for small and medium enterprises. The cost for the single solution also ends up being in reach for the SME vs. some of the other available solutions.
    Incentivized
    Chose LevelBlue USM Anywhere
    The combination of price, performance and third-party reviews.
    Incentivized
    Chose LevelBlue USM Anywhere
    AlienVault may be slightly less refined when compared to other enterprise offerings. But in our testing, we found either the cost, licensing model, learning curve, or any combination of the three, made AlienVault's competitors not appropriate for our environment. Over the past …
    Incentivized
    Key User Insights
    Would buy again
    92%
    Would buy again
    67 Answers
    86%
    Would buy again
    6 Answers
    Delivers good value for the price
    97%
    Delivers good value for the price
    61 Answers
    100%
    Delivers good value for the price
    6 Answers
    Happy with the feature set
    96%
    Happy with the feature set
    70 Answers
    100%
    Happy with the feature set
    7 Answers
    Lived up to sales and marketing promises
    86%
    Lived up to sales and marketing promises
    38 Answers
    No answers on this topic
    Implementation went as expected
    94%
    Implementation went as expected
    59 Answers
    86%
    Implementation went as expected
    6 Answers
    Features
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Security Information and Event Management (SIEM)
    Comparison of Security Information and Event Management (SIEM) features of IBM Security QRadar SIEM and LevelBlue USM Anywhere
    Feature
    IBM Security QRadar SIEM
    8.5
    69 Ratings
    7% above category average
    LevelBlue USM Anywhere
    -
    Ratings
    Centralized event and log data collection9.927 Ratings00 Ratings
    Correlation8.669 Ratings00 Ratings
    Event and log normalization/management9.527 Ratings00 Ratings
    Deployment flexibility7.827 Ratings00 Ratings
    Integration with Identity and Access Management Tools8.965 Ratings00 Ratings
    Custom dashboards and workspaces7.569 Ratings00 Ratings
    Host and network-based intrusion detection9.725 Ratings00 Ratings
    Data integration/API management9.07 Ratings00 Ratings
    Behavioral analytics and baselining7.648 Ratings00 Ratings
    Rules-based and algorithmic detection thresholds8.049 Ratings00 Ratings
    Response orchestration and automation7.75 Ratings00 Ratings
    Reporting and compliance management7.947 Ratings00 Ratings
    Incident indexing/searching8.97 Ratings00 Ratings
    Best Alternatives
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Small Businesses
    No answers on this topic
    Microsoft Defender XDR
    Score8.7 out of 10
    Medium-sized Companies
    Sumo Logic
    Score8.9 out of 10
    InsightIDR
    Score8.5 out of 10
    Enterprises
    SolarWinds Security Event Manager (SEM)
    Score8 out of 10
    Microsoft Defender XDR
    Score8.7 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Likelihood to Recommend
    8.6
    (89 ratings)
    9.8
    (390 ratings)
    Likelihood to Renew
    8.8
    (5 ratings)
    7.2
    (18 ratings)
    Usability
    8.0
    (2 ratings)
    6.7
    (34 ratings)
    Availability
    9.0
    (1 ratings)
    6.4
    (3 ratings)
    Performance
    9.0
    (1 ratings)
    7.3
    (3 ratings)
    Support Rating
    8.1
    (62 ratings)
    7.3
    (25 ratings)
    In-Person Training
    9.0
    (1 ratings)
    4.5
    (1 ratings)
    Online Training
    9.0
    (1 ratings)
    8.3
    (6 ratings)
    Implementation Rating
    8.0
    (1 ratings)
    6.4
    (38 ratings)
    Configurability
    8.0
    (1 ratings)
    8.0
    (3 ratings)
    Contract Terms and Pricing Model
    9.0
    (1 ratings)
    -
    (0 ratings)
    Ease of integration
    8.1
    (58 ratings)
    7.3
    (3 ratings)
    Product Scalability
    8.0
    (1 ratings)
    6.3
    (3 ratings)
    Professional Services
    10.0
    (1 ratings)
    -
    (0 ratings)
    Vendor post-sale
    9.0
    (1 ratings)
    7.6
    (3 ratings)
    Vendor pre-sale
    9.0
    (1 ratings)
    8.2
    (3 ratings)
    User Testimonials
    IBM Security QRadar SIEMLevelBlue USM Anywhere
    Likelihood to Recommend
    IBM
    I would only recommend IBM Security QRadar SIEM in a few situations. For one, it's very easy to setup and use if all your log sources are generic from known vendors. It's also significantly cheaper than Splunk, which is nice if you're trying to save money or be more efficient. I would not recommend IBM Security QRadar SIEM for environments with a lot of custom logs and complicated detection requirements.
    Incentivized
    Read full review
    LevelBlue
    At this point I'm saying a 4. While the marketing material make it appear to be easy to use and it was relatively easy to set up, as previously mentioned, each event description is based upon the individual asset making it nearly impossible for the administrator to be a SME for each asset. For example, if one of the assets reporting is a router, the administrator monitoring alerts would need to know what the various events are that can be triggered as an event for the particular router; however, if the asset is a workstation, the administrator would need to know the various events that are triggered for workstations.
    Incentivized
    Read full review
    Pros
    IBM
    • Enables identification and prioritization of vulnerabilities in IT infrastructure for corrective action.
    • Facilitates security incident investigation and forensic analysis.
    • Provides a real-time view of security events, enabling immediate incident response.
    • Can integrate with external threat intelligence sources to enrich data and improve threat detection.
    • Enables the generation of detailed and customized reports.
    Incentivized
    Read full review
    LevelBlue
    • AlienVault USM is simple and easy to deploy. Sensors can be deployed in as little as 15 minutes through the setup wizard.
    • The USM UI is easy to understand. I've trained multiple analysts who are able to perform their duties on their first day, in part because of USM Anywhere's ease of use.
    • Top-notch built-in compliance templates and reporting features.
    Incentivized
    Read full review
    Cons
    IBM
    • Need to spend more time configuring the system to properly interpret and normalize different type of data collected from multiple resources.
    • While Rule creation QRadar uses that rules to detect security threats and generate alerts, but to creating and managing rules is bit complex & tedious work to complete.
    • IBM Security QRadar SIEM is excellent in handling large & complex systems that requires in-depth knowledge and extensive training to configure and maintain the system which includes upgrading, optimization of performance & issue troubleshooting.
    Incentivized
    Read full review
    LevelBlue
    • Personally, I've wished I could purchase a service that would configure AV for my environment. I get a lot of traffic on a daily basis and I almost need to hire an analyst that just works on AV.
    • Some of the filters when looking for a specific alert aren't that easy to use.
    Incentivized
    Read full review
    Likelihood to Renew
    IBM
    QRadar is an established and stable product, we have been using it for many years and want to continue to focus on it. Anyone who has used the product and knows it knows how reliable it is and how it facilitates continuous monitoring of threats from outside and inside. it is an exceptional product that is very useful for us.
    Incentivized
    Read full review
    LevelBlue
    The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
    Incentivized
    Read full review
    Usability
    IBM
    As a grade I give 8 as QRadar is not easy to learn. It requires some time to master it. It also needs a team of people actively working on the product. Once you learn to use it the software works very well and it is easy to correlate and understand detected threats. It only takes time to learn how to use it well and configure it properly.
    Incentivized
    Read full review
    LevelBlue
    Once you are able to navigate the different panels, finding what you need is quite easily. Before getting used it it can be a bit of challenge . Each panel is quite well laid out and the filtering search capabilities are quite strong.
    Incentivized
    Read full review
    Reliability and Availability
    IBM
    No answers on this topic
    LevelBlue
    We do have issues with maintenance on the AlienVault USM as the disk fills up from time to time with other data sources. Sources for scanning logs and net flow data isn't calculated in regular disk maintenance and can easily fill up our disk if we do not keep an eye on it with some custom Nagios plugins. The system does properly trim logging data from logging sources properly.
    Incentivized
    Read full review
    Performance
    IBM
    No answers on this topic
    LevelBlue
    With the latest release of AlienVault USM overall performance has not been an issue. We have noticed single source events per second does not scale well with the overall system. 2,000eps on a vmware system with a single source produces delays of up to an hour for us. Pages, reporting and even raw log searches are rather quick though.
    Incentivized
    Read full review
    Support Rating
    IBM
    Customer support is Good of IBM, While Using IBM QRadar its deployment is to slow and suddenly stop working and crashed we have contacted IBM Support and Rised a Ticket within a few minute we get call back from customer support and Query Resolved by them Fast And Rapid Support of Ibm
    Incentivized
    Read full review
    LevelBlue
    The support we received from alienvault was excellent. They went above and beyond in making sure everything was working as it needed to be. They REALLY want their product implementation to be a success and our security goals be achieved. They are like a member of our security team.
    Incentivized
    Read full review
    In-Person Training
    IBM
    The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
    Incentivized
    Read full review
    LevelBlue
    I did not have any experience with "in person" training directly. The free online classes offered for a half a day are based on the actual training offered. These little teasers are very good and well worth your time to learn a few quick and dirty ways of getting more information from your SIEM
    Incentivized
    Read full review
    Online Training
    IBM
    The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
    Incentivized
    Read full review
    LevelBlue
    It was very well organized and helpful in using the product to the fullest extent. The instructor allowed time for folks who were involved with managed services to receive tuning tips in order to better support their customers. In addition, the course materials were automatically updated when the new version came out.
    Incentivized
    Read full review
    Implementation Rating
    IBM
    Initial patience is required to learn how to use the product, and it takes a dedicated team to use it. One person is not enough, and it's not enough to just set it up and check it once in a while. It has to be used daily and kept under control to be used effectively
    Incentivized
    Read full review
    LevelBlue
    AlienVault USM was a very simple to implement and get up and running. We started with a trial version and had that up and going within an hour of receiving email instructions from the sales engineer. We never had to contact support to get the system up and going. It was extremely easy to convert over to a full license once we started with a paid version.
    Incentivized
    Read full review
    Alternatives Considered
    IBM
    IBM Qradar takes the best from its competitors. Reliable and stable but sometimes very expensive, the SIEM from IBM offers a wide range of scenarios in which the customers can suite and size their own infrastructures. IBM Qradar doesn't really needs to stack up againt its competitors because it already sets an example in the SIEM world.
    Incentivized
    Read full review
    LevelBlue
    Splunk's ES is a paid add-on on top of an already pricey product. Finding a MSSP that supports Splunk and isn't a 6 figure annual commitment seems unlikely. LogRhythm did not have a cloud-based solution when we were considering SIEMs. Fantastic product though and have a good MSSP base. Devo did not have a MSSP partner base when we looked. Their product is fantastic too. AlienVault USM has good partners to choose from as well as an affordable cloud model, that's why we chose it.
    Incentivized
    Read full review
    Scalability
    IBM
    No answers on this topic
    LevelBlue
    The AlienVault USM is not very scalable. Some scalability can be achieved by installing additional sensors, but this only offers 500eps per sensor and is still overall limited by the installation type of VM or physical. We have also noticed the EPS (events per second) is rated overall and not towards a single source. A single source on a very healthy VMware partition tops out at 2,000eps for us, no matter how we configure it. Maybe this is a problem of the 5.2 release?
    Incentivized
    Read full review
    Return on Investment
    IBM
    • Offense investigation was really helped in tackling the incidents. It was accurate and brief
    • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
    • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
    Incentivized
    Read full review
    LevelBlue
    • Once you hit the 150 asset mark, you have to jump to their unlimited license. There is no middle ground. We were only 10 or so assets above the 150 so we had to chose to either not monitor those assets or pay the price of the upgrade.
    • AlienVault brings all the information to one place which makes it much quicker to track down problems.
    Incentivized
    Read full review
    ScreenShots

    IBM Security QRadar SIEM Screenshots

    Screenshot of QRadar SIEM Cloud native- Threat intelligence preview