IBM Security QRadar SIEM vs. LevelBlue USM Anywhere

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
IBM Security QRadar SIEM
Score 8.7 out of 10
N/A
IBM Security QRadar is security information and event management (SIEM) Software.N/A
LevelBlue USM Anywhere
Score 7.5 out of 10
N/A
The LevelBlue USM Anywhere XDR platform (replacing the former AlienVault USM) delivers threat detection, incident response, and compliance management.
$1,075
per month
Pricing
IBM Security QRadar SIEMLevelBlue USM Anywhere
Editions & Modules
No answers on this topic
Essentials
$1,075
per month
Standard
$1,695
per month
Premium
$2,595
per month
Offerings
Pricing Offerings
IBM Security QRadar SIEMLevelBlue USM Anywhere
Free Trial
YesYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
NoYes
Entry-level Setup FeeNo setup feeOptional
Additional Details
More Pricing Information
Community Pulse
IBM Security QRadar SIEMLevelBlue USM Anywhere
Considered Both Products
IBM Security QRadar SIEM
Chose IBM Security QRadar SIEM
With IBM supplying this solution, you're inherently getting the globally recognized IBM support environment as well. As an enterprise solution, Qradar is among stiff competition but the reliability and availability make it a cut above the rest. While I also recommend …
LevelBlue USM Anywhere
Chose LevelBlue USM Anywhere
AlienVault USM offers a user-friendly interface and comprehensive features at a lower cost compared to QRadar, making it our preferred choice for effective threat detection and response.
Chose LevelBlue USM Anywhere
Easy to deploy and ease of use, good training by ATT
Chose LevelBlue USM Anywhere
QRadar is one of the top SIEMs on the market. AlienVault USM is more suitable for companies or clients having a smaller budget, as AlienVault USM is cheaper than QRadar. Regarding features, QRadar trumps AlienVault USM, as it is a product with a vast array of features.
Chose LevelBlue USM Anywhere
AlienVault USM is considerably more user-friendly, but it does fall short with the search functionality that a query language offers when looking for specific logs/statistics/data.
Chose LevelBlue USM Anywhere
The price and the ease-of-use, and the support from AlienVault are better. I had a lot of trouble starting out, but they guided me very well. The training provided by AlienVault was fantastic, because I could play without the fear of breaking anything.
Chose LevelBlue USM Anywhere
I didn't select either product but I have used both. I suspect IBM QRadar is more expensive, however, it is also more responsive, includes support for e-streamer, does parse the "blocked" field in source fire logs, and includes UEBA.
Chose LevelBlue USM Anywhere
Compared to the main competitor's products, the AlienVault USM is particularly good in terms of cost effectiveness. Your company does not need to spend a huge amount of money in the first place just to test out the result. By using AlienVault USM, you can also get great support …
Chose LevelBlue USM Anywhere
AlienVault USM is particularly outperforming the competitors in terms of security threats detection. However, like all the other tools, it does not automatically do the thing that you want to do. But with correctly setting up the rules and properly tuning the tool, it can …
Chose LevelBlue USM Anywhere
The tool works well compared with the two others. As I said previously, AlienVault USM gives you a lot of visibility right out of the box and with very little configuration.

However, I like the ability to customize pieces, such as log parsers and dashboards, as I see fit without …
Chose LevelBlue USM Anywhere
Alienvault was the most aggressive in their pricing and marketing of ease of deployment. The ease of deployment was what really aided in their ability to win our business. The ROI was worth the investment for our security at the time. Also being a market leader aided in our …
Chose LevelBlue USM Anywhere
AlienVault USM is more affordable than the other solutions and much easier to deploy and maintain.
Chose LevelBlue USM Anywhere
We selected AlienVault USM because it was a lot less expensive than many other SIEM tools in the marketplace.
Chose LevelBlue USM Anywhere
Honestly, pricing is the main reason. AlienVault was already purchased when I was hired as Director, and the company did not have enough budget for anything else. Implementation was subpar, very disappointing, and renewal was a nightmare.
Chose LevelBlue USM Anywhere
With the exception of Solar Winds, AlienVault USM is far easier to administer and support, but far less extensible. LogRhythm and Splunk are going to offer far more advanced capabilities in the way of deployment models, features, and automation capabilities. Also, other …
Chose LevelBlue USM Anywhere
AlienVault was the cheapest solution compared with the competition and had similar or better features. Also, the SaaS based solution made it easy to deploy the solution without the need to maintain additional servers on premise. It was very easy to use and had a great UI which …
Chose LevelBlue USM Anywhere
SIEM vendors are having to adapt and thus it is difficult to perform a true apples-to-apples comparison between all the vendors. They offer different features and can even take different approaches to solving the logging and SIEM issue. Still, with that consideration in mind, …
Chose LevelBlue USM Anywhere
Though IBM QRadar is a good product, it is not easy to manage and maintain. It's too bulky to understand and manage. The correlation rules are also not easy to work with. AlienVault has great support and knowledge. The community strength derived from being open source gives …
Chose LevelBlue USM Anywhere
Both of the products I have used in the past were much more medium-large sized businesses. They both had functionalities which are helpful from a trending perspective, have better reporting, and a much more involved user base. The cost of these are prohibitive compared to …
Chose LevelBlue USM Anywhere
While they have a comparable range of features and functionality as SIEM's, QRadar was built to be a SIEM first and foremost where AlienVault USM has amore rounded all-inclusive set of features. Despite having more elements, AlienVault USM Anywhere is the more intuitive and …
Chose LevelBlue USM Anywhere
IBM QRadar - long and clunky installation process, after which we weren't blown away by the tired and over-complicated user interface - wasn't a good fit for us.
InsightIDR - disappointing engagement with their sales team, who weren't able to answer surface-level questions about …
Chose LevelBlue USM Anywhere
For us it came down to cost. AlienVault's competitors just could not compare on cost for a small organization like us. They are out of touch. Everyone needs a solid tool like AlienVault, but too often the industry only caters to big budgets. More often than not, that results in …
Chose LevelBlue USM Anywhere
Being able to integrate multiple uses into a single appliance is a great win for small and medium enterprises. The cost for the single solution also ends up being in reach for the SME vs. some of the other available solutions.
Chose LevelBlue USM Anywhere
Comparisons with other products can be tricky, since AlienVault packs a lot into its product, and that essentially is its main strength vs. the competition. For people just looking for SIEM like functionality it is definitely compatible to other products, but some of the …
Chose LevelBlue USM Anywhere
AlienVault Unified Security Management is a budget-friendly solution to a typical SIEM implementation. Although it is not as robust and well known as others, my organization decided to purchase AlienVault due to the cost savings and user-friendly interface that is available out …
Features
IBM Security QRadar SIEMLevelBlue USM Anywhere
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
IBM Security QRadar SIEM
8.6
69 Ratings
9% above category average
LevelBlue USM Anywhere
-
Ratings
Centralized event and log data collection9.927 Ratings00 Ratings
Correlation8.769 Ratings00 Ratings
Event and log normalization/management9.527 Ratings00 Ratings
Deployment flexibility7.827 Ratings00 Ratings
Integration with Identity and Access Management Tools8.865 Ratings00 Ratings
Custom dashboards and workspaces7.469 Ratings00 Ratings
Host and network-based intrusion detection9.725 Ratings00 Ratings
Data integration/API management9.07 Ratings00 Ratings
Behavioral analytics and baselining7.748 Ratings00 Ratings
Rules-based and algorithmic detection thresholds8.149 Ratings00 Ratings
Response orchestration and automation7.75 Ratings00 Ratings
Reporting and compliance management8.047 Ratings00 Ratings
Incident indexing/searching8.97 Ratings00 Ratings
Best Alternatives
IBM Security QRadar SIEMLevelBlue USM Anywhere
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 7.5 out of 10
SentinelOne Singularity
SentinelOne Singularity
Score 8.9 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 8.8 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 8.8 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
IBM Security QRadar SIEMLevelBlue USM Anywhere
Likelihood to Recommend
8.4
(89 ratings)
9.7
(390 ratings)
Likelihood to Renew
8.4
(5 ratings)
7.2
(18 ratings)
Usability
8.1
(2 ratings)
6.7
(34 ratings)
Availability
9.0
(1 ratings)
6.4
(3 ratings)
Performance
9.0
(1 ratings)
7.3
(3 ratings)
Support Rating
8.1
(62 ratings)
7.3
(25 ratings)
In-Person Training
9.0
(1 ratings)
4.5
(1 ratings)
Online Training
9.0
(1 ratings)
8.3
(6 ratings)
Implementation Rating
8.0
(1 ratings)
6.4
(38 ratings)
Configurability
8.0
(1 ratings)
8.0
(3 ratings)
Contract Terms and Pricing Model
9.0
(1 ratings)
-
(0 ratings)
Ease of integration
8.0
(58 ratings)
7.3
(3 ratings)
Product Scalability
8.0
(1 ratings)
6.3
(3 ratings)
Professional Services
10.0
(1 ratings)
-
(0 ratings)
Vendor post-sale
9.0
(1 ratings)
7.6
(3 ratings)
Vendor pre-sale
9.0
(1 ratings)
8.2
(3 ratings)
User Testimonials
IBM Security QRadar SIEMLevelBlue USM Anywhere
Likelihood to Recommend
IBM
I would only recommend IBM Security QRadar SIEM in a few situations. For one, it's very easy to setup and use if all your log sources are generic from known vendors. It's also significantly cheaper than Splunk, which is nice if you're trying to save money or be more efficient. I would not recommend IBM Security QRadar SIEM for environments with a lot of custom logs and complicated detection requirements.
Read full review
LevelBlue
At this point I'm saying a 4. While the marketing material make it appear to be easy to use and it was relatively easy to set up, as previously mentioned, each event description is based upon the individual asset making it nearly impossible for the administrator to be a SME for each asset. For example, if one of the assets reporting is a router, the administrator monitoring alerts would need to know what the various events are that can be triggered as an event for the particular router; however, if the asset is a workstation, the administrator would need to know the various events that are triggered for workstations.
Read full review
Pros
IBM
  • Enables identification and prioritization of vulnerabilities in IT infrastructure for corrective action.
  • Facilitates security incident investigation and forensic analysis.
  • Provides a real-time view of security events, enabling immediate incident response.
  • Can integrate with external threat intelligence sources to enrich data and improve threat detection.
  • Enables the generation of detailed and customized reports.
Read full review
LevelBlue
  • AlienVault USM is simple and easy to deploy. Sensors can be deployed in as little as 15 minutes through the setup wizard.
  • The USM UI is easy to understand. I've trained multiple analysts who are able to perform their duties on their first day, in part because of USM Anywhere's ease of use.
  • Top-notch built-in compliance templates and reporting features.
Read full review
Cons
IBM
  • Need to spend more time configuring the system to properly interpret and normalize different type of data collected from multiple resources.
  • While Rule creation QRadar uses that rules to detect security threats and generate alerts, but to creating and managing rules is bit complex & tedious work to complete.
  • IBM Security QRadar SIEM is excellent in handling large & complex systems that requires in-depth knowledge and extensive training to configure and maintain the system which includes upgrading, optimization of performance & issue troubleshooting.
Read full review
LevelBlue
  • Personally, I've wished I could purchase a service that would configure AV for my environment. I get a lot of traffic on a daily basis and I almost need to hire an analyst that just works on AV.
  • Some of the filters when looking for a specific alert aren't that easy to use.
Read full review
Likelihood to Renew
IBM
QRadar is an established and stable product, we have been using it for many years and want to continue to focus on it. Anyone who has used the product and knows it knows how reliable it is and how it facilitates continuous monitoring of threats from outside and inside. it is an exceptional product that is very useful for us.
Read full review
LevelBlue
The centralized logging and retention for PCI compliance was our main driver, and it is meeting that need. Otherwise there has been enough frustration with the lack of documentation and the need to customize through the CLI that I would be open to alternatives.
Read full review
Usability
IBM
As a grade I give 8 as QRadar is not easy to learn. It requires some time to master it. It also needs a team of people actively working on the product. Once you learn to use it the software works very well and it is easy to correlate and understand detected threats. It only takes time to learn how to use it well and configure it properly.
Read full review
LevelBlue
Once you are able to navigate the different panels, finding what you need is quite easily. Before getting used it it can be a bit of challenge . Each panel is quite well laid out and the filtering search capabilities are quite strong.
Read full review
Reliability and Availability
IBM
No answers on this topic
LevelBlue
We do have issues with maintenance on the AlienVault USM as the disk fills up from time to time with other data sources. Sources for scanning logs and net flow data isn't calculated in regular disk maintenance and can easily fill up our disk if we do not keep an eye on it with some custom Nagios plugins. The system does properly trim logging data from logging sources properly.
Read full review
Performance
IBM
No answers on this topic
LevelBlue
With the latest release of AlienVault USM overall performance has not been an issue. We have noticed single source events per second does not scale well with the overall system. 2,000eps on a vmware system with a single source produces delays of up to an hour for us. Pages, reporting and even raw log searches are rather quick though.
Read full review
Support Rating
IBM
Customer support is Good of IBM, While Using IBM QRadar its deployment is to slow and suddenly stop working and crashed we have contacted IBM Support and Rised a Ticket within a few minute we get call back from customer support and Query Resolved by them Fast And Rapid Support of Ibm
Read full review
LevelBlue
The support we received from alienvault was excellent. They went above and beyond in making sure everything was working as it needed to be. They REALLY want their product implementation to be a success and our security goals be achieved. They are like a member of our security team.
Read full review
In-Person Training
IBM
The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
Read full review
LevelBlue
I did not have any experience with "in person" training directly. The free online classes offered for a half a day are based on the actual training offered. These little teasers are very good and well worth your time to learn a few quick and dirty ways of getting more information from your SIEM
Read full review
Online Training
IBM
The training was very useful and the people who taught us were very knowledgeable. Although the software may initially seem difficult to learn they made things much easier for us.
Read full review
LevelBlue
It was very well organized and helpful in using the product to the fullest extent. The instructor allowed time for folks who were involved with managed services to receive tuning tips in order to better support their customers. In addition, the course materials were automatically updated when the new version came out.
Read full review
Implementation Rating
IBM
Initial patience is required to learn how to use the product, and it takes a dedicated team to use it. One person is not enough, and it's not enough to just set it up and check it once in a while. It has to be used daily and kept under control to be used effectively
Read full review
LevelBlue
AlienVault USM was a very simple to implement and get up and running. We started with a trial version and had that up and going within an hour of receiving email instructions from the sales engineer. We never had to contact support to get the system up and going. It was extremely easy to convert over to a full license once we started with a paid version.
Read full review
Alternatives Considered
IBM
IBM Qradar takes the best from its competitors. Reliable and stable but sometimes very expensive, the SIEM from IBM offers a wide range of scenarios in which the customers can suite and size their own infrastructures. IBM Qradar doesn't really needs to stack up againt its competitors because it already sets an example in the SIEM world.
Read full review
LevelBlue
Splunk's ES is a paid add-on on top of an already pricey product. Finding a MSSP that supports Splunk and isn't a 6 figure annual commitment seems unlikely. LogRhythm did not have a cloud-based solution when we were considering SIEMs. Fantastic product though and have a good MSSP base. Devo did not have a MSSP partner base when we looked. Their product is fantastic too. AlienVault USM has good partners to choose from as well as an affordable cloud model, that's why we chose it.
Read full review
Scalability
IBM
No answers on this topic
LevelBlue
The AlienVault USM is not very scalable. Some scalability can be achieved by installing additional sensors, but this only offers 500eps per sensor and is still overall limited by the installation type of VM or physical. We have also noticed the EPS (events per second) is rated overall and not towards a single source. A single source on a very healthy VMware partition tops out at 2,000eps for us, no matter how we configure it. Maybe this is a problem of the 5.2 release?
Read full review
Return on Investment
IBM
  • Offense investigation was really helped in tackling the incidents. It was accurate and brief
  • The automation with IBM resilient (SOAR) was a milestone in elimination of user mistakes
  • The X-Force threat intelligence supported us in getting the work done without any 3rd party enterprise OSINT database
Read full review
LevelBlue
  • Once you hit the 150 asset mark, you have to jump to their unlimited license. There is no middle ground. We were only 10 or so assets above the 150 so we had to chose to either not monitor those assets or pay the price of the upgrade.
  • AlienVault brings all the information to one place which makes it much quicker to track down problems.
Read full review
ScreenShots

IBM Security QRadar SIEM Screenshots

Screenshot of QRadar SIEM Cloud native- Threat intelligence preview