IBM Security QRadar SOAR vs. Arcsight by OpenText

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
IBM Security QRadar SOAR
Score 9.3 out of 10
N/A
IBM Security® QRadar® SOAR is designed to help your security team respond to cyberthreats with confidence, automate with intelligence and collaborate with consistency. It guides your team in resolving incidents by codifying established incident response processes into dynamic playbooks.N/A
Arcsight by OpenText
Score 5.2 out of 10
N/A
A combined SIEM and SOAR, used to accelerate threat detection and response with holistic security analytics, native SOAR, and intelligent automation.N/A
Pricing
IBM Security QRadar SOARArcsight by OpenText
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
IBM Security QRadar SOARArcsight by OpenText
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsUsage-based pricing: This simple, scalable option allows starting small with an initial users and capabilities and scaling up as more users are added, as well as capabilities and data. Enterprise-wide pricing: This option is based on either the size of the enterprise-wide IT infrastructure or the size and type of data sources being secured.
More Pricing Information
Community Pulse
IBM Security QRadar SOARArcsight by OpenText
Considered Both Products
IBM Security QRadar SOAR
Chose IBM Security QRadar SOAR
I think both, IBM Security QRadar SOAR and Splunk Enterprise are great tools.
Chose IBM Security QRadar SOAR
We choose IBM Security QRadar SOAR because we were having resource having knowledge of QRadar.
Chose IBM Security QRadar SOAR
IBM Analytics Engine
Chose IBM Security QRadar SOAR
The elasticity of the IBM Security QRadar SOAR solution is what had driven us. We knew that the solution would require nurturing, training over the personnel but once the initial road blocks were destroyed, we went going faster. The other solutions lacked this elasticity, …
Chose IBM Security QRadar SOAR
IBM QRadar SOAR integrates seamlessly with IBM’s QRadar SIEM, making it an excellent choice for organizations that already use IBM's security solutions. This tight integration offers an end-to-end experience in threat detection and response.

Cortex XSOAR integrates well with a …
Chose IBM Security QRadar SOAR
Overall, IBM Security QRadar SOAR offered the same set of functionality that was needed by the organization as offered by Splunk SOAR, but the former is less expensive and solves all the purpose within budget. In addition, integration with other IBM products was easier and made …
Chose IBM Security QRadar SOAR
Better log sourcing
Chose IBM Security QRadar SOAR
I have been able to use other programs and IBM Security QRadar SOAR is able to show me what I was missing with the other programs. I would like to say it is the best that I have had the pleasure of using.
Chose IBM Security QRadar SOAR
I have selected this since we are highly dependent on this tool for our applications in healthcare where 1600+ users are working across the world where we need a high level of security and actions to be taken when it is more vulnerable.
Chose IBM Security QRadar SOAR
IBM QRadar SOAR is more suited for reliability and simpler integrations
Arcsight by OpenText
Chose Arcsight by OpenText
ArcSight Intelligence easily provides visibility to understand the logs and monitor the different devices .have features to manage multiple client with asingle console.searching is little bit hectic but we can mange these thing while using its filter creation process. It costs …
Chose Arcsight by OpenText
We are currently using Elastic search as well for better management of our devices and to keep all the loopholes filled that have been created around the non-upgraded version of Arcsight Enterprise Manager. Elastic searches have the latest mechanism to fetch logs and correlated …
Chose Arcsight by OpenText
Multiple platforms are already supported by Arcsight. Support is good. Scripts can be used to get data from multiple threat intel sources & the same can be used in correlation rules to detect any suspicious activity. Reporting features are good & you can check any backdated …
Chose Arcsight by OpenText
Actually we weren't [in a] decisive situation at that time. We had only a few weeks to make a decision and our firm has good relationships with the HP Support team. That's why I can't compare them all properly, but we searched these 2 different solutions to show differences.
Features
IBM Security QRadar SOARArcsight by OpenText
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
IBM Security QRadar SOAR
-
Ratings
Arcsight by OpenText
5.5
Ratings
34% below category average
Centralized event and log data collection00 Ratings8.00 Ratings
Correlation00 Ratings9.00 Ratings
Event and log normalization/management00 Ratings8.00 Ratings
Deployment flexibility00 Ratings6.00 Ratings
Integration with Identity and Access Management Tools00 Ratings6.00 Ratings
Custom dashboards and workspaces00 Ratings5.00 Ratings
Host and network-based intrusion detection00 Ratings8.00 Ratings
Data integration/API management00 Ratings5.00 Ratings
Behavioral analytics and baselining00 Ratings2.00 Ratings
Rules-based and algorithmic detection thresholds00 Ratings8.00 Ratings
Response orchestration and automation00 Ratings2.00 Ratings
Reporting and compliance management00 Ratings4.00 Ratings
Incident indexing/searching00 Ratings1.00 Ratings
Best Alternatives
IBM Security QRadar SOARArcsight by OpenText
Small Businesses

No answers on this topic

LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.7 out of 10
Medium-sized Companies
Splunk SOAR
Splunk SOAR
Score 9.0 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
Enterprises
Palo Alto Networks Cortex XSOAR
Palo Alto Networks Cortex XSOAR
Score 7.1 out of 10
Sumo Logic
Sumo Logic
Score 9.4 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
IBM Security QRadar SOARArcsight by OpenText
Likelihood to Recommend
8.8
(0 ratings)
9.0
(0 ratings)
Likelihood to Renew
8.0
(0 ratings)
-
(0 ratings)
Usability
5.6
(0 ratings)
7.0
(0 ratings)
Support Rating
6.0
(0 ratings)
8.0
(0 ratings)
Vendor post-sale
7.3
(0 ratings)
-
(0 ratings)
Vendor pre-sale
8.2
(0 ratings)
-
(0 ratings)
User Testimonials
IBM Security QRadar SOARArcsight by OpenText
Likelihood to Recommend
IBM Security QRadar SOAR is particularly useful in guarding againt a phishing event. When a malware downloaded via a phishing email was detected, IBM Security QRadar SOAR was able to automate a response by isolating the infected device, blocking the malicious URL and removing the emails from all the user inbox based on hash signatures identified as attachment.
Read full review
In the current lot of hundreds of SIEM solutions out there in the market, ArcSight ESM is fairly less expensive with strong fundamentals in place. The log ingestion, correlation are very well performing and totally worth ROI. However, the tool has lost its way when it comes to staying abreast with current feature curve of SIEM technology and the evolution has not been done by MicroFocus. Search times are high and there is no major plug-in that has been introduced as part of the product life cycle.
Read full review
Pros
  • Increasing the severity of incidents when threats or outages happened and informing the IT team/management to take action. Our application is a .net one which is a legacy with SQL server. The number of times it is more vulnerable to threats and the action to be taken was identified using this tool.
  • Prior to using this tool, we were informed of threats by IBM customer support and we took action in around 2 to 3 hours to prevent using NOC team support. However, after we deployed this tool we were able to respond quickly based on the action plan provided along with threat level and severities.
  • Prior to deploying this tool, our incidents were provided by IBM customer support with no necessary information on the same. After this tool was installed in our organization, we were able to get the security alerts instantly and take action with the severity level for threats/attacks.
Read full review
  • User friendly interface.
  • Easy to create queries and rules to make all the things automatic.
  • Backup, maintenance and support of this product are always nearly perfect.
Read full review
Cons
  • You still have to generate reports manually. Reports are very limited and practically not useful.
  • The solution should not be SOAR class. Automations usually don't work. It's apparent that it's not designed for that.
  • Lack of flexibility.
  • Practically no support. The reported integration problems have not been resolved.
Read full review
  • ArcSight is a really complex tool, but it's not that easy to implement and maintain.
  • Troubleshooting issues on ArcSight can be hard if you have a large environment.
Read full review
Likelihood to Renew
I'd rate my likelihood of renewing the use of IBM Security QRadar SOAR as an 8 out of 10. Its strong automation, customization, and integration capabilities make it highly valuable for incident response and cybersecurity research. However, occasional complexity and the need for more streamlined usability prevent it from being a perfect score.
Read full review
No answers on this topic
Usability
I would rate IBM Security QRadar SOAR's overall usability a 7 out of 10. The interface is quite functional and offers a wide range of features, but it can be somewhat complex and intimidating for beginners. Additionally, the configuration and customization can require a significant learning curve, especially for those without prior experience with security orchestration and automation platforms.
Read full review
Overall, it is a good investment in order for an organization to stay compliant and stay secure from all the wild things happening. It is definitely a cost effective tool with some good features including correlation, log storage, reporting and dashboards. If a customer is looking for advanced set of features, then I would highly not recommend this.
Read full review
Reliability and Availability
I would rate IBM Security QRadar SOAR's availability as 9 out of 10. The platform is highly reliable, with minimal unplanned outages or application errors, ensuring it’s available when needed. However, occasional minor maintenance periods or rare connectivity issues prevent it from achieving a perfect score in terms of availability.
Read full review
No answers on this topic
Performance
I would rate IBM Security QRadar SOAR's performance as 8 out of 10. Pages generally load quickly, and reports complete in a reasonable time frame, even for complex data. While integration with other systems is smooth, there can be occasional slowdowns when handling very large datasets or during peak usage, which affects the perfect score.
Read full review
No answers on this topic
Support Rating
I would rate IBM Security QRadar SOAR's support an 8 out of 10. The support team is knowledgeable, responsive, and generally provides helpful solutions. However, there can be occasional delays when addressing more complex issues, which prevents it from being a perfect score. Overall, the support experience has been positive.
Read full review
If you go for platinum support, it's good as you have priority for support. They will take remote control of your machines and troubleshoot. Also, they arrange requirement SEM depending on the issue.
Read full review
Implementation Rating
I would rate my satisfaction with the implementation of IBM Security QRadar SOAR as 7 out of 10. The process was generally straightforward, supported by helpful documentation and responsive support. However, certain advanced configurations proved more challenging and required more technical effort than anticipated, making the overall experience less seamless.
Read full review
No answers on this topic
Alternatives Considered
The elasticity of the IBM Security QRadar SOAR solution is what had driven us. We knew that the solution would require nurturing, training over the personnel but once the initial road blocks were destroyed, we went going faster. The other solutions lacked this elasticity, meaning we did not want to work with the things that were given to us but we wanted to make our own playground. We found IBM solution is the only one to provide this answer seamlessly. Also ease-of-integration and native integration with IBM SIEM is another factor of choose on our part.
Read full review
We are currently using Elastic search as well for better management of our devices and to keep all the loopholes filled that have been created around the non-upgraded version of Arcsight Enterprise Manager. Elastic searches have the latest mechanism to fetch logs and correlated data, as well as process them in a more useful way.
Read full review
Scalability
I would rate IBM Security QRadar SOAR's overall scalability as 9 out of 10. It effectively scales to handle large volumes of incidents and can be deployed across multiple departments or sites. Its architecture supports growing data and integration needs, but advanced configuration for larger deployments may require more effort, preventing a perfect score.
Read full review
No answers on this topic
Return on Investment
  • QRadar has significantly enhanced our security posture by enabling us to detect, respond to, and mitigate security threats more effectively.
  • As we expand construction projects, QRadar SOAR has seamlessly scaled with our growing security needs. We haven't needed to invest in additional security personnel at the same rate as our project expansion, resulting in cost savings and efficient resource allocation.
Read full review
  • It is recommended for handle small enterprises.
  • Cant integrate any threat intel tool so we majorly works through filters.
  • It is slow takes time for large searches.
Read full review
ScreenShots

IBM Security QRadar SOAR Screenshots

Screenshot of the IBM Security QRadar SOAR Breach Response solution. The software helps customers manage more than 180 global privacy reporting regulations including GDPR.Screenshot of the Playbooks Landing page, that shows all active playbooks in a single view, including how many are actively running, disabled, or are in draft.Screenshot of IBM Security QRadar SOAR’s Playbook Designer canvas, designed to lower the barrier to entry necessary to build automations through a graphical interface.Screenshot of the Tasks view shows all response tasks, organized by phase, that have either completed or are set to be executed.Screenshot of Threat Investigator automatically correlates incident information, curating an incident timeline from start to finish, including related artifacts and MITRE ATT&CK mappings.