Notifications
Clear all
Topic starter
17/07/2026 12:32 pm
We just moved from Splunk Enterprise Security to IBM's QRadar. Our team is about 200 users, mostly using cloud apps and a few on-prem servers. The switch was driven by cost, but now I'm worried we might have lost some important features.
For a company our size, which platform is actually better for day-to-day threat monitoring? I found Splunk ES alerts very flexible, but the licensing was complex. QRadar seems more bundled, but I'm not sure if it's as good for investigating cloud storage logs. Has anyone else made this change?