IBM QRadar vs Splunk cost: 2026 EPS-vs-GB comparison
Independent head-to-head cost comparison. Per-EPS QRadar versus per-GB Splunk at five environment profiles, EPS-to-GB conversion math, five-year TCO, and where each vendor genuinely wins on compliance and depth. Splunk baseline corrected against 2026 pricing; QRadar figures are estimates (IBM publishes no list price). Updated August 2026.
Per-EPS versus per-GB: how the meters collide
QRadar and Splunk priced their products around different historical realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered. Both pricing models survived because they roughly track the underlying cost driver, but they make direct cross-shop comparisons require a conversion step. The honest conversion sits at approximately 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.
The conversion varies materially with source mix. Windows event logs average 60-80 EPS per GB. Firewall and NetFlow data run 200-400 EPS per GB. SaaS audit logs run 30-50 EPS per GB. EDR telemetry averages 100-150 EPS per GB. Sampling actual environment EPS over 60 days before any vendor comparison is essential discipline; assumed conversions routinely produce wrong vendor decisions. Customers who sign QRadar contracts based on assumed EPS-to-GB conversion frequently under-buy capacity and pay overage rates; customers who sign Splunk contracts based on assumed conversion routinely over-buy ingest capacity that they never use.
The comparison changed in 2026 as Splunk Cloud's effective pricing settled well below its old list reputation: roughly $50K base ingest at 50 GB per day, and about $100K all-in once Enterprise Security is added (Enterprise Security roughly doubles the base). We cannot put a QRadar figure beside that. IBM publishes no list price for QRadar on any channel, and the only public QRadar price anywhere is an AWS Marketplace contract covering 500 EPS and 10,000 FPM at $12,074.40 a year, a footprint far below the profiles compared here and not something that can be scaled into a tier without inventing a discount curve. This page used to carry a QRadar column of estimates and a five-year QRadar total; both were unsourced and both are gone. What that means in practice: price Splunk from its published rates, get IBM to quote your actual sustained EPS, and put the two side by side yourself. The non-price case for QRadar rests on its bundled compliance content packs, its on-premise appliance model and predictable per-EPS billing, none of which depend on a headline cost win. One material change: IBM sold the QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks, which ended sales on 14 April 2025 and end-of-lifed QRadar on Cloud on 14 April 2026 with customers steered to Cortex XSIAM, and IBM now sells and supports only on-premise QRadar on the per-EPS model.
Same environment, both vendors
| Profile | QRadar | Splunk Cloud + ES | Cost verdict | Note |
|---|---|---|---|---|
| 1,500 EPS / ~20 GB/day | Quote only | $40K-$55K (with ES) | Cannot be called on price | Below the 500 EPS footprint IBM has publicly priced; the only tier where a marketplace contract is even in range |
| 5,000 EPS / ~70 GB/day | Quote only | $115K-$135K (with ES) | Cannot be called on price | Ten times the publicly priced QRadar footprint; get IBM to quote and compare against the Splunk figure |
| 15,000 EPS / ~210 GB/day | Quote only | $300K-$340K (with ES) | Cannot be called on price | No public QRadar list price exists at this scale, and we will not model one |
| 50,000 EPS / ~700 GB/day | Quote only | $700K-$850K (with ES) | Cannot be called on price | Negotiated enterprise agreements dominate real pricing on both sides at this scale |
| 100,000 EPS / ~1.4 TB/day | Quote only | $1.2M-$1.5M (with ES) | Cannot be called on price | Both vendors are bespoke here; the Splunk figure is a list reference, not a deal price |
Annual ranges. Splunk is list Cloud plus Enterprise Security before EA discount; QRadar has no public list price, so QRadar figures are estimates at the stated EPS. EPS-to-GB conversion at a typical enterprise mix of 70-80 EPS per GB.
Five-year TCO at 5,000 EPS / 70 GB per day
| Year | QRadar | Splunk Cloud + ES |
|---|---|---|
| Year 1 (5,000 EPS / 70 GB/day) | Quote only | $125K (with ES) |
| Year 2 | Quote only | $110K (year-one services roll off) |
| Year 3 | Quote only | $108K (steady state) |
| Year 4 | Quote only | $113K (5% inflation) |
| Year 5 | Quote only | $119K |
| 5-year total | Quote only | $575K |
Mid-scale comparison, Splunk side only. The Splunk line is built from published rates and is shown so you have a five-year benchmark to hold an IBM quote against. There is no QRadar column because IBM publishes no rate to build one from, and a modelled QRadar TCO would be a guess dressed as arithmetic. Excludes one-time migration costs.
When QRadar genuinely wins
- +Compliance-driven enterprises (PCI Level 1, HIPAA, SOX, FedRAMP, defence) where the in-product compliance content packs save real implementation effort
- +On-premise deployment requirements where QRadar's appliance model and Cloud Pak for Security flexibility win over Splunk Enterprise self-managed
- +Stable, predictable log sources where per-EPS billing matches the underlying cost driver more cleanly than per-GB
- +Existing IBM-centric IT organisations where Cloud Pak for Security broader integration delivers operational simplification
- +Risk-averse buyers preferring IBM's enterprise support model and long-term product lifecycle commitments over best-of-breed depth
When Splunk genuinely wins
- +Mature SOCs with deep custom Splunk ES content built over years where the migration cost outweighs licence saving
- +High-velocity, search-heavy SIEM use cases where Splunk's analytics performance and content library depth are the binding constraint
- +Cloud-native deployment preferences where Splunk Cloud's operational model is genuinely better than QRadar on Cloud (Cloud Pak for Security)
- +Premium content pack requirements (ITSI, Splunk Mission Control, Splunk SOAR) that QRadar does not match
- +Engineering-strong SOCs that value Splunk's API-driven workflow, broader community, and richer third-party app ecosystem