Editorially independent. Sponsors are disclosed and never influence our analysis.
Independent research, supported bycriblSponsor
Compare / QRadar vs Splunk

IBM QRadar vs Splunk cost: 2026 EPS-vs-GB comparison

Independent head-to-head cost comparison. Per-EPS QRadar versus per-GB Splunk at five environment profiles, EPS-to-GB conversion math, five-year TCO, and where each vendor genuinely wins on compliance and depth. Splunk baseline corrected against 2026 pricing; QRadar figures are estimates (IBM publishes no list price). Updated August 2026.

QRadar
Per EPS
Compliance packs included
Splunk
Per GB
Plus ES separate licence
Conversion
~70-80 EPS/GB
Typical mixed enterprise
QRadar list price
Not published
Splunk publishes rates; IBM quotes

Per-EPS versus per-GB: how the meters collide

QRadar and Splunk priced their products around different historical realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered. Both pricing models survived because they roughly track the underlying cost driver, but they make direct cross-shop comparisons require a conversion step. The honest conversion sits at approximately 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.

The conversion varies materially with source mix. Windows event logs average 60-80 EPS per GB. Firewall and NetFlow data run 200-400 EPS per GB. SaaS audit logs run 30-50 EPS per GB. EDR telemetry averages 100-150 EPS per GB. Sampling actual environment EPS over 60 days before any vendor comparison is essential discipline; assumed conversions routinely produce wrong vendor decisions. Customers who sign QRadar contracts based on assumed EPS-to-GB conversion frequently under-buy capacity and pay overage rates; customers who sign Splunk contracts based on assumed conversion routinely over-buy ingest capacity that they never use.

The comparison changed in 2026 as Splunk Cloud's effective pricing settled well below its old list reputation: roughly $50K base ingest at 50 GB per day, and about $100K all-in once Enterprise Security is added (Enterprise Security roughly doubles the base). We cannot put a QRadar figure beside that. IBM publishes no list price for QRadar on any channel, and the only public QRadar price anywhere is an AWS Marketplace contract covering 500 EPS and 10,000 FPM at $12,074.40 a year, a footprint far below the profiles compared here and not something that can be scaled into a tier without inventing a discount curve. This page used to carry a QRadar column of estimates and a five-year QRadar total; both were unsourced and both are gone. What that means in practice: price Splunk from its published rates, get IBM to quote your actual sustained EPS, and put the two side by side yourself. The non-price case for QRadar rests on its bundled compliance content packs, its on-premise appliance model and predictable per-EPS billing, none of which depend on a headline cost win. One material change: IBM sold the QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks, which ended sales on 14 April 2025 and end-of-lifed QRadar on Cloud on 14 April 2026 with customers steered to Cortex XSIAM, and IBM now sells and supports only on-premise QRadar on the per-EPS model.

Same environment, both vendors

ProfileQRadarSplunk Cloud + ESCost verdictNote
1,500 EPS / ~20 GB/dayQuote only$40K-$55K (with ES)Cannot be called on priceBelow the 500 EPS footprint IBM has publicly priced; the only tier where a marketplace contract is even in range
5,000 EPS / ~70 GB/dayQuote only$115K-$135K (with ES)Cannot be called on priceTen times the publicly priced QRadar footprint; get IBM to quote and compare against the Splunk figure
15,000 EPS / ~210 GB/dayQuote only$300K-$340K (with ES)Cannot be called on priceNo public QRadar list price exists at this scale, and we will not model one
50,000 EPS / ~700 GB/dayQuote only$700K-$850K (with ES)Cannot be called on priceNegotiated enterprise agreements dominate real pricing on both sides at this scale
100,000 EPS / ~1.4 TB/dayQuote only$1.2M-$1.5M (with ES)Cannot be called on priceBoth vendors are bespoke here; the Splunk figure is a list reference, not a deal price

Annual ranges. Splunk is list Cloud plus Enterprise Security before EA discount; QRadar has no public list price, so QRadar figures are estimates at the stated EPS. EPS-to-GB conversion at a typical enterprise mix of 70-80 EPS per GB.

Five-year TCO at 5,000 EPS / 70 GB per day

YearQRadarSplunk Cloud + ES
Year 1 (5,000 EPS / 70 GB/day)Quote only$125K (with ES)
Year 2Quote only$110K (year-one services roll off)
Year 3Quote only$108K (steady state)
Year 4Quote only$113K (5% inflation)
Year 5Quote only$119K
5-year totalQuote only$575K

Mid-scale comparison, Splunk side only. The Splunk line is built from published rates and is shown so you have a five-year benchmark to hold an IBM quote against. There is no QRadar column because IBM publishes no rate to build one from, and a modelled QRadar TCO would be a guess dressed as arithmetic. Excludes one-time migration costs.

When QRadar genuinely wins

When Splunk genuinely wins

FAQ

Common questions

Is QRadar or Splunk cheaper at 5,000 EPS or roughly 70 GB per day?

Honestly, nobody can tell you from public sources, and anyone who does is estimating. Splunk Cloud at 70 GB per day plus Enterprise Security is roughly $115K to $135K per year all-in, following Splunk's corrected 2026 pricing (about $50K base ingest at 50 GB per day, roughly doubled once Enterprise Security is added). Splunk publishes rates; IBM does not. There is no QRadar list price at 5,000 EPS on any IBM channel, and the only public QRadar price in existence is an AWS Marketplace contract at 500 EPS, a tenth of this profile. So the comparison has to be made with a real IBM quote in hand. The decision rarely turns on raw cost at this scale anyway; it turns on QRadar's in-product compliance content packs (PCI, HIPAA, SOX), SOC familiarity (which platform the existing analysts know), deployment preference (on-premise QRadar versus cloud Splunk), and broader IT consolidation strategy. Note that QRadar's own SaaS option is no longer sold to new customers.

Why does QRadar charge per EPS and Splunk per GB?

The two vendors built their pricing models around different historical product realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource genuinely consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered for that product. Both models survived because they roughly track the underlying cost driver, even though customers find one or the other easier to reason about depending on their environment. The conversion is roughly 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.

What about QRadar Cloud (the SaaS option)?

IBM sold its QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks (deal closed September 2024). Palo Alto ended sales of those SaaS products on 14 April 2025 (end of sale), and QRadar on Cloud, SOAR, and Log Insights reached end of life on 14 April 2026 (QRadar EDR/XDR on 31 August 2026), with customers migrated toward Palo Alto's Cortex XSIAM. For new buyers, the QRadar SaaS option is gone. What IBM continues to sell and support is on-premise QRadar, still priced on the per-EPS model with appliance or software deployment. Organisations that specifically wanted QRadar-as-a-service now choose between staying on-premise with IBM QRadar or moving to a different cloud-native SIEM. This is a material change from prior years, when QRadar on Cloud was a straightforward SaaS alternative to Splunk Cloud.

How do EPS spikes affect QRadar pricing versus GB spikes affecting Splunk?

QRadar contracts on sustained EPS with peak excursion allowances; sustained breach of contracted EPS triggers tier upgrade rather than per-event overage. Splunk contracts on per-GB ingest where spikes bill at the same per-GB rate (so no overage, but the bill rises in proportion to spike volume). The practical effect is that QRadar billing is more forgiving of bursty log profiles (you pay the contracted rate regardless of weekly or monthly variation) where Splunk billing scales linearly with every gigabyte of spike. For environments with predictable log profiles, the difference is immaterial; for environments with bursty workloads (SaaS apps, batch processing, periodic compliance scans), QRadar's flatter pricing reduces budget volatility.

What is the migration cost between QRadar and Splunk?

Both directions are moderately complex. QRadar uses AQL (QRadar's query language) and Splunk uses SPL; detection content does not port cleanly between them. Migration of 200-300 detections runs $200K-$400K in professional services plus 6-12 months calendar time. The decision should also weigh content pack equivalence: QRadar's compliance content packs do not have direct Splunk equivalents (ES content packs cover similar ground but require analyst-hours to deploy). Migrations are rarely cost-justified by licence savings alone; they typically require a separate strategic driver (consolidation onto IBM Cloud Pak, exit from on-premise data centre, broader SIEM modernisation initiative).

Didn't find your answer?

Ask us. A real person reads every question and we answer the ones we can, with sources. If your question would help other readers, we may publish an anonymised version, with your permission. General reference only.

Updated 13 July 2026