Independent reference. Not affiliated with any vendor mentioned on this site.
Compare / QRadar vs Splunk

IBM QRadar vs Splunk cost: 2026 EPS-vs-GB comparison

Independent head-to-head cost comparison. Per-EPS QRadar versus per-GB Splunk at five environment profiles, EPS-to-GB conversion math, five-year TCO, and where each vendor genuinely wins on compliance and depth. Splunk baseline corrected against 2026 pricing; QRadar figures are estimates (IBM publishes no list price). Updated July 2026.

QRadar
Per EPS
Compliance packs included
Splunk
Per GB
Plus ES separate licence
Conversion
~70-80 EPS/GB
Typical mixed enterprise
At ~50 GB
Splunk on base
QRadar wins on compliance packs

Per-EPS versus per-GB: how the meters collide

QRadar and Splunk priced their products around different historical realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered. Both pricing models survived because they roughly track the underlying cost driver, but they make direct cross-shop comparisons require a conversion step. The honest conversion sits at approximately 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.

The conversion varies materially with source mix. Windows event logs average 60-80 EPS per GB. Firewall and NetFlow data run 200-400 EPS per GB. SaaS audit logs run 30-50 EPS per GB. EDR telemetry averages 100-150 EPS per GB. Sampling actual environment EPS over 60 days before any vendor comparison is essential discipline; assumed conversions routinely produce wrong vendor decisions. Customers who sign QRadar contracts based on assumed EPS-to-GB conversion frequently under-buy capacity and pay overage rates; customers who sign Splunk contracts based on assumed conversion routinely over-buy ingest capacity that they never use.

The comparison changed in 2026 as Splunk Cloud's effective pricing settled well below its old list reputation: roughly $50K base ingest at 50 GB per day, and about $100K all-in once Enterprise Security is added (Enterprise Security roughly doubles the base). That is close to where a comparable QRadar deployment of around 3,500 EPS lands, at an estimated $110K to $140K. At mid scale the two are genuinely close, and QRadar frequently sits higher on base licence. IBM publishes no list price for QRadar, so every QRadar figure here is an estimate; the decision turns on QRadar's bundled compliance content packs, its on-premise appliance model, and predictable per-EPS billing rather than a clear raw-cost win. One material 2026 change: IBM sold the QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks, that cloud product reached end of life in April 2025 with customers steered to Cortex XSIAM, and IBM now sells and supports only on-premise QRadar on the per-EPS model.

Same environment, both vendors

ProfileQRadarSplunk Cloud + ESWinnerNote
1,500 EPS / ~20 GB/day$55K-$75K$40K-$55K (with ES)Splunk on costQRadar higher on licence but bundles compliance content
5,000 EPS / ~70 GB/day$150K-$190K$115K-$135K (with ES)Splunk on costQRadar higher on base licence; compliance packs included in QRadar
15,000 EPS / ~210 GB/day$375K-$450K$300K-$340K (with ES)Splunk on costQRadar is an estimate; no public list price to verify against
50,000 EPS / ~700 GB/day$1.0M-$1.2M$700K-$850K (with ES)Splunk on costEstimates at scale; negotiated EA discounts dominate real pricing
100,000 EPS / ~1.4 TB/day$1.8M-$2.2M$1.2M-$1.5M (with ES)Splunk on costQRadar carries no public list; per-EPS scaling stays costly

Annual ranges. Splunk is list Cloud plus Enterprise Security before EA discount; QRadar has no public list price, so QRadar figures are estimates at the stated EPS. EPS-to-GB conversion at a typical enterprise mix of 70-80 EPS per GB.

Five-year TCO at 5,000 EPS / 70 GB per day

YearQRadarSplunk Cloud + ES
Year 1 (5,000 EPS / 70 GB/day)$165K (estimate)$125K (with ES)
Year 2$155K (year-one services roll off)$110K (year-one services roll off)
Year 3$150K (steady state)$108K (steady state)
Year 4$158K (5% inflation)$113K (5% inflation)
Year 5$165K$119K
5-year total$793K$575K

Mid-scale comparison. Splunk's corrected Cloud plus Enterprise Security baseline sits below QRadar's estimated per-EPS licence at this profile; QRadar figures are estimates (no public list). Excludes one-time migration costs.

When QRadar genuinely wins

When Splunk genuinely wins

FAQ

Common questions

Is QRadar or Splunk cheaper at 5,000 EPS or roughly 70 GB per day?

At this profile Splunk now lands somewhat below QRadar on cost. Splunk Cloud at 70 GB per day plus Enterprise Security is roughly $115K to $135K per year all-in, following Splunk's corrected 2026 pricing (about $50K base ingest at 50 GB per day, roughly doubled once Enterprise Security is added). QRadar at 5,000 EPS is an estimated $150K to $190K per year; IBM publishes no list price, so treat every QRadar figure here as an estimate. The decision rarely turns on raw cost at this scale; it turns on QRadar's in-product compliance content packs (PCI, HIPAA, SOX), SOC familiarity (which platform the existing analysts know), deployment preference (on-premise QRadar versus cloud Splunk), and broader IT consolidation strategy. Note that QRadar's own SaaS option is no longer sold to new customers.

Why does QRadar charge per EPS and Splunk per GB?

The two vendors built their pricing models around different historical product realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource genuinely consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered for that product. Both models survived because they roughly track the underlying cost driver, even though customers find one or the other easier to reason about depending on their environment. The conversion is roughly 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.

What about QRadar Cloud (the SaaS option)?

IBM sold its QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks. That cloud-hosted product reached end of life in April 2025, with customers migrated toward Palo Alto's Cortex XSIAM. For new buyers, the QRadar SaaS option is effectively gone. What IBM continues to sell and support is on-premise QRadar, still priced on the per-EPS model with appliance or software deployment. Organisations that specifically wanted QRadar-as-a-service now choose between staying on-premise with IBM QRadar or moving to a different cloud-native SIEM. This is a material change from prior years, when QRadar on Cloud was a straightforward SaaS alternative to Splunk Cloud.

How do EPS spikes affect QRadar pricing versus GB spikes affecting Splunk?

QRadar contracts on sustained EPS with peak excursion allowances; sustained breach of contracted EPS triggers tier upgrade rather than per-event overage. Splunk contracts on per-GB ingest where spikes bill at the same per-GB rate (so no overage, but the bill rises in proportion to spike volume). The practical effect is that QRadar billing is more forgiving of bursty log profiles (you pay the contracted rate regardless of weekly or monthly variation) where Splunk billing scales linearly with every gigabyte of spike. For environments with predictable log profiles, the difference is immaterial; for environments with bursty workloads (SaaS apps, batch processing, periodic compliance scans), QRadar's flatter pricing reduces budget volatility.

What is the migration cost between QRadar and Splunk?

Both directions are moderately complex. QRadar uses AQL (QRadar's query language) and Splunk uses SPL; detection content does not port cleanly between them. Migration of 200-300 detections runs $200K-$400K in professional services plus 6-12 months calendar time. The decision should also weigh content pack equivalence: QRadar's compliance content packs do not have direct Splunk equivalents (ES content packs cover similar ground but require analyst-hours to deploy). Migrations are rarely cost-justified by licence savings alone; they typically require a separate strategic driver (consolidation onto IBM Cloud Pak, exit from on-premise data centre, broader SIEM modernisation initiative).

Updated 13 July 2026