IBM QRadar vs Splunk cost: 2026 EPS-vs-GB comparison
Independent head-to-head cost comparison. Per-EPS QRadar versus per-GB Splunk at five environment profiles, EPS-to-GB conversion math, five-year TCO, and where each vendor genuinely wins on compliance and depth. Splunk baseline corrected against 2026 pricing; QRadar figures are estimates (IBM publishes no list price). Updated July 2026.
Per-EPS versus per-GB: how the meters collide
QRadar and Splunk priced their products around different historical realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered. Both pricing models survived because they roughly track the underlying cost driver, but they make direct cross-shop comparisons require a conversion step. The honest conversion sits at approximately 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.
The conversion varies materially with source mix. Windows event logs average 60-80 EPS per GB. Firewall and NetFlow data run 200-400 EPS per GB. SaaS audit logs run 30-50 EPS per GB. EDR telemetry averages 100-150 EPS per GB. Sampling actual environment EPS over 60 days before any vendor comparison is essential discipline; assumed conversions routinely produce wrong vendor decisions. Customers who sign QRadar contracts based on assumed EPS-to-GB conversion frequently under-buy capacity and pay overage rates; customers who sign Splunk contracts based on assumed conversion routinely over-buy ingest capacity that they never use.
The comparison changed in 2026 as Splunk Cloud's effective pricing settled well below its old list reputation: roughly $50K base ingest at 50 GB per day, and about $100K all-in once Enterprise Security is added (Enterprise Security roughly doubles the base). That is close to where a comparable QRadar deployment of around 3,500 EPS lands, at an estimated $110K to $140K. At mid scale the two are genuinely close, and QRadar frequently sits higher on base licence. IBM publishes no list price for QRadar, so every QRadar figure here is an estimate; the decision turns on QRadar's bundled compliance content packs, its on-premise appliance model, and predictable per-EPS billing rather than a clear raw-cost win. One material 2026 change: IBM sold the QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks, that cloud product reached end of life in April 2025 with customers steered to Cortex XSIAM, and IBM now sells and supports only on-premise QRadar on the per-EPS model.
Same environment, both vendors
| Profile | QRadar | Splunk Cloud + ES | Winner | Note |
|---|---|---|---|---|
| 1,500 EPS / ~20 GB/day | $55K-$75K | $40K-$55K (with ES) | Splunk on cost | QRadar higher on licence but bundles compliance content |
| 5,000 EPS / ~70 GB/day | $150K-$190K | $115K-$135K (with ES) | Splunk on cost | QRadar higher on base licence; compliance packs included in QRadar |
| 15,000 EPS / ~210 GB/day | $375K-$450K | $300K-$340K (with ES) | Splunk on cost | QRadar is an estimate; no public list price to verify against |
| 50,000 EPS / ~700 GB/day | $1.0M-$1.2M | $700K-$850K (with ES) | Splunk on cost | Estimates at scale; negotiated EA discounts dominate real pricing |
| 100,000 EPS / ~1.4 TB/day | $1.8M-$2.2M | $1.2M-$1.5M (with ES) | Splunk on cost | QRadar carries no public list; per-EPS scaling stays costly |
Annual ranges. Splunk is list Cloud plus Enterprise Security before EA discount; QRadar has no public list price, so QRadar figures are estimates at the stated EPS. EPS-to-GB conversion at a typical enterprise mix of 70-80 EPS per GB.
Five-year TCO at 5,000 EPS / 70 GB per day
| Year | QRadar | Splunk Cloud + ES |
|---|---|---|
| Year 1 (5,000 EPS / 70 GB/day) | $165K (estimate) | $125K (with ES) |
| Year 2 | $155K (year-one services roll off) | $110K (year-one services roll off) |
| Year 3 | $150K (steady state) | $108K (steady state) |
| Year 4 | $158K (5% inflation) | $113K (5% inflation) |
| Year 5 | $165K | $119K |
| 5-year total | $793K | $575K |
Mid-scale comparison. Splunk's corrected Cloud plus Enterprise Security baseline sits below QRadar's estimated per-EPS licence at this profile; QRadar figures are estimates (no public list). Excludes one-time migration costs.
When QRadar genuinely wins
- +Compliance-driven enterprises (PCI Level 1, HIPAA, SOX, FedRAMP, defence) where the in-product compliance content packs save real implementation effort
- +On-premise deployment requirements where QRadar's appliance model and Cloud Pak for Security flexibility win over Splunk Enterprise self-managed
- +Stable, predictable log sources where per-EPS billing matches the underlying cost driver more cleanly than per-GB
- +Existing IBM-centric IT organisations where Cloud Pak for Security broader integration delivers operational simplification
- +Risk-averse buyers preferring IBM's enterprise support model and long-term product lifecycle commitments over best-of-breed depth
When Splunk genuinely wins
- +Mature SOCs with deep custom Splunk ES content built over years where the migration cost outweighs licence saving
- +High-velocity, search-heavy SIEM use cases where Splunk's analytics performance and content library depth are the binding constraint
- +Cloud-native deployment preferences where Splunk Cloud's operational model is genuinely better than QRadar on Cloud (Cloud Pak for Security)
- +Premium content pack requirements (ITSI, Splunk Mission Control, Splunk SOAR) that QRadar does not match
- +Engineering-strong SOCs that value Splunk's API-driven workflow, broader community, and richer third-party app ecosystem