IBM QRadar vs Splunk cost: 2026 EPS-vs-GB comparison
Independent head-to-head cost comparison. Per-EPS QRadar versus per-GB Splunk at five environment profiles, EPS-to-GB conversion math, five-year TCO, and where each vendor genuinely wins on compliance and depth. Splunk baseline corrected against 2026 pricing; QRadar figures are estimates (IBM publishes no list price). Updated August 2026.
Per-EPS versus per-GB: how the meters collide
QRadar and Splunk priced their products around different historical realities. QRadar's correlation engine performance scales with event rate, so per-EPS billing aligned costs with the resource consumed. Splunk's analytics engine scales with data volume, so per-GB billing aligned costs with the constraint that mattered. Both pricing models survived because they roughly track the underlying cost driver, but they make direct cross-shop comparisons require a conversion step. The honest conversion sits at approximately 70-80 EPS per GB for typical enterprise log mix, which means a 5,000 EPS QRadar deployment is roughly equivalent to a 62-71 GB-per-day Splunk deployment.
The conversion varies materially with source mix. Windows event logs average 60-80 EPS per GB. Firewall and NetFlow data run 200-400 EPS per GB. SaaS audit logs run 30-50 EPS per GB. EDR telemetry averages 100-150 EPS per GB. Sampling actual environment EPS over 60 days before any vendor comparison is essential discipline; assumed conversions routinely produce wrong vendor decisions. Customers who sign QRadar contracts based on assumed EPS-to-GB conversion frequently under-buy capacity and pay overage rates; customers who sign Splunk contracts based on assumed conversion routinely over-buy ingest capacity that they never use.
The comparison changed in 2026 as Splunk Cloud's effective pricing settled well below its old list reputation: roughly $50K base ingest at 50 GB per day, and about $100K all-in once Enterprise Security is added (Enterprise Security roughly doubles the base). That is close to where a comparable QRadar deployment of around 3,500 EPS lands, at an estimated $110K to $140K. At mid scale the two are genuinely close, and QRadar frequently sits higher on base licence. IBM publishes no list price for QRadar, so every QRadar figure here is an estimate; the decision turns on QRadar's bundled compliance content packs, its on-premise appliance model, and predictable per-EPS billing rather than a clear raw-cost win. One material change: IBM sold the QRadar SaaS business (QRadar on Cloud) to Palo Alto Networks, which ended sales on 14 April 2025 and end-of-lifed QRadar on Cloud on 14 April 2026 with customers steered to Cortex XSIAM, and IBM now sells and supports only on-premise QRadar on the per-EPS model.
Same environment, both vendors
| Profile | QRadar | Splunk Cloud + ES | Winner | Note |
|---|---|---|---|---|
| 1,500 EPS / ~20 GB/day | $55K-$75K | $40K-$55K (with ES) | Splunk on cost | QRadar higher on licence but bundles compliance content |
| 5,000 EPS / ~70 GB/day | $150K-$190K | $115K-$135K (with ES) | Splunk on cost | QRadar higher on base licence; compliance packs included in QRadar |
| 15,000 EPS / ~210 GB/day | $375K-$450K | $300K-$340K (with ES) | Splunk on cost | QRadar is an estimate; no public list price to verify against |
| 50,000 EPS / ~700 GB/day | $1.0M-$1.2M | $700K-$850K (with ES) | Splunk on cost | Estimates at scale; negotiated EA discounts dominate real pricing |
| 100,000 EPS / ~1.4 TB/day | $1.8M-$2.2M | $1.2M-$1.5M (with ES) | Splunk on cost | QRadar carries no public list; per-EPS scaling stays costly |
Annual ranges. Splunk is list Cloud plus Enterprise Security before EA discount; QRadar has no public list price, so QRadar figures are estimates at the stated EPS. EPS-to-GB conversion at a typical enterprise mix of 70-80 EPS per GB.
Five-year TCO at 5,000 EPS / 70 GB per day
| Year | QRadar | Splunk Cloud + ES |
|---|---|---|
| Year 1 (5,000 EPS / 70 GB/day) | $165K (estimate) | $125K (with ES) |
| Year 2 | $155K (year-one services roll off) | $110K (year-one services roll off) |
| Year 3 | $150K (steady state) | $108K (steady state) |
| Year 4 | $158K (5% inflation) | $113K (5% inflation) |
| Year 5 | $165K | $119K |
| 5-year total | $793K | $575K |
Mid-scale comparison. Splunk's corrected Cloud plus Enterprise Security baseline sits below QRadar's estimated per-EPS licence at this profile; QRadar figures are estimates (no public list). Excludes one-time migration costs.
When QRadar genuinely wins
- +Compliance-driven enterprises (PCI Level 1, HIPAA, SOX, FedRAMP, defence) where the in-product compliance content packs save real implementation effort
- +On-premise deployment requirements where QRadar's appliance model and Cloud Pak for Security flexibility win over Splunk Enterprise self-managed
- +Stable, predictable log sources where per-EPS billing matches the underlying cost driver more cleanly than per-GB
- +Existing IBM-centric IT organisations where Cloud Pak for Security broader integration delivers operational simplification
- +Risk-averse buyers preferring IBM's enterprise support model and long-term product lifecycle commitments over best-of-breed depth
When Splunk genuinely wins
- +Mature SOCs with deep custom Splunk ES content built over years where the migration cost outweighs licence saving
- +High-velocity, search-heavy SIEM use cases where Splunk's analytics performance and content library depth are the binding constraint
- +Cloud-native deployment preferences where Splunk Cloud's operational model is genuinely better than QRadar on Cloud (Cloud Pak for Security)
- +Premium content pack requirements (ITSI, Splunk Mission Control, Splunk SOAR) that QRadar does not match
- +Engineering-strong SOCs that value Splunk's API-driven workflow, broader community, and richer third-party app ecosystem