DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
Cortex XSIAM

Palo Alto Networks Bought Selected IBM QRadar SaaS Assets: What Customers Need to Know

Palo Alto Networks’ 2024 deal covered selected IBM QRadar SaaS assets, not IBM’s broader cloud-security portfolio. Here is what happened to the services and what SaaS and on-premises customers should know.

By TheFinanceBase Team 5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Palo Alto Networks completed its acquisition of selected IBM QRadar security-threat-management SaaS assets on August 31, 2024. The deal was not a purchase of IBM’s entire cloud-security business: IBM’s on-premises QRadar products were excluded. For affected SaaS customers, the immediate issue is the retirement schedule—some acquired services reached end of life on April 14, 2026, and several others are scheduled to reach it on August 31, 2026.

What Palo Alto Networks actually bought

The companies announced the proposed transaction on May 15, 2024, as part of a broader partnership. IBM described the announced price as approximately $500 million; that figure was announced transaction value, not a separately confirmed final cash consideration. The acquisition closed on August 31, 2024, and Palo Alto Networks announced the closing on September 4.

The acquired assets were selected IBM QRadar Software as a Service (SaaS) assets, including related intellectual-property rights, customer relationships and SaaS contracts. That is narrower than buying “IBM’s cloud security software.” The agreement concerned a defined set of security-threat-management offerings, not IBM’s full security, data-protection, identity or hybrid-cloud portfolio. IBM’s transaction announcement and Palo Alto Networks’ closing announcement describe the deal’s scope.

What was not included

  • IBM QRadar on-premises: The divestiture did not include IBM’s on-premises QRadar products or SKUs. IBM said it would continue support for those products, including security and usability improvements, critical bug fixes and connector updates. IBM’s product notice addresses the distinction.
  • IBM’s wider security and cloud portfolio: The transaction was not a sale of IBM Cloud, Cloud Pak for Security as a whole, or all IBM security software. Certain SaaS offerings associated with the deal are listed in the retirement notices, but that does not mean IBM’s broader businesses transferred.
  • Prisma Cloud: Palo Alto Networks already offered Prisma Cloud, its own code-to-cloud security platform. It was not acquired from IBM. IBM described collaboration involving Prisma Cloud and IBM Consulting; that partnership language is not a sale of Prisma Cloud or IBM Cloud. See Palo Alto Networks’ Prisma Cloud overview and IBM’s partnership announcement.

Why the deal paired an acquisition with a partnership

The transaction gave Palo Alto Networks selected QRadar SaaS assets and a defined customer migration opportunity. The company positioned Cortex XSIAM as a destination for those customers, describing a security-operations platform that brings together capabilities associated with SIEM, SOAR, XDR, security analytics, attack-surface management, and automated investigation and response. That is the vendor’s strategic positioning, not proof that every QRadar configuration or workflow has a direct equivalent.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

IBM’s role shifted toward consulting, implementation and partnership rather than ownership of the acquired SaaS assets. IBM Consulting was to assist customers with adoption and migration, and IBM said it would make Palo Alto Networks a preferred cybersecurity partner across network, cloud and security operations. Palo Alto Networks also said IBM would train more than 1,000 security consultants on its products and deploy technologies including Cortex XSIAM and Prisma SASE. Those commitments are described in the closing announcement.

QRadar SaaS retirement dates

As of August 16, 2026, Palo Alto Networks’ published lifecycle summary lists these end-of-life dates for offerings associated with the acquisition. End of life is a product lifecycle milestone; check the notices and your own contract for the applicable service, support and data-handling terms.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Listed end-of-life date Products in Palo Alto Networks’ summary
April 14, 2026 IBM Security QRadar on Cloud; IBM Security QRadar Suite – Cloud-Native SIEM; IBM Security QRadar Suite – SOAR; the SOAR portion of Cloud Pak for Security as a Service (excluding Guardium and Identity Access Management portions); IBM Security SOAR on Cloud; IBM Security Randori Recon; IBM Security QRadar Suite – Log Insights.
August 31, 2026 IBM Security QRadar Suite – EDR; IBM Security QRadar Suite – XDR; IBM Security X-Force Threat Intelligence; IBM Security Randori Attack; IBM Security QRadar Advisor with Watson.

The August 31, 2026 date is still upcoming as of the stated cutoff. The lifecycle list does not extend these SaaS dates to IBM’s on-premises QRadar products. Consult Palo Alto Networks’ end-of-life summary for the published product list, and its end-of-sale notice for migration information and conditions.

What affected customers should do

If you use QRadar SaaS

Do not assume that an advertised migration offer covers every cost or that moving preserves existing operations unchanged. Palo Alto Networks said eligible customers could receive no-cost migration services for the remainder of applicable subscription terms, subject to the stated conditions. Confirm eligibility, subscription treatment, migration scope and any charges for custom work directly with the vendors. “No-cost migration services” does not by itself establish that retraining, redesign, retention, integrations or all implementation work are free.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Before selecting Cortex XSIAM or another platform, assess whether your organization needs SIEM alone or broader endpoint, cloud, XDR and automation capabilities. Map existing integrations, rules, dashboards, data sources and retention obligations. XSIAM licensing documentation identifies NG-SIEM, Enterprise and Premium tiers, with feature differences, add-ons, data-ingestion and workload requirements; pricing is not a simple public per-seat comparison. Review the current Cortex XSIAM licensing documentation against your actual volumes and requirements.

If you use QRadar on-premises

This acquisition alone does not require you to move from IBM’s on-premises QRadar products. IBM says those products remain outside the divestiture and continue to receive support. Confirm your own product’s roadmap and support terms with IBM; continued on-premises support does not mean the acquired SaaS services remain available.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Migration checklist for SaaS environments

  1. Confirm whether each system is QRadar SaaS, on-premises QRadar or a mixed deployment, and list exact product names and SKUs.
  2. Check each SaaS product’s lifecycle notice, subscription end date and contractual data-export or retention terms.
  3. Ask for written confirmation of migration eligibility, covered services, subscription treatment and any work that would be chargeable.
  4. Inventory custom rules, correlation logic, offenses and use cases; log sources, DSMs and parsers; dashboards and reports; SOAR playbooks; threat-intelligence feeds; and retention or compliance requirements.
  5. Map each high-priority detection and response workflow to the proposed target, then validate data sources, ingestion volumes, workload assumptions and license tier.
  6. Test critical detections and response procedures in parallel, and agree on incident-response and rollback arrangements for the transition.
  7. Confirm export, access and retention arrangements before the applicable service is retired. Palo Alto Networks’ QRadar-to-XSIAM design guide covers architecture, data centralization, detection, automation and incident management.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate the migration destination

Cortex XSIAM is the named migration direction in Palo Alto Networks’ materials, but it is not automatically the best fit for every customer. A broader platform can consolidate tools, while moving systems may require rebuilding rules, integrations, dashboards and response workflows. Data ingestion, workload counts, licensing structure, retention requirements, staffing and dependence on one vendor ecosystem all affect the business case.

Organizations that prefer to compare platforms can evaluate other SIEM or security-operations vendors against the same requirements, rather than treating the transaction as a mandate to buy a particular product. Include transition effort, data residency, ongoing operating costs, existing ecosystem fit and the ability to reproduce priority detections. The purchase of assets does not establish feature-for-feature equivalence or make any one migration path objectively superior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.