endoflife.ai
EOL Checker Products EOL Watch Get Support

The QRadar SaaS Shutdown: What Dies August 31, What Is Already Gone, and Why There Is No Extended Support

By Scott Bissett  ·  Published: August 24, 2026  ·  EOL Watch — deadline coverage  ·  Every date verified against Palo Alto Networks’ SKU-level datasheet — methodology

On August 31, 2026, four security products go dark: IBM QRadar EDR, IBM X-Force Threat Intelligence, Randori Attack, and IBM QRadar Advisor with Watson. These are the SaaS products Palo Alto Networks acquired from IBM on August 31, 2024 — exactly two years before the lights go out. The End of Sale and End of Life were announced on April 14, 2025, in a single SKU-level datasheet that most of the affected customers have never read.

This is a shutdown, not a support cutoff. When self-hosted software reaches end of life, it keeps running unpatched and you can buy extended support. When a SaaS product reaches end of life, the service stops. There is no server to keep alive, no binary for a third party to patch, and — for once — nothing anyone can sell you to extend it. Migration is the entire menu.

What dies, and what is already dead

Every row from Palo Alto Networks’ datasheet “End-of-Sale and End-of-Life Dates for Threat Management SaaS Products” (published April 14, 2025; 41 pages of SKUs), checked August 24, 2026.

Product familyEnd of lifeWhat it does
IBM QRadar EDRAugust 31, 2026Endpoint detection and response
IBM X-Force Threat IntelligenceAugust 31, 2026Threat-intelligence feeds and enrichment
Randori Attack / Randori SaaS AttackAugust 31, 2026Continuous automated red teaming
IBM QRadar Advisor with WatsonAugust 31, 2026AI-assisted investigation
Randori Recon (all tiers)April 14, 2026 — already goneAttack-surface management
Resilient IRP / SOAR on CloudApril 14, 2026 — already goneIncident response / SOAR
QRadar XDR-package log archival SKUsApril 14, 2026 — already goneLog archival for the XDR package

The April 14 wave matters for a reason beyond housekeeping: if your organization ran Randori Recon or SOAR on Cloud and nobody noticed the shutdown, that capability has been silently absent for four months. The August 31 wave is the second half of the same event — and the last call to export anything you still can.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

The one-week checklist

  1. Confirm which side of the SKU list you are on. On-premises QRadar SIEM is not part of this shutdown; the SaaS products above are. Entitlement paperwork, not memory, is the source of truth.
  2. Export what you can while the consoles still answer. Detection rules, investigation notes, threat-intel watchlists, Randori findings and reports — after August 31 there is no “read-only period” promised anywhere in the datasheet.
  3. Close the capability gap deliberately. Palo Alto’s path is Cortex XSIAM, and its datasheet points transitioning customers to migration offers. Whether you follow it or replace each function elsewhere, the decision should be made before the deadline makes it for you.

The pattern worth noticing

This is the third hard-shutdown cluster of the season, after AWS’s July retirements and Azure’s seven September dates. Acquired SaaS products are the highest-risk lifecycle category there is: the acquirer’s incentive is migration, the timeline is short, and the announcement usually lives in a PDF datasheet rather than a headline. If a product your security program depends on gets acquired, the clock starts that day — the announcement just formalizes it.

Frequently Asked Questions

Which QRadar SaaS products reach end of life on August 31, 2026?

Per Palo Alto Networks' SKU-level datasheet: IBM QRadar EDR, IBM X-Force Threat Intelligence, Randori Attack (including Randori SaaS Attack), and IBM QRadar Advisor with Watson. These are the SaaS products Palo Alto Networks acquired from IBM on August 31, 2024; the End of Sale and End of Life were announced on April 14, 2025.

Which QRadar-family products are already gone?

Randori Recon (all tiers), the IBM Resilient Incident Response Platform / SOAR on Cloud subscriptions, and the QRadar XDR-package log-archival SKUs reached end of life on April 14, 2026, per the same datasheet. If you were running any of these, the shutdown has already happened.

Can I buy extended support for these products?

No — and not from anyone. Extended support exists for self-hosted software because the software keeps running after the vendor stops patching it, so a third party can supply the patches. A SaaS product is operated by the vendor: when it reaches end of life, the service itself stops. There is no binary to keep alive and nothing for an extended-support vendor to sell. The only paths are migration or doing without the capability.

Does this affect on-premises QRadar SIEM?

No. This shutdown covers the SaaS products acquired by Palo Alto Networks from IBM. On-premises QRadar SIEM deployments follow their own lifecycle and are not part of the August 31, 2026 date. Check your entitlements against the SKU list in Palo Alto's datasheet if you are unsure which side of the line you are on.

What is the migration path?

Palo Alto Networks acquired the QRadar SaaS business to move customers to Cortex XSIAM, and its end-of-life datasheet points transitioning customers to its migration offers. Existing subscriptions are honored through the earlier of the subscription's own end or the End of Life date — after August 31, 2026 there is nothing left to honor.

Where is the authoritative list?

Palo Alto Networks' End-of-Life Announcements page and, for exact SKUs, the datasheet "End-of-Sale and End-of-Life Dates for Threat Management SaaS Products" (published April 14, 2025). Every date in this article was checked against that datasheet on August 24, 2026.

Related Resources

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)