Whether or not there is benefit in integrating, primarily has to do with how vested you are in the use of qradar but also in how you want to use your data. The possibility for use cases, beyond what qradar can reasonably handle, is huge in Splunk. Of course, I'm speaking of the core capabilities of Splunk and not just ES.
Splunk is a platform and it does not require that your data be fully parsed when it is indexed, so unlike database driven SIEMs, data can be parsed at search-time, to accommodate different use cases. In addition, data not relevant in a SIEM can be utilized in Splunk.
... View more