@Chris_321 Typically, if a client has 2 SIEMs, one would be in the cloud (AKA MS Sentinel) and the other would be on-prem (Qradar in this case). Some companies don't like to send information from on-prem to the cloud and vice versa (since you have to pay egress charges when data leaves Azure).
I have had clients do this when they still have a contract for their existing SIEM and want to move to MS Sentinel as well. This way they can see what rules may be missing (if they copy all the data from on-prem into MS Sentinel) and to make sure their needs will be met.
As far as integration goes, yes you can use the APIs for the various MS security products, however there is much better integration between the other MS security products and MS Sentinel, which is only getting better as time goes on.
The biggest disadvantage is that now you have two places to look to see what is going on in your environment and two systems to keep up to date (although with MS Sentinel being a SaaS product it is not hard).