"All in One" option can scale up depending on the resources assigned to it - so, it is possible it supports over 3000 EPS. Bear in mind that the EPS rate and performance does not only depend on CPU and RAM but very much on the performance of underlying storage. In addition, when sizing storage space, you should also consider the retention required.
Backup of the virtual machine is fine, but you should probably consider another storage mount for the backup of config and data (for offline retention).
QRadar can be implemented in HA mode - either using shared storage or DRBD - the latter is also possible for virtual machines. You can also opt to use native recovery options provided by VMware - such as HA restart on alternative host (but choice depends if you can afford that downtime).
If you go with distributed deployment, you would need to use event processors and dedicated console instances. Event processor should be kept close to the console to maintain proper performance. On customer's side you may use e.g. the DLC or event collector instances.
------------------------------
Dusan VIDOVIC
------------------------------