Try our new research platform with insights from 80,000+ expert users

ArcSight Analytics vs One Identity Safeguard vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
ArcSight Analytics1.4%
Exabeam9.9%
IBM Security QRadar9.0%
Other79.7%
User Entity Behavior Analytics (UEBA)
Privileged Access Management (PAM) Market Share Distribution
ProductMarket Share (%)
One Identity Safeguard3.6%
CyberArk Privileged Access Manager15.8%
WALLIX Bastion7.2%
Other73.4%
Privileged Access Management (PAM)
Risk-Based Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightVM13.8%
Qualys VMDR16.1%
Microsoft Defender Vulnerability Management9.7%
Other60.4%
Risk-Based Vulnerability Management
 

Featured Reviews

Subhadip Pakrashi - PeerSpot reviewer
A scalable solution that provides a deeper insight and threat analysis about the network
ArcSight Analytics is used to get a deeper insight and threat analysis about the network. The solution's threat analysis gives a good view of the network. We can then compare those vulnerabilities and CVS scores worldwide and get a good understanding of how likely the network is to be hit. The kind of report ArcSight Analytics gives is really good. ArcSight Analytics is a very scalable solution that is easy to deploy.
Tor Nordhagen - PeerSpot reviewer
Transparent mode for privileged sessions will greatly simplify our client's administrative situation
We're introducing the solution's transparent mode for privileged sessions. This is part of what the client hasn't used before. It will simplify their administrative situation greatly. So far, the rollout of this feature has been a seamless process, but we're still in the midst of rolling it out. The benefits will be on the risk side. Right now, the way accounts are managed, you don't necessarily know who is using an account. There's a shared admin account, and that's not a good thing. And those accounts are shared in wallets by several people. One of the real benefits of safeguarding here is that the client will have an absolute audit of who is using an administrative interface, whether it's server or network.
Anusha Sadasivani - PeerSpot reviewer
Rapid deployment and user-friendly architecture streamline vulnerability management but customer support response needs improvement
We are still using Rapid7 InsightVM I personally still use Rapid7 InsightVM. We use Rapid7 InsightVM for vulnerability scanning. It supports both agent-based and agentless scanning, which is part of our vulnerability management strategy. The agentless scan in Rapid7 InsightVM is effective and…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The correlation engine is good."
"The two most valuable features of this solution are its stability and scalability."
"ArcSight Analytics has improved our system and network policy monitoring."
"The data collection and the integration with different products are valuable features."
"The solution is easy to implement."
"This solution allows us to identify connections for all users."
"One of the most valuable features is the alerts."
"Less resource consumption in terms of memory and processing."
"It offers high availability and enables end users to deploy the solution with 99.999 percent uptime, which is crucial in an enterprise environment with a large number of endpoints."
"The solution's most valuable features are the efficiency and the quality of the recording."
"Being able to use a proxy server is an advantage."
"One of the real benefits of safeguarding here is that the client will have an absolute audit of who is using an administrative interface, whether it's server or network."
"We use the solution’s Approval Anywhere feature which enables us to add an extra layer of security for critical passwords without adding time-consuming approval processes. By using this platform, if someone goes on a vacation, out of office, or needs urgent/planned leave, then our setup will select the functions tied to that person and automatically delegate them to the next person. That person can start performing that duty based on their access. No sharing of passwords is required."
"I like Safeguard's snapshot feature that enables us to review the last time an application was opened and by whom. If there are any issues, we can look behind the scenes to see what has been done. We can suspend a user's access or close off a server."
"One Identity Safeguard is stable and provides great performance."
"There is ease of implementation. Compared to other PAM solutions, it is easy to implement and use from an administrator's point of view."
"The most valuable feature is the vulnerability scan."
"The ease of deployment and configuration allows users to onboard quickly."
"We feel the interface is very good. It is very easy to use, even a nontechnical person can use it."
"The most valuable feature for me is the risk calculation based on monthly effects."
"The discovery and prioritization of vulnerabilities."
"The main functionality of identifying item endpoints that weren't properly patched or had vulnerabilities is the solution's most valuable feature."
"It is good and fits well with pretty much all of our use case needs."
"InsightVM has a very organized GUI with ease of use."
 

Cons

"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"Their support team could be better."
"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."
"I would like to see integration with automation products, such as Phantom Automation."
"Inactive connections from servers, which are upgraded or downgraded within a VM, should be automatically revoked."
"I faced stability issues with Windows Operating System. The installed connectors hang if they remain idle for a long period of time."
"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"Network integration is very crucial, and you need to have the knowledge to get it done."
"I rate customer support six out of ten. It needs improvement as it can significantly impact customer access."
"The interface is better now, but it still could be improved a lot. It needs more organization, menus, automatic refresh of information, and Web 2.0."
"There is room for improvement in the launch module. They built in a launch button but they don't have effective instructions for configuring it to allow it to launch an RDP session. They're working on that, but the button is in the live product. If they were going to install something that wasn't useful, they should have just disabled it and not rolled it out with the product."
"The high availability function of the box requires a long time to switch over from one appliance to another."
"We currently have a problem with the Active Directory integrations on Windows. Some of our users need to be logged with Active Directory, but we are having communication issues between One Identity and Active Directory. It seems that Active Directory is not well-integrated."
"Support for One Identity Safeguard could be improved because sometimes the support team doesn't have an answer or solution for some bugs. A feature I found in a competitor would make One Identity Safeguard better, and that is the ability to load balance the traffic in the target."
"Something for One Identity to look at is having integration guidelines for how to logically group accounts."
"We have feature requests and would like to see the turnaround times on those features to be faster."
"It would be great to have a mobile application client. Currently, you have to use a mobile web browser on a device, but it is not similar to the desktop web browser in terms of user experience. It would be nice to have a mobile application to access the platform."
"Some of our customers want to be completely cloud based, and Rapid7 doesn't offer this as an option."
"The team needs to improve the speed and focus on the new bandwidth feed. Sometimes, it takes a while to scan, especially with new updates."
"We have some issues with how it scans patches."
"There are certain limitations because of the product being used on a hybrid model. Rapid7 InsightVM doesn't offer a solution purely in the cloud."
"The drawback is that it is still not a fully SaaS solution, so you must deploy a console."
"This solution integrates with another module in Metasploit, that doesn't exist in the other solutions. It is subscribed to on our roadmap, but we chose to implement both Nexppose and AppSpider."
"A definite improvement would be to make it easier to run ad-hoc scans without needing to assign the asset to a site or group."
 

Pricing and Cost Advice

"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"This solution is expensive."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"The license is very expensive for us, partly due to inflation and partly because of the exchange rate between the Dollar and the Iranian Rial. We purchased a perpetual license that we've been using up until now, but I believe that we are not going to update it in the future. Instead, we plan to find another third-party to support us with the license, in the sense that we would have access to their license as a shared agreement."
"It was definitely cheaper than the other two products that we evaluated."
"As compared to other products, it is reasonable, but the training sessions are too expensive."
"Setup cost, pricing and licensing are all very expensive."
"It is cheaper than CyberArk. Its price is fair."
"The license is around $3,000 per month."
"The pricing depends on our perspective, our budget, and, of course, the competitors we are taking into account."
"One Identity Safeguard is expensive and the cost goes up as we scale."
"It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself."
"We purchase annual licenses."
"It is less expensive compared to other competitors."
"InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
"The license is IP based. How many IPs you are using to scan is the amount of the license you have to buy. The number of users doesn't matter; many users can use it or only person. It depends on the culture of the organization."
"I do not have experience with the pricing of the solution."
"Licensing fees are paid on a yearly basis."
"The price of the solution is less than the competitors."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
868,654 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
22%
Comms Service Provider
7%
Financial Services Firm
7%
Government
7%
Financial Services Firm
12%
Computer Software Company
11%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise12
Large Enterprise19
By reviewers
Company SizeCount
Small Business29
Midsize Enterprise13
Large Enterprise23
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about ArcSight Analytics?
ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
What is your experience regarding pricing and costs for ArcSight Analytics?
My customers pay a yearly licensing fee for ArcSight Analytics.
What do you like most about One Identity Safeguard?
The identity discovery is good, and the performance is pretty good value.
What is your experience regarding pricing and costs for One Identity Safeguard?
The pricing of One Identity Safeguard is fairly priced and cheaper than other solutions of the same enterprise level....
What needs improvement with One Identity Safeguard?
There is room for improvement in integration between modules. The native integration between SPP and SPS, which is cu...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither ...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Information Not Available
Cavium
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about IBM, Exabeam, Cynet and others in User Entity Behavior Analytics (UEBA). Updated: August 2025.
868,654 professionals have used our research since 2012.