No more typing reviews! Try our Samantha, our new voice AI agent.

ArcSight Analytics vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Analytics
Ranking in User Entity Behavior Analytics (UEBA)
18th
Average Rating
6.8
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
11th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (19th)
 

Mindshare comparison

As of August 2026, in the User Entity Behavior Analytics (UEBA) category, the mindshare of ArcSight Analytics is 1.9%, up from 1.1% compared to the previous year. The mindshare of Rapid7 InsightIDR is 4.6%, down from 9.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR4.6%
ArcSight Analytics1.9%
Other93.5%
User Entity Behavior Analytics (UEBA)
 

Q&A Highlights

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
 

Featured Reviews

reviewer1311453 - PeerSpot reviewer
Consultant at a tech vendor with 10,001+ employees
Good filtering and reporting tools but can be difficult to use
It can scale as needed. It's not a problem. There are different teams using it. We have CSOC, which is internal, which is onshore, then we have a security operations center that is offshore, which would be in India. The onshore team might be a group of three, and the offshore might be a group of five. Likely, we have eight to ten people in total using the product directly.
Prajwal Chougale - PeerSpot reviewer
SPC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have seen a measurable decrease in the mean time to detect and respond to threats."
"ArcSight Analytics has improved our system and network policy monitoring."
"The most valuable features are that you get lots of connectors, which make it easy to log in to my ASM, and lots of prebuilt roles from the company."
"Our organization has improved because ArcSight allows multiple integrations with multiple systems which we did not do before using the product."
"The ability to correlate different logs is the solution's most valuable feature."
"One of the most valuable features is the alerts."
"The stability of the solution is perfect."
"This solution allows us to identify connections for all users, and we can see the name, login time, IP address, and other information for each connection to each server."
"They can subscribe to Rapid7 because it is more valuable and delivers a greater return on investment."
"Great coverage of all systems within our network from endpoint to firewall."
"Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
"The most valuable features have to do with ease-of-use, as it is easy to check the events, investigate suspicious activities, and do forensic analysis, and the web interface is great — very useful and user-friendly."
"Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
"I like the tool's user analysis feature."
"​​User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
 

Cons

"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"I would like to see integration with automation products, such as Phantom Automation."
"The reporting and the way it is worded needs to be improved in future releases. The dashboards are quite poorly designed."
"The ArcSight Analytic is not so easy."
"You can use this solution for limited use cases. But for more advanced use cases, there are other solutions which are better than ArcSight."
"I faced stability issues with Windows Operating System. The installed connectors hang if they remain idle for a long period of time."
"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"Personally, I feel it would greatly benefit from more supported log sources."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"The main problem lies in the processes within the client's operating systems."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"One thing that springs to mind is easier API integration with ITSMs."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"Inability to get access to compliance reports within the solution."
"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
 

Pricing and Cost Advice

"My customers pay a yearly licensing fee for ArcSight Analytics."
"This solution is expensive."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"It is more reasonably priced than other vendors."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"The solution has a mid-range price point in the market"
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Answers from the Community

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
Aug 10, 2021
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, remember that any EDR/XDR should integrate to the SIEM/SOAR and a strong threat intel source. If you consider SOC outsourcing take your time and find one you can integrate like a virtual team member. They a...
2 out of 12 answers
KM
IT Infrastructure Analyst at AG Group
Jul 26, 2021
I haven't used these big-name ones like Splunk etc. but I feel they're overpriced. I think they charge an arm and a leg for each module. The ROI justification is not there. Why not try a cheaper and robust alternative like Elasticsearch?
KA
Unit Head Titanium (Security Solution) at RapidCompute
Jul 26, 2021
We are using LogRthythm SIEM complete case management and offer SIEM/SOC as service.
 

Top Industries

By visitors reading reviews
Construction Company
18%
Outsourcing Company
9%
Marketing Services Firm
9%
Financial Services Firm
9%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
What is your primary use case for Rapid7 InsightIDR?
Rapid7 InsightIDR serves as our SIEM solution where all kinds of activity, including network logs, endpoint logs, user activity, user behavior analytics, and threat hunting, are tracked. Additional...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
InsightIDR
 

Overview

 

Sample Customers

Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about ArcSight Analytics vs. Rapid7 InsightIDR and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.