No more typing reviews! Try our Samantha, our new voice AI agent.

ArcSight Analytics vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Analytics
Ranking in User Entity Behavior Analytics (UEBA)
18th
Average Rating
6.8
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
10th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
32
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), Endpoint Detection and Response (EDR) (39th), Threat Deception Platforms (6th), Extended Detection and Response (XDR) (23rd)
 

Mindshare comparison

As of May 2026, in the User Entity Behavior Analytics (UEBA) category, the mindshare of ArcSight Analytics is 1.9%, up from 1.0% compared to the previous year. The mindshare of Rapid7 InsightIDR is 4.6%, down from 10.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR4.6%
ArcSight Analytics1.9%
Other93.5%
User Entity Behavior Analytics (UEBA)
 

Q&A Highlights

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
 

Featured Reviews

reviewer1311453 - PeerSpot reviewer
Consultant at a tech vendor with 10,001+ employees
Good filtering and reporting tools but can be difficult to use
It can scale as needed. It's not a problem. There are different teams using it. We have CSOC, which is internal, which is onshore, then we have a security operations center that is offshore, which would be in India. The onshore team might be a group of three, and the offshore might be a group of five. Likely, we have eight to ten people in total using the product directly.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This is a very stable solution. It is the most stable ESM that I have worked with."
"The most valuable feature is the log monitoring."
"The correlation engine is good."
"The solution is easy to implement."
"ArcSight Analytics has improved our system and network policy monitoring."
"The stability of the solution is perfect."
"We have seen a measurable decrease, by about 20 percent, in the mean time to detect and respond to risks."
"Our organization has improved because ArcSight allows multiple integrations with multiple systems which we did not do before using the product."
"During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an application belongs to a known ransomware group. The system rates the threat, offering a clear detection ratio, such as 97 out of 100. It not only identifies threats but also illustrates the associated behaviors, helping us understand the potential risk to a particular endpoint."
"Rapid7's reporting is more robust than Tenable's."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
"I have seen that Rapid7 InsightIDR provides security to the networks and endpoints in the company."
"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
 

Cons

"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"The customer service could be improved, and additional integrations with other APIs could be added."
"The reporting and the way it is worded needs to be improved in future releases."
"The interactive dashboard is more complicated comparing to his concurrent Qradar and you need to have training in order to do complexe configuration, so I think that it could be made easier to use."
"Their support team could be better."
"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"Their support team could be better. They've gone downhill since their product has been acquired."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"The main problem lies in the processes within the client's operating systems."
"The interface for doing investigation needs to be enhanced with minor improvements that would make it more useful."
"Lacks a mobile application."
"The searching feature in Rapid7 InsightIDR needs to evolve"
"I feel it would greatly benefit from more supported log sources."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"Cloud risk assessment is one area where I think they need a lot of improvement."
 

Pricing and Cost Advice

"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"This solution is expensive."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"The pricing is good, and it is not very expensive."
"The pricing and licensing are competitive."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"​Accurately predict your licensing counts as this is a subscription based product.​"
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Answers from the Community

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
Aug 10, 2021
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, remember that any EDR/XDR should integrate to the SIEM/SOAR and a strong threat intel source. If you consider SOC outsourcing take your time and find one you can integrate like a virtual team member. They a...
2 out of 12 answers
KM
IT Infrastructure Analyst at AG Group
Jul 26, 2021
I haven't used these big-name ones like Splunk etc. but I feel they're overpriced. I think they charge an arm and a leg for each module. The ROI justification is not there. Why not try a cheaper and robust alternative like Elasticsearch?
KA
Unit Head Titanium (Security Solution) at RapidCompute
Jul 26, 2021
We are using LogRthythm SIEM complete case management and offer SIEM/SOC as service.
 

Top Industries

By visitors reading reviews
Marketing Services Firm
15%
Construction Company
13%
Financial Services Firm
11%
Manufacturing Company
9%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature...
What is your primary use case for Rapid7 InsightIDR?
I am working with Rapid7 InsightOps and Rapid7 InsightIDR because the requirement is as such from the customer side, particularly the banks. Whatever the requirement is, these are the products that...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
InsightIDR
 

Overview

 

Sample Customers

Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about ArcSight Analytics vs. Rapid7 InsightIDR and other solutions. Updated: April 2026.
894,738 professionals have used our research since 2012.