Try our new research platform with insights from 80,000+ expert users

Commvault Cloud vs Rapid7 InsightIDR vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Backup and Recovery
Security Information and Event Management (SIEM)
Security Information and Event Management (SIEM)
 

Featured Reviews

Cassandra Cinar - PeerSpot reviewer
Provides excellent visibility and helps reduce costs and time
We use intuitive administrative tools that readily reveal the volume of backed-up data. Our Commvault CommCell servers alert us to failed backups and provide detailed information. This transparency allows our managed service provider to easily grasp our pre-established thresholds and readily scale up with new technologies. We're highly satisfied with Commvault's automated data security and management policies. They meet our stringent requirements for secure and private data storage, including anti-ransomware protection and encryption. Notably, they also ensure compliance with GDPR for backups stored in Europe and other regions, fulfilling our regulatory obligations. Threat Scan's ability to scan backup data for threats is invaluable because it proactively identifies and neutralizes certain viruses and threats that may originate from our G Suite or be reported by our security incident response team, preventing potential outages. Commvault provides excellent visibility across our entire organization's data. They perform regular health checks, informing us of areas of strength and offering recommendations for improvement. These recommendations may include upgrading to newer product versions or addressing issues identified during the checks. It is important for our organization that Commvault provides a unified platform for recovery across cloud, on-premises, and software-as-a-service workloads. This is particularly important because many of our existing cloud environments rely on basic backups that are insufficient for our needs. Commvault empowers us to address this issue. We have implemented it not only in our own operating company but also across the corporate structure, rolling it out to virtually all AWS users. This is because the standard backup methods, such as snapshot backups, fail to meet our stringent requirements for recovery, service level agreements, and crucial functionalities like threat detection and other security features. Commvault ensures a robust and comprehensive backup infrastructure that satisfies all our essential needs. It has improved our organization by ensuring we meet our infrastructure requirements, adhere to our vulnerability methodology, and achieve service level agreements for both backup and storage requirements. The quarterly risk analysis allows us to effectively manage the lifecycle of both data and backups. It also sheds light on the types of data and backups we have, providing valuable insights. Commvault's risk analysis is one of the tools we use to meet our compliance requirements and implement the necessary controls for immediate security policy action. To ensure comprehensive data protection and comply with international regulations like GDPR, we rely on Commvault alongside our established financial systems and SOC-compliant practices. Commvault has helped us reduce our organization's data management costs by 75 percent, particularly for long-term backups. We ditched tapes and virtual tapes thanks to Commvault, replacing them with a fully disk-based backup system and cloud backups in AWS and Azure. By implementing Commvault, we've significantly reduced our backup times. This is achieved through a combination of incremental backups and data aging. Aged data is then moved to cheaper disk or cloud storage, ensuring cost-effective long-term retention while still meeting our recovery SLAs. While the overall time savings may be around 10-15 percent, the main benefit is not keeping everything on expensive primary storage and efficiently aging it out. Consequently, retrieving data from the Azure bucket typically takes five days or more, reflecting our agreed-upon SLA. It has reduced our recovery point objective, allowing us to store more backups. However, new regulatory and compliance requirements mandate that some backups cannot be deleted and must be retained indefinitely. To address this while still improving efficiency, we've implemented solutions for long-term data storage and improved data management practices. Commvault has helped our organization not only decrease our threat detection time but also improve threat prevention to such an extent that we often avoid facing the full impact of a threat altogether. By preventing these incidents, we're often unsure of the precise amount of time saved, but the benefit is clear: we don't need to activate disaster recovery mechanisms. It has not only helped us reduce our recovery time objective, but it has also ensured that our backups and long-term storage are secure, thanks to its comprehensive capabilities. In terms of total cost of ownership, Commvault has enabled us to significantly reduce both hardware and media costs for storage and backup. After factoring in encryption and compression, the total savings amount to close to 80 percent. It has been able to reduce downtime, but having a quick recovery plan and policy and SLAs that are published are met regularly.
Asim Naeem - PeerSpot reviewer
Providing comprehensive insight into alerts while working towards AI enhancement
I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product. Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product alerts the security team about threats."
"It provides us a good holistic view of everything that we have backed up so far. It also provides us all the recovery points. If we look at an an object that has been backed up, we can tell how many retention copies it has, how far we can go, and recover any data, if needed."
"Not everyone has agents for everything and Commvault has agents for most products. It's the most complete."
"Commvault can actually come in and assist you with aspects of the implementation - and they are quite helpful."
"We have VMware, Hyper-V, Oracle, and Microsoft SQL. We have a lot of different systems, and all of them are supported under one licensing agreement. That's one of the benefits."
"The most valuable feature of Metallic is its flexibility and user-friendly."
"The backup and restore capabilities are key. The most useful things to us about Commvault, in general, is the breadth of the applications that it can protect as well as the features inside of it, like deduplication and encryption. When people get their data encrypted, Commvault has a way to tell if somebody is being attacked through a cybersecurity threat because their data changes. So, Commvault has what they call honeypot files out there to look to see if anybody is changing these files. Only Commvault knows which files those are, so nobody should be messing with those files. If it changes, then it will alert you to say, "Oh, I potentially have somebody messing with my files." It will alert you to something going on in your environment that probably shouldn't be happening. We deploy that with all our customers so they have this capability as well."
"It's very stable."
"Simple configuration and automatically syncs to the cloud platform."
"Rapid7's reporting is more robust than Tenable's."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"The platform offers unlimited storage and agent-based solutions."
"InsightIDR helps us investigate an environment to discover information about incidents."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
"The solution is easy to use, and the interface is intuitive."
"Splunk Enterprise Security is a valuable tool that allows us to monitor data from the APS daily."
"The most valuable feature of Splunk Enterprise Security is website activity monitoring."
"Splunk Enterprise Security has helped speed up our security investigations."
"Speeds up root cause analysis and can help identify issues that your organization never realized were occurring."
"The site is constantly up, and it's been really easy to adjust the data."
"Visualizations helped the organisation with a better understanding of its KPIs."
"The solution's most valuable feature is that it helps with our use cases to detect anomalies in our data and it is important to my company since we have a lot of data on different logs on the systems."
"It has quite extensive support in terms of integration. If you want to do anything, there are tools for that."
 

Cons

"The deployment process should be simplified because it is not something that just anybody can do."
"They reply to the support portal weekly, but there are some delays."
"We've faced problems backing up our virtual machines."
"It would be nice to have just one email report come in, then we can filter out failures. If everything is backed up, we really don't need to see the report. If it is in a single report. A simpler customised report would be good."
"The stability of the tool could be improved."
"Its competitor, Veeam, includes backup and replication in the same product. I don't know if Commvault has it or not, but they should if they don't."
"Endpoint backup."
"My customers are not satisfied with the tool because there is a little trouble with the throughput of Metallic."
"Needs a better ability to customize the check within the console."
"There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on."
"There are certain limitations with Rapid7 that I am working on."
"The product allows us to make only 30 custom rules."
"The searching feature in Rapid7 InsightIDR needs to evolve"
"Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."
"The APIs can be further improved in Rapid7."
"The dashboard is an area that could be simplified."
"Its setup is a little bit complex for a distributed environment. Their support can also be better. If we miss the response for more than a week, they usually close the case. Sometimes, it can take us more than a week to reply."
"Configuring a few apps is complex, not straightforward."
"Their technical support sucks."
"It is very complicated to write your own correlation rules without the help of Splunk support."
"Its pricing model and integration with third-party services can be improved. We had faced an issue with integration. The alerting feature is currently not available with Splunk, but it is definitely available with Datadog and PagerDuty. They should include this feature. A few dashboards in Splunk look quite old and are not that modern. They aren't bad, but improving these dashboards will definitely make Splunk more attractive and usable. I read in a few blog posts that there were a few security incidents related to Splunk agents. So, it can be made more secure."
"Splunk Enterprise Security provides us with the relevant context to help guide our investigations, but it would be interesting to add even more context, for instance, in order to raise the level of risk."
"We would like more integrations with other cloud products, not just AWS, e.g., Azure."
"The incident response dashboard could be more user-friendly."
 

Pricing and Cost Advice

"The price should be reduced because it is too expensive for our customers."
"On a scale of one to ten, where ten is the highest price, I rate the pricing an eight."
"The price of Commvault HyperScale X is a lot higher than competitors. As a government institution, we have annual costs. We made a budget for one year in advance. It was difficult to calculate the other solution's costs because each solution has another way of licensing. The solution is expensive but it is very good and we know the good quality we will be receiving."
"The pricing is fairly in line with the other products we've compared it with recently. We do spend more on it than we did in our Backup Exec days, but it's fairly competitive with some of the other best-in-class data protection platforms."
"Licensing could be better explained. Sometimes, it's unclear what features are available in different licensing models."
"If budget allows using the per socket license and not the agent based with per GB counter for Dedup is the way to go."
"It is not the cheapest solution. I think the pricing is fair for mid-side customers. It is between all the other options."
"There is now a subscription based licence option that, depending on your environment, could offer a more efficient method to licence the solution if you are OPEX cost driven rather than CAPEX."
"It is more reasonably priced than other vendors."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"It is a reasonably priced solution."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"The solution is a little expensive."
"Splunk is really expensive."
"Splunk has always been on the expensive side."
"It is a pretty high cost solution, but if your organization has the funds, it can bring many benefits."
"We had a yearly subscription."
"Licensing is a yearly, one-time cost."
"Splunk is not free."
"Most people share the same thought that the ingestion rates can get pretty pricey. There is a lot of work we do to curate the data that we send to Splunk so that it is not too noisy or too expensive."
report
Use our free recommendation engine to learn which Backup and Recovery solutions are best for your needs.
850,747 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
10%
Manufacturing Company
9%
Government
8%
Computer Software Company
16%
Financial Services Firm
9%
Manufacturing Company
7%
Government
7%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Commvault?
The tool is affordable. I rate the pricing a six out of ten. Implementation requires additional costs because we need...
What needs improvement with Commvault?
Data center backup must be improved. We also want the product to provide us with a cloud-based backup. If we use Micr...
What do you like most about Commvault Complete Data Protection?
IntelliSnap and file system backups are valuable features.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
What do you like most about Splunk?
There are a lot of third-party applications that can be installed.
 

Also Known As

Commvault Complete Data Protection, Commvault Backup & Recovery, Commvault HyperScale X, Metallic, ThreatWise
InsightIDR
No data available
 

Overview

 

Sample Customers

Aberdeenshire Council, Acxiom, BAM Group Ireland, Catholic Education Diocese of Parramatta, CI Investments, Clifford Chance, American Municipal Power, American Pacific Mortgage, AstraZeneca, Dongbu Steel, Denver Health, Dow Jones, Emirates Steel, Penn State Health, Prime Healthcare, Sonic Healthcare, Sony Network Communications, TiVO, UCONN Health, The Weitz Company
Liberty Wines, Pioneer Telephone, Visier
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Veeam Software, Zerto, Commvault and others in Backup and Recovery. Updated: April 2025.
850,747 professionals have used our research since 2012.