No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Next-Gen SIEM vs Rapid7 InsightIDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CrowdStrike Falcon Next-Gen...
Ranking in Security Information and Event Management (SIEM)
95th
Average Rating
9.8
Reviews Sentiment
7.6
Number of Reviews
4
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in Security Information and Event Management (SIEM)
23rd
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (32nd), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
 

Featured Reviews

KS
IAM Senior Software Engineer at MGM Resorts International
Centralized log onboarding has transformed root-cause analysis and streamlined alert-driven triage
I do not use automations within CrowdStrike Falcon Next-Gen SIEM at this point, but that is something that we want to do in the future. Maybe I did not experiment or did not investigate, but if we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything. Actually, the circumstances that prompted my company to explore new SIEM solutions maybe include a point where the storage space or the license that we have, probably compared to other SIEM products, they have more, or the pricing and sales that go into the picture there. Again, that is above my pay grade to comment on, but it probably could be better if we can provide more storage of the data for the license that has been provided for organizations.
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CrowdStrike Falcon Next-Gen SIEM is a very vast tool, and while we discussed it, it can be used for many purposes, but we are using it only for the log onboarding at this point."
"The use of functions and lookup tables in CrowdStrike Falcon Next-Gen SIEM dramatically improves investigation outcomes because of reduced latency."
"The feature I like the most about CrowdStrike Falcon Next-Gen SIEM is the speed, as it has changed the speed at which my team searches, investigates, and responds to security events, with things going from days to minutes or hours."
"I think everything is good about CrowdStrike Falcon Next-Gen SIEM, as we have many features available."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
"The solution is very stable and works very well for what I need it to do."
"The solution provides satisfying native integration features"
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"I like the tool's user analysis feature."
"During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an application belongs to a known ransomware group. The system rates the threat, offering a clear detection ratio, such as 97 out of 100. It not only identifies threats but also illustrates the associated behaviors, helping us understand the potential risk to a particular endpoint."
"Features for user behavior analytics and the rules for attack review are good."
 

Cons

"The number one thing that would be an improvement for me is making dashboard creation easier."
"Maybe I did not experiment or did not investigate, but if we can get alerts based upon the CPU utilizations and the metrics over there, probably that would make this one tool used for everything."
"The product allows us to make only 30 custom rules."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."
"The dashboard is an area that could be simplified. For management, it should be clear and the files should be there."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one."
"Needs a better ability to customize the check within the console."
 

Pricing and Cost Advice

Information not available
"The solution has a mid-range price point in the market"
"The pricing and licensing are competitive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"It is more reasonably priced than other vendors."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
914,351 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Next-Gen SIEM?
Pricing, setup costs, and licensing of CrowdStrike Falcon Next-Gen SIEM is not my area.
What needs improvement with CrowdStrike Falcon Next-Gen SIEM?
I do not use automations within CrowdStrike Falcon Next-Gen SIEM at this point, but that is something that we want to do in the future. Maybe I did not experiment or did not investigate, but if we ...
What is your primary use case for CrowdStrike Falcon Next-Gen SIEM?
I work on Identity Governance for this solution. We onboard the logs into the SIEM, into CrowdStrike Falcon, and we ensure that we get alerts on time and create dashboards using that data. Our work...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
 

Also Known As

No data available
InsightIDR
 

Overview

 

Sample Customers

Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about CrowdStrike Falcon Next-Gen SIEM vs. Rapid7 InsightIDR and other solutions. Updated: September 2026.
914,351 professionals have used our research since 2012.