No more typing reviews! Try our Samantha, our new voice AI agent.

Darktrace vs Illumio vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Darktrace15.5%
Vectra AI12.0%
ExtraHop Reveal(x)6.3%
Other66.2%
Network Detection and Response (NDR)
Cloud and Data Center Security Mindshare Distribution
ProductMindshare (%)
Illumio17.2%
Akamai Guardicore Segmentation16.0%
VMware NSX10.4%
Other56.4%
Cloud and Data Center Security
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR2.0%
Splunk Enterprise Security7.0%
IBM Security QRadar5.2%
Other85.8%
Security Information and Event Management (SIEM)
 

Featured Reviews

AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Irfan Sharfi - PeerSpot reviewer
Security Professional at a tech vendor with 10,001+ employees
Micro-segmentation has transformed endpoint protection and now isolates internal threats effectively
Illumio can be improved in several areas based on our feedback. Sometimes, the PCE experiences slowness, especially when deploying around 300,000 endpoint devices. When these devices communicate within the network, loading the map or connections can cause latency, which needs improvement for a more user-friendly and faster experience. Regarding improvements to the interface, I believe we can add more features to the graphical user interface, such as proper logs. While the logs currently indicate what was blocked or allowed, clicking on a specific log should provide more information, such as which extra-scope rule is causing a denial, offering better analysis for troubleshooting.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that it works autonomously."
"It is very easy to work with Darktrace once you know how it works and the type of permissions that you need to get related to the security over a network. The interface is awesome. I'm sure that you have seen Ironman, and you know Jarvis, the computer of Tony Stark. The interface of Darktrace is very similar, and you can see in 3D, like a hologram, the whole network, traffic, and all the traces inside the network. The interface is awesome, and it provides a lot of information. At least for us, it is very easy to handle this interface, get the reports, and do the interpretation of those reports. Darktrace also provides mobile monitoring. With an app on your mobile phone, you can view the information live, which is very useful for area directors and field engineers. Darktrace can be also correlated with any type of big data solution, such as Splunk."
"It's a very stable product."
"We are able to detect a lot of things, actually, and see what is happening in our network."
"We allow customers to access our Wi-Fi as guests, and some of them were going to restricted sites. Darktrace showed us what they were doing so we could block them."
"The most valuable feature of Darktrace is its ability to detect and counter threats before they occur."
"One thing I appreciate is Antigena Email, which is for email protection."
"The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7."
"The solution is easy to use."
"The solution helps to maintain logs and monitor activities. It also helps us with access management. The tool helps us to secure organizational data that include files."
"Customer support is excellent."
"Illumio serves as a single endpoint technology where I can implement various features, including a zero-trust network, north-to-south and east-to-west configurations, and micro-segmentation, all coming from one platform, which ultimately saves us time and money."
"The dependency map is most valuable feature."
"The strongest aspect of Illumio is the visual traffic interface, which allows us to see all traffic that communicates with our servers and allied companies."
"It has helped us to understand internal network visibility and firewall policy implementation. We use the product to simplify firewall policy implementation."
"The product provides visibility into how the applications communicate and how the network protocols are being used."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless."
"The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
"I've used other products such as QRadar and other SIEM solutions and I find this solution is much more simplified and user-friendly."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
"Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
"Log search allows us to dive deep into aggregated logs and query all event types at once.​"
 

Cons

"There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market."
"The solution could have better integration capabilities."
"The cost is a bit on the higher side."
"It can have more integration with orchestration or event management solutions."
"The solution could be easier to use."
"This product needs more in terms of prevention."
"The main portal needs improvement as it is difficult to use."
"The Darktrace Mobile app needs improvement as it's currently limited in functionality, and the learning AI takes a while to adapt to new devices, flagging new users as threats for up to a month before recognizing them as regular network users."
"Illumio Adaptive Security Platform could improve by supporting more operating systems, for example, Cisco and Apache appliances."
"It requires a low-level re-architecting of the product."
"Illumio does not have much in terms of application dependency mapping features."
"I would like to see better data security in the product."
"There should be an option to upgrade from the console to the latest version instead of performing manual upgrades."
"The customer service is lagging a bit. It could be better."
"Sometimes, the PCE experiences slowness, especially when deploying around 300,000 endpoint devices."
"Illumio requires me to create policies for each type of traffic, and for new users, the policy design can be a bit complex."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"Needs a better ability to customize the check within the console."
"I'd like to be able to get the compliance report within the solution which is currently not possible."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"The dashboard is an area that could be simplified."
"Inability to get access to compliance reports within the solution."
"One of the things that could be better is digital forensics. It is there, but it can be better."
"If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is."
 

Pricing and Cost Advice

"The pricing is expensive. It costs over $100,000 a year."
"They are too expensive compared with other vendors."
"The pricing is very flexible for Darktrace. Sometimes, a customer does not have the appropriate budget, but Darktrace can handle that. They offer monthly payments, so the customer can acquire the solution very easily."
"We had an issue with pricing initially and had to cancel some of the features of the projects to fit the budget. I would like to see pricing that is not broken up into parts so that we can buy the whole package once. Darktrace is more expensive than an average solution, but it's functionality won't match that of an average solution."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"The solution is about $6,000 per quarter."
"The product is expensive."
"The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution."
"The product's pricing is around 10,000-15,000 USD. The pricing is on a yearly basis."
"There is a subscription needed to use Illumio Adaptive Security Platform and we pay every three years. Overall the solution is expensive."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"The pricing and licensing are competitive."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"It is a reasonably priced solution."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
889,955 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
9%
Government
7%
Financial Services Firm
17%
Computer Software Company
11%
Manufacturing Company
8%
Insurance Company
6%
Financial Services Firm
9%
Computer Software Company
9%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise12
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
What is your experience regarding pricing and costs for Illumio Adaptive Security Platform?
It will be the same price as the Akamai price for Guardicore. It's expensive, that's true. But when you compare it to...
What needs improvement with Illumio Adaptive Security Platform?
Illumio does not have much in terms of application dependency mapping features. They lack layer 7 process level segme...
What is your primary use case for Illumio Adaptive Security Platform?
Illumio's use case compared to Akamai is exactly the same. For the purpose of micro-segmentation, it is the same.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as ...
 

Also Known As

No data available
Illumio Adaptive Security Platform, Illumio ASP
InsightIDR
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Plantronics, NTT Innovation Institute Inc.
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Darktrace, Vectra AI, TrendAI and others in Network Detection and Response (NDR). Updated: April 2026.
889,955 professionals have used our research since 2012.