Try our new research platform with insights from 80,000+ expert users

Fortinet FortiSIEM vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortinet FortiSIEM
Ranking in Security Information and Event Management (SIEM)
8th
Average Rating
7.6
Reviews Sentiment
6.2
Number of Reviews
75
Ranking in other categories
AI Observability (8th)
Rapid7 InsightIDR
Ranking in Security Information and Event Management (SIEM)
21st
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
32
Ranking in other categories
User Entity Behavior Analytics (UEBA) (10th), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (8th), Extended Detection and Response (XDR) (20th)
 

Mindshare comparison

As of March 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Fortinet FortiSIEM is 2.7%, down from 3.1% compared to the previous year. The mindshare of Rapid7 InsightIDR is 2.1%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Fortinet FortiSIEM2.7%
Rapid7 InsightIDR2.1%
Other95.2%
Security Information and Event Management (SIEM)
 

Featured Reviews

SY
Network Engineer at Ogma Consulting
Comprehensive monitoring boosts security, yet incident management features need expansion
Fortinet FortiSIEM should broaden its remediation part to include more features for incident management. Currently, to manage repetitive incidents or for remediation, I need to use a separate software called FortiSOAR. Additionally, the search functionality in FortiAI should be improved to provide more precise results, making it easier for me to understand what actions need to be taken.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In large-sized medium-sized and a small-sized organizations, it improves the ability to quickly drill down into events that occur, perform analysis, and find root cause."
"FortiSIEM provides a single PIN to monitor SOC and NOC, is a nice tool for integration and monitoring, and provides multiple categories for monitoring based on security designations like low, medium, and high."
"The most valuable features for us are the built-in reports and alerts, along with the extreme flexibility in reporting and rule generation."
"FortiSIEM's log correlation is good."
"I like FortiSIEM because it integrates natively with our other Fortinet solutions and the Fortinet Fabric, but it also integrates with Cisco, Palo Alto and other security fabrics."
"Our customer did not have security monitoring in the first place. With this solution, it provided security posture management and visibility about the security landscape and threats that they had."
"Analytics is the most valuable feature. The business service summaries in the dashboards and the correlations for the SIEM are also valuable features."
"The primary valuable feature is that it has replaced a whole lot of other products with one platform."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
"I like that it's a cloud-based solution."
"The solution is very cost-effective because they are not charging based on the EPS but on the number of assets."
"Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
"The incident case management is the most valuable feature, and the ability to quickly sort through all the logs, network and endpoint data, and add it to an incident case as part of the investigation, with automatic timelining and correlation to other notable events and activities on the network, results in a huge improvement in our overall confidence that we have quickly traced down the right source of an issue."
"I like the tool's user analysis feature."
"It improved my organization by building a security alerting program."
"The biggest reason why we chose Rapid7 was to gain value in a really quick time. Its deployment doesn't take months. It just takes a few days."
 

Cons

"The backup and recovery process for this solution needs improvement."
"Fortinet FortiSIEM is a little out of sight and needs more marketing efforts to be popular in the market."
"They should enhance the solution's AI capabilities, including XDR and EDR."
"Fortinet FortiSIEM could improve by having a signature update."
"They need to integrate better with Cisco and Palo Alto."
"Customer support service could be better."
"The biggest thing that could be better is a quicker response to support cases."
"Fortinet FortiSIEM could improve by having better integration and extensions. This would benefit by allowing us to give more rules."
"Personally, I feel it would greatly benefit from more supported log sources."
"Needs a better ability to customize the check within the console."
"It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required."
"The APIs can be further improved in Rapid7."
"One thing that springs to mind is easier API integration with ITSMs."
"The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination)."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"The interface for doing investigation needs to be enhanced with minor improvements that would make it more useful."
 

Pricing and Cost Advice

"Manageable, however would be better as pay as you go versus CapEX."
"Pricing is determined based on the customer's budget."
"Please be cheaper and more simplified."
"Fortinet FortiSIEM is cheaper compared to other products."
"The solution is available for both, perpetual and subscription licenses."
"FortiSIEM's licensing is based on EPS, and its pricing is competitive in the market."
"This is probably more on the lower cost end of the spectrum compared to competing products. Fortinet's license model is based on events per second, which makes sense, but that's not typical. It makes it very hard to calculate what your costs are going to be as you scale the platform because some log sources, such as firewall logs, are very noisy, and there are lots and lots of events per second, but some of them are not. So, it becomes a bit of a science experiment trying to guess what your costs are going to be as you scale the solution. This is where other competing products perhaps have a more straightforward license model."
"There are additional features that cost more than the standard licensing fees."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"The solution has a mid-range price point in the market"
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"The pricing and licensing are competitive."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
884,976 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Comms Service Provider
9%
Financial Services Firm
9%
Manufacturing Company
7%
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business34
Midsize Enterprise22
Large Enterprise24
By reviewers
Company SizeCount
Small Business20
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What do you like most about Fortinet FortiSIEM?
Fortinet FortiSIEM needs to provide better API integrations to users.
What is your experience regarding pricing and costs for Fortinet FortiSIEM?
My experience with pricing, setup cost, and licensing for Fortinet FortiSIEM is wonderful, as it offers an excellent license compared to other vendors.
What needs improvement with Fortinet FortiSIEM?
Fortinet FortiSIEM is great overall. Performance could be enhanced, but I do not wish to elaborate on needed improvements.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature...
 

Also Known As

FortiSIEM, AccelOps
InsightIDR
 

Overview

 

Sample Customers

FortiSIEM has hundreds of customers worldwide in markets including managed services, technology, financial services, healthcare, and government. Customers include Aruba Networks, Compushare, Port of San Diego, Cleveland Indians, Infoblox, Healthways, and Referentia.
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Fortinet FortiSIEM vs. Rapid7 InsightIDR and other solutions. Updated: March 2026.
884,976 professionals have used our research since 2012.