Try our new research platform with insights from 80,000+ expert users

LogRhythm UEBA [EOL] vs Palo Alto Networks Advanced Threat Prevention vs Rapid7 InsightVM comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Featured Reviews

Sheikh Abu Ayub Azad - PeerSpot reviewer
Great at managing cyber incidents; the technical support could be improved
The initial setup is easy, partly because LogRhythm is primarily based on the Windows platform. It's good to have two engineers for deployment but it can be done with one. It's more about the knowledge. Deployment is typically done in two or three different phases. It usually takes up to three full months to get good deployment. There's the initial onboarding of all the log sources, then collecting data in the data lake, followed a couple of weeks later with some minor tuning before the final tuneup.
Nasir Akbar - PeerSpot reviewer
Numerous support challenges arise but unique security features impress
In this scenario with Palo Alto Networks Advanced Threat Prevention, I did not get any opportunity to work on it. The only thing I did was forward the logs to the SIEM solution.For government entities, they are not allowing configuration changes. For non-government users, there is a support portal to get the configuration file and upload it to the portal. We can identify misconfigurations and where the loop is very big, so we can get the report and establish it. In Saudi Arabia specifically, the support service needs improvement. When customers have incidents with Palo Alto Networks Advanced Threat Prevention and want to open a case with the Palo Alto team, the available number in Saudi Arabia leads to a long procedure. They're not able to answer within one or two hours. This needs to be implemented. They may need to open offices in Dubai or other places for Arabic-speaking people to access TAC support.
Anusha Sadasivani - PeerSpot reviewer
Rapid deployment and user-friendly architecture streamline vulnerability management but customer support response needs improvement
We are still using Rapid7 InsightVM I personally still use Rapid7 InsightVM. We use Rapid7 InsightVM for vulnerability scanning. It supports both agent-based and agentless scanning, which is part of our vulnerability management strategy. The agentless scan in Rapid7 InsightVM is effective and…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has a lot of features. It has file integration monitoring."
"The most valuable features are file activity monitoring and registry activity monitoring."
"The solution's most valuable features are the graphical user interface and the reporting."
"It is easy to monitor users and that is how the solution is adding value to our firm."
"I can investigate attacks more quickly using machine learning tools."
"I typically use the product for reducing cyber risk, and I can investigate attacks more quickly using machine learning tools."
"Good capability pinpointing specific cyber incidents."
"The solution is useful for privilege accounts and super admin accounts. It is beneficial from a security perspective. The tool uses machine learning rather than threshold-based alerts. For instance, it can detect unusual user logins, such as a user logging in from a new browser or location."
"I rate Palo Alto Networks Advanced Threat Prevention as nine out of ten."
"The most valuable feature is its use of machine learning to detect potentially unknown threats."
"Palo Alto Networks Threat Prevention is the market leader as far as security gateways and endpoint protection. Additionally, the threat database that is used is one of the best."
"We are currently using the URL filtering feature, which is the most popular."
"The sandboxing tools offer great prevention for cloud feeds."
"The most valuable features are the simplicity, transparency, and overall ease of management."
"The application control and vulnerability protection are the most valuable features."
"It's very easy to use and configure. What is nice about Palo Alto is that even if you don't understand how to use it, you can just click on upload and upload everything that needs to be blocked."
"NeXpose is a pretty good vulnerability scanner... There's a nice dashboard."
"The solution is automatically scheduled so it runs by itself."
"Has great reporting features."
"The solution works well."
"The most important aspect of the solution is that it rarely gives false positives, especially compared to other products. It provides very clear reports for our IT teams to look at."
"I liked the dashboard on it. I could customize my dashboard with different widgets and different heat maps."
"The most valuable feature of the Rapid7 InsightVM solution is the Live Risk Score."
"The most valuable feature for us is the different types of reporting it provides."
 

Cons

"The on-premises LogRhythm is not very scalable. When considering packets per second or the MPS needed for additional logs such as web application logs, scalability is usually found in cloud products."
"It should have better mitigation with other solutions and be tightly integrated with other solutions. It has to be improved."
"The UI could be improved a little bit."
"In general, if something needs to be improved in the algorithm, it would be the dashboards."
"LogRhythm UEBA's data aggregation needs to be improved. Open-source users do not have much documentation available. Documentation is available only for enterprise users."
"The cloud version is lacking and not up to par."
"The product should improve its dashboards. Splunk has neat dashboards. Additionally, we would like to enhance the use cases provided by LogRhythm as its use case library is not as extensive as other tools. Its machine-learning capabilities need to improve when compared to other solutions. It lacks risk quantification in a single, transparent view for individuals such as CSOs."
"It would be helpful if there were more guidance provided for integrating with unsupported devices."
"Right now we are focusing on email. If Palo Alto can increase the features related to email filtering and the new malware, it would help us protect our systems."
"I think they can use some improvement on FID."
"Sometimes when you want to group a set of ports, and communicate with Palo Alto, you cannot group TCP and UDP ports together. This needs to be adjusted."
"Generally, to deploy it will take some downtime, about a day."
"The solution could benefit from improved AI analytics to predict potential attacks before they occur, similar to NDR systems."
"It's not so easy to set up a test environment, because it's not so easy to get the test license. The vendor only gives you 90 days for a test license; it's a tough license to get."
"In terms of what needs improvement, the only thing I don't like is the support."
"The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems."
"Within InsightVM, there is no feature to assign a ticket. If we can have more API calls, we can do that from InsightVM."
"I would say that it improved our visibility, but it left things open."
"Rapid7 InsightVM is expensive, possibly one of the highest in pricing among similar products."
"A definite improvement would be to make it easier to run ad-hoc scans without needing to assign the asset to a site or group."
"There are end-user needs and expectations that are being overlooked in the development that could be addressed by appointing a customer advisory board."
"It would be nice to have an additional feature that would provide reports on who has logged onto the console or who did what on the console."
"They should improve the cybersecurity feature of the solution."
"Their customer support should be improved, and the effectiveness of scans also needs to be improved."
 

Pricing and Cost Advice

"Licensing is on a yearly basis. It's not expensive compared to its competitors."
"I rate the product's pricing a three out of ten. However, the cloud version is expensive. You need to hire professional services for deployment and migrations, which can be expensive."
"As LogRhythm UEBA is pretty expensive, I'd give its pricing a seven out of ten."
"The pricing is nice when compared to other products in the industry."
"LogRhythm UEBA's pricing is affordable for small and medium businesses."
"It is quite a budget-friendly product."
"Palo Alto Networks Advanced Threat Prevention is quite competitive, offering extensive threat detection and prevention capabilities, though it is priced higher than some alternatives."
"From one to ten, with one being the most expensive, I would rate the pricing of Palo Alto Networks Threat Prevention a one out of ten. It is my understanding that Palo Alto Networks Threat Prevention is the most expensive one."
"Palo Alto Networks Threat Prevention could improve by having consistent pricing at system levels."
"It's not too expensive."
"The cost involves the price of the hardware, which is expensive. However, most of the Palo Alto solutions are expensive."
"The pricing and the licensing are pretty competitive at this stage. As a reseller, I would like to see the price come down a little bit so I can compete better against other firewalls because we do that all the time."
"There is an initial, expensive investment but the return is good."
"It is an expensive solution and I would like to see a drop in price."
"The product is cheaper than the other similar tools available in the market."
"Licensing fees are paid on a yearly basis."
"InsightVM is an expensive product, especially compared to its competitors, at around a million NOK per year."
"In some cases, we procure the licenses. In some cases, the customers directly buy the license from Rapid7."
"Its pricing depends on the number of users per month."
"The solution's pricing is better than Nexus which charges a high amount for very little use."
"It is pretty expensive. It depends on what you consider pricey, however, if you only look at vulnerability management solutions, such as within VM or VMDR, there are, I suppose the prices are almost the same. But I believe you will discover that for yourself."
"The licensing is asset-based and very straightforward."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
865,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
9%
Retailer
9%
Comms Service Provider
7%
Computer Software Company
14%
Manufacturing Company
9%
Government
9%
Financial Services Firm
8%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about LogRhythm UserXDR?
The solution is useful for privilege accounts and super admin accounts. It is beneficial from a security perspective....
What is your experience regarding pricing and costs for LogRhythm UserXDR?
I rate the product's pricing a three out of ten. However, the cloud version is expensive. You need to hire profession...
What needs improvement with LogRhythm UserXDR?
In general, if something needs to be improved in the algorithm, it would be the dashboards. The dashboards with solut...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What is your experience regarding pricing and costs for Palo Alto Networks Threat Prevention?
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to comp...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What do you like most about Rapid7 InsightVM?
The product's initial setup phase was very easy.
What is your experience regarding pricing and costs for Rapid7 InsightVM?
The customers are mostly SMBs, though some enterprise organizations have also deployed the solution. This is neither ...
 

Also Known As

LogRhythm UserXDR, LogRhythm Enterprise UEBA
No data available
InsightVM, NeXpose
 

Overview

 

Sample Customers

Information Not Available
University of Arkansas, JBG SMITH, SkiStar AB, TRI-AD, Temple University, Telkom Indonesia
ACS, Acosta, AllianceData, amazon.com, biogen idec, CBRE, CATERPILLAR, Deloitte, COACH, GameStop, IBM
Find out what your peers are saying about IBM, Exabeam, Cynet and others in User Entity Behavior Analytics (UEBA). Updated: July 2025.
865,164 professionals have used our research since 2012.