No more typing reviews! Try our Samantha, our new voice AI agent.

NetWitness NDR vs Rapid7 InsightIDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
NetWitness NDR
Ranking in Endpoint Detection and Response (EDR)
56th
Ranking in Extended Detection and Response (XDR)
38th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (48th), Threat Intelligence Platforms (TIP) (33rd), Security Orchestration Automation and Response (SOAR) (23rd), Network Detection and Response (NDR) (19th)
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
32nd
Ranking in Extended Detection and Response (XDR)
18th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (4th)
 

Mindshare comparison

As of September 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.6%, down from 3.9% compared to the previous year. The mindshare of NetWitness NDR is 1.0%, up from 0.5% compared to the previous year. The mindshare of Rapid7 InsightIDR is 1.3%, up from 1.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.6%
Rapid7 InsightIDR1.3%
NetWitness NDR1.0%
Other94.1%
Endpoint Detection and Response (EDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its interface and pricing are most valuable, and it is better than other vendors in terms of security."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
"The tool's use cases are relevant to security."
"Its ability to react to cyber data attacks is awesome."
"Cortex XDR by Palo Alto Networks is easy to use and does not consume a lot of hardware resources."
"Cortex is the best solution for avoiding security breaches, malware attacks, and other kinds of security issues."
"The anti-exploit is impenetrable."
"It helps our security team respond more accurately when there are threats, then we get less false positives or negatives."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
"They have recently updated the features and the most valuable ones are the instant threat response, ease of use, web interface, integration, and easy access. RSA NetWitness Endpoint is very compatible with other solutions and technologies. However, they do not rely on third-party solutions and have most features built-in."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"It is stable. We have been using it for some time, without any issues."
"The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good."
"I would recommend others to use RSA NetWitness Endpoint at this time because they have evolved from an MD to an EDR solution to an XDR solution."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"The solution is very cost-effective because they are not charging based on the EPS but on the number of assets."
"I like the tool's user analysis feature."
"It improved my organization by building a security alerting program."
"Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable."
"It gives all the advantages of a SIEM, however, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts."
"The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"The solution is easy to use, and the interface is intuitive."
 

Cons

"It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"The price could be a little lower."
"The technical support is not very good. I find the process difficult."
"The server sometimes stops continuously to check things so it would be helpful to receive access updates or technical reasons."
"Threat detection could be better."
"This solution needs an upgrade in reporting. I have heard from RSA that they are working on this, but as of yet it is not available."
"The integration of the solution needs to be improved. The dashboard needs lots of updates as well. In the next release, we would like to see advanced fraud detection features."
"RSA NetWitness Endpoint is a scalable solution. However, the problem which we normally face is in terms of the migration of the solution."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"RSA NetWitness Network could improve on integration with non-native application integration."
"The solution is modular, for example you can buy the RSA ePack, which you buy as a module is not part of the conduit solution. They could include it and have it as an all-in-one solution."
"The product allows us to make only 30 custom rules."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"Personally, I feel it would greatly benefit from more supported log sources."
"The dashboard is an area that could be simplified. For management, it should be clear and the files should be there."
"I'd like to see a mobile application included and some feature related to the generality of segregation for internal users that access the application."
"I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part."
 

Pricing and Cost Advice

"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"Very costly product."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"Cortex XDR by Palo Alto Networks is quite an expensive solution."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"The pricing is okay, although direct support can be expensive."
"I don't have any issues with the pricing. We are satisfied with the price."
"It is "expensive" and flexible."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"It is highly scalable. It can be bought based on your requirements."
"We are on a three-year contract to use RSA NetWitness Network."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"I do not have any opinion on the pricing or licensing of the product."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"It is a reasonably priced solution."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
11%
Outsourcing Company
10%
Comms Service Provider
9%
Construction Company
8%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise6
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
RSA ECAT, NetWitness Network
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
ADP, Ameritas, Partners Healthcare
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about NetWitness NDR vs. Rapid7 InsightIDR and other solutions. Updated: September 2026.
914,109 professionals have used our research since 2012.