No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 InsightIDR vs Splunk User Behavior Analytics comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
11th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), Endpoint Detection and Response (EDR) (34th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
Splunk User Behavior Analytics
Ranking in User Entity Behavior Analytics (UEBA)
4th
Average Rating
8.2
Reviews Sentiment
6.6
Number of Reviews
25
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (9th)
 

Mindshare comparison

As of October 2026, in the User Entity Behavior Analytics (UEBA) category, the mindshare of Rapid7 InsightIDR is 4.6%, down from 8.1% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 4.9%, down from 8.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Splunk User Behavior Analytics4.9%
Rapid7 InsightIDR4.6%
Other90.5%
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.
Ahmed Naguib - PeerSpot reviewer
Director at Techpace
Dashboard design excels while prediction algorithms need improvement
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavior Analytics need to be more tuned. The logic needs to be reviewed because it has many false positives. For Splunk User Behavior Analytics, it is not yet a mature product and we are not recommending this to mature customers for now. The machine learning algorithm in Splunk User Behavior Analytics is actually the core thing that needs to be updated because this feeds all the other functions inside it. If the ML functions are not good enough, that means the risk scoring and all other related information will not be correct.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very cost-effective because they are not charging based on the EPS but on the number of assets."
"Great coverage of all systems within our network from endpoint to firewall."
"InsightIDR helps us investigate an environment to discover information about incidents."
"Integration with threat modeling from the Metasploit and InsightIDR repositories."
"Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable."
"​​User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day."
"I rate Rapid7 nine out of 10 for affordability"
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"Splunk is more user-friendly than some competing solutions we tried."
"It's easily scalable."
"It's straightforward in terms of configuration and troubleshooting and log management and monitoring as well. These are the edge points in addition to it being a modular solution where you can capitalize on your current licenses with extra licensing models, which can match the customer's business requirement and it can help the customer to design or to actually plan for their own roadmap."
"The most valuable features are its data aggregation and the ability to automatically identify a number of threats, then suggest recommended actions upon them."
"We have seen a measurable decrease in the mean time to detect and respond to threats, and we are now 40 percent or more effective or faster."
"The most valuable feature is the ability to search through a large amount of data."
"The solution offers good searching and allows for easy creation of dashboards and reports."
"Features like alerts and auto report generation are valuable."
 

Cons

"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."
"Inability to get access to compliance reports within the solution."
"There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on."
"InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."
"I think they could have a built-in user behavior analytics engine, and more advanced artificial intelligence features as well."
"The machine learning algorithm in Splunk User Behavior Analytics is actually the core thing that needs to be updated because this feeds all the other functions inside it."
"If the price was lowered and the setup process was less complex, I would consider rating it higher."
"A disadvantage is that it can lead to cost overrun if not properly factored or governed."
"The initial setup was complex because some of the configurations that we required needed customization."
"They should work to add more built-in correlation searches and more use cases based on worldwide customer experiences. They need more ready-made use cases."
"The price of Splunk UBA is too high."
"High data ingestion costs can be an issue, especially for large enterprises, as Splunk charges based on the amount of data processed."
 

Pricing and Cost Advice

"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"The pricing is good, and it is not very expensive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"I am not aware of the price, but it is expensive."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"There are additional costs associated with the integrator."
"Pricing varies based on the packages you choose and the volume of your usage."
"The licensing costs is around 10,000 dollars."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Computer Software Company
6%
Financial Services Firm
12%
Manufacturing Company
8%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise7
Large Enterprise12
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
Splunk User Behavior Analytics is a premium product. Compared to all other products in the market, it is the most expensive one in all aspects including professional service and licenses, even the ...
What needs improvement with Splunk User Behavior Analytics?
Splunk User Behavior Analytics is still an immature product, so it still needs some R&D to be able to be mature in the market. The prediction, algorithms, and ML codes behind Splunk User Behavi...
What is your primary use case for Splunk User Behavior Analytics?
The main use cases for Splunk User Behavior Analytics include threat detection. I detect insider threats, compromised users, account misuse, and all those things. I use unsupervised and supervised ...
 

Also Known As

InsightIDR
Caspida, Splunk UBA
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Rapid7 InsightIDR vs. Splunk User Behavior Analytics and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.