Try our new research platform with insights from 80,000+ expert users

Commvault Cloud vs Rapid7 InsightIDR vs Splunk Enterprise Security comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Backup and Recovery
Security Information and Event Management (SIEM)
Security Information and Event Management (SIEM)
 

Featured Reviews

Matt Reller - PeerSpot reviewer
Provides extremely fast backup, is easy to manage, and is flexible
Commvault Cloud's automated policies provide the notification we need to ensure our data is secure and managed correctly. Commvault Cloud provides excellent visibility across all of our organization's data. It is extremely important to our organization that Commvault has a unified platform that offers recovery across cloud, on-prem, and SaaS workloads. It has helped our organization improve by simplifying the way we manage our environment. We could not manage the same environment with only half of our current staff. We have yet to find anything in our environment that Commvault does not support. Commvault Cloud's Risk Analysis helps us identify, categorize, and classify sensitive data enabling us to take the appropriate actions to protect it. Commvault does a good job helping us limit our exposure and ensure compliance. Commvault has helped us reduce our data management costs significantly. Compared to Dell Avamar, the costs are vastly different. Commvault is much more cost-effective. We are licensed by capacity, so we don't have to worry about licensing different features. We have all the features that are licensed by capacity. And as far as ongoing support costs and other expenses, they are much lower than what they were with Dell Avamar. Commvault also gives us the flexibility to use any storage we want, while Avamar is tied to the Data Domain, which is not cheap to support. It has helped us reduce our backup time unless we are using Data Domain. This is because we can perform deduplication and compression on the client layer, which reduces the load on the network. We cannot do this with Data Domain. In fact, if we even attempt to perform a quick progress check before sending data to the Data Domain, the system fails completely. We learned this the hard way. We are using many more advanced features in Commvault Cloud than we ever did in Dell Avamar, simply because we had to license each feature separately in Avamar. As a result, we did not perform many backups in Avamar, such as all database backups (DB2, SAP HANA, Oracle, and SQL). These backups were performed outside of Avamar. We are now using Direct Connect agents for all of our databases. This allows us to perform incremental backups, which we could not do with the previous method. As a result, we have reduced our backup times by two-thirds, or even more in some cases. Compared to when we were backing up directly to Data Domain, Commvault is now running our backups ten times faster. This has resulted in a significant reduction in our backup times. Commvault has helped us reduce the RPO. Even in Data Domain, it has reduced our storage times by about half. It has also helped us reduce the threat detection time. We reduced the RTO significantly with Commvault. Commvault has helped us reduce downtime primarily due to the increase in the performance of resources.
Asim Naeem - PeerSpot reviewer
Providing comprehensive insight into alerts while working towards AI enhancement
I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product. Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.
ROBERT-CHRISTIAN - PeerSpot reviewer
Has many predefined correlation rules and is brilliant for investigation and log analysis
It is very complicated to write your own correlation rules without the help of Splunk support. What Splunk could do better is to create an API to the standard SIEM tools, such as Microsoft Sentinel. The idea would be to make it less painful. In ELK Stack, Kibana is the query language with which you can search log files. I believe Splunk has also a query language in which they search their log files, but once you have identified the log file that you want to use for further security correlation, you want to very quickly transport that into your SIEM tool, such as Microsoft Sentinel. That is something that Splunk could make a little bit less painful because it is a lot of effort to find that log file and forward it. An API with Microsoft Sentinel or a similar SIEM tool would be a good idea.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Commvault is a very stable product."
"We are using a KVM system in our cloud, and this solution works very well with it."
"We have VMware, Hyper-V, Oracle, and Microsoft SQL. We have a lot of different systems, and all of them are supported under one licensing agreement. That's one of the benefits."
"The email archiving feature is very smooth and better than others."
"The compression and deduplication are great for optimizing bandwidth and speed. I don't have to worry about it or think about it, and, because it's a SaaS solution, I don't have to worry about the storage size."
"Complete Data Protection is convenient because you can manage various types of databases, and it's pretty easy to set it up."
"All workloads can be integrated with Commvault. If we use a new technology, Commvault integrates with it. Commvault is a data management solution with support for building the DR side of things. With Commvault we can rapidly back up and restore any application we add to our environment."
"Great archive feature, OnePass, for the file system and Exchange servers."
"Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
"The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily."
"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
"Great coverage of all systems within our network from endpoint to firewall."
"Features for user behavior analytics and the rules for attack review are good."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an application belongs to a known ransomware group. The system rates the threat, offering a clear detection ratio, such as 97 out of 100. It not only identifies threats but also illustrates the associated behaviors, helping us understand the potential risk to a particular endpoint."
"Splunk's interface is user-friendly, and it has apps and add-ons for most applications. We can easily normalize the data to make it readable and understand the logs. We easily get all the field extractions and enrichment done by using the apps and add-ons. This helps us understand the application logs because the raw data is useless unless we extract some useful information from it. These add-ons make it so much easier."
"I really like the user interface and how it works."
"It is very simple to tweak or write a small piece of glue code to go ahead and create a new dashboard for a business unit to make near real-time decisions to focus more on other geographies when launching the product."
"The ability to ingest different log types from many different products in our environment is most valuable."
"The most valuable feature of Splunk Enterprise Security is the comprehensive logging capabilities it provides."
"I like the search feature and the indexing. It's very fast and comprehensive."
"Correlation search, in general, is valuable because it allows us to search multiple data sources easily."
"Low barrier to start searching with the ability to normalize data on the fly."
 

Cons

"They need to improve when it comes to large, video file archiving. They're good, but they have not met my expectations as a customer in this area."
"The workflow has room for improvement."
"The initial setup is rather complex, especially when switching versions."
"They can improve the VMware recovery and VMware backup. There is an improvement area on the VMware infrastructure. They can make available what they call a VSA proxy. They can have an appliance-type setup to deploy VSA backups and help recover quicker. They can have an appliance ready. Instead of having to have a server dedicated to that and installing software on a server, they can just provide an actual appliance for that."
"I would like them to keep working on the new web interface to migrate out of the old interface because the old interface is a bit complex. It was driving customers away because of the complexity. If they migrate everything (100 percent of the features), this would make the product be perfect."
"The HTML interface is a remarkable improvement. However, there are still some features that are not available in that interface that are available in the Java console, but I'm sure that will come with time."
"There is room for improvement in the data center application running on the cloud for the platform."
"Its dashboard could be improved to provide a summarized version of all the jobs instead of having to go through each one of them. We should easily be able to glance at all issues. If I had not gone with the on-premise version, I would have had regular reports with the cloud version. It would be an advantage if they increase the compression rate of the backup. I am keeping it on-prem, so I'll need more disks depending on the policies that I have in the retention period. Its price could also be lower. If a good solution can be cheaper, it is always an advantage."
"There are certain limitations with Rapid7 that I am working on."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level."
"The ability to tune the collector for custom logs would greatly help."
"Inability to get access to compliance reports within the solution."
"They should add more configuration and security features to it."
"I feel it would greatly benefit from more supported log sources."
"InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."
"This solution could be improved by better pricing in general and by easier installation."
"Search head clustering is often temperamental in its current state and should be improved, replaced by something better, or be reverted to search head pooling."
"You can run a script from an event, but it needs many clicks to run that integration, which could be made easier."
"We were inundated with the amount of alerts and alarms that we could get out of it. It is also a resource hog and we didn't have the resources to support it on-prem so we're taking it offline now."
"The solution could improve by giving more email details."
"We've sometimes faced issues with upgrades. The incident review dashboard sometimes breaks after updates. When we add a space or something in the description or anywhere in the SQL, the drill-down value may be reset with a blank value. Before rolling out any software, they should test it thoroughly and ensure clients won't have issues with the upgraded version. It should be compatible with all or most of the apps. All major issues must be addressed before rolling out the upgrade."
"It is very complicated to write your own correlation rules without the help of Splunk support."
"Splunk should align its security principles with those of other vendors like SentinelOne. Splunk has mature APIs that can communicate with various security applications and devices. Splunk can process more to produce an understandable dashboard."
 

Pricing and Cost Advice

"The solution is expensive, but it is worth the money."
"Its cost is reasonable, but anybody else can do better benchmarking."
"Commvault is more expensive than Veeam, which is the reason that we are changing to Veeam for cloud environments."
"Commvault's license fee is per server-based."
"...the battle came down to pricing, as well as some small features, and Commvault was the best in all the criteria."
"We like that there is no extra cost for SharePoint, Teams, or OneDrive. It is all mimicking Microsoft's model. Every user has one terabyte of space. When users start using OneDrive, everybody has one terabyte that will be backed up included in the price."
"The cost of an integrator license is moderate and its features cover most customers."
"It is cheaper than NetBackup, but its price can be lower. If a good solution can be cheaper, it is always an advantage. Its licensing is on a yearly basis."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"The solution has a mid-range price point in the market"
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing is good, and it is not very expensive."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"The pricing and licensing are competitive."
"Rapid7 InsightIDR's pricing is reasonable."
"Splunk is not a cheap solution and the license is billed annually."
"It is expensive. I work for multiple clients. I am working for more than five clients, but most of the clients are switching from Splunk to Sentinel because of the cost. Even though Sentinel is very limited, clients are moving to Sentinel."
"Pricing and licensing are quite high compared to other tools or SIEM tools, but the features justify it."
"Splunk has always been on the expensive side."
"Splunk Enterprise Security is not a cheap product, but I think it is worth every dollar that you pay."
"The pricing is a little bit on the higher side, but looking at what Splunk provides us, it is reasonable."
"I think the price could be improved."
"The price of Splunk is reasonable."
report
Use our free recommendation engine to learn which Backup and Recovery solutions are best for your needs.
859,438 professionals have used our research since 2012.
 

Comparison Review

VS
Feb 26, 2015
HP ArcSight vs. IBM QRadar vs. ​McAfee Nitro vs. Splunk vs. RSA Security vs. LogRhythm
We at Infosecnirvana.com have done several posts on SIEM. After the Dummies Guide on SIEM, we are following it up with a SIEM Product Comparison – 101 deck. So, here it is for your viewing pleasure. Let me know what you think by posting your comments below. The key products compared here are…
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
11%
Manufacturing Company
9%
Government
7%
Computer Software Company
15%
Financial Services Firm
8%
Manufacturing Company
8%
Government
6%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is your experience regarding pricing and costs for Commvault?
The tool is affordable. I rate the pricing a six out of ten. Implementation requires additional costs because we need...
What needs improvement with Commvault?
Data center backup must be improved. We also want the product to provide us with a cloud-based backup. If we use Micr...
What do you like most about Commvault Complete Data Protection?
IntelliSnap and file system backups are valuable features.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingest...
How does Splunk compare with Azure Monitor?
Splunk handles a high amount of data very well. We use Splunk to capture information and as an aggregator for monitor...
What do you like most about Splunk?
There are a lot of third-party applications that can be installed.
 

Also Known As

Commvault Complete Data Protection, Commvault Backup & Recovery, Commvault HyperScale X, Metallic, ThreatWise
InsightIDR
No data available
 

Overview

 

Sample Customers

Aberdeenshire Council, Acxiom, BAM Group Ireland, Catholic Education Diocese of Parramatta, CI Investments, Clifford Chance, American Municipal Power, American Pacific Mortgage, AstraZeneca, Dongbu Steel, Denver Health, Dow Jones, Emirates Steel, Penn State Health, Prime Healthcare, Sonic Healthcare, Sony Network Communications, TiVO, UCONN Health, The Weitz Company
Liberty Wines, Pioneer Telephone, Visier
Splunk has more than 7,000 customers spread across over 90 countries. These customers include Telenor, UniCredit, ideeli, McKenney's, Tesco, and SurveyMonkey.
Find out what your peers are saying about Veeam Software, Zerto, Commvault and others in Backup and Recovery. Updated: June 2025.
859,438 professionals have used our research since 2012.