Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightIDR vs WatchGuard EPDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
24th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
32
Ranking in other categories
Security Information and Event Management (SIEM) (13th), User Entity Behavior Analytics (UEBA) (3rd), Threat Deception Platforms (5th), Extended Detection and Response (XDR) (15th)
WatchGuard EPDR
Ranking in Endpoint Detection and Response (EDR)
32nd
Average Rating
9.0
Reviews Sentiment
7.3
Number of Reviews
5
Ranking in other categories
Endpoint Protection Platform (EPP) (43rd)
 

Mindshare comparison

As of May 2025, in the Endpoint Detection and Response (EDR) category, the mindshare of Rapid7 InsightIDR is 1.1%, up from 0.7% compared to the previous year. The mindshare of WatchGuard EPDR is 0.6%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR)
 

Featured Reviews

Asim Naeem - PeerSpot reviewer
Providing comprehensive insight into alerts while working towards AI enhancement
I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product. Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.
Phillip Evely - PeerSpot reviewer
Provides good reporting features, saves time, and protects endpoints
The setup is very easy. We have deployed the solution on-premise but can also do it on the cloud. It has a cloud functionality. I can push it from the cloud directly to the endpoint, or I can do it via a group policy. The enterprise-wide deployment takes a day. It is very simple. Once the agent is deployed in any subnet, it monitors the network traffic and informs me about endpoints that don't have the agent. I get alerted via a report. If I have a problem, I can manually deploy on those endpoints. The product is set to auto-update. It updates on its own.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Features for user behavior analytics and the rules for attack review are good."
"InsightIDR helps us investigate an environment to discover information about incidents."
"The solution is very scalable in terms of the licensing model."
"Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
"The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame."
"I definitely recommend Rapid7 InsightIDR."
"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
"Simple configuration and automatically syncs to the cloud platform."
"WatchGuard is commendable for its work on threats."
"The product's most valuable features are the zero-trust application service and its capability to detect threats and attacks."
"The reporting feature is valuable."
"I can put tons of load on it."
"WatchGuard EPDR improves organization primarily by supporting the IT team rather than the end users directly. It helps IT teams accomplish more with fewer people. One of its standout features is the patch management solution, which allows companies without up-to-date services like WSUS to manage patches for Windows and Linux systems. Additionally, it provides the usual endpoint protection features such as virus and malware protection, application control, and website control."
 

Cons

"InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"The dashboard is an area that could be simplified."
"The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"The main problem lies in the processes within the client's operating systems."
"The product is available at a very high price, making it an area where improvements are required."
"The AV and scanning features could be a little bit better."
"The categories in the web filtering should be more comprehensive."
"WatchGuard EPDR does have areas for improvement. One significant gap is the lack of a virtual patching feature integrated into the endpoint security. This would be particularly useful for endpoints running operating systems that are no longer supported, such as Windows 7."
"The categories in the web filtering should be more comprehensive. When a URL is not categorized, I face issues."
 

Pricing and Cost Advice

"It is more reasonably priced than other vendors."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"The pricing and licensing are competitive."
"It is a reasonably priced solution."
"The solution's pricing is better compared to other products."
"The product is available at a high price."
"The price is excellent."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
850,491 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
9%
Manufacturing Company
7%
Government
7%
Comms Service Provider
15%
Computer Software Company
11%
Construction Company
7%
Security Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an applicati...
What do you like most about WatchGuard EPDR?
The product's most valuable features are the zero-trust application service and its capability to detect threats and attacks.
What is your experience regarding pricing and costs for WatchGuard EPDR?
The pricing is slightly high, but the product quality justifies it. The price is fair, neither too high nor too low. Considering all its features, an increase in price would be justifiable.
What needs improvement with WatchGuard EPDR?
I have not found anything requiring improvement. However, overall, the category level should be enhanced. The categories in the web filtering should be more comprehensive. When a URL is not categor...
 

Also Known As

InsightIDR
No data available
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
Information Not Available
Find out what your peers are saying about Rapid7 InsightIDR vs. WatchGuard EPDR and other solutions. Updated: April 2025.
850,491 professionals have used our research since 2012.