Try our new research platform with insights from 80,000+ expert users
Head of Infrastructure at Pearl Data Direct
Real User
Top 5
Great UEB feature, simple configuration that automatically syncs to the cloud platform
Pros and Cons
  • "Simple configuration and automatically syncs to the cloud platform."
  • "Inability to get access to compliance reports within the solution."

What is our primary use case?

We're using Rapid7 as our SIEM. I'm the head of infrastructure and we are customers of Rapid7.

What is most valuable?

There are numerous valuable features in this solution. Since it's cloud-based, the configuration is very simple, the collector will automatically sync to the cloud platform. The UEB, the User, Entity, and Behavioral Analytics, has helped us a lot. If there's a slight change in user behavior such as login patterns, my SOX is now able to detect it immediately.

What needs improvement?

I'd like to be able to get the compliance report within the solution which is currently not possible. For example, the P-Series was around 77001 compliance report of your SIEM solution. That option is unfortunately not available. 

For how long have I used the solution?

I've been using this solution for about 10 months. 

Buyer's Guide
Rapid7 InsightIDR
May 2025
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

Given that this is a cloud solution there are no limits to scalability. The company is constantly evaluating and evolving and that's reflected in the product.

How are customer service and support?

We have two levels of support. They have a local presence and help us a lot although response times could be improved. The community is also very powerful, and the documentation is commendable.

How was the initial setup?

The initial setup was very easy, it took us only 24 hours to set up around 1000 assets. Implementation was carried out in-house.

What's my experience with pricing, setup cost, and licensing?

Licensing costs are based on a subscription model. The solution is very cost-effective because they are not charging based on the EPS but on the number of assets.

What other advice do I have?

The solution suits any size company, whether small, medium, or enterprise, it's a very good fit for all devices. The only drawback, for now, is the intel feeds which don't support any TAXII or STIX feeds so they need to be done manually. 

I rate the solution eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1388853 - PeerSpot reviewer
Marketing Expert at a comms service provider with 51-200 employees
Reseller
Top 5Leaderboard
A cost-effective and stable solution but lacks an AI-driven capability
Pros and Cons
  • "It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."

    What needs improvement?

    The solution lacks an AI-driven capability. While other competitors emphasize AI as the most important feature.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR as a distributor for seven years.

    What do I think about the stability of the solution?

    The product's stability is high. I rate the solution’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Due to its cloud-based nature and numerous agents, its scalability is high. This, combined with its on-premise environment, ensures rapid performance. It can handle several thousand. It is best suited for large-scale businesses.

    How are customer service and support?

    Support is slow. I'm not satisfied with the support so far.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    Due to the product's complexity, the initial setup can be challenging. Additionally, setting up the product and training the customer can be quite demanding. Deploying the appliance or sensor on-premises can take up to twelve months.

    What's my experience with pricing, setup cost, and licensing?

    The product pricing is very cheap.

    What other advice do I have?

    InsightIDR automates everything through InsightConnect in a seven-day cycle.

    The product has improved significantly since its inception. However, based on feedback I've received from other products in the market, aside from InsightIDR.

    It improved because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively. 

    If you combine it with InsightIDR, then it may become more compact. Maybe IBM was a bit larger. So, having MDR is the main key point for this product.

    Overall, I rate the solution a four out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    PeerSpot user
    Buyer's Guide
    Rapid7 InsightIDR
    May 2025
    Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
    856,873 professionals have used our research since 2012.
    CoFounder & Head of Technology at intuity
    Real User
    Very intuitive, stable and integrates easily with other security products
    Pros and Cons
    • "Very intuitive and easy to set up."
    • "Lacks a mobile application."

    What is our primary use case?

    We use this solution to develop our business and we also provide it to some of our customers. The primary use case is for security information and event management, monitoring and acting on any event. 

    What is most valuable?

    The solution is very intuitive, it's easy to set up, is absolutely stable, and has a lot of integration with other security products.

    What needs improvement?

    I'd like to see a mobile application included and some feature related to the generality of segregation for internal users that access the application.

    What do I think about the stability of the solution?

    This solution is absolutely stable. 

    What do I think about the scalability of the solution?

    This solution is scalable. 

    How are customer service and technical support?

    The technical support is very good and respond quickly when there is a problem.

    How was the initial setup?

    The initial setup is reasonably straightforward, it takes a few hours. We've deployed it for 10 different clients and we have several engineers and eight certified technical staff that carry out implementation. 

    What's my experience with pricing, setup cost, and licensing?

    You can scale the license as needed. It's really easy to update and upgrade.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    reviewer1526580 - PeerSpot reviewer
    Linux admin at a wholesaler/distributor with 51-200 employees
    Real User
    Suitably priced, stable, and easy to set up, but the dashboard needs improvement
    Pros and Cons
    • "It is a very stable solution."
    • "The dashboard is an area that could be simplified."

    What is our primary use case?

    We use this solution for monitoring intrusion detection and prevention.

    What is most valuable?

    The most valuable feature is monitoring.

    What needs improvement?

    The dashboard is an area that could be simplified.  For management, it should be clear and the files should be there.

    For how long have I used the solution?

    I have only recently started using this solution. It's been a couple of months.

    I believe that we are using th latest version.

    What do I think about the stability of the solution?

    It is very stable.

    What do I think about the scalability of the solution?

    It's a scalable solution. We have more than 1,000 users and we plan to continue using it.

    How are customer service and technical support?

    We have not had the need to contact technical support.

    Which solution did I use previously and why did I switch?

    Previously, we were using another solution. We changed because the price was completely suitable.

    How was the initial setup?

    The initial setup was straightforward. It was simple.

    We have a team of four to deploy and maintain this solution.

    What's my experience with pricing, setup cost, and licensing?

    It is a reasonably priced solution.

    What other advice do I have?

    I am not able to recommend this solution at this time. I don't know it well enough yet. Similarly, it is difficult to say at this time what needs to be improved. We need more time to explore.

    I would rate this solution a seven out of ten, only because I have recently started using it.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1339392 - PeerSpot reviewer
    Enterprise Sales at a tech vendor with 11-50 employees
    Real User
    Easy to use with a simple setup and good scalability
    Pros and Cons
    • "If you were on other solutions, you would notice that they use agents from third-party, from open-source, from a native OS, or from other tools. Here, however, it is an agent from Rapid7 itself. This adds to the solution's overall capabilities."
    • "Cloud risk assessment is one area where I think they need a lot of improvement."

    What is our primary use case?

    We primarily use the solution for a combination of log management as well as threat detection.

    What is most valuable?

    The ease of use of the solution is excellent.

    The individual setup is great. You can set it up and get it going in a short amount of time.

    They have one agent for Insight where, basically, we can also install agents on Linux and Windows Servers as well as the endpoints. This agent provides for more capabilities in terms of threat detection. Normally, SIEM is more centered around log management and data mining. It's nice to have this extra layer. 

    If you look at the agent part, the Insight agent, which is an optional component of InsightIDR, that agent also helps us to detect more threats, due to the fact that the endpoints are also vulnerable to a lot of security breaches. 

    If you were on other solutions, you would notice that they use agents from third-party, from open-source, from a native OS, or from other tools. Here, however, it is an agent from Rapid7 itself. This adds to the solution's overall capabilities.

    What needs improvement?

    Earlier they didn't have a network flow capture product, so they were not able to capture the network flows. We were able to capture the logs but not the network flows. Now, they have acquired a company called NetFort, and now they are also using the capture network flows. This was one of the shortcomings of the product which they have now rectified after acquisition of the company.

    Cloud risk assessment is one area where I think they need a lot of improvement.

    The solution should have a CIS Benchmark in terms of, I would say, config change detection.

    For how long have I used the solution?

    I've been using the solution for about one year.

    What do I think about the scalability of the solution?

    Since it is on cloud, so we need to just provision the collectors, which is like a sensor that captures logs on-premise and sends it to their cloud, the metadata. We are able to scale more. The scalability is high. There is no issue related to redundancy or high availability. Since it is on cloud, it is taken care of from their data center.

    The solution is more suited towards larger enterprises, and not really ideal for smaller companies.

    How are customer service and technical support?

    The technical support is good. They follow and adhere to their SLA terms. Based on the customer's needs, they can go with a higher level of support. Based on their standard support, they adhere to whatever is their SLA terms are and they are typically good enough. There's no complaints of any lag in service. They do a good job.

    Which solution did I use previously and why did I switch?

    I've used other products such as QRadar and other SIEM solutions and I find this solution is much more simplified and user-friendly. Their DNA is also really in security, which they can feed quite effectively into their SIEM. They understand security far better than other OEMs.

    How was the initial setup?

    The initial setup is not complex. It's straightforward. Deployment takes less than two weeks. It is based on the customer's environment, however, on average, you can assume it will take one to two weeks. You only need about two to three people to handle the deployment.

    What about the implementation team?

    We're an integrator for Rapid7. We handle deployments for our customers.

    What's my experience with pricing, setup cost, and licensing?

    If you look at any other SIEM solution, the license is based on events per second or EPS based licensing. Here, the licensing is the number of assets, and the number of days the log would be retained on their cloud. That is one of the huge differences between this solution and the competition.

    What other advice do I have?

    We are solution partners.

    The solution has a console with everything on the cloud, however, only the centers, the log collectors, are on-premise. This solution is actually cloud-based.

    People who want a solution, a very simplified and easy to start, and then they want to start immediately on a solution with fewer complications, so those would be the right customers. You can say SME, mid and large actually, but I think mid and large enterprises would be the right fitment.

    I would recommend the solution. Rapid7's professional services, including their planning, architecture, deployment, et cetera is up to the mark. I would recommend having a few workdays, in the initial planning stage, maybe for assessment of the solution and to take some time to understand everything before beginning. New users should reach out to their Rapid7 professional services for the planning portion of the implementation process.

    I would rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    reviewer1256475 - PeerSpot reviewer
    IT Engineer Security Operation Team at a tech services company with 201-500 employees
    Real User
    An effective tool for identifying threats to a network infrastructure
    Pros and Cons
    • "The web interface is great — very useful and user-friendly."
    • "The interface for doing investigation needs to be enhanced with minor improvements that would make it more useful."

    What is our primary use case?

    I use it to track events on our infrastructure to help with secure access and detection. We have many firewalls and antivirus DHCP (The Dynamic Host Configuration Protocol) DNS (Domain Name System), logs of Office 365, et cetera. We use this software to monitor and track our traffic and usage by creating logs.  

    What is most valuable?

    The most valuable features have to do with ease-of-use. It is easy to check the events, investigate suspicious activities, and do forensic analysis. The web interface is great — very useful and user-friendly.  

    What needs improvement?

    The only thing I can think of to improve the product is that the interface for doing investigation needs to be enhanced. For example, we can add notes through the interface, but we can not attach files to the investigation. It would be a useful addition. It would give us more flexibility to resolve more complicated situations. 

    For how long have I used the solution?

    I have been using this solution for about six months.  

    What do I think about the stability of the solution?

    This solution is stable. Because it is a software as a service product, when any bugs appear, the manufacturer can correct the problems quickly and deploy the solutions immediately. This is better than other solutions on-premises that we would need to install an upgrade to resolve any bugs or other issues.  

    What do I think about the scalability of the solution?

    Because this is a software as a service solution, the provider manages the scalability. It has never been an issue from our end.  

    How was the initial setup?

    The setup for the product was straightforward.  

    What about the implementation team?

    Although we did do the deployments by ourselves, we did it with some support from the provider, but it was easy to deploy.  

    What other advice do I have?

    On a scale from one to ten where one is the worst and ten is the best, I would rate this product as a nine-out-of-ten. It is very good but it could be better with a few details that would improve the utility of the investigations interface.  

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Informate3db - PeerSpot reviewer
    Information Security Manager at a tech vendor with 51-200 employees
    Real User
    Users/endpoints focus gives us more understanding of network events, allowing us to see behavior patterns
    Pros and Cons
    • "The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
    • "The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in."

    What is our primary use case?

    Centralized SIEM / Intrusion Detection System.

    How has it helped my organization?

    The focus on users/endpoints gives us so much more understanding of the events going on across the network, allowing us to step back from looking at logs only to see the actual behavior patterns instead.

    What is most valuable?

    The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue.

    What needs improvement?

    The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    We have rarely encountered any issues with stability. The primary source of stability issues has been the couple times where there have been lost log messages online. While that's unavoidable, it's definitely not desirable if I happen to have an incident at that time.

    What do I think about the scalability of the solution?

    We haven't had any issues with scalability yet. (We'll keep trying).

    How are customer service and technical support?

    Technical support for InsightIDR has been fantastic. We've used Rapid7 for over a year now, and, while support calls happen, it's rarely over something simple that's just not working. Normally we call because of something heavily situational, and the techs have always figured it out.

    Which solution did I use previously and why did I switch?

    A private ELK stack was used originally. We moved off of it as we wanted to ensure that we were focusing on the security of the company, and not writing log parsing rules all day.

    How was the initial setup?

    The initial setup was pretty straightforward, but it takes a little bit of a mental leap to understand how it all works together. What's key to remember is that it is user and endpoint centric, and not account centric. That means that, over time, it will start associating user.a on host1 to user.a on host2 and treating them as the same. It could be a little confusing for some companies if they don't use standardized permissions or don't use administrative-only accounts, but for most current user-access mechanisms, it shouldn't lead to any abnormal results.

    What's my experience with pricing, setup cost, and licensing?

    Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement.

    Which other solutions did I evaluate?

    AlienVault, LogRhythm, Qualys.

    What other advice do I have?

    Have a plan going forward (Syslog exports, agent-based collection, etc.) and ensure WMI is available if using Windows Servers. It was very easy to set up, but troubleshooting can be "fun" if an endpoint doesn't connect correctly. Don't be shy of support requests. They'd rather you be "that person" that keeps getting support, rather than being the one that ran into an issue and stopped using the product.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Security7d6d - PeerSpot reviewer
    Security Manager
    Real User
    It improved my organization by building a security alerting program
    Pros and Cons
    • "The alerting to drive investigations and remediation has been its most valuable feature.​"
    • "It improved my organization by building a security alerting program."
    • "Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."

    What is our primary use case?

    The following are our main use cases for InsightIDR:

    • Log correlation and searching, as well as alerting;
    • IDR Vulnerability management;
    • IVM;
    • Incident response;
    • Breach detection.

    How has it helped my organization?

    The tool has improved my organization by:

    • Building a security alerting program;
    • IDR-driven improved patching;
    • Implementing IVM.

    What is most valuable?

    The alerting to drive investigations and remediation has been its most valuable feature. Plus the ability to quickly search multiple logs makes investigations easier. Log correlation and alerting are also helpful.

    It gives us one place to have everything easily accessible and the ability to alert (including customisation of alerts).

    What needs improvement?

    Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    While we have encountered stability issues, these are resource intensive systems so additional hardware solved this problem.

    What do I think about the scalability of the solution?

    There have been no scalability issues. It's easy to add servers.

    How are customer service and technical support?

    The technical support can be considered competent. However, they can be slow to discover solutions to tricky problems.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution.

    How was the initial setup?

    Very simple. Spin up a couple of servers, create all the log connectors and you are up and running. The setup was complete within days and we had alerts being generated straight away.

    What about the implementation team?

    We did the installation without any technical help. The configuration was performed by non-technical staff.

    What's my experience with pricing, setup cost, and licensing?

    The pricing and licensing are competitive. Licensing is simple and straightforward.

    Which other solutions did I evaluate?

    We did not evaluate any other solution in the market.

    What other advice do I have?

    You should use it to drive change within your IT from a security point of view. Run a PoC and see exactly what it can do for you. The simple setup means it will be running in no time and you will get meaningful alerts straight away.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: May 2025
    Buyer's Guide
    Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.