Try our new research platform with insights from 80,000+ expert users

ExtraHop Reveal(x) vs Rapid7 InsightIDR comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

ExtraHop Reveal(x)
Average Rating
8.6
Number of Reviews
12
Ranking in other categories
Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (8th)
Rapid7 InsightIDR
Average Rating
8.4
Number of Reviews
31
Ranking in other categories
Security Information and Event Management (SIEM) (9th), User Entity Behavior Analytics (UEBA) (3rd), Endpoint Detection and Response (EDR) (20th), Threat Deception Platforms (5th), Extended Detection and Response (XDR) (15th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. ExtraHop Reveal(x) is designed for Network Traffic Analysis (NTA) and holds a mindshare of 21.0%, up 14.5% compared to last year.
Rapid7 InsightIDR, on the other hand, focuses on Security Information and Event Management (SIEM), holds 2.3% mindshare, down 2.5% since last year.
Network Traffic Analysis (NTA)
Security Information and Event Management (SIEM)
 

Featured Reviews

Jordan Swanson - PeerSpot reviewer
Sep 7, 2022
It helps you visualize how data moves across your network
I rate ExtraHop Reveal(x) 10 out of 10. This is more of a nice-to-have rather than a must-have solution. Something like a CrowdStrike or a next-gen AV is an essential product, whereas NDR is more of a nice-to-have thing. If you only have a little bit of traffic, you're probably not going to get anything out of it. It's better for a medium-to-large enterprise. It's more appropriate for companies wh a massfootprints or industrial applications using use nonstandard devices. It's helpful for things that use SCADA, the Internet of Things, somethingings that don't fit neatly into other management categories. Itty common for industrial, construction, or maintenance devices to be a little lackluster in their security. Major breaches like the Colonial Pipeline hack and attempted hacks on nuclear power plants all went through Internet of Things vulnerabilities and other devices where security wasn't part of their plan. This helps you cover yourself by monitoring the traffic. With something like CrowdStrike, you need to put the CrowdStrike sensor on it, but Reveal(x) looks at everything on the network.
JensWolf - PeerSpot reviewer
Sep 28, 2023
A solution that offers easy setup and deployment phases, along with great scalability and stability
I use Rapid7 InsightIDR to collect logs and information from throughout our company's entire IT environment The most valuable feature of the solution is the single pane of glass that allows me to see all the information in one spot. I can see at one spot to see all the information from all the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution works well for sending sensors."
"Reveal X integrates seamlessly with CrowdStrike. If you see something sketchy on the network, you can quarantine devices through ExtraHop and it'll push to the CrowdStrike server."
"When there are performance issues with an HTTP app, ExtraHop enables us to identify the causes within a few minutes. We can see what transactions are being impacted by something that may be happening within the server environment."
"With ExtraHop Reveal(x), it gives me more visibility into the packets. It doesn't provide the entire packet capture, but it offers more information on how connections are made at the network layer. This can be helpful for detecting network attacks. Additionally, I really like the customizable dashboards and reports. The incident dashboard and alerts provide a good summary initially, and diving deeper into them gives more detailed information. It's also great for analyzing specific attacks and victim logs. The feature that tracks the full attack chain makes it easier to monitor the progress of attacks. Plus, it's connected to the Netria.com app, which I find useful for certain tasks."
"The solution's initial setup process is easy."
"The security features of this solution are the most valuable."
"ExtraHop Reveal(x) is one of the tools that works out of the box when it comes to threat hunting."
"The solution's ability to decrypt SSL traffic is its most valuable feature."
"I like the tool's user analysis feature."
"I like that it's a cloud-based solution."
"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"The solution is very stable and works very well for what I need it to do."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"Great coverage of all systems within our network from endpoint to firewall."
"InsightIDR helps us investigate an environment to discover information about incidents."
 

Cons

"The solution's reporting part and GUI are areas with certain shortcomings where improvements are required."
"They used to have the ability to decode Citrix sign-on, setup, and tear down. Unfortunately, Citrix has stopped sharing that knowledge. Citrix has continued to change its model of processing, making it harder and harder to troubleshoot."
"I think the tuning capabilities could be improved. We're working on minimizing false positives. Apart from that, everything seems fine to me."
"Netflow - Processing Netflow can be cumbersome as it requires triggers to truly gain value and insight. This in turn can add a bit of load to the hardware. The focus of ExtraHop Reveal (x) is live packet data."
"Agent management could certainly use some focus. It should also be a little bit easier to work with collections. We should be able to nest collections within collections. There should be better nesting."
"The solution’s pricing could be improved."
"The solution is expensive and gets more expensive if a company needs to scale it."
"I would like to see more cloud capability."
"Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already."
"I feel it would greatly benefit from more supported log sources."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources."
 

Pricing and Cost Advice

"The solution is based on an annual subscription model and is expensive."
"I rate the price of ExtraHop Reveal(x) a seven on a scale of one to ten, where one is a high price, and ten is a low price."
"I would rate the price a three out of five. It could be less expensive."
"I rate ExtraHop Reveal(x) six out of 10 for affordability. We pay for an annual license. It's always one of those trade-offs. You get a lot of value, but ExtraHop isn't exorbitantly priced. You can pay extra for additional features like the ability to decode HL7 traffic, which is crucial for EMR environments."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"It is more reasonably priced than other vendors."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"The solution has a mid-range price point in the market"
"​Accurately predict your licensing counts as this is a subscription based product.​"
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
report
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
15%
Healthcare Company
6%
Government
6%
Computer Software Company
16%
Financial Services Firm
8%
Manufacturing Company
8%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What is the best network monitoring software for large enterprises?
We just did an assessment for our 47 datacenters around North America. The top two enterprise-level network monitoring solutions were ExtraHop first, Riverbed SteelCenter second. Their negotiated c...
What open source tool can one use to measure bandwidth from one's upstream service provider?
One I am looking closely at is AppNeta. They have an appliance that can digest the flow and do a better job than Netflow. The other one we are using is ExtraHop. This has both a Datacenter Hig...
What do you like most about ExtraHop Reveal(x)?
With ExtraHop Reveal(x), it gives me more visibility into the packets. It doesn't provide the entire packet capture, but it offers more information on how connections are made at the network layer....
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an applicati...
 

Also Known As

Reveal(x), Revealx
InsightIDR
 

Overview

 

Sample Customers

Wood County Hospital
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Darktrace, Auvik, Cisco and others in Network Traffic Analysis (NTA). Updated: November 2024.
814,649 professionals have used our research since 2012.