No more typing reviews! Try our Samantha, our new voice AI agent.

Logpoint vs Rapid7 InsightIDR comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
7th
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Logpoint
Ranking in Endpoint Detection and Response (EDR)
34th
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
24
Ranking in other categories
Log Management (30th), Security Information and Event Management (SIEM) (29th), User Entity Behavior Analytics (UEBA) (15th), Security Orchestration Automation and Response (SOAR) (19th)
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
38th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
32
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (7th), Extended Detection and Response (XDR) (21st)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Rifat Hasan - PeerSpot reviewer
System Engineer at Corporate Projukti Limited
Has lacked proper integration and consistent support communication
I selected Logpoint for the pricing as it is reasonable. I am located in Bangladesh, South Asia, Dhaka. I have tried to contact Exabeam by mail repeatedly, but there has been no response. My company, Corporate Projukti Limited, including my Bangladesh area head, technical director, and team manager, have sent emails to contact Exabeam solution, but there is no response. There is already a distributor in Bangladesh. The weakness with Logpoint is UEBA. UEBA is recommended, but not extra. Exabeam's UEBA is an extra feature. SOAR is extra, but Logpoint's product measurement is 40 or 50. There is a 10% difference with the UEBA and SOAR, so Logpoint is weak there. I would appreciate extra features in Logpoint such as SOAR. SOAR and UEBA are included features in Logpoint. Logpoint's UEBA is a weak point, while Exabeam's UEBA has extra AI through automation. Exabeam has a license included, and the extra license is an add-on. In Logpoint, it is included, which makes it a weak point.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR by Palo Alto Networks has helped lighten the load of our security analysts because it was the major tool that we were using and the one we utilized most."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"From a single pane of glass, you can easily manage all of your endpoints."
"These days it's machine-learning technology and behavior-based analytics features that make us more secure."
"The product's most valuable features are massive user and feature intelligence exploit detection."
"We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us."
"Automation and playbooks have helped me significantly, as Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, efficiently detecting and blocking malicious attacks with firewalls while eliminating workload and speeding responses for next-generation operations."
"It's a nice product that's stable and scalable."
"Technical support is responsive and very friendly."
"The flexibility of the search feature and the solution's analytics features are the most valuable parts of the solution."
"The search feature is valuable. The dashboards are also valuable for our bosses. Another valuable feature, which is the main feature of the product, is the centralization of all the logs."
"The solution's most valuable aspect is the combination of the software and the support that they have."
"Log collection, dashboards and reporting are good."
"The most valuable feature, which is endpoint security, is included in Logpoint, and an extra feature is the integration."
"I use the product for my research and development to enhance my work."
"The main advantage of Logpoint is the support service. They reply within ten minutes to an hour to our queries."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"If you were on other solutions, you would notice that they use agents from third-party, from open-source, from a native OS, or from other tools. Here, however, it is an agent from Rapid7 itself. This adds to the solution's overall capabilities."
"The solution is very intuitive, it's easy to set up, is absolutely stable, and has a lot of integration with other security products."
"The solution is easy to use, and the interface is intuitive."
"Integration with threat modeling from the Metasploit and InsightIDR repositories."
"They can subscribe to Rapid7 because it is more valuable and delivers a greater return on investment."
"It is a very stable solution."
"​​User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day."
 

Cons

"In general, the price could be more competitive."
"To jump from the partner to Palo Alto directly was challenging."
"Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
"If he is using a smaller company, he can depend on some other tools because Cortex XDR by Palo Alto Networks is a bit expensive."
"There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
"Cortex XDR could be improved with more GUI features."
"It tends to do 99.9% of things. The only thing I'd like is single sign-on authentication into their cloud platform so that my users can be properly authenticated against it."
"The playbooks could be improved to include more functionalities or actions."
"Logpoint's UEBA is a weak point, while Exabeam's UEBA has extra AI through automation."
"Our customers were not happy with firewalling and the endpoint antivirus."
"My issues with the product are mainly with regard to how it handles collecting logs."
"Logpoint is not flexible. Its documentation is not user-friendly."
"One of the things we faced last year was that we had some memory issues with the server running. We were running them as virtual services, and we were facing some performance issues. Back then, there were some things that had already been solved at the end, but one of the small issues we had was that it was quite memory-consuming. After one upgrade that we did, we faced some performance issues."
"Customer Service: This is a HUGE problem."
"The general public wasn't looking for that type of product unless you had a company that was medical or financial and needed 24-hour responsiveness."
"Log management could be better because transporting the log from a password to the client system takes time."
"There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on."
"The APIs can be further improved in Rapid7."
"The dashboard is an area that could be simplified."
"It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required."
"The interface for doing investigation needs to be enhanced with minor improvements that would make it more useful."
"InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."
"Lacks a mobile application."
"Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already."
 

Pricing and Cost Advice

"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"The solution is expensive. It's pricing is on a yearly-basis."
"Very costly product."
"The price of the product is not very economical."
"The cost of Cortex XDR by Palo Alto Networks is $55 to $90 USD per endpoint per month."
"I am using the Community edition."
"It has reasonable pricing for the use cases it provides to the company."
"We pay about $50,000 USD per year for a bundle that includes Cortex XDR."
"Logpoint's pricing is mid-ranged and depends on the number of devices."
"It's getting more expensive, which is one of the reasons we're looking around just to see if there's anything better value."
"My company used to pay for LogPoint costs annually. It's a cost-effective solution. I'm not part of the Finance team, though, so I'm not sure exactly what the licensing fee is or what license my company had."
"On a scale of one to ten, where one is cheap, and ten is expensive, I would rate LogPoint's pricing a seven. It is not very expensive compared to some of the more costly products, and it is not very cheap compared to some of the cheaper products in the SIEM market."
"For a hundred user deployment the cost is about $10,000. The next year it would be the same because it's a subscription-based license. There are separate costs as well, for example, if a customer asks for training for their staff."
"It has a fixed price, which is what I like about LogPoint. I bought the system and paid for it, and I pay maintenance. It is not a consumption model. Most SIEMs or most of the log management systems are consumption-based, which means that you pay for how many logs you have in the system. That's a real problem because logs can grow very quickly in different circumstances, and when you have a variable price model, you never know what you're going to pay. Splunk is notoriously expensive for that reason. If you use Splunk or QRadar, it becomes expensive because there are not just the logs; you also have to parse the logs and create indexes. Those indexes can be very expensive in terms of space. Therefore, if they charge you by this space, you can end up paying a significant amount of money. It can be more than what you expect to pay. I like the fact that LogPoint has a fixed cost. I know what I'm going to pay on a yearly basis. I pay that, and I pay the maintenance, and I just make it work."
"Our licensing fees are about $10,000 USD per month, which I think is fair."
"It was on a yearly basis at about $100K. It was not a huge environment. We were running it on our own virtual server environment, which, of course, had a cost. There was hardware and some energy cost, and then there were Microsoft Windows licenses for servers. That's all, but there was nothing in comparison to the licensing costs."
"The pricing and licensing are competitive."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"It is a reasonably priced solution."
"It is more reasonably priced than other vendors."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"​Accurately predict your licensing counts as this is a subscription based product.​"
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
892,383 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Financial Services Firm
12%
Comms Service Provider
8%
Manufacturing Company
8%
Computer Software Company
15%
Construction Company
13%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
10%
Computer Software Company
9%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise20
Large Enterprise48
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for LogPoint?
I rate the pricing at eight, suggesting it's relatively good or affordable.
What needs improvement with LogPoint?
I selected Logpoint for the pricing as it is reasonable. I am located in Bangladesh, South Asia, Dhaka. I have tried ...
What is your primary use case for LogPoint?
I had experience with Logpoint before, and I contacted the Exabeam solution, but there was no response; they did not ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
AP Pension, Copenhagen Airports, KMD, Terma, DISA, Danish Crown, Durham City Council, Game, TopDanmark, Lahti Energia, Energi Midt, Synoptik, Eissmann Group Automotive, Aligro, CG50...
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Logpoint vs. Rapid7 InsightIDR and other solutions. Updated: April 2026.
892,383 professionals have used our research since 2012.