No more typing reviews! Try our Samantha, our new voice AI agent.

Logpoint vs Rapid7 InsightIDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Logpoint
Ranking in Endpoint Detection and Response (EDR)
40th
Average Rating
7.6
Reviews Sentiment
6.7
Number of Reviews
24
Ranking in other categories
Log Management (34th), Security Information and Event Management (SIEM) (30th), User Entity Behavior Analytics (UEBA) (15th), Security Orchestration Automation and Response (SOAR) (20th)
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
34th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (24th), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (19th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Rifat Hasan - PeerSpot reviewer
System Engineer at Corporate Projukti Limited
Has lacked proper integration and consistent support communication
I selected Logpoint for the pricing as it is reasonable. I am located in Bangladesh, South Asia, Dhaka. I have tried to contact Exabeam by mail repeatedly, but there has been no response. My company, Corporate Projukti Limited, including my Bangladesh area head, technical director, and team manager, have sent emails to contact Exabeam solution, but there is no response. There is already a distributor in Bangladesh. The weakness with Logpoint is UEBA. UEBA is recommended, but not extra. Exabeam's UEBA is an extra feature. SOAR is extra, but Logpoint's product measurement is 40 or 50. There is a 10% difference with the UEBA and SOAR, so Logpoint is weak there. I would appreciate extra features in Logpoint such as SOAR. SOAR and UEBA are included features in Logpoint. Logpoint's UEBA is a weak point, while Exabeam's UEBA has extra AI through automation. Exabeam has a license included, and the extra license is an add-on. In Logpoint, it is included, which makes it a weak point.
Prajwal Chougale - PeerSpot reviewer
SPC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR features advanced threat detection capabilities."
"The user interface of the solution is sophisticated and straightforward."
"Cortex XDR is a simple platform that's easy for administrators and users. You have a lot of flexibility to change or customize the features."
"The solution's most valuable feature is the user interface."
"The anti-exploit is impenetrable. We chose Traps because it is the only product that we were not able to get anything past."
"Has great threat detection capabilities."
"Threat identification and detection are the most valuable features of this solution."
"Overall, it's a great platform; it integrates very well with other solutions from Palo Alto and also with our vendors, the ease of use is excellent, I love the root cause analysis from Cortex, which is amazing, and in a few clicks you can have the full root cause."
"It is highly recommended. It is a solid SIEM tool. It is very dependable and well-recognized."
"The most valuable feature, which is endpoint security, is included in Logpoint, and an extra feature is the integration."
"It is an AI technology because it is using machine learning technology. So far, there is nothing better out there for UEBA in terms of monitoring endpoints and user activity. It is using machine learning language, so it is right at the top. It provides that capability and monitors all the activities. It devises a baseline and monitors if there is any deviation from the baseline."
"The solution's user interface is quite simple, and the integration is better than other products."
"The most valuable feature of LogPoint is that they have the SIEM and SOAR combined in one solution. They are not on a separate platform."
"They basically charge you in a better way."
"In my experience with medium-sized operations, LogPoint's scalability is excellent, so I would rate it a ten out of ten."
"We like the user and entity behaviour analytics (UEBA) and find it valuable."
"Rapid7's reporting is more robust than Tenable's."
"Very intuitive and easy to set up."
"I rate Rapid7 nine out of 10 for affordability"
"This is a great product and the team is very willing to work with companies."
"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"Simple configuration and automatically syncs to the cloud platform."
"It gives all the advantages of a SIEM, however, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
 

Cons

"As an improvement, I would like to see enhanced connection speeds."
"It tends to do 99.9% of things. The only thing I'd like is single sign-on authentication into their cloud platform so that my users can be properly authenticated against it."
"Enhancing UI simplicity and playbook flexibility are areas that could benefit from more low-code automation options for smoother integrations."
"It is a complex solution to implement."
"In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."
"They are charging for Network Traffic Analyzer (NTA) services, so if the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better."
"Cortex XDR by Palo Alto Networks could improve its user interface, which is more complicated compared to competitors such as SentinelOne."
"If they had pulse rate detection, it would be better."
"The interface needs things like wizards that will assist with creating complex correlation rules."
"Customer Service: This is a HUGE problem."
"One of the downsides is it is not a SaaS solution. It must be on-premises."
"Dashboards could be developed further."
"The solution should offer more integrations with third-party solutions, like incident response platforms, or allow access to third-party big data."
"We were missing visuals and graphics. Recently, a new version seems to have come out, and it has a new graphical user interface. When I was integrating it, it was usable, but the GUI needed improvement."
"The documentation part is something that needs to be improved, as well as the threat intelligence investigation part."
"It needs to improve performance. That's somehow something that others do better."
"I'd like to see a mobile application included and some feature related to the generality of segregation for internal users that access the application."
"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
"If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is."
"Rapid7 doesn't integrate well with all our security tools from various vendors, so we plan to switch. Many of our solutions work with Rapid7, but some do not. We are already searching for a replacement already."
"Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."
"The integration capabilities of the solution have certain shortcomings where improvements are required."
"Cloud risk assessment is one area where I think they need a lot of improvement."
 

Pricing and Cost Advice

"It is "expensive" and flexible."
"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The price of the solution is high for the license and in general."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"Cortex XDR’s pricing is very reasonable."
"This is an expensive solution."
"It's about $55 per license on a yearly basis."
"For a hundred user deployment the cost is about $10,000. The next year it would be the same because it's a subscription-based license. There are separate costs as well, for example, if a customer asks for training for their staff."
"It's getting more expensive, which is one of the reasons we're looking around just to see if there's anything better value."
"LogPoint seemed like it was a good product, but it was expensive and there wasn't any room to move the pricing when customers needed a lower-costing solution."
"It has a fixed price, which is what I like about LogPoint. I bought the system and paid for it, and I pay maintenance. It is not a consumption model. Most SIEMs or most of the log management systems are consumption-based, which means that you pay for how many logs you have in the system. That's a real problem because logs can grow very quickly in different circumstances, and when you have a variable price model, you never know what you're going to pay. Splunk is notoriously expensive for that reason. If you use Splunk or QRadar, it becomes expensive because there are not just the logs; you also have to parse the logs and create indexes. Those indexes can be very expensive in terms of space. Therefore, if they charge you by this space, you can end up paying a significant amount of money. It can be more than what you expect to pay. I like the fact that LogPoint has a fixed cost. I know what I'm going to pay on a yearly basis. I pay that, and I pay the maintenance, and I just make it work."
"On a scale of one to ten, where one is cheap, and ten is expensive, I would rate LogPoint's pricing a seven. It is not very expensive compared to some of the more costly products, and it is not very cheap compared to some of the cheaper products in the SIEM market."
"It's less expensive than the competitors. The Logpoint marketing team is very accommodating and client-friendly. They offer very good reductions in price. They are pretty good in this aspect. They are transparent in their licensing and pricing."
"Logpoint's pricing is mid-ranged and depends on the number of devices."
"Our licensing fees are about $10,000 USD per month, which I think is fair."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"Rapid7 InsightIDR is priced very well and is cost-effective."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"The pricing and licensing are competitive."
"It is more reasonably priced than other vendors."
"The pricing is good, and it is not very expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
911,473 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Construction Company
12%
Comms Service Provider
10%
Financial Services Firm
10%
Construction Company
15%
Computer Software Company
11%
Manufacturing Company
11%
Outsourcing Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise3
Large Enterprise4
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for LogPoint?
I rate the pricing at eight, suggesting it's relatively good or affordable.
What needs improvement with LogPoint?
I selected Logpoint for the pricing as it is reasonable. I am located in Bangladesh, South Asia, Dhaka. I have tried ...
What is your primary use case for LogPoint?
I had experience with Logpoint before, and I contacted the Exabeam solution, but there was no response; they did not ...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
AP Pension, Copenhagen Airports, KMD, Terma, DISA, Danish Crown, Durham City Council, Game, TopDanmark, Lahti Energia, Energi Midt, Synoptik, Eissmann Group Automotive, Aligro, CG50...
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Logpoint vs. Rapid7 InsightIDR and other solutions. Updated: August 2026.
911,473 professionals have used our research since 2012.