Try our new research platform with insights from 80,000+ expert users

Rapid7 InsightIDR vs Splunk User Behavior Analytics comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
3rd
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
31
Ranking in other categories
Security Information and Event Management (SIEM) (9th), Endpoint Detection and Response (EDR) (20th), Threat Deception Platforms (5th), Extended Detection and Response (XDR) (15th)
Splunk User Behavior Analytics
Ranking in User Entity Behavior Analytics (UEBA)
4th
Average Rating
8.2
Reviews Sentiment
6.5
Number of Reviews
19
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (14th)
 

Mindshare comparison

As of December 2024, in the User Entity Behavior Analytics (UEBA) category, the mindshare of Rapid7 InsightIDR is 10.9%, up from 8.1% compared to the previous year. The mindshare of Splunk User Behavior Analytics is 10.1%, down from 11.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA)
 

Featured Reviews

Gerard Konan - PeerSpot reviewer
Helps in the management of compliance, secret events and information
One of our customers had a Huawei firewall and we required help to do the configuration. However, the installation was easy with other standard vendors like Cisco and Check Point. The product's deployment got completed in four to five days and we required three people to handle it. One person was in charge of the portal's initial set up and the other one handled the integration of on-premises devices. The third one took care of Office 365 integration.
Hamada-Elewa - PeerSpot reviewer
Decreases the false positives but storage model complexity hampers efficiency
I recommend it to my customers, but I'm a salesman. I am not implementing it myself It decreases the false positives, so it will decrease the time consumed by the operation team to work on Splunk. The most effective one is the integration with other vendors. This is the most attractive one.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"The UI is very good."
"Integration with threat modeling from the Metasploit and InsightIDR repositories."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
"It is a very stable solution."
"Rapid7's reporting is more robust than Tenable's."
"I like that it's a cloud-based solution."
"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
"The most valuable features are the indexing and powerful search features."
"The solution is fast, flexible, and easy to use."
"This intelligent user behavior analytics package is easy to configure and use while remaining feature filled."
"The product is at the forefront of auto-remediation networking. It's great."
"The most valuable feature is the ability to search through a large amount of data."
"Splunk is more user-friendly than some competing solutions we tried."
"We are really pleased with Splunk and its features. It would be practically impossible to function without it. To provide a general overview of the system, it's important to note that the standard log files are currently around 250 gigabytes per day. It would be impossible to manually walk through these logs by hand, which is why automation is essential."
"This is a good security product."
 

Cons

"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"They should add more configuration and security features to it."
"The ability to tune the collector for custom logs would greatly help."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"Cloud risk assessment is one area where I think they need a lot of improvement."
"Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."
"The solution's XDR agents cannot compete with the XDR solutions out there yet."
"The APIs can be further improved in Rapid7."
"The ability to do more complicated data investigation would be a welcome addition for pros, though the functionality now gives most people what they need."
"It would be good if the solution had an analytics tool that allowed us to analyze the data without writing specific queries."
"I'm not aware of any lacking features."
"Enhancing the storage model that they are using is necessary."
"The correlation engine should have persistent and definable rules."
"The initial setup was complex because some of the configurations that we required needed customization."
"There are occasional bugs."
"I would like improved downward integration with other tools such as McAfee and other GCP solutions."
 

Pricing and Cost Advice

"It is more reasonably priced than other vendors."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"The pricing and licensing are competitive."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"Pricing varies based on the packages you choose and the volume of your usage."
"I hope we can increase the free license to be more than 5 gig a day. This would help people who want to introduce a POC or a demo license for the solution."
"My biggest complaint is the way they do pricing... You can never know the pricing for next year. Every single time you adjust to something new, the price goes up. It's impossible to truly budget for it. It goes up constantly."
"The licensing costs is around 10,000 dollars."
"I am not aware of the price, but it is expensive."
"There are additional costs associated with the integrator."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
8%
Manufacturing Company
8%
Government
6%
Computer Software Company
15%
Financial Services Firm
13%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about Rapid7 InsightIDR?
During simulations or demonstrations, the tool generates alerts, providing details such as the specific application, its origin, and potential threats. For instance, it can identify if an applicati...
What do you like most about Splunk User Behavior Analytics?
The solution's most valuable feature is Splunk queries, which allow us to query the logs and analyze the attack vectors.
What is your experience regarding pricing and costs for Splunk User Behavior Analytics?
It's too expensive. If you need observability, you will pay for the whole package of observability. But if you need anything in security, you will pay for the whole package, then you can select the...
What needs improvement with Splunk User Behavior Analytics?
Enhancing the storage model that they are using is necessary. It's too much. The number of VMs, the total number of VMs, is overwhelming. The system is stable, but for the storage issues requiring ...
 

Also Known As

InsightIDR
Caspida, Splunk UBA
 

Learn More

Video not available
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
8 Securities, AAA Western, AdvancedMD, Amaya, Cerner Corporation, CJ O Shopping, CloudShare, Crossroads Foundation, 7-Eleven Indonesia
Find out what your peers are saying about Rapid7 InsightIDR vs. Splunk User Behavior Analytics and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.