No more typing reviews! Try our Samantha, our new voice AI agent.

LevelBlue USM Anywhere vs Rapid7 InsightIDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 24, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
120
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
LevelBlue USM Anywhere
Ranking in Endpoint Detection and Response (EDR)
37th
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
115
Ranking in other categories
Log Management (29th), Security Information and Event Management (SIEM) (27th), Compliance Management (12th)
Rapid7 InsightIDR
Ranking in Endpoint Detection and Response (EDR)
34th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), User Entity Behavior Analytics (UEBA) (11th), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
"The initial setup is pretty easy."
"The tool's use cases are relevant to security."
"Stability is one of the features we like the most."
"Cortex XDR by Palo Alto Networks has given us better endpoint visibility and richer investigation context, allowing us to identify suspicious activity, understand the attack path, and contain potential threats much faster than before."
"But overall, when we speak about security and protection, they are one of the top providers."
"The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly. The way they have done everything and integrated all the solutions that they've purchased over the years to make it a very seamless, effective product is very good. One thing about Palo Alto is that they take the products or services that they purchase and make them seamless for the end user as compared to some companies that purchase other companies and then just kind of have their products off to the side or keep different interfaces. Palo Alto doesn't do that."
"The most valuable aspect of Cortex XDR by Palo Alto Networks for me is its integration with AI detection, where we get to know the behavioral detection based on users, traffic patterns, and different services that we consume."
"AlienVault has streamlined our security functions by combining several different functions into one package."
"AlienVault provides us with a very easy to use, central spot to view log files, and take appropriate action."
"The other big selling feature for us was its integration capabilities with all the other security-based products."
"AlienVault support is what really makes this product a great investment."
"Monitoring customer's critical network is now almost a one man job."
"AlienVault has an advanced component within one package. With this, we can cover more area with one solution."
"We had used previous products and found AlienVault centralized the logging for our security."
"The AlienVault solution has enabled us to create a SOC on a budget with smaller than usual staff requirements, offering a wider range of solutions for our customers."
"I have seen that Rapid7 InsightIDR provides security to the networks and endpoints in the company."
"Simple configuration and automatically syncs to the cloud platform."
"The solution is very stable and works very well for what I need it to do."
"The solution is very intuitive, it's easy to set up, is absolutely stable, and has a lot of integration with other security products."
"Features for user behavior analytics and the rules for attack review are good."
"The solution's initial setup is easy."
"Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
"If you were on other solutions, you would notice that they use agents from third-party, from open-source, from a native OS, or from other tools. Here, however, it is an agent from Rapid7 itself. This adds to the solution's overall capabilities."
 

Cons

"The solution eats memory of the computer, unlike anything I've ever seen."
"The onboarding process could be better."
"The tool needs to be improved in terms of integration and interface."
"The solution should force customers to integrate with network traffic to see the full benefits of XDR."
"The technical support is not very good. I find the process difficult."
"One thing that was missing was the integration part. Currently, they don't have out-of-box integration with IBM QRadar, or if they have the integration, the integration doesn't work well."
"It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
"The playbooks could be improved to include more functionalities or actions."
"The reporting aspect could be improved. While there are a lot of different options available, there are still pieces which are missing."
"I would not recommend anyone to use it. I rate ATT AlienVault USM a one out of ten."
"The menu system can be a little confusing, until you use it for a while."
"AT&T AlienVault USM can improve searchable data. It should be available for more than 90 days. If you need more than 90 days of data, you have to put a request and they give you raw data, which is not easy to search. A good addition would be to allow users to search data older than 90 days."
"I've been using it just for my own personal upskilling in terms of how the product works. At the moment, it is pretty straightforward and simple, and it is working how it is supposed to. The feedback would come once it is deployed to customer sites. They'll be using it on a more frequent basis, and that's when the feedback would come in terms of the areas in which they're facing issues or are looking for simplicity."
"The solution doesn't scale well if you are talking about enterprises using it."
"Their threat intelligence platform needs to be broadened."
"It would be great if there was a feature to add in watch lists, like McAfee or QRadar have -- to keep track of IPs, domain, etc. that I have identified as being malicious."
"The searching feature in Rapid7 InsightIDR needs to evolve"
"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
"It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"
"Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."
"Inability to get access to compliance reports within the solution."
"Needs a better ability to customize the check within the console."
"The dashboard is an area that could be simplified. For management, it should be clear and the files should be there."
"Cloud risk assessment is one area where I think they need a lot of improvement."
 

Pricing and Cost Advice

"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"The price of the product is not very economical."
"This is an expensive solution."
"This is an expensive solution."
"The pricing is a little high. It is per user per year."
"The pricing is okay, although direct support can be expensive."
"The return on investment is from the user side because we have seen the performance of it increase the delivery time of the product if we are using too many web-based and on-premise applications. In indirect ways, we saw the return of investment in terms of performance and user satisfaction increase."
"It's very reasonably priced. It was one of the lowest among the ones I looked at. Licensing is pretty flexible. They can do a two-year or a three-year, even a one-year, perhaps."
"It is a product that is priced in a medium range, making it neither a cheap nor a costly product."
"AlienVault is flexible on their pricing for unlimited licenses."
"We pay around $12,000 a year including storage."
"QRadar, ArcSight and Splunk are some of the most expensive SIEM products out there in the market and not everyone has the budget to buy them. In such cases, AV USM is a very cost effective alternative."
"I rate the price of AT&T AlienVault USM a four out of five."
"They are a little more expensive than Microsoft."
"The ROI is quite good."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"The pricing is good, and it is not very expensive."
"Rapid7 InsightIDR is priced very well and is cost-effective."
"It is more reasonably priced than other vendors."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
916,212 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
13%
Outsourcing Company
12%
Construction Company
11%
Manufacturing Company
10%
Construction Company
18%
Outsourcing Company
17%
Comms Service Provider
9%
Financial Services Firm
9%
Manufacturing Company
10%
Financial Services Firm
10%
Comms Service Provider
8%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise21
Large Enterprise56
By reviewers
Company SizeCount
Small Business65
Midsize Enterprise29
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also...
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about LevelBlue USM Anywhere vs. Rapid7 InsightIDR and other solutions. Updated: September 2026.
916,212 professionals have used our research since 2012.