Try our new research platform with insights from 80,000+ expert users
Informate3db - PeerSpot reviewer
Information Security Manager at a tech vendor with 51-200 employees
Real User
Users/endpoints focus gives us more understanding of network events, allowing us to see behavior patterns
Pros and Cons
  • "The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue."
  • "The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in."

What is our primary use case?

Centralized SIEM / Intrusion Detection System.

How has it helped my organization?

The focus on users/endpoints gives us so much more understanding of the events going on across the network, allowing us to step back from looking at logs only to see the actual behavior patterns instead.

What is most valuable?

The incident case management is the most valuable feature. Even though there's always something I find I would like to add to that feature, the ability to quickly sort through all the logs, network and endpoint data, etc., and add it to an incident case as part of the investigation, is nice. Having it automatically timeline that additional data into the original incident timeline, and correlate it to other notable events and activities on the network, results in a huge improvement in our overall confidence that we've quickly traced down the right source of an issue.

What needs improvement?

The reporting is the weakest aspect. There needs to be multi-level grouping for events (for example, group by user and destination). Right now, we can do a group by user and a separate table or group by destination. But I'd be more interested in where a person was logging into instead of who was logging in or where he was logging in.

Buyer's Guide
Rapid7 InsightIDR
January 2025
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

We have rarely encountered any issues with stability. The primary source of stability issues has been the couple times where there have been lost log messages online. While that's unavoidable, it's definitely not desirable if I happen to have an incident at that time.

What do I think about the scalability of the solution?

We haven't had any issues with scalability yet. (We'll keep trying).

How are customer service and support?

Technical support for InsightIDR has been fantastic. We've used Rapid7 for over a year now, and, while support calls happen, it's rarely over something simple that's just not working. Normally we call because of something heavily situational, and the techs have always figured it out.

Which solution did I use previously and why did I switch?

A private ELK stack was used originally. We moved off of it as we wanted to ensure that we were focusing on the security of the company, and not writing log parsing rules all day.

How was the initial setup?

The initial setup was pretty straightforward, but it takes a little bit of a mental leap to understand how it all works together. What's key to remember is that it is user and endpoint centric, and not account centric. That means that, over time, it will start associating user.a on host1 to user.a on host2 and treating them as the same. It could be a little confusing for some companies if they don't use standardized permissions or don't use administrative-only accounts, but for most current user-access mechanisms, it shouldn't lead to any abnormal results.

What's my experience with pricing, setup cost, and licensing?

Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement.

Which other solutions did I evaluate?

AlienVault, LogRhythm, Qualys.

What other advice do I have?

Have a plan going forward (Syslog exports, agent-based collection, etc.) and ensure WMI is available if using Windows Servers. It was very easy to set up, but troubleshooting can be "fun" if an endpoint doesn't connect correctly. Don't be shy of support requests. They'd rather you be "that person" that keeps getting support, rather than being the one that ran into an issue and stopped using the product.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer1388853 - PeerSpot reviewer
Marketing Expert at a comms service provider with 51-200 employees
Reseller
Top 5
A cost-effective and stable solution but lacks an AI-driven capability
Pros and Cons
  • "It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."

    What needs improvement?

    The solution lacks an AI-driven capability. While other competitors emphasize AI as the most important feature.

    For how long have I used the solution?

    I have been using Rapid7 InsightIDR as a distributor for seven years.

    What do I think about the stability of the solution?

    The product's stability is high. I rate the solution’s stability an eight out of ten.

    What do I think about the scalability of the solution?

    Due to its cloud-based nature and numerous agents, its scalability is high. This, combined with its on-premise environment, ensures rapid performance. It can handle several thousand. It is best suited for large-scale businesses.

    How are customer service and support?

    Support is slow. I'm not satisfied with the support so far.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    Due to the product's complexity, the initial setup can be challenging. Additionally, setting up the product and training the customer can be quite demanding. Deploying the appliance or sensor on-premises can take up to twelve months.

    What's my experience with pricing, setup cost, and licensing?

    The product pricing is very cheap.

    What other advice do I have?

    InsightIDR automates everything through InsightConnect in a seven-day cycle.

    The product has improved significantly since its inception. However, based on feedback I've received from other products in the market, aside from InsightIDR.

    It improved because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively. 

    If you combine it with InsightIDR, then it may become more compact. Maybe IBM was a bit larger. So, having MDR is the main key point for this product.

    Overall, I rate the solution a four out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Rapid7 InsightIDR
    January 2025
    Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
    831,265 professionals have used our research since 2012.
    RicardoSilva3 - PeerSpot reviewer
    Coordinator & Teacher at Pahldata
    Real User
    Top 10
    A stable solution that works well for playbooks and viewing events
    Pros and Cons
    • "The solution is very stable and works very well for what I need it to do."
    • "The main problem lies in the processes within the client's operating systems."

    What is our primary use case?

    Normally, we use the solution as an event viewer to collect and resume cases and playbooks.

    What needs improvement?

    The main problem lies in the processes within the client's operating systems. XDR is superior to CMs. Observing how the processes function within the machine is essential if you are monitoring the client or servers, and not only the event with the first or second line but the third line is most important.

    For how long have I used the solution?

    I've been familiar with the solution for six months.

    What do I think about the stability of the solution?

    The solution is very stable and works very well for what I need it to do. The solution is completely different in an experienced environment and a real environment.

    Which solution did I use previously and why did I switch?

    I have worked with Wazuh before, but only to try it. Wazuh is more or less the same as Rapid7 InsightIDR.

    What other advice do I have?

    I rate Rapid7 InsightIDR an eight out of ten.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Databasea5f3 - PeerSpot reviewer
    Database Administrator with 501-1,000 employees
    Real User
    User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day
    Pros and Cons
    • "​​User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day."
    • "Log search allows us to dive deep into aggregated logs and query all event types at once.​"
    • "The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily."
    • "InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
    • "It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.​"

    What is our primary use case?

    • Security incident
    • Event management

    How has it helped my organization?

    InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly.

    What is most valuable?

    • User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day. 
    • Log search allows us to dive deep into aggregated logs and query all event types at once.

    What needs improvement?

    Threat Intelligence: It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.

    For how long have I used the solution?

    Less than one year.

    What do I think about the stability of the solution?

    During the entire duration of use, there have been no issues noted with stability.

    What do I think about the scalability of the solution?

    The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily. The only constriction point in deployment is the collectors as they are required for agentless logging. However, keeping with the documentation provided for deployment, it handles the load appropriately if the documentation is adhered to.

    How are customer service and technical support?

    Among the best! Their support responds promptly. They fully resolve issues before closing tickets.

    Which solution did I use previously and why did I switch?

    We did not use a previous solution.

    How was the initial setup?

    The initial setup is quite straightforward and can be accomplished from their Quick Start Guide. As the platform is quite adaptable, it can continue to be expanded to add many different log types, which you may find to be a continuous process.

    What's my experience with pricing, setup cost, and licensing?

    Accurately predict your licensing counts as this is a subscription based product.

    Which other solutions did I evaluate?

    We evaluated FireEye Helix, LogRhythm, Splunk, and IBM QRadar.

    What other advice do I have?

    The product is a shift in paradigm being cloud-based with cloud storage. Be prepared to set up several virtual collector servers within your network, if you have a large network.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    it_user836481 - PeerSpot reviewer
    Information Security Officer at a tech vendor with 201-500 employees
    Real User
    Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns
    Pros and Cons
    • "Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
    • "Great coverage of all systems within our network from endpoint to firewall."
    • "Integration with threat modeling from the Metasploit and InsightIDR repositories."
    • "Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
    • "One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."

    What is our primary use case?

    It is used to maintain our security posture by monitoring inside our network for behavior likely to be conducive with elements of the kill chain.

    I was an early adopter of the product. I have seen it get better over time, making use of the data and methodologies used by the industry standard and Rapid7 Metasploit community.

    How has it helped my organization?

    We were able to identify criminals attempting to login from China and put a stop on their IP locations.

    What is most valuable?

    • Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs.
    • Great coverage of all systems within our network from endpoint to firewall.
    • Integration with threat modeling from the Metasploit and InsightIDR repositories.
    • Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns.

    It gives all the advantages of a SIEM. However, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts.

    What needs improvement?

    Although the solution has been improving continually in the time I have been using it, there could be areas of improvement. 

    The one thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    None at all. Even as an early adopter, there were no significant issues with stability. Due to the continual improvement, I do not recall the last issue that I had with the system.

    What do I think about the scalability of the solution?

    We are only a small PLC with 300 staff over six sites and two continents, so scalability has never been a major concern. However, the InsightIDR system looks to be scalable, if required.

    How are customer service and technical support?

    Technical support is excellent both technically, timely, and professional throughout any incident or enhancement request.

    Which solution did I use previously and why did I switch?

    This was our first look at a security as a single entity. After creating a threat register, we were able to mitigate over two-thirds of the threats with this one product.

    How was the initial setup?

    It is very simple. It is a case of requesting a trial from Rapid7, then connecting the relevant logging devices, such as our AD servers or DNS servers to it and sitting back. 

    Obviously, there is more to it than that, but that is the principle.

    What's my experience with pricing, setup cost, and licensing?

    I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.

    Which other solutions did I evaluate?

    At the time, there was no other product that came close to InsightIDR feature set coupled with Rapid7's world leading security position producing other products, such as Metasploit and Nexpose (InsiteVR), which we also use.

    What other advice do I have?

    Use it. The setup is minimal, but the payback is phenomenal.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer1591461 - PeerSpot reviewer
    Product Manager at a tech services company with 11-50 employees
    Reseller
    Top 5
    A cloud-based solution that is licensed based on the number of assets instead of the number of EPS
    Pros and Cons
    • "The solution is very scalable in terms of the licensing model."
    • "The solution's XDR agents cannot compete with the XDR solutions out there yet."

    What is most valuable?

    Rapid7 InsightIDR is a cloud-based solution. Customers don't have to provision storage either internally or externally, and everything is already factored into the cost of the solution. So that takes out the headache.

    The solution is very scalable in terms of the licensing model. It's not licensed based on the number of EPS as in a traditional SIEM solution. It's licensed based on the number of assets, and I believe the customers have more control over their assets than their EPS.

    What needs improvement?

    The solution's XDR agents cannot compete with the XDR solutions out there yet. It has to be a stand-alone XDR solution, and I know they are working on that. They have to ensure that it has the full capabilities of an XDR solution.

    For how long have I used the solution?

    I have been working with Rapid7 InsightIDR for about two years.

    What do I think about the stability of the solution?

    Rapid7 InsightIDR is a stable solution.

    How are customer service and support?

    Rapid7 InsightIDR's technical support is great and very responsive. Of course, their support depends on the SLAs.

    How would you rate customer service and support?

    Positive

    What about the implementation team?

    Rapid7 InsightIDR can be up or running in a matter of hours or minutes. It takes about a week or two to deploy the solution for an enterprise account with full integration of an IT use case.

    What's my experience with pricing, setup cost, and licensing?

    Rapid7 InsightIDR's pricing is reasonable.

    What other advice do I have?

    Overall, I rate Rapid7 InsightIDR a nine out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    PeerSpot user
    Head of Infrastructure at Pearl Data Direct
    Real User
    Great UEB feature, simple configuration that automatically syncs to the cloud platform
    Pros and Cons
    • "Simple configuration and automatically syncs to the cloud platform."
    • "Inability to get access to compliance reports within the solution."

    What is our primary use case?

    We're using Rapid7 as our SIEM. I'm the head of infrastructure and we are customers of Rapid7.

    What is most valuable?

    There are numerous valuable features in this solution. Since it's cloud-based, the configuration is very simple, the collector will automatically sync to the cloud platform. The UEB, the User, Entity, and Behavioral Analytics, has helped us a lot. If there's a slight change in user behavior such as login patterns, my SOX is now able to detect it immediately.

    What needs improvement?

    I'd like to be able to get the compliance report within the solution which is currently not possible. For example, the P-Series was around 77001 compliance report of your SIEM solution. That option is unfortunately not available. 

    For how long have I used the solution?

    I've been using this solution for about 10 months. 

    What do I think about the stability of the solution?

    The solution is stable. 

    What do I think about the scalability of the solution?

    Given that this is a cloud solution there are no limits to scalability. The company is constantly evaluating and evolving and that's reflected in the product.

    How are customer service and technical support?

    We have two levels of support. They have a local presence and help us a lot although response times could be improved. The community is also very powerful, and the documentation is commendable.

    How was the initial setup?

    The initial setup was very easy, it took us only 24 hours to set up around 1000 assets. Implementation was carried out in-house.

    What's my experience with pricing, setup cost, and licensing?

    Licensing costs are based on a subscription model. The solution is very cost-effective because they are not charging based on the EPS but on the number of assets.

    What other advice do I have?

    The solution suits any size company, whether small, medium, or enterprise, it's a very good fit for all devices. The only drawback, for now, is the intel feeds which don't support any TAXII or STIX feeds so they need to be done manually. 

    I rate the solution eight out of 10. 

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Security7d6d - PeerSpot reviewer
    Security Manager
    Real User
    It improved my organization by building a security alerting program
    Pros and Cons
    • "The alerting to drive investigations and remediation has been its most valuable feature.​"
    • "It improved my organization by building a security alerting program."
    • "Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."

    What is our primary use case?

    The following are our main use cases for InsightIDR:

    • Log correlation and searching, as well as alerting;
    • IDR Vulnerability management;
    • IVM;
    • Incident response;
    • Breach detection.

    How has it helped my organization?

    The tool has improved my organization by:

    • Building a security alerting program;
    • IDR-driven improved patching;
    • Implementing IVM.

    What is most valuable?

    The alerting to drive investigations and remediation has been its most valuable feature. Plus the ability to quickly search multiple logs makes investigations easier. Log correlation and alerting are also helpful.

    It gives us one place to have everything easily accessible and the ability to alert (including customisation of alerts).

    What needs improvement?

    Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition.

    For how long have I used the solution?

    One to three years.

    What do I think about the stability of the solution?

    While we have encountered stability issues, these are resource intensive systems so additional hardware solved this problem.

    What do I think about the scalability of the solution?

    There have been no scalability issues. It's easy to add servers.

    How are customer service and technical support?

    The technical support can be considered competent. However, they can be slow to discover solutions to tricky problems.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution.

    How was the initial setup?

    Very simple. Spin up a couple of servers, create all the log connectors and you are up and running. The setup was complete within days and we had alerts being generated straight away.

    What about the implementation team?

    We did the installation without any technical help. The configuration was performed by non-technical staff.

    What's my experience with pricing, setup cost, and licensing?

    The pricing and licensing are competitive. Licensing is simple and straightforward.

    Which other solutions did I evaluate?

    We did not evaluate any other solution in the market.

    What other advice do I have?

    You should use it to drive change within your IT from a security point of view. Run a PoC and see exactly what it can do for you. The simple setup means it will be running in no time and you will get meaningful alerts straight away.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2025
    Buyer's Guide
    Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.