- Security incident
- Event management
Database Administrator at a educational organization with 501-1,000 employees
User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day
Pros and Cons
- "User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day."
- "Log search allows us to dive deep into aggregated logs and query all event types at once."
- "The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily."
- "InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
- "It would be useful to import threat intelligence in YARA format along with known incorrect email addresses."
What is our primary use case?
How has it helped my organization?
InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly.
What is most valuable?
- User behavioral analytics allows us to pinpoint abnormal or suspicious behavior among millions of events every day.
- Log search allows us to dive deep into aggregated logs and query all event types at once.
What needs improvement?
Threat Intelligence: It would be useful to import threat intelligence in YARA format along with known incorrect email addresses.
Buyer's Guide
Rapid7 InsightIDR
October 2025

Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,008 professionals have used our research since 2012.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
During the entire duration of use, there have been no issues noted with stability.
What do I think about the scalability of the solution?
The log aggregation and storage provided by InsightIDR has shown no issues with scalability; aggregating over one hundred millions events daily. The only constriction point in deployment is the collectors as they are required for agentless logging. However, keeping with the documentation provided for deployment, it handles the load appropriately if the documentation is adhered to.
How are customer service and support?
Among the best! Their support responds promptly. They fully resolve issues before closing tickets.
Which solution did I use previously and why did I switch?
We did not use a previous solution.
How was the initial setup?
The initial setup is quite straightforward and can be accomplished from their Quick Start Guide. As the platform is quite adaptable, it can continue to be expanded to add many different log types, which you may find to be a continuous process.
What's my experience with pricing, setup cost, and licensing?
Accurately predict your licensing counts as this is a subscription based product.
Which other solutions did I evaluate?
We evaluated FireEye Helix, LogRhythm, Splunk, and IBM QRadar.
What other advice do I have?
The product is a shift in paradigm being cloud-based with cloud storage. Be prepared to set up several virtual collector servers within your network, if you have a large network.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.

Information Security Systems Administrator at a non-tech company with 5,001-10,000 employees
I am able to run automated actions based on the output of reports
Pros and Cons
- "I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
- "The ability to ingest Office 365 log files, then process them into events and display them on a map."
- "The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame."
- "I feel it would greatly benefit from more supported log sources."
- "The ability to tune the collector for custom logs would greatly help."
What is our primary use case?
Visibility and response.
How has it helped my organization?
I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters.
What is most valuable?
The ability to ingest Office 365 log files, then process them into events and display them on a map. This feature is particularly useful as it allows us to view students who are attempting to bypass our content filters, and it shows us users who have been phished.
What needs improvement?
Personally, I feel it would greatly benefit from more supported log sources. Additionally, the ability to tune the collector for custom logs would greatly help.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
Product is cloud-based. Thus far, it has proven to be stable.
What do I think about the scalability of the solution?
No product scales extremely well
How is customer service and technical support?
The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame.
How was the initial setup?
Initial setup was straightforward.
What about the implementation team?
I had a support engineer sit with me through the whole process over the course of three days. He was a huge help!
What's my experience with pricing, setup cost, and licensing?
This is a great product. The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.
Which other solutions did I evaluate?
We did PoC with a couple of other products. However, Rapid7 InsightIDR was the best product for our needs and budget.
We evaluated LogRhythm and AlienVault. Both were inferior in regards to pricing or performance.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Rapid7 InsightIDR
October 2025

Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,008 professionals have used our research since 2012.
Information Security Officer at PTCI
Dashboards provide critical information at a glance, without hours of coding
Pros and Cons
- "Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
- "InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
- "Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
- "I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
What is our primary use case?
I was looking for a behavior analytics solution to help me monitor our users' activity and to notify of any suspicious activity.
InsightIDR was able to meet those needs and even exceed it by providing full SIEM capabilities, even for devices they don’t support directly. Most importantly, I don’t need a team of people dedicated to log collecting and sifting.
How has it helped my organization?
With the full suite of Rapid7 products, I am able to provide effective oversight to the information security program with measurable progress. This is a very difficult thing to measure with the ever-changing threat landscape. Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well.
What is most valuable?
InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level, which is very important to me as a one-person security department.
Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network.
What needs improvement?
I would like the ability to adjust the threshold of certain existing alerts.  Currently the only option is to change the notifications or create my own alert. 
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
I have not encountered any stability issues with the local collector. On the rare occasion that the cloud part of insightIDR is undergoing maintenance or having other issues, I usually receive a notification from Rapid7 before I even notice a problem.
What do I think about the scalability of the solution?
I have not seen any issues with scalability. On average, insightIDR is processing about 60 million events per day from my environment.
How are customer service and technical support?
The technical support folks at Rapid7 are a great bunch of folks. I haven’t had much need to contact them, but when I have they have been extremely professional and will escalate issues and suggestions to developers, if needed.
Which solution did I use previously and why did I switch?
I actually purchased the predecessor, InsightUBA, which quickly changed into the insightIDR that we have today. There was no other previous solution.
How was the initial setup?
Setup was extremely simple. An implementation specialist was assigned to me to help get me started and to learn my environment and challenges.
For the most part, all communications are sent to a log aggregation server. It is as simple as pointing syslogs to that server. For some, such as Active Directory and Exchange, there are plugins that are simple to install on those servers to make sure the appropriate logs are sent.
From InsightIDR, it is as simple as choosing from a list of supported log sources, or you can create a generic log source by specifying a port number. It’s that simple.
What's my experience with pricing, setup cost, and licensing?
Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help.
Which other solutions did I evaluate?
I did not consider any other options in depth. Most other options I saw required one or more full-time employees to maintain.
What other advice do I have?
In the past I have made several requests and have had the opportunity to work with developers and user-interface specialists to add enhancements to the product. The effort that Rapid7 puts into the user interface, after gaining first-hand use-case information directly from us, the end users, is unprecedented. Even when I worked for much larger companies, I did not see so many suggestions turn into reality.
Be sure to take full advantage of the agents. I have not seen any performance problems on the endpoints, and having this level of information from outside the network is difficult otherwise.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Information Security Officer at a tech vendor with 201-500 employees
Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns
Pros and Cons
- "Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
- "Great coverage of all systems within our network from endpoint to firewall."
- "Integration with threat modeling from the Metasploit and InsightIDR repositories."
- "Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
- "One thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not."
What is our primary use case?
It is used to maintain our security posture by monitoring inside our network for behavior likely to be conducive with elements of the kill chain.
I was an early adopter of the product. I have seen it get better over time, making use of the data and methodologies used by the industry standard and Rapid7 Metasploit community.
How has it helped my organization?
We were able to identify criminals attempting to login from China and put a stop on their IP locations.
What is most valuable?
- Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs.
- Great coverage of all systems within our network from endpoint to firewall.
- Integration with threat modeling from the Metasploit and InsightIDR repositories.
- Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns.
It gives all the advantages of a SIEM. However, using clever AI, it looks for patterns of behavior rather than just flooding me with all the alerts.
What needs improvement?
Although the solution has been improving continually in the time I have been using it, there could be areas of improvement.
The one thing that springs to mind is easier API integration with ITSMs. We are evaluating a new ITSM and I would like to have InsightIDR create a ticket when an attack is identified, and the ticket would be closed in InsightIDR when the ITSM resolution is completed. This would take out the "single point of failure" we currently have, if the email recipient is somehow absent, in recording the risk appetite for the incident and the actions taken to mitigate or not.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
None at all. Even as an early adopter, there were no significant issues with stability. Due to the continual improvement, I do not recall the last issue that I had with the system.
What do I think about the scalability of the solution?
We are only a small PLC with 300 staff over six sites and two continents, so scalability has never been a major concern. However, the InsightIDR system looks to be scalable, if required.
How are customer service and technical support?
Technical support is excellent both technically, timely, and professional throughout any incident or enhancement request.
Which solution did I use previously and why did I switch?
This was our first look at a security as a single entity. After creating a threat register, we were able to mitigate over two-thirds of the threats with this one product.
How was the initial setup?
It is very simple. It is a case of requesting a trial from Rapid7, then connecting the relevant logging devices, such as our AD servers or DNS servers to it and sitting back.
Obviously, there is more to it than that, but that is the principle.
What's my experience with pricing, setup cost, and licensing?
I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.
Which other solutions did I evaluate?
At the time, there was no other product that came close to InsightIDR feature set coupled with Rapid7's world leading security position producing other products, such as Metasploit and Nexpose (InsiteVR), which we also use.
What other advice do I have?
Use it. The setup is minimal, but the payback is phenomenal.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Consultant at a comms service provider with 51-200 employees
Great  user behavior analytics  feature; easy to integrate and collect data from other solutions
Pros and Cons
- "Features for user behavior analytics and the rules for attack review are good."
- "Needs a better ability to customize the check within the console."
What is our primary use case?
We are distributors and sell this product to our customers. I'm a security consultant.
What is most valuable?
The features for user behavior analytics and the rules for attack review are valuable. I also like the honeypot feature. It's easy to integrate and collect data from other solutions. 
What needs improvement?
I'd like to see a better ability to customize the check within the console. Rules can be customized better if the integration is improved. They now have integration with CrowdStrike so maybe they could have some kind of integration with Microsoft.
For how long have I used the solution?
I've been using this solution for a year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
This is a cloud-based product so it's scalable.
How are customer service and support?
The technical support could be improved. We've had times when our requests get stuck with the engineering team and we sometimes don't get a response. That's a problem for us. 
How would you rate customer service and support?
Neutral
How was the initial setup?
All Rapid7 solutions are easy to deploy because if you have any one of the products, the integrations between these products become easier because they have a lot of the important things within a single port. You get a single platform to visualize a lot of different kinds of data.
What's my experience with pricing, setup cost, and licensing?
The pricing is very competitive because the licensing model that we use is based on endpoints which is different from most other solutions.
What other advice do I have?
This solution is suited to all sizes of organizations. We generally deal with small and medium-sized companies.  
I rate this solution eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Threat Intelligence Engineer at a tech services company with 11-50 employees
It's easy to install, but the components inside are a bit complicated.
Pros and Cons
- "Rapid7's reporting is more robust than Tenable's."
- "Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
What is most valuable?
Rapid7's reporting is more robust than Tenable's.
What needs improvement?
Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps.
For how long have I used the solution?
I worked with InsightIDR for about two years, but I switched to Tenable Nessus around two months ago.
How are customer service and support?
Rapid7's customer support is awful. They didn't respond at all. Tenable's support is always available. I didn't have to visit the customer every time they wanted to perform a scan.
How was the initial setup?
InsightIDR is easy to install, but the components inside are a bit complicated. Tenable was much easier.
What other advice do I have?
I rate Rapid7 InsightIDR seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Network Support Engineer at a tech services company with 51-200 employees
Lets you simplify threat detection and has a fast deployment
Pros and Cons
- "Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling."
- "The APIs can be further improved in Rapid7."
What is our primary use case?
The solution is used as a platform for a better understanding of the Intelligence products that different vendors sell.
What is most valuable?
Rapid7 is easy to use and deploy. It is a simple solution and has easy data pulling.
What needs improvement?
The APIs can be further improved in Rapid7.
For how long have I used the solution?
I have been using Rapid7 InsightIDR for two months.
What do I think about the stability of the solution?
It is stable solution.
What do I think about the scalability of the solution?
It is a scalable solution. Presently, there are only small businesses working with the solution.
How are customer service and support?
The technical support team is good.
How was the initial setup?
The initial setup is easy. The deployment took only half an hour. It's just a cloud platform. You just have to deploy a connector like Select Pro, and it will set the data from the on-premise. It will send it to the cloud platform, and you can have it installed in five to ten minutes.
What's my experience with pricing, setup cost, and licensing?
The pricing of the solution depends on the user. But there is a yearly licensing cost.
What other advice do I have?
It is a good solution but just has some API issues. I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP

Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros
        sharing their opinions. 
Updated: October 2025
Product Categories
Security Information and Event Management (SIEM) User Entity Behavior Analytics  (UEBA) Endpoint Detection and Response (EDR) Threat Deception Platforms Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
Splunk Enterprise Security
Microsoft Sentinel
Darktrace
SentinelOne Singularity Complete
Commvault Cloud
IBM Security QRadar
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Elastic Security
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros
        sharing their opinions. 
Quick Links
Learn More: Questions:
- What SOC product do you recommend?
- Is Rapid7 InsightIDR the right choice to be used in SOC?
- What is the difference between IDR and EDR?
- What Solution for SIEM is Best To Be NIST 800-171 Compliant?
- When evaluating Security Information and Event Management (SIEM), what aspect do you think is the most important feature to look for?
- What are the main differences between Nessus and Arcsight?
- What's The Best Way to Trial SIEM Solutions?
- Which is the best SIEM solution for a government organization?
- What is the difference between IT event correlation and aggregation?
- What Is SIEM Used For?


















