Product Manager at Bizinfo
Real User
Top 20
An easy-to-use and stable solution with an intuitive interface
Pros and Cons
  • "The solution is easy to use, and the interface is intuitive."
  • "Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA)."

What is our primary use case?

I use the solution for its SIEM functionalities, log analysis, and behavioral analysis.

What is most valuable?

The solution is easy to use, and the interface is intuitive.

What needs improvement?

Currently, it lacks the functionalities provided by Rapid7's User Behavior Analytics (UBA). So, User Behavior Analytics (UBA) should be added in the new release.

For how long have I used the solution?

I have been using the solution for two years. My company has a partnership with Rapid7.

Buyer's Guide
Rapid7 InsightIDR
April 2024
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,857 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is a stable solution. My customers are happy to use it.

What do I think about the scalability of the solution?

I do not have any plans to expand the usage of the solution. Currently, one hundred people are using the solution.

How are customer service and support?

I have not used the technical support.

Which solution did I use previously and why did I switch?

Previously, I used IBM.

How was the initial setup?

I was not involved in the initial setup as I am not an engineer.

What's my experience with pricing, setup cost, and licensing?

The pricing is good, and it is not very expensive.


What other advice do I have?

I rate the overall solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Prasanth Prasad - PeerSpot reviewer
Director of Technology at a tech vendor with 11-50 employees
Real User
Top 5
Offers capabilities in areas like threat intelligence and vulnerability management but needs to improve support
Pros and Cons
  • "Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable."
  • "It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required."

What is most valuable?

The most valuable feature of the product for managing security events stems from the fact that the product's intelligence part is very good since it offers its own threat intelligence and vulnerability management platform. The tool also has its own cloud security posture management platform. The tool also is a dynamic application security testing platform. The aforementioned tools fall under Rapid7 InsightIDR's kitty. The intelligence and the data that Rapid7 gathers from customers across the globe enrich the quality of its detection capabilities. All other tools in the market depend on third-party solutions for intelligence. Rapid7 InsightIDr has the intelligence part natively available within the product, giving it a good edge over other vendors.


What needs improvement?

I believe that Rapid7 InsightIDR has moved to a complete cloud-first strategy. The tools offered by Rapid7 InsightIDR are amazing. The product should have provided some capabilities to users who wanted to stay or use the tool's on-premises version, as it would have provided the solution with more acceptance in the market, especially in the Middle East region.

It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required.

For how long have I used the solution?

I have been using Rapid7 InsightIDR for three to four years.

What do I think about the stability of the solution?

As I haven't heard any complaints about the product, I rate the solution's stability a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable.

The product is meant for medium-sized customers and large enterprises and not for corporate or government organizations since the product is available only on the cloud. Customers who have the privilege of using cloud solutions can use Rapid7 InsightIDR. Cloud solutions' use is less in government spaces in the Middle East region since there are some regulations to use cloud-based products. In the private space, I feel that Rapid7 InsightIDR is considered to be a fairly strong product.

It is difficult for enterprise businesses to use the solution, especially the ones regulated by governments. There are no problems with the solution when it comes to a private company or a private enterprise. I think Rapid7 InsightIDR provides the best tools. The tool won't work for you if you are not allowed to use a public cloud.

How are customer service and support?

I rate the technical support a six to seven out of ten.

How would you rate customer service and support?

Neutral

What other advice do I have?

The tool has improved the efficiency of security incident detection and response in our company as it works fairly well. It is possible to enhance the capabilities of the platform since the solution offers a whole stack or suite of tools. When dealing with Rapid7 InsightIDR, you will see the integration capabilities offered are extremely seamless. Rapid7 InsightIDR offers its own set of features that enrich the capabilities of the vulnerability management tool. In general, the product's features increase the solution's overall capabilities in terms of reporting and detection of vulnerabilities.

I can't remember a scenario where the product was effective in threat hunting or investigation. Rapid7 InsightIDR is a very acceptable product for people who want a cloud-based solution. The product is not available on an on-premises version. The product can be useful for industries ranging from SMBs to large-sized companies where there is a need for a tool that can be very easily rolled out at a very effective and attractive price point that gives them very good coverage from a cybersecurity perspective.

Speaking about how the product has enhanced the security posture in our company, I would say that I am not really sure about the capabilities of the UABA part of the solution since I haven't seen many use cases around it.

Rapid7 InsightIDR mean time-to-detect and mean time-to-respond are fairly good because Rapid7's support team does pick up a ticket whenever it is raised from the users' end, but its mean time-to-resolve has some concerns since some of the tools under Rapid7 are available on an on-premises model. In specific to InsightIDR, I think that everything is very good, including areas like detection, MTTD, and MTTR, which are very good in InsightIDR specifically. The product can improve a bit in the area of MTTD and MTTR.

Rapid7 InsightIDR's integration capabilities with other tools are not an area I have experience with since the product is completely available on the cloud. I believe that whatever integrations users want from the product would work since it is a solution that is available on the cloud. I don't have personal experience with the integration part.

I rate the overall tool a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
PeerSpot user
Buyer's Guide
Rapid7 InsightIDR
April 2024
Learn what your peers think about Rapid7 InsightIDR. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,857 professionals have used our research since 2012.
Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Real User
Top 10
Can install, gather, and monitor logs easily
Pros and Cons
  • "The solution's initial setup is easy."
  • "They should add more configuration and security features to it."

What is our primary use case?

I used the solution to monitor networks and prevent them from real-time threats.

What is most valuable?

The solution's most valuable feature is its ability to fetch insights on threats and log activities. 

What needs improvement?

They should add more configuration and security features to the solution.

For how long have I used the solution?

I have used the solution for more than a year and a half.

What do I think about the stability of the solution?

I rate the solution's stability as a seven.

What do I think about the scalability of the solution?

We have two thousand customers using the solution. It works best for the medium-scale industry. I rate its scalability as an eight.

How was the initial setup?

The solution's initial setup is easy. The deployment process involves installing and collecting agents to communicate with the systems. In the case of multiple machines, it takes around five to six months to complete it. I rate the process as an eight.

What's my experience with pricing, setup cost, and licensing?

The solution's license costs around Rs. 20,00,000. It is more reasonable than other vendors. I rate its pricing as an eight.

What other advice do I have?

Compared to other solutions, Rapid7 is more flexible to use. We install, gather, and monitor logs easily with its help. I rate it as an eight.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Information Security Systems Administrator at a non-tech company with 5,001-10,000 employees
Real User
I am able to run automated actions based on the output of reports
Pros and Cons
  • "I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
  • "The ability to ingest Office 365 log files, then process them into events and display them on a map."
  • "The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame."
  • "I feel it would greatly benefit from more supported log sources."
  • "The ability to tune the collector for custom logs would greatly help."

What is our primary use case?

Visibility and response.

How has it helped my organization?

I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters.

What is most valuable?

The ability to ingest Office 365 log files, then process them into events and display them on a map. This feature is particularly useful as it allows us to view students who are attempting to bypass our content filters, and it shows us users who have been phished.

What needs improvement?

Personally, I feel it would greatly benefit from more supported log sources. Additionally, the ability to tune the collector for custom logs would greatly help.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

Product is cloud-based. Thus far, it has proven to be stable.

What do I think about the scalability of the solution?

No product scales extremely well

How is customer service and technical support?

The technical support is a solid 10 out of 10 as they take the time to answer any questions or problems which may arise in a reasonable time frame.

How was the initial setup?

Initial setup was straightforward. 

What about the implementation team?

I had a support engineer sit with me through the whole process over the course of three days. He was a huge help!

What's my experience with pricing, setup cost, and licensing?

This is a great product. The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.

Which other solutions did I evaluate?

We did PoC with a couple of other products. However, Rapid7 InsightIDR was the best product for our needs and budget.

We evaluated LogRhythm and AlienVault. Both were inferior in regards to pricing or performance.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Chad Kliewer - PeerSpot reviewer
Information Security Officer at PTCI
Real User
Dashboards provide critical information at a glance, without hours of coding
Pros and Cons
  • "Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
  • "InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level."
  • "Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
  • "I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."

What is our primary use case?

I was looking for a behavior analytics solution to help me monitor our users' activity and to notify of any suspicious activity.

InsightIDR was able to meet those needs and even exceed it by providing full SIEM capabilities, even for devices they don’t support directly. Most importantly, I don’t need a team of people dedicated to log collecting and sifting.

How has it helped my organization?

With the full suite of Rapid7 products, I am able to provide effective oversight to the information security program with measurable progress. This is a very difficult thing to measure with the ever-changing threat landscape. Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well.

What is most valuable?

InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless. InsightIDR has the alerts tuned, and has the ability to quickly drill down to determine the threat level, which is very important to me as a one-person security department.

Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network.

What needs improvement?

I would like the ability to adjust the threshold of certain existing alerts.  Currently the only option is to change the notifications or create my own alert. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

I have not encountered any stability issues with the local collector. On the rare occasion that the cloud part of insightIDR is undergoing maintenance or having other issues, I usually receive a notification from Rapid7 before I even notice a problem.

What do I think about the scalability of the solution?

I have not seen any issues with scalability. On average, insightIDR is processing about 60 million events per day from my environment.

How are customer service and technical support?

The technical support folks at Rapid7 are a great bunch of folks. I haven’t had much need to contact them, but when I have they have been extremely professional and will escalate issues and suggestions to developers, if needed.

Which solution did I use previously and why did I switch?

I actually purchased the predecessor, InsightUBA, which quickly changed into the insightIDR that we have today. There was no other previous solution.

How was the initial setup?

Setup was extremely simple. An implementation specialist was assigned to me to help get me started and to learn my environment and challenges.

For the most part, all communications are sent to a log aggregation server. It is as simple as pointing syslogs to that server. For some, such as Active Directory and Exchange, there are plugins that are simple to install on those servers to make sure the appropriate logs are sent.

From InsightIDR, it is as simple as choosing from a list of supported log sources, or you can create a generic log source by specifying a port number. It’s that simple.

What's my experience with pricing, setup cost, and licensing?

Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help.

Which other solutions did I evaluate?

I did not consider any other options in depth. Most other options I saw required one or more full-time employees to maintain.

What other advice do I have?

In the past I have made several requests and have had the opportunity to work with developers and user-interface specialists to add enhancements to the product. The effort that Rapid7 puts into the user interface, after gaining first-hand use-case information directly from us, the end users, is unprecedented.  Even when I worked for much larger companies, I did not see so many suggestions turn into reality.

Be sure to take full advantage of the agents. I have not seen any performance problems on the endpoints, and having this level of information from outside the network is difficult otherwise.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
RicardoSilva3 - PeerSpot reviewer
Coordinator & Teacher at Pahldata
Real User
Top 20
A stable solution that works well for playbooks and viewing events
Pros and Cons
  • "The solution is very stable and works very well for what I need it to do."
  • "The main problem lies in the processes within the client's operating systems."

What is our primary use case?

Normally, we use the solution as an event viewer to collect and resume cases and playbooks.

What needs improvement?

The main problem lies in the processes within the client's operating systems. XDR is superior to CMs. Observing how the processes function within the machine is essential if you are monitoring the client or servers, and not only the event with the first or second line but the third line is most important.

For how long have I used the solution?

I've been familiar with the solution for six months.

What do I think about the stability of the solution?

The solution is very stable and works very well for what I need it to do. The solution is completely different in an experienced environment and a real environment.

Which solution did I use previously and why did I switch?

I have worked with Wazuh before, but only to try it. Wazuh is more or less the same as Rapid7 InsightIDR.

What other advice do I have?

I rate Rapid7 InsightIDR an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
System Engineer at Starlabs Limited
Reseller
Top 20
It provides excellent visibility a fast response
Pros and Cons
  • "InsightIDR helps us investigate an environment to discover information about incidents."
  • "InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."

What is our primary use case?

We provide InsightIDR for our banking and ICT clients. 

What is most valuable?

InsightIDR helps us investigate an environment to discover information about incidents. 

What needs improvement?

InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal. 

For how long have I used the solution?

I have used InsightIDR for four years. 

What do I think about the stability of the solution?

I rate InsightIDR 10 out of 10 for stability. 

What do I think about the scalability of the solution?

I rate InsightIDR six out of 10 for scalability. The licensing model limits the scalability. The licenses are defined based on assets, so you have to purchase more licenses as you add assets. It's suitable for a small or medium-sized company. We have about 250 users. 

How are customer service and support?

I rate Rapid7 support nine out of 10.

How would you rate customer service and support?

Positive

How was the initial setup?

I rate InsightIDR eight out of 10 for ease of setup. It takes about seven working days to deploy. We install a connector on the LAN, which links up to the cloud and becomes one of your event sources. Next, you need to integrate everything with the console.

What's my experience with pricing, setup cost, and licensing?

I rate InsightIDR six out of 10 for affordability. It isn't the cheapest solution I've seen, but it offers a greater value than less expensive competitors. 

What other advice do I have?

I rate InsightIDR eight out of 10. It's worth a try. InsightIDR provides excellent visibility and threats. The network detection is fast, so you get alerts as soon as something happens. 

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
KimeangSuon - PeerSpot reviewer
Pre-Sale Consultant at Yip In Tsoi Co., LTD.
Real User
Top 10
Initial setup is quick, there is no need to pay for hardware, and it's easy to scale
Pros and Cons
  • "Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log."
  • "InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment."

What is our primary use case?

The main use case for InsightIDR is to investigate threat activity that can compromise the internal customer environment. We can track a threat from the first attempt or breach. Then we can investigate the threat from start to finish. 

What is most valuable?

InsightIDR's dashboard shows you live activity from the threat. 

What needs improvement?

InsightIDR is only available in a cloud version. Some of our customers prefer an on-prem solution because they want to manage the security within their environment. So it's a challenge to get the customer to see the benefits of a cloud-based product in terms of ROI. If they switch to a cloud application, they won't have to pay for hardware maintenance or inventory. So with the next update, the customers want to see how it applies to their environment and its advantages over on-premise solutions. 

For how long have I used the solution?

We've been using InsightIDR for two years.

What do I think about the stability of the solution?

InsightIDR runs on the cloud and communicates with the log collector on a local computer, so performance depends on the internet connection. It's just sending packets and TCP encryption, so it's not spending much bandwidth. If the internet connection is smooth, the performance will be fine.

What do I think about the scalability of the solution?

InsightIDR can work with any size of business. It's easy to scale because it is on the cloud platform. It depends on the customer and the number of endpoints that they need to manage. 

How are customer service and support?

I have contacted Rapid7 support but not for InsightIDR. It is with for another product of theirs. I think their support is good. The support team helped us run diagnostic tests and walked us through everything until the case was resolved.

Which solution did I use previously and why did I switch?

I have experience with other SIEM tools as well. Last time, I used LogRhythm company for security intelligence. LogRhythm has two options for the deployment — on-prem and cloud— so customers have a choice when they are looking to invest with SIEM solution. Rapid7 does not have the same option. But with LogRhythm, we would have to pay hardware maintenance as it is an on-prem product.

How was the initial setup?

The initial setup it's straightforward, and it's not complex to deploy or configure. Because it is a cloud product and cloud platform, we just have to start it up and integrate with the local collector. After that, we do the customization. Currently, we provide installation and support for customers who subscribe to Rapid7 InsightIDR.

What's my experience with pricing, setup cost, and licensing?

InsightIDR is quite expensive. But with on-prem solutions, you need to wait for delivery then spend more money on maintenance and hardware. So any customer who understands cloud applications knows they just need to buy the license for the year. Then they can use it, and it's not hard to manage.

What other advice do I have?

I rate InsightIDR eight out of a 10.  I would recommend it for a customer who isn't dead-set on an on-prem deployment. They can subscribe to Rapid7 because it is more valuable and delivers a greater return on investment. The initial setup is quick. There's no need to pay for hardware and it's easy to scale. Rapid7 InsightIDR integrates well with other solutions. It's also easy to configure because Rapid7 InsightIDR has a lot of instructions posted on their website that customers can follow if they need to get the source log. With other products, you might need to contact a consultant certified by the vendor to do the integration. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Rapid7 InsightIDR Report and get advice and tips from experienced pros sharing their opinions.