• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. InsightIDR
Logo of InsightIDR

InsightIDR

byRapid7
in
4.4
Market Presence: Security Information and Event Management, Insider Risk Management Solutions

Overview

Product Information on InsightIDR

Updated 13th June 2024

What is InsightIDR?

InsightIDR, Rapid7's next-gen SIEM built for the cloud-first era, is the detection-centric focusing on empowering security teams to pinpoint and eliminate threats as quickly as possible. InsightIDR unifies and transforms relevant security data from across the modern environment to provide security teams with high-context, actionable insights in order to effectively and efficiently detect and respond to threats.

InsightIDR Pricing

InsightIDR Product Images

InsightIDR
InsightIDR
InsightIDR
InsightIDR

Overall experience with InsightIDR

AVP Information Securtity
250M - 500M USD, Finance (non-banking)
FAVORABLE

“Rapid7’s Effective Threat Detection and Alert Prioritization Enhance Security Operations Efficiency”

4.0
Aug 7, 2025
My experience with InsightIDR has been very solid, as we've relied on it to grow our information security maturity. It replaced a previous Security Information and Event Management (SIM) solution that lacked crucial visibility and Managed Detection and Response (MDR) capabilities, which were essential for our small team to maximize our investment. The initial setup and deployment were smooth, with Rapid7 providing hands-on assistance. Automated logging for Active Directory (AD) and other functions, combined with their team's expertise, ensured proper log ingestion. The product scales well with business growth, demonstrated by flexible licensing changes when we shifted from on-premise to cloud. InsightIDR has been effective in detecting real threats and anomalies, allowing us to integrate other alerts (e.g., Azure) for a "single pane of glass" view. With our MDR service, alerts are reviewed and false positives resolved externally, providing essential visibility that we wouldn't achieve otherwise. For instance, it successfully alerted us to malicious software downloads from infected links, offering deeper insights through agent and firewall logging. This capability, combined with MDR, helps our team focus on actual incidents The alerts provided by Rapid7 are actionable, accurate, and well-prioritized. Rapid7 maintains a weekly process where they track current global threats, threat groups, and attack types, constantly adjusting their system's detection criteria. This ensures we receive high-level threat assessments (low, medium, or high). All relevant information is centralized, allowing us to easily drill down into log records to understand the origin and cross-correlate everything for a comprehensive understanding of an event. The user interface is user-friendly, making it easy for new analysts to investigate threats through simple clicks and utilize internal notes for seamless team collaboration.
DEVSECOPS ARCHITECT
500M - 1B USD, Telecommunication
CRITICAL

“Frequent Feature Segmentation Leads to Additional Costs for Existing Customers, Zero Flexibility”

1.0
Aug 28, 2025
Product is ok, but there can be an annoying pattern of new features being pulled out as separate, chargeable products, so you never get any real new features in the product you're paying for. Their service and support teams are almost comically mercenary - there is no notion of partnership or flexibility, even for very long term customers.

About Company

Company Description

Updated 25th July 2024

Rapid7, Inc. aims to create a safer digital world by simplifying and making cybersecurity simpler and more accessible. Rapid7 empowers security professionals worldwide to manage a modern attack surface through its technology, research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help over 11,000 customers unite cloud risk management with threat detection and response to reduce attack surfaces and eliminate threats quickly and precisely.

Company Details

Updated 26th February 2025
Company type
Public
Year Founded
2000
Head office location
Boston, United States
Number of employees
1001 - 5000
Annual Revenue
500M-1B USD
Website
www.rapid7.com

Do You Manage Peer Insights at Rapid7?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About InsightIDR
Reviewer Insights for: InsightIDR
Deciding Factors: InsightIDR Vs. Market Average
Performance of InsightIDR Across Market Features

InsightIDR Likes & Dislikes

Like

One of the aspects I absolutely love about Rapid7 InsightIDR is its ability to provide a single pane of glass view across our entire environment. This capability allows me to see everything from my cloud environment to our on-premise assets through its robust logging capabilities. Being able to monitor user activities comprehensively is hugely important from a security perspective. Secondly, I greatly appreciate the ease of its logging capabilities, particularly the ability to parse logs. Even if Rapid7 does not have a pre-existing parsing tool for specific logs, I can easily go in and parse them myself, making them usable for our needs. This flexibility ensures we can integrate various log sources effectively. Furthermore, the log searches themselves are remarkably easy to learn. For someone new to this field or just starting, there is abundant information available from Rapid7. With just a few minutes of reviewing their documentation, new users can quickly learn to query logs, find specific information, and extract actionable data. This user-friendliness extends to the UI and navigation experience, which is intuitive for analysts. Investigating threats is streamlined, often requiring just a few clicks within the interface to dig into details. Finally, a significant benefit is the system's support for team collaboration and continuity. For instance, if a ticket is assigned to a team member, they can add notes directly within the system. If that person is unavailable, another team member can seamlessly take over, reviewing all the same information, clicking through logs, and accessing notes left by their colleague. This feature makes it a really good system for ensuring that no data or information is missed, fostering effective teamwork and incident management.

Like

Regularly updated intelligence means less time needed deciphering events

Like

There are a large number of detection rules that come out of the box and can just be enabled, provided you have the right log sources coming into the platform. The Mitre Att&ck framework is integrated with the platform and helps to assess tactics and techniques that may be being used. The community threats feature is also great as it provides some insight on what others across the industry are monitoring / assessing within their environments.

Dislike

One of the most frustrating aspects we've encountered is the turnover of the assigned Rapid7 agent who works with us on a monthly basis as part of our licensing agreement. While the current representative is excellent and I hope we retain him, the frequency with which these representatives change has been our biggest complaint. This turnover makes it difficult to establish a strong rapport and for the representative to fully understand our specific goals and environmental needs. Related to this, we sometimes face a struggle getting answers to our tickets when we submit them. Although we eventually receive the necessary responses, the process can be painful at times. Another area for improvement, from my perspective, concerns the features offered through the InsightIDR tool. Rapid7 offers certain functionalities, such as automations, but they are presented as separate add-ons. I would prefer to see these features included directly in the licensing rather than requiring an additional purchase.

Dislike

Constant addition of adverts posing as new features

Dislike

We haven't been able to integrate Sophos properly yet with our SIEM solution, we bought the platform being advised we could, as a new app would be released soon, but this hasn't come out yet and so our existing integration with Sophos is in place, but via workarounds, which is less than ideal.

Top InsightIDR Alternatives

Logo of Splunk Enterprise
1. Splunk Enterprise
4.5
(1025 Ratings)
Logo of LogRhythm SIEM
2. LogRhythm SIEM
4.3
(715 Ratings)
Logo of IBM Security QRadar SIEM
3. IBM Security QRadar SIEM
4.3
(657 Ratings)
View All Alternatives

Peer Discussions

InsightIDR Reviews and Ratings

Showing data for 371 ratings and reviews for Security Information and Event Management market. View all 407 ratings and reviews across markets for a complete picture.

4.4

(371 Ratings)

Rating Distribution

5 Star
50%
4 Star
43%
3 Star
6%
2 Star
1%
1 Star
1%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.5

Integration & Deployment

4.5

Service & Support

4.4

Product Capabilities

4.4

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • AVP Information Securtity
    50M-1B USD
    Finance (non-banking)
    Review Source

    Rapid7’s Effective Threat Detection and Alert Prioritization Enhance Security Operations Efficiency

    4.0
    Aug 7, 2025
    My experience with InsightIDR has been very solid, as we've relied on it to grow our information security maturity. It replaced a previous Security Information and Event Management (SIM) solution that lacked crucial visibility and Managed Detection and Response (MDR) capabilities, which were essential for our small team to maximize our investment. The initial setup and deployment were smooth, with Rapid7 providing hands-on assistance. Automated logging for Active Directory (AD) and other functions, combined with their team's expertise, ensured proper log ingestion. The product scales well with business growth, demonstrated by flexible licensing changes when we shifted from on-premise to cloud. InsightIDR has been effective in detecting real threats and anomalies, allowing us to integrate other alerts (e.g., Azure) for a "single pane of glass" view. With our MDR service, alerts are reviewed and false positives resolved externally, providing essential visibility that we wouldn't achieve otherwise. For instance, it successfully alerted us to malicious software downloads from infected links, offering deeper insights through agent and firewall logging. This capability, combined with MDR, helps our team focus on actual incidents The alerts provided by Rapid7 are actionable, accurate, and well-prioritized. Rapid7 maintains a weekly process where they track current global threats, threat groups, and attack types, constantly adjusting their system's detection criteria. This ensures we receive high-level threat assessments (low, medium, or high). All relevant information is centralized, allowing us to easily drill down into log records to understand the origin and cross-correlate everything for a comprehensive understanding of an event. The user interface is user-friendly, making it easy for new analysts to investigate threats through simple clicks and utilize internal notes for seamless team collaboration.
  • Manager, Security Architecture and Engin
    50M-1B USD
    Media
    Review Source

    Overall great SIEM solution, with a few small integration issues to iron out.

    4.0
    Jan 5, 2026
    Overall the integrations for the SIEM solution are easy to set up and there are a number of integrations that can be made with other SaaS solutions as well as local syslog servers. Some dashboards come ready out of the box for use and others need to be created based on requirements.
  • IT-Sicherheitsexperte / IT Security Analyst
    <50M USD
    IT Services
    Review Source

    Data Collection and Dashboard Insights Stand Out in Rapid7 InsightIDR Platform

    5.0
    Sep 2, 2025
    Our experience with Rapid7 InsightIDR has been quite positive in general. The platform was easy to set up (especially with the help of the support team), clearly structured, and intuitive to navigate from the very beginning. The Rapid7 agents stand out compared to other solutions we have worked with, delivering reliable data collection not only for on premises but also for devices from remote workers. The seamless integration with other Rapid7 products makes it easy to manage security operations from a single ecosystem. We have not encountered any deal-breaker, and the solution has met our expectations in terms of performance and usability. Just the very own query language is sometimes a bit difficult to handle.
  • DEVSECOPS ARCHITECT
    50M-1B USD
    Telecommunication
    Review Source

    Frequent Feature Segmentation Leads to Additional Costs for Existing Customers, Zero Flexibility

    1.0
    Aug 28, 2025
    Product is ok, but there can be an annoying pattern of new features being pulled out as separate, chargeable products, so you never get any real new features in the product you're paying for. Their service and support teams are almost comically mercenary - there is no notion of partnership or flexibility, even for very long term customers.
  • Manager, IT Security and Risk Management
    1B-10B USD
    Media
    Review Source

    Detection and Response Effective but Legacy Log Search Requires Workarounds

    4.0
    Aug 13, 2025
    Overall the detection and response capabilities are great, what I do find a bit sometimes a bit annoying is the legacy search and legacy log search, it does not populate unless I use a private tab. This is even after clearing my cache.
...
Showing Result 1-5 of 381

Recommended Gartner Research

  • Critical Capabilities for Security Information and Event Management
  • Magic Quadrant for Security Information and Event Management

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.