Overview
Product Information on InsightIDR
What is InsightIDR?
InsightIDR Pricing
InsightIDR Product Images


Overall experience with InsightIDR
“Rapid7’s Effective Threat Detection and Alert Prioritization Enhance Security Operations Efficiency”
“Frequent Feature Segmentation Leads to Additional Costs for Existing Customers, Zero Flexibility”
About Company
Company Description
Rapid7, Inc. aims to create a safer digital world by simplifying and making cybersecurity simpler and more accessible. Rapid7 empowers security professionals worldwide to manage a modern attack surface through its technology, research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help over 11,000 customers unite cloud risk management with threat detection and response to reduce attack surfaces and eliminate threats quickly and precisely.
Company Details
Do You Manage Peer Insights at Rapid7?
Access Vendor Portal to update and manage your profile.
Key Insights
A Snapshot of What Matters - Based on Validated User Reviews
User Sentiment About InsightIDR
Reviewer Insights for: InsightIDR
Deciding Factors: InsightIDR Vs. Market Average
Performance of InsightIDR Across Market Features
InsightIDR Likes & Dislikes
One of the aspects I absolutely love about Rapid7 InsightIDR is its ability to provide a single pane of glass view across our entire environment. This capability allows me to see everything from my cloud environment to our on-premise assets through its robust logging capabilities. Being able to monitor user activities comprehensively is hugely important from a security perspective. Secondly, I greatly appreciate the ease of its logging capabilities, particularly the ability to parse logs. Even if Rapid7 does not have a pre-existing parsing tool for specific logs, I can easily go in and parse them myself, making them usable for our needs. This flexibility ensures we can integrate various log sources effectively. Furthermore, the log searches themselves are remarkably easy to learn. For someone new to this field or just starting, there is abundant information available from Rapid7. With just a few minutes of reviewing their documentation, new users can quickly learn to query logs, find specific information, and extract actionable data. This user-friendliness extends to the UI and navigation experience, which is intuitive for analysts. Investigating threats is streamlined, often requiring just a few clicks within the interface to dig into details. Finally, a significant benefit is the system's support for team collaboration and continuity. For instance, if a ticket is assigned to a team member, they can add notes directly within the system. If that person is unavailable, another team member can seamlessly take over, reviewing all the same information, clicking through logs, and accessing notes left by their colleague. This feature makes it a really good system for ensuring that no data or information is missed, fostering effective teamwork and incident management.
Regularly updated intelligence means less time needed deciphering events
There are a large number of detection rules that come out of the box and can just be enabled, provided you have the right log sources coming into the platform. The Mitre Att&ck framework is integrated with the platform and helps to assess tactics and techniques that may be being used. The community threats feature is also great as it provides some insight on what others across the industry are monitoring / assessing within their environments.
One of the most frustrating aspects we've encountered is the turnover of the assigned Rapid7 agent who works with us on a monthly basis as part of our licensing agreement. While the current representative is excellent and I hope we retain him, the frequency with which these representatives change has been our biggest complaint. This turnover makes it difficult to establish a strong rapport and for the representative to fully understand our specific goals and environmental needs. Related to this, we sometimes face a struggle getting answers to our tickets when we submit them. Although we eventually receive the necessary responses, the process can be painful at times. Another area for improvement, from my perspective, concerns the features offered through the InsightIDR tool. Rapid7 offers certain functionalities, such as automations, but they are presented as separate add-ons. I would prefer to see these features included directly in the licensing rather than requiring an additional purchase.
Constant addition of adverts posing as new features
We haven't been able to integrate Sophos properly yet with our SIEM solution, we bought the platform being advised we could, as a new app would be released soon, but this hasn't come out yet and so our existing integration with Sophos is in place, but via workarounds, which is less than ideal.
Top InsightIDR Alternatives
Peer Discussions
InsightIDR Reviews and Ratings
- AVP Information Securtity50M-1B USDFinance (non-banking)Review Source
Rapid7’s Effective Threat Detection and Alert Prioritization Enhance Security Operations Efficiency
My experience with InsightIDR has been very solid, as we've relied on it to grow our information security maturity. It replaced a previous Security Information and Event Management (SIM) solution that lacked crucial visibility and Managed Detection and Response (MDR) capabilities, which were essential for our small team to maximize our investment. The initial setup and deployment were smooth, with Rapid7 providing hands-on assistance. Automated logging for Active Directory (AD) and other functions, combined with their team's expertise, ensured proper log ingestion. The product scales well with business growth, demonstrated by flexible licensing changes when we shifted from on-premise to cloud. InsightIDR has been effective in detecting real threats and anomalies, allowing us to integrate other alerts (e.g., Azure) for a "single pane of glass" view. With our MDR service, alerts are reviewed and false positives resolved externally, providing essential visibility that we wouldn't achieve otherwise. For instance, it successfully alerted us to malicious software downloads from infected links, offering deeper insights through agent and firewall logging. This capability, combined with MDR, helps our team focus on actual incidents The alerts provided by Rapid7 are actionable, accurate, and well-prioritized. Rapid7 maintains a weekly process where they track current global threats, threat groups, and attack types, constantly adjusting their system's detection criteria. This ensures we receive high-level threat assessments (low, medium, or high). All relevant information is centralized, allowing us to easily drill down into log records to understand the origin and cross-correlate everything for a comprehensive understanding of an event. The user interface is user-friendly, making it easy for new analysts to investigate threats through simple clicks and utilize internal notes for seamless team collaboration. - Manager, Security Architecture and Engin50M-1B USDMediaReview Source
Overall great SIEM solution, with a few small integration issues to iron out.
Overall the integrations for the SIEM solution are easy to set up and there are a number of integrations that can be made with other SaaS solutions as well as local syslog servers. Some dashboards come ready out of the box for use and others need to be created based on requirements. - IT-Sicherheitsexperte / IT Security Analyst<50M USDIT ServicesReview Source
Data Collection and Dashboard Insights Stand Out in Rapid7 InsightIDR Platform
Our experience with Rapid7 InsightIDR has been quite positive in general. The platform was easy to set up (especially with the help of the support team), clearly structured, and intuitive to navigate from the very beginning. The Rapid7 agents stand out compared to other solutions we have worked with, delivering reliable data collection not only for on premises but also for devices from remote workers. The seamless integration with other Rapid7 products makes it easy to manage security operations from a single ecosystem. We have not encountered any deal-breaker, and the solution has met our expectations in terms of performance and usability. Just the very own query language is sometimes a bit difficult to handle. - DEVSECOPS ARCHITECT50M-1B USDTelecommunicationReview Source
Frequent Feature Segmentation Leads to Additional Costs for Existing Customers, Zero Flexibility
Product is ok, but there can be an annoying pattern of new features being pulled out as separate, chargeable products, so you never get any real new features in the product you're paying for. Their service and support teams are almost comically mercenary - there is no notion of partnership or flexibility, even for very long term customers. - Manager, IT Security and Risk Management1B-10B USDMediaReview Source
Detection and Response Effective but Legacy Log Search Requires Workarounds
Overall the detection and response capabilities are great, what I do find a bit sometimes a bit annoying is the legacy search and legacy log search, it does not populate unless I use a private tab. This is even after clearing my cache.



