Comparisec
SIEMRapid7 InsightIDR
StrongStrongStrongStrong
4.4

VendorsSIEMRapid7 InsightIDR

Rapid7 InsightIDR logo

Rapid7 InsightIDR

Rapid7

Founded 2000·US·Public
4.4

Combined score

G2
4.5156
Gartner
4.398

Editorial verdict

Rapid7 InsightIDR has positioned itself deliberately as the lowest risk entry point for organisations deploying their first SIEM, and the per-asset pricing model delivers on that promise in a way per-GB competitors cannot match for budget predictability. The built-in deception technology, planting fake credentials and network shares to detect lateral movement early, is a genuine differentiator that most SIEM platforms treat as a bolt-on rather than a native capability. For mid-market organisations without an established SOC, this combination of predictable cost and fast time to value makes InsightIDR a sensible starting point rather than an aspirational one.

The honest ceiling is real. Rapid7 sits as a Challenger rather than Leader in Gartner's SIEM Magic Quadrant, and detection content depth and third-party integration breadth trail Splunk's mature marketplace meaningfully.

The verdict: Rapid7 InsightIDR is right for mid-market organisations deploying their first SIEM wanting predictable pricing and fast time to value without an established SOC. Large enterprises with high data volumes or complex environments should evaluate Splunk or Microsoft Sentinel instead.

Last reviewed: September 2026

G2

4.5156 reviews

Gartner

4.398 reviews

PeerSpot

8.245 reviews
Gartner MQ: Challenger

SIEM assessment

PROTECTIONStrong
Log source coverage
4 / 5
Detection content
4 / 5
OPERATIONSStrong
SOAR & automation
5 / 5
Cost model
5 / 5
ANALYTICSStrong
Compliance reporting
4 / 5
TRUST & ECOSYSTEMStrong
Ecosystem support
4 / 5

Strongest: SOAR & automation

Watch out for: Ecosystem support

Strengths & limitations

Strengths

Per-asset pricing model is significantly more predictable and budget-friendly than per-GB alternatives, making total cost easier to forecast
Built-in deception technology provides early warning of attacker lateral movement that pure log correlation based SIEMs do not offer natively
The lowest risk, fastest time to value entry point for organisations without an established SOC deploying their first SIEM

Watch out for

Detection content depth and third-party integration ecosystem breadth is narrower than Splunk's mature marketplace
Positioned as a Challenger rather than Leader in Gartner's SIEM Magic Quadrant, reflecting a capability ceiling below the category leaders
Less suited to organisations with very high data volumes or complex multi-cloud environments than Google SecOps or Elastic

Best for

Mid-market organisations deploying their first SIEM wanting predictable per-asset pricing, fast time to value, and built-in deception technology without an established SOC.

Not suitable for: Large enterprises with very high data volumes, complex multi-cloud environments, or organisations needing the deepest detection content library available.

Compliance coverage

Essential Eight
AU Privacy Act
SOC 2
HIPAA
NIST CSF
PCI-DSS
GDPR
ISO 27001
CIS Benchmarks
CMMC
NIS2
DORA

Switching intelligence

Switching from

Common migration paths based on review data

Also considering

Vendors typically shortlisted alongside

Also in our database

Rapid7 also appears in:

← Back to SIEMCompare with other SIEM vendors ➲

Quick facts

Pricing modelPer asset, annual
Pricing rangeFrom approximately $6,600/year for small deployments, per-asset pricing
Free trialYes - 30 days
Min seatsNo minimum
Deployment time1-2 weeks
Complexity2 / 5
Pricing transparency4 / 5
AU presenceYes
IRAP assessedNo
Open sourceProprietary

Deployment

ModelsSaaS
OS supportWindows, macOS, Linux
CloudAWS, Azure, GCP
SupportPhone, Email, Chat, Dedicated CSM
Data residencyUS, EU, AU

Company

Rapid7

Founded 2000 · 1000+ employees · Public

HQ: US

$800M revenue

Certifications

SOC 2, ISO 27001

Integrations

OktaCrowdStrikeMicrosoft 365SlackServiceNow