Custom subscription
Rapid7 does not publish a complete public price list. Current purchasing information directs organizations to request a quote. Earlier Rapid7 materials describe asset-based pricing.
Check current pricing →Rapid7 InsightIDR is a cloud SIEM for threat detection, investigation, log analysis, endpoint visibility, and automated incident response.
The product combines cloud SIEM, log search, behavioral analytics, endpoint telemetry, investigation workflows, deception technology, integrations, and response automation. G2 reports a 4.4 out of 5 rating from 74 reviews. Public pricing is not fully disclosed, reducing confidence in value assessmen
This profile combines documented product information and independent evidence where available. It is not a hands-on test unless TechZella explicitly identifies one.
A quick way to understand who this product may suit, where its limits matter, and which facts are most relevant before you compare alternatives.
Linux, macOS, REST API, Web, Windows
8.3/10
Rapid7 InsightIDR is a cloud-hosted security information and event management platform. It collects security data from endpoints, cloud services, identity systems, network infrastructure, and third-party security products.
The platform correlates asset, user, log, and behavioral data. Analysts can search events, investigate incidents, manage cases, and perform response actions from a centralized interface.
Rapid7 now presents related capabilities under its broader SIEM and Incident Command product direction. The InsightIDR name remains widely used in product documentation, APIs, integrations, and customer environments.
For security-sensitive software, TechZella focuses on documented architecture, authentication, data handling, deployment and privacy details that can affect a buying decision. This is product research, not an independent security audit.
| Deployment | Cloud-hosted SaaS |
|---|
Security claims are presented only when supported by documented sources. The presence of this section does not constitute a penetration test, certification or independent security audit.
Rapid7 does not publish a complete public price list. Current purchasing information directs organizations to request a quote. Earlier Rapid7 materials describe asset-based pricing.
Check current pricing →Rapid7 product materials advertise a 30-day InsightIDR trial. Trial access is subject to account and administrator requirements.
Check current pricing →Pricing may change. Verify current plans on the vendor's website.
Comparable SIEM and security operations products include Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar SIEM, Elastic Security, Sumo Logic Cloud SIEM, and Google Security Operations.
Microsoft Sentinel is a natural alternative for organizations centered on Microsoft cloud and identity services. Splunk Enterprise Security suits teams seeking broad data analytics and extensive ecosystem support.
Elastic Security may suit organizations that prefer an extensible search and analytics stack. IBM QRadar remains relevant for established enterprise SIEM programs with existing IBM investments.
| Deployment | Cloud-hosted SaaS |
|---|---|
| Product category | Security Information and Event Management |
| Primary interface | Web application |
| Endpoint operating systems | Windows, macOS, and Linux through the Rapid7 Agent |
| API | Regional REST APIs using API-key authentication |
| Pricing model | Quote-based subscription |
| Free trial | 30 days |
| Log retention | Up to 13 months in documented standard subscriptions |
| Company founded | 2000 |
| Headquarters | Boston, Massachusetts, United States |
A proprietary editorial score based on product capabilities, usability, value, performance, support and user sentiment evidence.
The product combines cloud SIEM, log search, behavioral analytics, endpoint telemetry, investigation workflows, deception technology, integrations, and response automation. G2 reports a 4.4 out of 5 rating from 74 reviews. Public pricing is not fully disclosed, reducing confidence in value assessment.
Methodology v1.0. The assessment weighs feature coverage (25%), ease of use (15%), value for money (20%), performance (15%), support (10%) and user sentiment (15%), using researched product evidence and verified review evidence where available. It is a TechZella editorial assessment, not a direct user-review average.
No reviews yet. Be the first to share your experience.
Please log in to submit a review.
InsightIDR is Rapid7’s cloud SIEM for collecting security data, detecting threats, investigating incidents, and coordinating response.
Yes. Rapid7 documents REST APIs for alerts, assets, investigations, detection rules, log search, accounts, users, comments, attachments, and threat indicators.
The Rapid7 Agent supports supported versions of Windows, macOS, and Linux. Exact operating-system support varies by agent version and product function.
Documented integrations include AWS CloudTrail, Microsoft Azure, Microsoft 365, Google Cloud, Okta, Duo Security, Salesforce, CrowdStrike Falcon, Microsoft Defender, ServiceNow, Splunk, Slack-related workflows, and other security and cloud platforms.
Rapid7 advertises a time-limited free trial rather than a permanent free edition. Product materials specify a 30-day trial.
Rapid7 uses quote-based commercial pricing. Earlier Rapid7 materials describe pricing by monitored assets rather than event volume, but current package quotes should be confirmed with Rapid7.