No more typing reviews! Try our Samantha, our new voice AI agent.

AlienVault OSSIM vs Rapid7 InsightIDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AlienVault OSSIM
Ranking in Security Information and Event Management (SIEM)
25th
Average Rating
7.4
Reviews Sentiment
7.1
Number of Reviews
31
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in Security Information and Event Management (SIEM)
23rd
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (32nd), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of AlienVault OSSIM is 1.2%, down from 3.1% compared to the previous year. The mindshare of Rapid7 InsightIDR is 2.3%, down from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR2.3%
AlienVault OSSIM1.2%
Other96.5%
Security Information and Event Management (SIEM)
 

Featured Reviews

BP
Independent Contractor at a comms service provider with 5,001-10,000 employees
Enables cost-effective security management for small businesses
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implementation. The main area where the AlienVault product was lacking around the 2018 timeframe was in its ability to scale. By pushing it to a cloud-based system, they've largely alleviated scale issues. It's native in Amazon but will also run in Azure. They have worked with cloud service providers to offer enough throughput at a cost reasonable for a corporation. Scaling was their biggest problem, and they've largely conquered those issues.
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution is very stable; it runs on a Linux box, you only interface with it through the GUI, it works behind the scenes, and it has never crashed in the time that I have used it."
"Most of the SOC or SIEM enterprise class products are very expensive, whereas with OSSIM you can start out with a smaller setup and then expand as you wish."
"The open vault component and the checking of vulnerabilities are the most valuable features, and the page management helps with this, because if you know how your device is vulnerable at least you can do something about it."
"The solution is free to use."
"AlienVault OSSIM's GUI is very user-friendly."
"Network traffic analysis is highly efficient."
"Better than other SIEM solutions because almost everything can be integrated."
"The tool's security detection is good. It helps us with login tracking and generating reports. We aim to identify potential issues, such as brute-force attacks on user accounts or server-level anomalies. For instance, if I receive a report indicating a server is at an abnormal level, I investigate and address the issue."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
"The solution is easy to use, and the interface is intuitive."
"It improved my organization by building a security alerting program."
"They can subscribe to Rapid7 because it is more valuable and delivers a greater return on investment."
"InsightIDR helps us investigate an environment to discover information about incidents."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"Features for user behavior analytics and the rules for attack review are good."
"The ability to ingest Office 365 log files, then process them into events and display them on a map."
 

Cons

"The incidence reporting could be better."
"Lacking in depth of reporting."
"The initial setup was a bit complex. You've got to do a lot of reading. It's not an intuitive implementation."
"I would advise others to not implement it for any enterprise-level organization."
"There needs to be more focus on the NOC and IIS in terms of developing applications for behavior detection."
"The log collection is okay, but tracing the logs or tracing the events is a bit difficult."
"It's so hard to configure and explore something new on it. It is not easy to find the steps we need to follow in order to use the solution effectively."
"The user interface needs to be friendlier across the board."
"I would like to see more development in InsightIDR towards building their SIEM solution and converting it to XDR."
"They should add more configuration and security features to it."
"One thing that springs to mind is easier API integration with ITSMs."
"One of the things that could be better is digital forensics. It is there, but it can be better. They could provide more on the endpoint detection level."
"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"Lacks a mobile application."
"Needs a better ability to customize the check within the console."
"The ability to tune the collector for custom logs would greatly help."
 

Pricing and Cost Advice

"AlienVault pricing is the best. Whatever cost you are paying, you are getting a return on every penny... It's not like your IBM, your QRadar, or Splunk, where the cost is too high."
"OSSIM is free."
"I used the paid version of the tool and found it to be expensive. It has been a while since I changed to Securonix. I will have to check whether AlienVault charges per device, user, or log."
"The tool's licensing costs are yearly."
"AlienVault OSSIM is an open-source solution."
"We are using a free version of the solution. If you purchase a license there are more features available but the price is a little high. The solution should be cheaper to allow more customers to be able to afford it."
"AlienVault OSSIM is expensive compared to its competitors."
"The licensing fees for the non-community edition are paid on an annual basis, and there are no costs in addition to this."
"Licensing is by endpoint and amount of retention time (at least ours is). Default retention was one year, but we are able to push the retention further if needed. There's also a provide-your-own-S3 option for longer retention if you don't want to pay for the additional retention years in your Rapid7 agreement."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"The pricing and licensing are competitive."
"The pricing is good, and it is not very expensive."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
15%
Financial Services Firm
8%
Manufacturing Company
7%
University
7%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise9
Large Enterprise8
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What is your experience regarding pricing and costs for AlienVault OSSIM?
It depends. I would need to review their cost models, but generally, they are on a scaled basis based on throughput usage. Because it's a software as a service solution for their core product for U...
What needs improvement with AlienVault OSSIM?
Scaling for USM is always challenging for any product unless it is purpose-built or overbuilt at the front end. They will use Palo Alto and its competitors, and LevelBlue will manage that implement...
What is your primary use case for AlienVault OSSIM?
This solution is very similar to most of the other MSSPs that you would find out there. When I look at use cases, AlienVault was initially aimed at small to medium businesses. It grew, and that was...
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
 

Also Known As

OSSIM
InsightIDR
 

Overview

 

Sample Customers

Council Rock School District
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about AlienVault OSSIM vs. Rapid7 InsightIDR and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.