No more typing reviews! Try our Samantha, our new voice AI agent.

ArcSight Analytics vs Rapid7 InsightIDR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 4, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Analytics
Ranking in User Entity Behavior Analytics (UEBA)
17th
Average Rating
6.8
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Rapid7 InsightIDR
Ranking in User Entity Behavior Analytics (UEBA)
11th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), Endpoint Detection and Response (EDR) (32nd), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
 

Mindshare comparison

As of September 2026, in the User Entity Behavior Analytics (UEBA) category, the mindshare of ArcSight Analytics is 1.9%, up from 1.2% compared to the previous year. The mindshare of Rapid7 InsightIDR is 4.5%, down from 8.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
User Entity Behavior Analytics (UEBA) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR4.5%
ArcSight Analytics1.9%
Other93.6%
User Entity Behavior Analytics (UEBA)
 

Q&A Highlights

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
 

Featured Reviews

reviewer1311453 - PeerSpot reviewer
Consultant at a tech vendor with 10,001+ employees
Good filtering and reporting tools but can be difficult to use
It can scale as needed. It's not a problem. There are different teams using it. We have CSOC, which is internal, which is onshore, then we have a security operations center that is offshore, which would be in India. The onshore team might be a group of three, and the offshore might be a group of five. Likely, we have eight to ten people in total using the product directly.
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The ability to correlate different logs is the solution's most valuable feature."
"We use this solution for monitoring our network."
"This solution makes it easy to create use cases, and it is easy to move queries from use cases to the report to the dashboard."
"The two most valuable features of this solution are its stability and scalability."
"Investigating an incident has become super easy and helpful."
"Less resource consumption in terms of memory and processing."
"We have seen a measurable decrease, by about 20 percent, in the mean time to detect and respond to risks."
"One of the most valuable features is the alerts."
"They can subscribe to Rapid7 because it is more valuable and delivers a greater return on investment."
"I like that it's a cloud-based solution."
"The solution is very stable and works very well for what I need it to do."
"This is a great product and the team is very willing to work with companies."
"The alerting to drive investigations and remediation has been its most valuable feature, plus the ability to quickly search multiple logs makes investigations easier."
"I've used other products such as QRadar and other SIEM solutions and I find this solution is much more simplified and user-friendly."
"The platform offers unlimited storage and agent-based solutions."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
 

Cons

"This is not a solution that I would recommend."
"There is a GUI, but it is not complete and lacks functionality that needs to be performed using the console."
"I would like to see orchestration."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"It's a difficult product to navigate, it's complex."
"ArcSight's features that can be improved include anything related to its visualization capabilities and user friendliness."
"Their support team could be better. They've gone downhill since their product has been acquired."
"You can use this solution for limited use cases. But for more advanced use cases, there are other solutions which are better than ArcSight."
"The dashboard is an area that could be simplified. For management, it should be clear and the files should be there."
"Sometimes, it is hard to get the right queries to use. Currently, the tool lacks a pre-made set of queries."
"I'd like to be able to get the compliance report within the solution which is currently not possible."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required."
"Inability to get access to compliance reports within the solution."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
"The APIs can be further improved in Rapid7."
 

Pricing and Cost Advice

"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"This solution is expensive."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"Rapid7 InsightIDR charges us based on the endpoints we connect to."
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"It is a reasonably priced solution."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Answers from the Community

Navin Rehnius - PeerSpot reviewer
SOC Analyst at Tata Consultancy Services, Ltd
Aug 10, 2021
Aug 10, 2021
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, remember that any EDR/XDR should integrate to the SIEM/SOAR and a strong threat intel source. If you consider SOC outsourcing take your time and find one you can integrate like a virtual team member. They a...
2 out of 12 answers
KM
IT Infrastructure Analyst at AG Group
Jul 26, 2021
I haven't used these big-name ones like Splunk etc. but I feel they're overpriced. I think they charge an arm and a leg for each module. The ROI justification is not there. Why not try a cheaper and robust alternative like Elasticsearch?
KA
Unit Head Titanium (Security Solution) at RapidCompute
Jul 26, 2021
We are using LogRthythm SIEM complete case management and offer SIEM/SOC as service.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Outsourcing Company
12%
Marketing Services Firm
9%
Financial Services Firm
9%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
What is your primary use case for Rapid7 InsightIDR?
Rapid7 InsightIDR serves as our SIEM solution where all kinds of activity, including network logs, endpoint logs, user activity, user behavior analytics, and threat hunting, are tracked. Additional...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
InsightIDR
 

Overview

 

Sample Customers

Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about ArcSight Analytics vs. Rapid7 InsightIDR and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.