No more typing reviews! Try our Samantha, our new voice AI agent.

Lumu vs Rapid7 InsightIDR comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Lumu
Ranking in Extended Detection and Response (XDR)
21st
Average Rating
9.2
Reviews Sentiment
7.5
Number of Reviews
8
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (14th), Network Detection and Response (NDR) (11th)
Rapid7 InsightIDR
Ranking in Extended Detection and Response (XDR)
18th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
Security Information and Event Management (SIEM) (23rd), User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (32nd), Threat Deception Platforms (4th)
 

Mindshare comparison

As of September 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.8%, down from 6.1% compared to the previous year. The mindshare of Lumu is 1.5%, down from 1.9% compared to the previous year. The mindshare of Rapid7 InsightIDR is 2.5%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks4.8%
Rapid7 InsightIDR2.5%
Lumu1.5%
Other91.2%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
JJ
Director, Information Technology at a educational organization with 201-500 employees
Constant monitoring and analysis boosts network security
There is always room for improvement. I am not giving it a perfect score because I am sure there is something that could be enhanced.Having some sort of certification or training, along with more periodic webinars might be helpful. Having a larger support network would be beneficial. Nobody I know has heard of Lumu, so they are in the same space as Darktrace or CrowdStrike, but people give blank stares. As the community grows for Lumu then that will improve, but that is not really a criticism of Lumu, they simply have not been around that long.
Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It'll not slow down your system when compared to others."
"The interface is easy to use and it is more up to date than our previous solution."
"The solution allows control over the user and his machine through Cortex XDR security policies."
"It is easy to use."
"The solution's most valuable feature is the user interface."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"It blocks malicious files, prevents attacks, and doesn't require many updates because it is a very light application."
"From a single pane of glass, you can easily manage all of your endpoints."
"Lumu protects against threats immediately and handles them in time."
"Lumu has allowed us to operate cybersecurity in a better way, with a manageable number of incidents that contain all the context including the Mitre matrix and much more, while providing visibility across on-premise, cloud, remote environments, and IoT such as IP cameras, with automatic mitigation that lets our team focus only on incidents that require our full attention."
"You can access external links, playbooks, MITRE Matrix, and a lot of information."
"The context provided by the tool is very complete, it includes the miter matrix, playbooks, links, hashes, and much more."
"Most of it is automated, so I do not have to watch it to get alerts."
"It's been helpful for overall extended network visibility."
"The tool's support team helps partners resolve any problems with the product."
"The automated response to incidents works effectively out of the box, and the number of interfaces and platforms it can work with is impressive."
"Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar."
"The UI is very good."
"I like that it's a cloud-based solution."
"This is a great product and the team is very willing to work with companies."
"I've used other products such as QRadar and other SIEM solutions and I find this solution is much more simplified and user-friendly."
"Enables the use of honey pots, honey users, and honey files to monitor for suspicious patterns."
"The solution is easy to use, and the interface is intuitive."
"I am able to run automated actions based on the output of reports, leaving me extra time to focus on more pressing matters."
 

Cons

"In an upcoming release, the solution could improve by proving hard disk encryption. If it could support this it would be a complete solution."
"There are some default policies which sometimes affect our applications and cause them to run around."
"If he is using a smaller company, he can depend on some other tools because Cortex XDR by Palo Alto Networks is a bit expensive."
"I recommend adding a data loss prevention (DLP) solution to Cortex XDR by Palo Alto Networks. The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products."
"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"The configuration could be simplified. I would like to see better protection, specifically to protect email applications."
"It is a complex solution to implement."
"There are some limitations on the Traps agents."
"The integration with different vendors and endpoints could be improved."
"It would be good if we could access the physical logs."
"Lumu's ability to discover threats is an area of concern where improvements are needed."
"Nothing so far needs to be improved."
"The reports need improvement."
"The free version is minimal compared to the full version."
"Having a larger support network would be beneficial. Nobody I know has heard of Lumu, so they are in the same space as Darktrace or CrowdStrike, but people give blank stares."
"I am happy with the current features. However, one important one is to improve the reports."
"The APIs can be further improved in Rapid7."
"The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources."
"Rapid7 InsightIDR is not intuitive to search for logs. It should be more user-friendly and improve the dashboards. We should be able to use ready-made templates instead of having to build one."
"I'd like to be able to get the compliance report within the solution which is currently not possible."
"Personally, I feel it would greatly benefit from more supported log sources."
"I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part."
"Customised alert recipients need to be added to allow better first-line action and quicker response. Configurable honeypots would be a welcome addition."
"Tenable Nessus is easier to deal with. It's more efficient and accurate. InsightIDR is heavier than Tenable in terms of performance and scanning. Rapid7 would be much easier to use if it had a network connector like Tenable. Tenable's connector allows continuous monitoring over the B caps."
 

Pricing and Cost Advice

"I don't recall what the cost was, but it wasn't really that expensive."
"The pricing is a little bit on the expensive side."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"I am using the Community edition."
"It has a higher cost than other solutions, like CrowdStrike or Microsoft’s EDR tools, but it reduces the cost of our operations because it’s a new generation antivirus tool."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"Our license will require renewal in August, after which the maintenance will continue as usual."
"The price was fine."
"Compared to Lumu, other solutions are more expensive. SentinelOne was a bit cheaper, and another provider's price structure is unclear, but Lumu fit our budget nicely. SentinelOne's cost depends on the number of devices, and it might be similar to Lumu's, depending on deployment."
"The tool is available at a good price. The tool offers a good and competitive price for customers."
"It is the cheapest solution we found."
"Licensing is straightforward. If, for some reason, you don’t meet the minimum licensing requirements, there is a third-party managed service that can help."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"The solution has a mid-range price point in the market"
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"​Accurately predict your licensing counts as this is a subscription based product.​"
"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
10%
Outsourcing Company
9%
Comms Service Provider
8%
Manufacturing Company
7%
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with Lumu?
There is always room for improvement. I am not giving it a perfect score because I am sure there is something that co...
What is your primary use case for Lumu?
We use it as our managed SOC instead of contracting with an MSP. It coordinates endpoint and gives us a single pane o...
What is your experience regarding pricing and costs for Lumu?
In our environment, it costs approximately 1200 a month.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great ...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or ...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
InsightIDR
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Liberty Wines, Pioneer Telephone, Visier
Find out what your peers are saying about Lumu vs. Rapid7 InsightIDR and other solutions. Updated: August 2026.
913,683 professionals have used our research since 2012.