Try our new research platform with insights from 80,000+ expert users

Microsoft Sentinel vs Rapid7 InsightConnect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Sentinel
Ranking in Security Orchestration Automation and Response (SOAR)
1st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
97
Ranking in other categories
Security Information and Event Management (SIEM) (3rd), Microsoft Security Suite (6th), AI-Powered Cybersecurity Platforms (5th)
Rapid7 InsightConnect
Ranking in Security Orchestration Automation and Response (SOAR)
19th
Average Rating
8.0
Reviews Sentiment
7.4
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Security Orchestration Automation and Response (SOAR) category, the mindshare of Microsoft Sentinel is 17.5%, down from 20.5% compared to the previous year. The mindshare of Rapid7 InsightConnect is 0.9%, up from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

Ivan Angelov - PeerSpot reviewer
Threat detection and response capabilities enhance investigation processes
My security team has been using Microsoft Sentinel for around two years. We also have Bastion and SolarWinds as part of our monitoring tools. We use a three-way tool, alongside Microsoft Sentinel, in our environment The most valuable features for us include threat collection, threat detection,…
Chamindu Pramodya - PeerSpot reviewer
Enables us to design workflows and integrate various processes
I design workflows and integrate various processes using Rapid7 InsightConnect. This includes integrating with value management and packaging and incorporating InsightVMware performance through Rapid7 InsightConnect The product is user-friendly. Customers are familiar with its usage. The…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"You can fine-tune the SOAR and you'll be charged only when your playbooks are triggered. That is the beauty of the solution because the SOAR is the costliest component in the market today... but with Sentinel it is upside-down: the SOAR is the lowest-hanging fruit. It's the least costly and it delivers more value to the customer."
"The solution offers a lot of data on events. It helps us create specific detection strategies."
"The solution has features that helped improve the security posture of our clients. It provides the ability to correlate a large variety of log sources very cost-effectively, especially for Microsoft sources."
"It's pretty powerful and its performance is pretty good."
"Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence."
"If you know how to do KQL (kusto query language) queries, which are how you query the log data inside Sentinel, the information is pretty rich. You can get down to a good level of detail regarding event information or notifications."
"The automation rules and playbooks are the most useful that I've seen. A number of other places segregate the automation and playbook as separate tools, whereas Microsoft is a SIEM and SOAR tool in one."
"It has a lot of great features."
"The fact that it's a security orchestration, automated response solution with a vast level of insights and the ability to integrate with a number of other security tools."
"InsightIDR's Attacker Behavioral Analytics (ABA) and User and Entity Behavior Analytics (UEBA) features have been very useful in maintaining our security posture."
"Based on my user experience, I would recommend InsightConnect for its user-friendly interface and excellent documentation."
"The tool is stable. The initial setup is straightforward. The product is user-friendly."
 

Cons

"Microsoft Sentinel can be improved in terms of automation or connecting with security products so that it is easier to use for general IT admins."
"The pricing tiers of Microsoft Sentinel should be improved. There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing."
"Microsoft Sentinel is relatively expensive, and its cost should be improved."
"The built-in SOAR is not really good out-of-the-box. The SOAR relies on logic apps and you almost need to have some kind of developer background to be able to make these logic apps. Most security people cannot develop anything..."
"If Azure Sentinel had the ability to ingest Azure services from different tenants into another tenant that was hosting Azure Sentinel, and not lose any metadata, that would be a huge benefit to a lot of companies."
"Only one thing is missing: NDR is not available out-of-the-box. The competitive cloud-native SIEM providers have the NDR component. Currently, Sentinel needs NDR to be powered from either Corelight or some other NDR provider."
"I think the number one area of improvement for Sentinel would be the cost."
"When we pass KPIs to the governance department, there's no option to provide rights to the data or dashboard to colleagues. We can use Power BI for this, but it isn't easy or convenient. They should just come up with a way to provide limited role-based access to auditing personnel"
"The GUI needs improvement, as creating workflows can be cumbersome."
"The technical support should be improved."
"The GUI needs improvement, as creating workflows can be cumbersome. More updated plugins are needed to leverage existing functionalities, such as APIs for functions like blocking malicious IPs in FortiGate."
 

Pricing and Cost Advice

"It is priced fairly given the value that you get from the use of the product. The biggest mistake people make with Microsoft Sentinel is not understanding the pricing model and the amount of data that they are going to be running through the tool because you are paying based on the flow. You are paying based on the amount of data that is moving through the tool. People do not plan, and therefore, they get surprised by the cost associated with using the tool. They connect everything because they want to know everything, but connecting everything is very expensive."
"Pricing for Microsoft Sentinel could always be lower, but it's workable. The ingestion costs for the data analytics is usually the highest cost, but the licensing per Microsoft Sentinel is fairly straightforward and transparent."
"Cost-wise, Sentinel is based on the volume of information being ingested, so it can be quite pricey. The ability to use strategies to control what data is being ingested is important."
"We only pay for the amount of data we bring in, which is fair."
"Microsoft can enhance the licensing side. I feel there is confusion sometimes... They should have a single license in which we have the opportunity to use the EDR or CASB solution."
"For us, it is not expensive at this time, but if we start to collect all logs from our on-premise SIEM solutions, it will cost more than QRadar. If we calculate its cost over the next five or ten years, it will cost more than what we paid for QRadar."
"Microsoft Sentinel is included in our E5 license."
"Sentinel is pretty competitive. The pricing is at the level of other SIEM solutions."
Information not available
report
Use our free recommendation engine to learn which Security Orchestration Automation and Response (SOAR) solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
10%
Manufacturing Company
8%
Government
8%
Computer Software Company
10%
Financial Services Firm
9%
Healthcare Company
8%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
What is your experience regarding pricing and costs for Rapid7 InsightConnect?
Compared to other SOAR solutions, the pricing is reasonable as Rapid7 provides it as a bundle called InsightIDR Ultimate, with unlimited workflows.
What needs improvement with Rapid7 InsightConnect?
The GUI needs improvement, as creating workflows can be cumbersome. More updated plugins are needed to leverage existing functionalities, such as APIs for functions like blocking malicious IPs in F...
What is your primary use case for Rapid7 InsightConnect?
We are using Rapid7 InsightConnect in a partner model, operating as a service provider. We buy licenses under World Data Direct and distribute them internally, acting as an MSSP.
 

Also Known As

Azure Sentinel
Rapid7 Insight Connect, Komand
 

Overview

 

Sample Customers

Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Starr Companies, Landmark Health
Find out what your peers are saying about Microsoft Sentinel vs. Rapid7 InsightConnect and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.