No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 InsightIDR vs Sentinel comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightIDR
Ranking in Security Information and Event Management (SIEM)
23rd
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
33
Ranking in other categories
User Entity Behavior Analytics (UEBA) (11th), Endpoint Detection and Response (EDR) (32nd), Threat Deception Platforms (4th), Extended Detection and Response (XDR) (18th)
Sentinel
Ranking in Security Information and Event Management (SIEM)
15th
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Security Information and Event Management (SIEM) category, the mindshare of Rapid7 InsightIDR is 2.3%, down from 2.4% compared to the previous year. The mindshare of Sentinel is 2.7%, down from 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Sentinel2.7%
Rapid7 InsightIDR2.3%
Other95.0%
Security Information and Event Management (SIEM)
 

Featured Reviews

Prajwal Chougale - PeerSpot reviewer
SOC L2 Analyst at a tech services company with 51-200 employees
Centralized threat hunting has improved alert accuracy and simplifies incident investigations
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the details are there, they could be more concise and easier to understand for any level of authority. The second area is alert tuning; compared to Microsoft Sentinel, Rapid7 InsightIDR provides fewer alerts with more static alert functionality and lacks dynamic alerting exposures. There could be improvements to learn from past alert activities for more dynamic alert configurations. These two areas are the main areas for improvement; everything else is good.
PT
Senior Specialist at a tech vendor with 10,001+ employees
Improved incident monitoring has reduced false positives and supports audit-ready reporting
The best features Sentinel offers, in my experience, include the filtering features and the ability to run KQL queries so that I can understand what table has what and when the last log has been monitored and reported. Sentinel has positively impacted my organization by improving monitoring significantly. As a pay-as-you-go service, we are ingesting logs as needed. When the pay-as-you-go service is enabled, we can either ingest whenever there is a spike in the logs, and when there are fewer logs, we can reduce the ingestion. This approach is helpful for both the organization and me. In terms of metrics showing how Sentinel has helped, as part of log filtering, we have reduced around thirty to thirty-five percent of false-positive incident creation. We have also cleared some audits by enabling log retention in Sentinel, allowing us to pull out data for audits when necessary using both hot retention and cold retention. This has helped the organization as a whole.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution provides satisfying native integration features"
"The platform offers unlimited storage and agent-based solutions."
"The product works well. Stability-wise, I rate the solution a ten out of ten."
"It is a very stable solution."
"Another very important part of insightIDR is the ability to collect data from endpoint devices via agent software. With a large remote workforce, this allows visibility into the endpoints that are connected to the internet, but not to the corporate network."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
"Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable."
"Dashboards, including the main screen, provide much-needed information at a glance, without hours of coding and sifting through logs to find it. In case of an actual security incident, I have faith that insightIDR has retained all logs in a secure manner that prevents log tampering as well."
"Novell SIEM was my second technology of this kind."
"The solution's Kusto Query Language (KQL) execution time is pretty good."
"The solution lets us get all the logs properly and regularly monitor customer infrastructure."
"The most valuable feature of this solution is that it provides a central locking system for many event sources."
"Transactional user information improves security, prevents fraud, and promotes best practices."
"If Sentinel is integrated with Identity Manager and User Application Portal, the solution runs simply perfect!"
"Sentinel is a tool that, if it's well configured, removes from view all unnecessary information and shows you only needful entries, so you can do your job faster, more conveniently, and with high performance."
"It provides real time security event analytics."
 

Cons

"I chose eight out of ten because of the analytical rules; they lack dynamic rules, and also due to the dashboard and reporting part."
"I'd like to be able to get the compliance report within the solution which is currently not possible."
"The dashboard is an area that could be simplified. For management, it should be clear and the files should be there."
"The main problem lies in the processes within the client's operating systems."
"If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"The product allows us to make only 30 custom rules."
"The solution needs improvement in threat intelligence. Increasing the depth of intelligence to help users understand more about threats is a possibility. My suggestion is to expand access to other websites or resources."
"Frankly speaking, we did not find this product to be valuable, at all."
"The dashboard and customer view should be improved."
"It's probably not a product that I would recommend to anyone."
"The solution does not allow outsourced authorizations."
"Documentation for security aspects could be improved. It is difficult to find clear information about encryption or risks that are addressed."
"This product's connection to certain types of cloud systems could be improved. We can do Microsoft, Google, and Amazon, but there are a lot of other things happening in the cloud that we do not connect well enough to. This product could be improved with better connection to cloud-based solutions."
"I would like to see a better reporting work structure on the dashboard."
"Some functions look great but, in practice, some key limitations turn the process into something opaque."
 

Pricing and Cost Advice

"I rate Rapid7 InsightIDR's price a four on a scale of one to ten, where one is cheap, and ten is expensive."
"​I am sure that there are cheaper products out there, but none that meet so many of our needs whilst maintaining stability and usability.​"
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"The solution has a mid-range price point in the market"
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"It is more reasonably priced than other vendors."
"The pricing and licensing are competitive."
"The pricing of the solution depends on the user. But there is a yearly licensing cost."
"We receive a pricing discount because of our ongoing partnership with Micro Focus."
"The solution’s pricing is aligned with its competitors."
"Sentinel is a subscription-based solution."
"We inquired about getting support from the vendor, Micro Focus, but the cost was very high."
"Sentinel's slightly on the expensive side."
"Sentinel is moderately priced."
report
Use our free recommendation engine to learn which Security Information and Event Management (SIEM) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
9%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
6%
Outsourcing Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise3
Large Enterprise8
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What is your experience regarding pricing and costs for Rapid7 InsightIDR?
My experience with pricing, setup costs, and licensing has been very positive; it is cost-effective and offers great value for the money. We bought the licensing through an agent, and the setup was...
What needs improvement with Rapid7 InsightIDR?
I would say there are two areas for improvement: the reporting dashboard that provides insights or reports weekly or monthly lacks detailed information about how logs are being ingested. While the ...
What is your experience regarding pricing and costs for NetIQ Sentinel?
My experience with pricing, setup cost, and licensing shows that while it is a little on the higher side, since it is part of a package for all Microsoft products, I feel it is a better choice comp...
What needs improvement with NetIQ Sentinel?
Sentinel needs minimal improvement, though improvements are ongoing. Everything seems to be functioning perfectly, and I don't have any specific inputs for improvements I would like to see in Senti...
What is your primary use case for NetIQ Sentinel?
My main use case for Sentinel is that I'm a subject matter expert for Sentinel, specifically for security incident event and event management. I head the SME for SIEM in LTIMindtree for this curren...
 

Also Known As

InsightIDR
NetIQ Sentinel, Novell SIEM
 

Overview

 

Sample Customers

Liberty Wines, Pioneer Telephone, Visier
Faysal Bank, GaVI, Handelsbanken, ISC Mªnster, Lambeth Council, Swisscard, The Municipality of Siena, Tukes, University of Dayton, University of the Sunshine Coast
Find out what your peers are saying about Rapid7 InsightIDR vs. Sentinel and other solutions. Updated: September 2026.
913,806 professionals have used our research since 2012.