LogRhythm NextGen SIEM Platform vs. Rapid7 InsightIDR

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
LogRhythm NextGen SIEM Platform
Score 7.6 out of 10
N/A
The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.N/A
InsightIDR
Score 9.5 out of 10
N/A
In addition to their incident response service, Rapid7 offers InsightIDR, a combined XDR and SIEM that provides user behavior and threat analytics.
$5.89
per month per asset
Pricing
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Editions & Modules
No answers on this topic
InsightIDR Advanced
$5.89
per month per asset
Offerings
Pricing Offerings
LogRhythm NextGen SIEM PlatformInsightIDR
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details*500 asset minimum. Billed annually. All amounts are shown in U.S. dollars. International prices vary.
More Pricing Information
Community Pulse
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Considered Both Products
LogRhythm NextGen SIEM Platform
Chose LogRhythm NextGen SIEM Platform
LogRhythm has consistently been in the top quadrants and reviews. The support provided by the vendor is top class. Once it is up and running, there is no much to be done in terms of setup. However, free trainings on the internet like youtube are not available as they should be.
Chose LogRhythm NextGen SIEM Platform
SIEMs are complex behemoths, regardless of the one you decide to go with. Even those that are supposedly turn-key solutions aren't really and can pose some tricky issues for veteran IT and InfoSec staff. LogRhythm has the best educational services and technical support, hands …
Chose LogRhythm NextGen SIEM Platform
LogRhythm is heads and tails above AlienVault and more well known and industry-standard compared to InsightIDR.
Chose LogRhythm NextGen SIEM Platform
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which …
Chose LogRhythm NextGen SIEM Platform
We researched Splunk as well but it seemed to require more programming experience than LogRhythm which we currently do not have and could not support another FTE for. SolarWinds SIEM product was another product we researched, although it's basic functionality was good, it was …
Chose LogRhythm NextGen SIEM Platform
LogRhythm's NextGen SIEM Platform is lightning fast when compared to other SIEM platforms. With our previous SIEM platform, it would take several hours to query for certain events over a 90 day period. For more advanced queries we'd sometimes have to let it run overnight. …
Chose LogRhythm NextGen SIEM Platform
Unlike other vendors, all modules of LogRhythm are integrated with the main solution. One could go for the Enterprise Architecture which offers separate hardware for separate modules. But in our case that wasn't needed. We needed something that was user-friendly and didn't take …
Chose LogRhythm NextGen SIEM Platform
We used Kiwi years ago before it was owned by Solarwinds and it worked great for our then small server stack, but we grew much bigger fast and needed something more robust and LogRhythm fit the bill.
Chose LogRhythm NextGen SIEM Platform
LogRhythm is easily differentiated from the other log analysis products I've used in terms of sheer functionality. The competitors can't keep up in performance, speed, or correlation. The only thing that the other products can do to hold a candle to LogRhythm is to integrate it …
Chose LogRhythm NextGen SIEM Platform
LR is inferior when compared to a cloud-native SIEM - the functionality is simply not there.
Chose LogRhythm NextGen SIEM Platform
AlienVault USM Appliance and USM Anywhere might lack some functionality where LogRhythm does well. For instance, SmartResponse functionality is more mature than the Orchestration rules at AlienVault USM Anywhere. You can easily script SmartResponse to act accordingly to each …
Chose LogRhythm NextGen SIEM Platform
We selected LogRhythm due to low overall time investment to meet our basic needs, very competitive pricing, a strong user community and a reputation for excellent support. We have been pleasantly surprised by the very personal nature of the partnership we enjoy with LogRhythm - …
Chose LogRhythm NextGen SIEM Platform
We did an RFP and evaluated several SIEM vendors. LogRhythm ended up being a very clear choice when compared with the other vendors.
In this RFP we invited all vendors that were in the leaders category of the Gartner magic quadrant for SIEM.
Chose LogRhythm NextGen SIEM Platform
We had business requirements for the following features:
  • Sustained flow acquisition and data collection of dissimilar log types from multiple sources.
  • Customization for Reporting and Alerting in near real time.
Chose LogRhythm NextGen SIEM Platform
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since …
Chose LogRhythm NextGen SIEM Platform
I work with every SIEM on the market and I believe LogRhythm simply provides the best overall value in terms of price, incident response capability, content capability, and ease of engineering.
InsightIDR
Chose InsightIDR
The biggest advantage it has the lightweight agent and smooth and less traffic chaos in network during log collection. Cloud Security always require extra efforts but InsightIDR reduce that burden as it has highly anticipated agents to which knows what they need to do when they …
Chose InsightIDR
Other products are OK, but they lack the robust permissions and their interfaces are much much less intuitive. Rapid7's prioritization system for vulnerabilities makes more sense given their context as the developers of Metasploit. We thought we might be able to switch and save …
Chose InsightIDR
We tried other solutions, but our Network, which is mostly in different locations with different OEMS , was well suited by Rapid7. Rapid7 works with different workflows and SIEM solutions, which was a requirement of the SOC solution. Visibility allows the security operation to …
Chose InsightIDR
Many of the top-tier providers of this technology do a comparable job. However, we selected Rapid7 because of their reputation in the area of user behavior analytics, cost, # of SOC locations (due to our selection of their MDR service), support, company growth in other areas …
Chose InsightIDR
Both products would do what we needed them to, but Rapid7 InsightIDR made more sense from a cost perspective. We did a proof of concept of both products, and they were pretty evenly matched in their own ways. Forescout had a better interface, but in the end the interface of …
Chose InsightIDR
Between Rapid7 InsightIDR and Crowdstrike, we liked Rapid7 InsightIDR due to the functionality of the system and the features Rapid7 InsightIDR has. Rapid7 InsightIDR was very easy to deploy in our environment to our endpoint devices. We like the scanning capabilities and the …
Features
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Security Information and Event Management (SIEM)
Comparison of Security Information and Event Management (SIEM) features of Product A and Product B
LogRhythm NextGen SIEM Platform
7.4
Ratings
5% below category average
Rapid7 InsightIDR
-
Ratings
Centralized event and log data collection9.00 Ratings00 Ratings
Correlation8.10 Ratings00 Ratings
Event and log normalization/management8.00 Ratings00 Ratings
Deployment flexibility4.60 Ratings00 Ratings
Integration with Identity and Access Management Tools7.10 Ratings00 Ratings
Custom dashboards and workspaces7.50 Ratings00 Ratings
Host and network-based intrusion detection7.10 Ratings00 Ratings
Data integration/API management8.00 Ratings00 Ratings
Behavioral analytics and baselining8.00 Ratings00 Ratings
Rules-based and algorithmic detection thresholds7.10 Ratings00 Ratings
Response orchestration and automation7.10 Ratings00 Ratings
Reporting and compliance management7.00 Ratings00 Ratings
Incident indexing/searching7.10 Ratings00 Ratings
Best Alternatives
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Small Businesses
LevelBlue USM Anywhere
LevelBlue USM Anywhere
Score 3.8 out of 10
Bitdefender GravityZone
Bitdefender GravityZone
Score 9.1 out of 10
Medium-sized Companies
Sumo Logic
Sumo Logic
Score 9.4 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
Enterprises
Sumo Logic
Sumo Logic
Score 9.4 out of 10
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Likelihood to Recommend
7.5
(0 ratings)
9.9
(0 ratings)
Likelihood to Renew
9.0
(0 ratings)
-
(0 ratings)
Usability
8.0
(0 ratings)
-
(0 ratings)
Support Rating
8.2
(0 ratings)
-
(0 ratings)
Implementation Rating
8.0
(0 ratings)
-
(0 ratings)
User Testimonials
LogRhythm NextGen SIEM PlatformRapid7 InsightIDR
Likelihood to Recommend
LogRhythm is good for providing a comprehensive view of the environment. It gives a great outline of whatever is going on in our servers and systems regarding security malfunctions. The SIEM sends real-time notifications when there are some occurrences; like creating a new user and inappropriate login attempts. It also avails a good use case that meets our HIPAA compliance.
Read full review
It has been brilliant for us in terms of understanding the behaviour affecting our endpoints and assets. We have full visibility of our alerts, which menas we can act on them immediately. We use a single pain of glass with dashboards that can be easily drilled down into to get further information. It has laso helped us eo create bespoke reports for senios Managmeent, while at the same time supports other teams like Network Mnagement and Operations.
Read full review
Pros
  • LogRhythm is a great SIEM to learn content on because the building blocks are very intuitive and easy to implement. All of the concepts relevant to content development are literally represented as drag and drop building blocks that can be easily manipulated.
  • The statistical building blocks contain powerful anomaly detection capabilities that are extremely difficult to implement in other SIEMs or not possible at all.
  • LogRhythm does better event classification than any other SIEM by far. My team typically drops all classification schemes from default installations of SIEMs and rebuilds them from scratch. I can actually use LogRhythms event classifications in rules without worrying about excessive partial matches or correlating unwanted events.
Read full review
  • Rapid7 InsightIDR does a very good job at keeping virus definitions up to date so that our threat intelligence is very up to date when knowing what to protect against.
  • It helps us by scanning all of our infrastructure components and highlights where improvements need to be made in security so we can be proactive with our security initiatives.
  • It has automated response mechanisms to triage and resolve any potentials risks allowing us to save time in the long run.
Read full review
Cons
  • While searching for log events is quick, the interface isn't as user-friendly as other SIEM products.
  • Many of the administrative/management functions are only available through the full LogRhythm desktop console, not through the web console.
  • The LogRhythm agent, when used for FIM and RIM, is very memory intensive.
Read full review
  • Sometimes Rapid7 InsightIDR will be too locked down and without knowing will block applications and processes needed for day to day operation.
  • System scans with Rapid7 InsightIDR can be very bandwidth-heavy on the network and system resources.
  • From a recent incident, we have seen more and more false positives from Rapid7 InsightIDR on areas that we know are secure.
Read full review
Likelihood to Renew
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
Read full review
No answers on this topic
Usability
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
Read full review
No answers on this topic
Support Rating
Support has always been fantastic for this product compared to many other support providers I've worked with. They are always very friendly and seem to be well trained and knowledgeable and never have to wait long for a solution. We usually get the issue fixed in the first call, but also we really haven't had to use support a ton so that's also a plus
Read full review
No answers on this topic
Implementation Rating
  • Buy professional services.
  • Buy and implement the system if possible.
  • Remember that the end point log configuration may require other teams in your company to assist you in getting the desired logs from all resources.
  • Attend the end user and daily operations training after a period of usage so you are not overwhelmed with information on concepts not yet seen.
  • Don't be afraid to call for help during your first months of use.
  • Don't close any ticket until you are sure the expected results are verified.
  • Use the community forums to discuss issues with your peers.
  • Watch the training videos offered by L R University.
Read full review
No answers on this topic
Alternatives Considered
The only thing we chose LogRhythm NextGen SIEM Platform for is to allow the Security Analysts to work on the dashboards which don't know much about programming and query languages but has good intuition about cyber-security. It is easy to get hands-on compared to Splunk, which has an initial learning curve before being able to start harnessing its true power. Also, the ticketing system is quite fancy and somehow shows us the recent tickets that we need to jump on, which is not in Splunk.
Read full review
Between Rapid7 InsightIDR and Crowdstrike, we liked Rapid7 InsightIDR due to the functionality of the system and the features Rapid7 InsightIDR has. Rapid7 InsightIDR was very easy to deploy in our environment to our endpoint devices. We like the scanning capabilities and the console we felt was very easy to use and can be easily caught up to our IT staff. Also during vulnerability scans, we felt that Rapid7 InsightIDR was able to detect more and any competitor out there.
Read full review
Return on Investment
  • We were able to retire a few older log collection platforms that we had in house. There were 2-3 systems doing the job of LogRhythm.
  • We were able to bring some part of the analysis of events back in house and not rely on third party MSS.
Read full review
  • Rapid7 InsightIDR has allowed us to be proactive in securing our systems as the vulnerability scans give us a lens at what we need to fortify when it comes to security.
  • In recent incidents its allowed us to save time and money as it mostly detects issues accurately and we are able to bring systems back quickly without too much downtime for the business.
  • With recent updates, we are confident that Rapid7 InsightIDR is a good solution for the long run as they are always making adjustments to their platform and improving it with every release.
Read full review
ScreenShots