Overview
Illumio Insights is designed for hyper-scale functionality across hybrid and multi-cloud environments. Insights offers comprehensive, real-time visibility into an organizations security landscape, covering all connected resources and data flows. By integrating with Illumio Segmentation, threats identified within environments can be quickly contained, and affected resources can be instantly quarantined.
Illumio Insights is particularly beneficial for the Blue Team, consisting of SOC analysts, incident responders, and threat hunters. It enables them to visualize and prioritize lateral movement risks across various environments, to facilitate rapid detection, identification, and response of threats.
With Insights, organizations gain,
Instant, agentless observability at scale. Visualize and understand connectivity across cloud and container environments using AI-driven flow decoration and threat labeling, which helps assess, triage, and confirm security events in cloud environments.
AI-driven threat detection and prioritization. Make swift, informed decisions in response to active attackers by revealing otherwise unseen attacker tactics, techniques, and procedures, as well as their lateral movement across cloud resources.
Effective threat mitigation with one-click containment. Neutralize potential threats with a one-click dynamic quarantine feature, containing and isolating compromised resources and dramatically reducing the Mean Time to Respond.
Highlights
- See risk. Visualize all communication and traffic between workloads and devices across the entire hybrid attack surface. Gain visibility with real-time telemetry and data, understand application communications, security policy, usage, access and security exposure with a comprehensive map of traffic flows.
- Set policy. Comprehensive monitoring and simplified labeling that helps eliminate blind spots by automatically setting granular and flexible segmentation policies that control communication between workloads and devices to only allow what is necessary and wanted.
- Stop the spread. Proactively isolate high-value assets or reactively isolate compromised systems during an active attack to stop the spread of a breach by programming dynamic workload policies for hybrid multi-cloud networks and endpoints, and applying automated policy recommendations.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Financing for AWS Marketplace purchases
Pricing
Free trial
Vendor refund policy
All fees are non-cancellable and non-refundable.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Illumio provides customers with 24/7 support by phone, email, and through our support portal. +1 888 631 6354 or support@illumio.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Micro-segmentation has improved threat visibility and supports ongoing zero-trust monitoring
What is our primary use case?
Illumio Insights plays its own role in enhancing threat visibility. Illumio Insights performs micro-segmentation according to the traffic, determining whether to trust it, allow it, or block it. Micro-segmentation is also a network access control at the network level. It does not understand or read the contents inside packets; it is not a WAF that can block SQL injection or web injection. It operates only at the TCP level and network level.
What is most valuable?
I use Illumio Insights' real-time analytics for micro-segmentation and zero-trust monitoring, which allows for analysis. However, the product coverage is not very broad, so I have to do my own filtering and analysis, and integration with other tools is necessary. The reporting and analysis features are not ready out of the product itself.
What needs improvement?
Deployment of Illumio Insights was not difficult, but the difficulty depends on how micro your design is. For Docker containers, it is not quite suitable for that kind of application traffic. For container architectures, it is not quite designed that way. For normal VMs it might be acceptable, but for container architectures, I cannot be as micro-segmented as I want to be.
Illumio Insights is not very well designed for containers, which is one of the drawbacks and weak sides of the product.
I use Illumio Insights' real-time analytics for micro-segmentation, and beyond zero-trust monitoring, I also want to do analysis. However, the product coverage is not very broad, so I have to do my own filtering and analysis, and integration with other tools is necessary. The reporting and analysis are not ready out of the product itself.
Reporting is another area for improvement in this product and is not very sufficient, so I have to further integrate or do it on my own.
Illumio Insights is stable and a mature product. The functionality, such as reporting and analysis, may extend in the roadmap, but it has not in the past. The current functionality is adequate and quite mature, which is how I chose it based on maturity and market share. However, it is not very modern for Kubernetes and containers. If this functionality can extend, that would be a valuable roadmap addition.
Streamline integration with Illumio Insights does not help me much since it does not require too much integration with my other operations.
For how long have I used the solution?
I have been using Illumio Insights for about five years.
What do I think about the stability of the solution?
Illumio Insights is stable and a mature product.
What do I think about the scalability of the solution?
The entire project depends on the scale of my farm. With my farm being not too small and not too big, it took more than one year to implement Illumio Insights because it had to be done in phases. It can affect the application traffic and cause issues. I could not implement it from design to implementation in a short time; it takes a while because it really depends on the scale.
How are customer service and support?
The support is reasonable.
What about the implementation team?
About two people participated in the deployment during this year. I was not directly involved; some team members participated in the deployment process for Illumio Insights.
What other advice do I have?
I would rate this review an 8.