Sign in
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Reviews from AWS customer

4 AWS reviews

External reviews

82 reviews
from and

External reviews are not included in the AWS star rating for the product.


3-star reviews ( Show all reviews )

    SohailHyder

Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration

  • November 05, 2025
  • Review provided by PeerSpot

What is our primary use case?

I am working with Rapid7 InsightOps and Rapid7 InsightIDR because the requirement is as such from the customer side, particularly the banks. Whatever the requirement is, these are the products that we are working with.

I usually recommend Rapid7 InsightIDR for banks because that is the bigger chunk here who do business in cybersecurity or whose requirement is that compliance requirements need to be filled by certain products, which Rapid7 InsightIDR is one of them.

What is most valuable?

UEBA is an important element these days, but usually the requirement is for threat detection, investigation, and response. This is what Rapid7 InsightIDR provides.

Banks typically go for threat detection, investigation, and response capabilities. End-user entity and behavior analysis, or UEBA, is certainly an important addition if we provide the solution along with UEBA. It provides that and this is something that the customer cannot ignore because they want to have a 360-degree coverage of their emails or for their users and what they are doing. This is definitely their requirement.

What needs improvement?

If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled.

Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.

For how long have I used the solution?

It has been about four to five years now that we have been working with Rapid7. Whatever the products, they were all related to vulnerability tools that we have been working with. It has been a journey of about five years with Rapid7.

What other advice do I have?

Rapid7 InsightIDR is budget-friendly and has a good market position because not everybody can afford to go for LogRhythm or Splunk or QRadar. It is good for a middle-tier organization. In that market, there is competition now.

I do not recommend Rapid7 InsightIDR for bigger companies because they trust these big brands such as QRadar or LogRhythm. The general perception is that these are the solutions for big organizations having hundreds of branches or more. Rapid7 InsightIDR fits in the middle tier.

The integration of Rapid7 InsightIDR with the security stack works fine because the systems in this part of the world are not so much cloud-driven. They have something around 20% or 30% of services running from the cloud. The rest are usually on-premises. Office 365 is one service that they get from the cloud. Networking typically includes Cisco and Fortinet in their networks. For endpoints, the operating system is usually Windows or Linux, not Mac in an enterprise environment. Windows and Linux can be easily integrated with this solution.

The dashboard functionalities of Rapid7 InsightIDR are usually about customer-friendliness. Customers want to have some rich enrichment of the analysis or the ticket alerts or the events that come out with some processing behind the scenes. They feel that it is a more rapid or more intense process at Splunk or LogRhythm or QRadar compared to Rapid7 InsightIDR.

For automated threat intelligence features, customers usually go for a full SOAR solution. They want to have playbooks and everything to run. Although Rapid7 InsightIDR does claim that it has integrated SOAR, called InsightConnect, this is not as advanced as a dedicated SOAR solution. LogRhythm solutions or Splunk solution or Sumo Logic solution are doing business here as well. These are considered more rich in features compared to Rapid7 InsightIDR.

I rate Rapid7 InsightIDR between a six and seven out of ten.


    Financial Services

IDR situation

  • August 06, 2025
  • Review provided by G2

What do you like best about the product?
It maps detections to MITRE ATT&CK, which helps a lot during investigations. So it makes the processes faster
What do you dislike about the product?
It's too limited. It's becomes difficult to create alerts and set up pattern based alerts do to the timing
What problems is the product solving and how is that benefiting you?
It gives us full visibility across endpoints, cloud apps, and logs. All in one place, and once


    Asim Naeem

Providing comprehensive insight into alerts while working towards AI enhancement

  • February 06, 2025
  • Review from a verified AWS customer

What is our primary use case?

I am using Rapid7 InsightIDR as an InsightIDR solution. This tool is integrated with other solutions like endpoint and NDR, and it correlates alerts, giving me a comprehensive picture of the alerts.

What is most valuable?

The platform offers unlimited storage and agent-based solutions. I have user behavior analytics (UBA) and MITRE ATT&CK as well. The user behavior analytics feature helps in enhancing the security posture by helping to identify user behaviors and engineering alerts based on them.

What needs improvement?

There is a future in AI with Rapid7, however, it is not fully operated. There are certain limitations with Rapid7 that I am working on. I have already opened a list of features with Rapid7, and they are working on it.

For how long have I used the solution?

I have been using Rapid7 InsightIDR for about two years.

What do I think about the stability of the solution?

So far, I have not had any performance issues with Rapid7 InsightIDR. It is working well, and I have not faced any downtime in the last two years.

What do I think about the scalability of the solution?

Every product has some limitations, and Rapid7 is no exception, yet it is working for me perfectly right now.

How are customer service and support?

I rate their technical team 8.5 out of ten, which is pretty good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Currently, I am not working with the LogRhythm solution. I have another SIEM solution in place. Previously, three years back, I was working with LogRhythm, however, now I do not.

How was the initial setup?

The initial setup was straightforward, and I did not face any complexities during the setup of the IDR product.

What was our ROI?

The incident response time is good, and I can easily find or search any incident. I easily build the queries in Rapid7 and search my relevant logs or relevant investigation logs.

Which other solutions did I evaluate?

I have EDR, XDR, NDR, TLP, and many other solutions like these.

What other advice do I have?

I definitely recommend Rapid7 InsightIDR. It is becoming better, with improvements being continuously made to the product.

Right now, I do not have any advice about Rapid7 for other users because every organization or user has different criteria or multiple use cases, so I refrain from commenting on that. I rate the overall solution seven out of ten.


    Prasanth Prasad

Offers capabilities in areas like threat intelligence and vulnerability management but needs to improve support

  • February 15, 2024
  • Review provided by PeerSpot

What is most valuable?

The most valuable feature of the product for managing security events stems from the fact that the product's intelligence part is very good since it offers its own threat intelligence and vulnerability management platform. The tool also has its own cloud security posture management platform. The tool also is a dynamic application security testing platform. The aforementioned tools fall under Rapid7 InsightIDR's kitty. The intelligence and the data that Rapid7 gathers from customers across the globe enrich the quality of its detection capabilities. All other tools in the market depend on third-party solutions for intelligence. Rapid7 InsightIDr has the intelligence part natively available within the product, giving it a good edge over other vendors.


What needs improvement?

I believe that Rapid7 InsightIDR has moved to a complete cloud-first strategy. The tools offered by Rapid7 InsightIDR are amazing. The product should have provided some capabilities to users who wanted to stay or use the tool's on-premises version, as it would have provided the solution with more acceptance in the market, especially in the Middle East region.

It takes time for the product's support team to resolve issues, making it an area of concern where improvements are required.

For how long have I used the solution?

I have been using Rapid7 InsightIDR for three to four years.

What do I think about the stability of the solution?

As I haven't heard any complaints about the product, I rate the solution's stability a nine out of ten.

What do I think about the scalability of the solution?

Scalability-wise, I rate the solution a ten out of ten. As a cloud tool, the product is highly scalable.

The product is meant for medium-sized customers and large enterprises and not for corporate or government organizations since the product is available only on the cloud. Customers who have the privilege of using cloud solutions can use Rapid7 InsightIDR. Cloud solutions' use is less in government spaces in the Middle East region since there are some regulations to use cloud-based products. In the private space, I feel that Rapid7 InsightIDR is considered to be a fairly strong product.

It is difficult for enterprise businesses to use the solution, especially the ones regulated by governments. There are no problems with the solution when it comes to a private company or a private enterprise. I think Rapid7 InsightIDR provides the best tools. The tool won't work for you if you are not allowed to use a public cloud.

How are customer service and support?

I rate the technical support a six to seven out of ten.

How would you rate customer service and support?

Neutral

What other advice do I have?

The tool has improved the efficiency of security incident detection and response in our company as it works fairly well. It is possible to enhance the capabilities of the platform since the solution offers a whole stack or suite of tools. When dealing with Rapid7 InsightIDR, you will see the integration capabilities offered are extremely seamless. Rapid7 InsightIDR offers its own set of features that enrich the capabilities of the vulnerability management tool. In general, the product's features increase the solution's overall capabilities in terms of reporting and detection of vulnerabilities.

I can't remember a scenario where the product was effective in threat hunting or investigation. Rapid7 InsightIDR is a very acceptable product for people who want a cloud-based solution. The product is not available on an on-premises version. The product can be useful for industries ranging from SMBs to large-sized companies where there is a need for a tool that can be very easily rolled out at a very effective and attractive price point that gives them very good coverage from a cybersecurity perspective.

Speaking about how the product has enhanced the security posture in our company, I would say that I am not really sure about the capabilities of the UABA part of the solution since I haven't seen many use cases around it.

Rapid7 InsightIDR mean time-to-detect and mean time-to-respond are fairly good because Rapid7's support team does pick up a ticket whenever it is raised from the users' end, but its mean time-to-resolve has some concerns since some of the tools under Rapid7 are available on an on-premises model. In specific to InsightIDR, I think that everything is very good, including areas like detection, MTTD, and MTTR, which are very good in InsightIDR specifically. The product can improve a bit in the area of MTTD and MTTR.

Rapid7 InsightIDR's integration capabilities with other tools are not an area I have experience with since the product is completely available on the cloud. I believe that whatever integrations users want from the product would work since it is a solution that is available on the cloud. I don't have personal experience with the integration part.

I rate the overall tool a seven out of ten.


    Consumer Goods

Great SIEM tool

  • August 17, 2021
  • Review provided by G2

What do you like best about the product?
Many data sources able to injest into SIEM
What do you dislike about the product?
Data parsing for alerts is limited. Some alerts give very little context.
What problems is the product solving and how is that benefiting you?
SIEM Tool for alerting on multiple data sources.


    Information Technology and Services

Good features and Powerful SIEM

  • June 01, 2021
  • Review provided by G2

What do you like best about the product?
The range of data ingestion options available. It'll ingest pretty much anything you send its way. If you happen to find something out of the norm, I found the product team was really keen to help solve our challenges and come up with solutions. If like us, you happen to use other products such as InsightVM, this product has excellent integration into it. and they continue to merge in other integration components from other 3rd party systems, which I think is great. A key differentiator, I believe, is that the solution doesn't charge based on data storage costs; This is a hugely positive thing, in my mind. When you start looking at SIEM solutions you're going to be asked by other vendors to calculate how much data you need to ingest. If you're new on a journey of implementing a full-featured SIEM, that question is like asking a question 'how long is a piece of string'. You might know what you're currently ingesting, but that's going to grow exponentially as you use the products. (If you have Cyber Insurance coverage, your insurers are going to want to see 12 months of logs held). With Insight IDR you're pricing is based on the number of assets monitored, not how much your logs will be. This makes your budget forecasts easier to plan. Another big plus.. given your data is all cloud-stored, that means you don't have to resort to tricks, as with other vendors, of archiving older data back to on-premise (to seemingly reduce costs).. ultimately that's going to cause you more management overhead as you now have to additionally back up that 'cold data' and have additional systems and processes to manage all of that - just do it the properly first time around (with Insight IDR)
What do you dislike about the product?
I'd like to see the same level of feature functionality with Azure, as they currently provide with AWS. Granted I was an early adopter of Insight IDR, Rapid7 (like many other vendors) went with AWS first. In our business, we manage both Azure and AWS. Many 'Microsoft houses' will use Azure, because of their enterprise agreements.. well ahead of AWS, so I'd have liked to have seen earlier stage product investment in Azure. I'd like to see more features added to try and get near to feature parity with Azure Sentinel (as I think the overall meta-analysis done by Rapid 7 using the Sonar dataset helps give me more contextual views into your risk). Additionally, RBAC needs prioritization they are working to address this, but it's something they do need to sort out. I'm trying to bring other departments into using Insight IDR, but at the moment as the access controls aren't there, I can't open it out to other teams at this time.
What problems is the product solving and how is that benefiting you?
We have a myriad of many different systems, many different vendors, many different work styles. We have a large global workforce who are highly mobile. I often say to people that trying to get all your systems to do what you want is like herding cats.. so I worked my way through all the vendors who could provide a system with a full feature set which would allow us to have 'once a source of truth', or 'one glass of pain' from which I could understand my risk areas that needed to be tackled. Hence Rapid7 was selected for the job. If and when we get to the stage where the alerting becomes too much, we can bring in their consulting arm (who knows the product) to take over the reins to further help us.


    Information Technology and Services

InsightIDR pros n cons..

  • September 10, 2018
  • Review provided by G2

What do you like best about the product?
Very intuitive tool, with very detailed dashboards and can be integrated with most enterprise systems
What do you dislike about the product?
Custom integration with APIs is kind of troublesome sometimes, client side APIs r not much feature rich.
What problems is the product solving and how is that benefiting you?
Real time issue management, ticket analysis, indepth root cause analysis.


    Gary G.

Rapid's insightIDR - simple yet elegant

  • September 04, 2018
  • Review provided by G2

What do you like best about the product?
InsightIDR is used for incident detection , response and authentication monitoring . Licensing is straightforward . The ability to ingest office 365 files then process them into events and display them on a map . This feature is useful . It shows who are the users who have been phished . Also intelligent alerting to avoid the common problem of fatigue associated with traditional SIEMs .
What do you dislike about the product?
After contract signing the attention towards the organisation reduces .
What problems is the product solving and how is that benefiting you?
For automated actions based on the output of the reports and thus leaving extra time for other critical issues .
Recommendations to others considering the product:
The technical support of rapid7's InsightIDR is awesome and the initial setup is straightforward .


showing 1 - 8