Rapid7 InsightIDR alternatives

3 tools to consider instead of Rapid7 InsightIDR, shown against it.

Rapid7 InsightIDR Microsoft Sentinel Exabeam Wazuh
Vendor Rapid7, Inc. Microsoft Corporation Exabeam, Inc. Wazuh, Inc.
Pricing model Quote only Usage-based Quote only Open source + paid options
Free tier No No No Yes
Deployment Cloud Cloud Cloud Cloud, Self-hosted
Open source No No No Yes (GPL-2.0)
Best for Lean security teams wanting predictable, asset-based SIEM pricing tied into vulnerability management context. Organizations already on Azure/Microsoft 365 wanting a natively integrated, elastically scaled SIEM. SOC teams prioritizing behavioral anomaly detection over hand-written correlation rules. Security teams and MSSPs wanting a fully open-source SIEM/XDR without per-GB licensing costs.
Pricing

Asset-based pricing (not per-GB), sold in Essential/Advanced/Ultimate tiers; exact rates require a quote, with volume discounts from ~500 assets.

Checked on the vendor's own page on September 21, 2026: no prices are published. Expect to be quoted.

Analytics tier bills per GB ingested/day (pay-as-you-go or discounted commitment tiers up to 52% off); a separate Data Lake tier bills per GB for low-cost long-term storage. No flat dollar figures are published; use Microsoft's calculator for a region-specific rate.

Checked on the vendor's own page on September 21, 2026: no prices are published. Expect to be quoted.

Custom-quoted, typically scaled by data volume or monitored identities; no published self-serve pricing.

Pricing has not been verified yet — see the vendor's site.

The core platform is free and open source; the vendor sells an optional managed cloud tier and paid support contracts.

Pricing has not been verified yet — see the vendor's site.

Features
  • Cloud SIEM with log search and correlation
  • User and entity behavior analytics (UEBA)
  • Endpoint detection and response (EDR) agent
  • Asset-based pricing model instead of per-GB
  • Shared context with Rapid7 vulnerability management
  • Managed detection and response (MDR) add-on available
  • Analytics and Data Lake ingestion tiers for cost-tiered retention
  • Prebuilt connectors for Microsoft 365, Entra ID, Defender and third-party sources
  • AI-assisted investigation via Copilot for Security
  • Automated response playbooks (SOAR)
  • User and entity behavior analytics (UEBA)
  • Commitment-tier discounts up to 50,000GB/day
  • User and entity behavior analytics (UEBA) baselining
  • Smart Timelines that auto-assemble related events
  • Prebuilt threat detection content and use-case coverage
  • Case management and investigation workflows
  • Can layer analytics on top of an existing SIEM (Fusion)
  • Cloud-native, SaaS-delivered
  • Host-based intrusion detection and log analysis
  • File integrity monitoring
  • Vulnerability detection against installed software
  • Compliance reporting (PCI-DSS, HIPAA, GDPR, NIST)
  • Agent-based architecture across Linux, Windows, macOS
  • SIEM and XDR use cases on the same open-source stack

In the index now