Talk to us
by Rapid7TechBag Intel Page

Rapid7 Incident Command

The SIEM formerly sold as InsightIDR — Rapid7 Incident Command is licensed per monitored asset, not per gigabyte, so a verbose log source never moves the invoice. Rapid7 writes the detection content, which is why it produces useful alerts in days rather than months.

Per asset, not per GBDetections work on day oneNo India data region

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Gartner Peer Insights
372 reviews, 83% would recommend
4.4 / 5
G2
~70 reviews; support rated 8.9
4.4 / 5
PeerSpot
33 reviews, 96% would recommend
4.2 / 5
Analyst position
2025 Gartner MQ for SIEM — not a Leader
Challenger

Data residency & processing — confirm before the PoC

Where data lives

Offshore — there is NO India region

Rapid7’s platform runs in five regions: the United States, Canada, Europe, Japan and Australia. Verified against Rapid7’s own trust page. For an Indian entity that means Tokyo or further afield, and it is the constraint most likely to decide this purchase.

Where it is processed

Rapid7’s cloud; SOC has no contractual geography

Detection and analyst work happen in Rapid7’s cloud. The Pune Global Capability Centre, opened April 2025, is a real SOC delivery node — but Rapid7’s contracts specify no geography, so there is no guarantee your alerts are handled in India, and people in India are not the same thing as data in India.

13-month retention exceeds CERT-In’s 180 days on duration and fails on location — two different tests, and only one is satisfied. One nuance that cuts against our own interest in selling you a second system: CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs remain producible in reasonable time, and many organisations keep source logs on-premises and treat this platform as a copy. Where it becomes unambiguous is sectoral — IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, see InsightVM, where the console is yours, or an India-hosted alternative.

Quick answer

Incident Command is Rapid7's cloud-delivered SIEM. If you are searching for InsightIDR, this is the same product: Rapid7 renamed it in July 2025, and the documentation still shows "SIEM (InsightIDR)" in places, so both names remain in circulation. It collects logs from your infrastructure, endpoint telemetry from the Rapid7 Agent and events from third-party tools, then applies detection rules, user behaviour analytics and attacker behaviour analytics to raise investigations. Rapid7 writes and maintains the detection content, which is the central design decision: you get detections that work on day one rather than a platform you must staff a detection-engineering team to populate. The commercial model is the standout feature — Incident Command is licensed per monitored asset rather than per gigabyte ingested. For teams who have watched an ingestion-priced SIEM invoice climb because someone enabled verbose logging on a firewall, that is a material change in how the budget behaves. Three tiers exist: Essential, Advanced and Ultimate. The dividing line that matters is retention — Essential holds logs 90 days, Advanced and Ultimate hold 180 — and the AI features, with agentic investigation workflows, AI-assisted triage and deception included at Ultimate and available as add-ons at Advanced. Alert and audit data is retained thirteen months on every tier. Be clear about where it sits in the market: in the 2025 Gartner Magic Quadrant for SIEM, Rapid7 is a Challenger, not a Leader — its seventh consecutive year of inclusion, which the company markets prominently. The Leaders are Microsoft, Splunk, Google, Securonix, Exabeam and Gurucul. Its genuine sweet spot is a mid-market organisation of roughly 500 to 5,000 endpoints whose security team has no dedicated SIEM engineer, and IDC named it a Leader specifically for SIEM in the SMB segment. For Indian buyers one constraint dominates: there is no India data region. Your logs will sit in Tokyo or further afield, which does not meet CERT-In's requirement to hold 180 days of ICT logs within Indian jurisdiction. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Rapid7 Incident Command — the SIEM. The other pillars:

Quick facts

30-second orientation
Category
Cloud-delivered next-generation SIEM
Former name
InsightIDR — renamed July 2025
Vendor
Rapid7 — CEO Wael Mohamed (June 2026)
Tiers
Essential · Advanced · Ultimate
Pricing model
Per monitored asset — NOT per GB ingested
Log retention
90 days Essential · 180 days Advanced/Ultimate
Alert retention
13 months, all tiers
Deployment
Cloud only — no on-premises option
Data regions
US · Canada · Europe · Japan · Australia
Data residency
NO India region — logs sit in Tokyo or further
Data processing
Rapid7's AWS cloud; seven regional endpoints
Gartner MQ 2025
Challenger — 7th year included, not a Leader
The honest gap
No ML/deep-learning analytics; 200 custom-rule cap
Buy in India via
TechBag — INR, GST, negotiated asset band
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Rapid7’s cloud-delivered SIEM, renamed from InsightIDR in July 2025. Collects logs, endpoint telemetry and third-party events, then applies detection content Rapid7 writes and maintains.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolIncident Command
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownPer monitored asset — grows with the estate
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Gathers endpoint telemetry

Rapid7 Agent

Endpoint collector

The same agent that serves InsightVM, installed once on Windows, Linux and macOS. It collects process starts, Windows event logs, authentication activity and file information, and supports endpoint detection and containment. Rapid7 engineers have acknowledged it can run hot on high-event systems such as busy database servers, so test on your noisiest hosts rather than a quiet desktop.

02
Forwards events to the cloud

Collector

On-premises aggregator

A virtual machine you host that aggregates log sources and forwards them to Rapid7's platform, and proxies agent traffic. Sized at roughly 600 endpoints per CPU core, so a four-core instance handles around 2,400 agents. Requires 8 GB RAM and 60 GB of disk. It is x86-64 only, so ARM and AWS Graviton are unsupported. Add another Collector above 40 percent sustained CPU.

03
Inspects mirrored traffic

Insight Network Sensor

Passive network monitor

An optional passive sensor attached to a SPAN port, mirror port or network TAP at a traffic aggregation point. It runs a Suricata intrusion detection engine with Rapid7-curated rules and extracts DNS and DHCP metadata. Being passive and out of band it cannot block traffic and adds no latency, but it needs a genuine aggregation point to see anything useful.

04
Detects, correlates and stores

Insight Platform

Cloud analytics layer

Rapid7's AWS-hosted cloud where detection rules, user behaviour analytics and attacker behaviour analytics run against collected data. This is where investigations are raised, searched with LEQL and worked. Available in seven regional endpoints across the US, Canada, Europe, Japan and Australia. There is no on-premises deployment option and no India region.

05
Sends data to other systems

Data Exporter

Outbound integration

Exports normalised event data to external platforms including Splunk, ServiceNow, HP ArcSight, Jira and generic webhooks. This matters for two reasons: it lets you keep an existing enterprise SIEM as a system of record, and it provides the route to push a copy of your logs into an in-India store where CERT-In localisation applies.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Ingestion

Third-party log ingestion

Collects logs from firewalls, servers, cloud platforms and security tools into one searchable store.

Collect
Endpoint

Agent telemetry

Captures process execution, authentication events and file activity from every host running the Rapid7 Agent.

Collect
Network

Suricata network monitoring

Inspects mirrored traffic with a curated intrusion detection ruleset and extracts DNS and DHCP metadata.

Collect
Cloud

Cloud and SaaS event sources

Pulls activity from AWS, Azure, Microsoft 365 and identity providers into the same timeline as on-premises events.

Detect
Analytics

User behaviour analytics

Baselines normal account activity and flags anomalies such as impossible travel or first-time administrative access.

Detect
Analytics

Attacker behaviour analytics

Matches observed activity against known attacker techniques curated by Rapid7 Labs from real incident data.

Detect
Content

Maintained detection rules

Ships and updates detection content written by Rapid7's own SOC so detections work without in-house engineering.

Detect
Deception

Honeypots and honey credentials

Plants decoy hosts, users, files and credentials that produce a high-confidence alert the moment an intruder touches them.

Detect
Intelligence

Embedded threat intelligence

Enriches events with indicators from Rapid7 Labs, Project Lorelei honeypots and the AttackerKB community.

Respond
Investigation

LEQL log search

Queries collected data with select, where and groupby clauses, plus a natural-language option for common questions.

Respond
Automation

Playbooks and SOAR

Runs automated response workflows such as ticket creation, account suspension and enrichment without analyst intervention.

Respond
AI

Agentic investigation workflows

Executes multi-step investigations built from Rapid7's own SOC playbooks and proposes a disposition for analyst review.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Rapid7 (official)·Overview

Rapid7 Incident Command

The SIEM, presented by Rapid7.

Rapid7 (official)·Demo

Rapid7 InsightIDR 3-Min Overview

The same product under its former name.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Incident Command

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

Per-asset pricing makes the budget predictable

Most SIEM platforms bill by data ingested, which creates a perverse dynamic: every improvement in logging coverage increases the invoice, so teams under-log to control cost and then cannot investigate properly. Incident Command meters by monitored asset instead — a host with a workstation or server operating system that has reported data in the last thirty days. Turn on verbose logging for a noisy application and the licence does not move. For Indian mid-market buyers this solves a real procurement problem: a finance director can approve a number that will not drift, and the security team can log what it should rather than what it can afford. Volume discounts begin above 500 assets. One caveat to check in writing: Rapid7's packaged marketplace listings do carry monthly data allowances, so the "unlimited ingestion" framing and the packaged SKU terms do not perfectly agree.

02

The detections work without a detection-engineering team

The defining question for any SIEM purchase is who writes the detection content. Splunk and Microsoft Sentinel are enormously capable, and both assume you have engineers to build and tune correlation logic. Most Indian mid-market security teams have three to eight people covering everything from patching to compliance, and no capacity for that. Rapid7 writes and maintains the detection content itself, drawn from its own managed SOC's experience across more than 11,500 customers. Attacker behaviour analytics encode observed techniques; user behaviour analytics baseline account activity automatically. The practical consequence is that the platform produces useful alerts within days of deployment rather than months. This is the single strongest argument for Incident Command, and the reason IDC placed Rapid7 as a Leader for SIEM in the SMB segment even while Gartner rates it a Challenger overall.

03

Deception delivers genuinely high-confidence alerts

Most SIEM alerts are probabilistic — this login looks unusual, this process is uncommon — and analysts spend their day deciding which probabilistic signals deserve attention. Deception inverts that. Incident Command lets you plant four kinds of decoy: honeypots (a hardened Ubuntu virtual appliance), honey users (an account that looks like a domain administrator but is used by nobody), honey files (documents nobody should open) and honey credentials (credentials that appear in memory but authenticate nothing). Legitimate users never touch any of these. So when one fires, the false-positive rate is close to zero and you are almost certainly watching an intruder performing reconnaissance or lateral movement. For a small team drowning in probabilistic alerts, a handful of near-certain ones is disproportionately valuable. Deception ships in Ultimate and is available as an add-on at Advanced.

04

One agent and one console across detection and vulnerabilities

The Rapid7 Agent feeds both Incident Command and InsightVM from a single installation. For an organisation running a few thousand endpoints, deploying, maintaining and troubleshooting one agent rather than two is a real reduction in operational burden and in the political cost of asking desktop teams for another rollout. The integration goes beyond deployment convenience: a detection in the SIEM can be read alongside the vulnerability posture of the same host, so an analyst triaging suspicious activity on a server can immediately see whether that server carries an actively exploited vulnerability. Active Risk prioritisation appears in both products. If you intend to buy vulnerability management and log monitoring anyway, this coherence is worth something concrete — and Managed Threat Complete bundles unlimited InsightVM scanning into the MDR price.

05

The honest caveat: it will frustrate a sophisticated detection team

Gartner's published 2025 cautions are direct, and we repeat them rather than soften them. Incident Command lacks advanced analytics such as supervised machine learning and custom deep-learning models, and lacks the breadth of out-of-the-box compliance reports competing platforms offer. Reviewers add specifics: reports group by only one field at a time, so you cannot group by user and destination simultaneously; the platform ships without a useful library of pre-built queries, so writing effective LEQL takes trial and error; and there is a default cap of 200 custom detection rules per organisation, raisable on request but a real ceiling. Gartner also notes customers get the most value when the product is used alongside the rest of the Rapid7 suite, which is a fair description of both a platform benefit and a switching cost. Threat-intelligence depth rates below Splunk and QRadar. Support response times draw consistent criticism. And it is cloud-only — no on-premises deployment, which excludes some regulated Indian environments outright.

06

The honest positioning

Incident Command is the right SIEM for a mid-market organisation that needs credible 24/7 detection coverage and does not have, and does not intend to hire, a detection-engineering function. Between roughly 500 and 5,000 endpoints, with a security team in single figures, it is frequently the best-value choice available, and the per-asset model removes the budget anxiety that characterises this category. It is the wrong SIEM in three situations. If you run a large, complex, multi-vendor enterprise with engineers who want to build sophisticated correlation logic, Splunk is the better platform. If your estate is predominantly Microsoft and you hold E5 licences, Sentinel's native integration and bundled economics are very hard to beat. If Indian data localisation binds you — and CERT-In's 180-day in-India log rule binds a great many regulated entities — Rapid7's lack of an India region is disqualifying for the SIEM specifically, however well the product otherwise fits. We sell Splunk and Microsoft security alongside Rapid7. If your situation is one of those three, we will tell you so before you run an evaluation.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

372
Gartner Peer Insights reviews
Gartner Peer Insights
83%
Reviewers who would recommend
Gartner Peer Insights
180 days
Log retention, Advanced and Ultimate
Rapid7 SIEM packages
13 months
Alert and audit data retention, all tiers
Rapid7 SIEM packages
7 years
Consecutive Gartner MQ inclusions (as Challenger)
Rapid7, October 2025
600 endpoints
Supported per Collector CPU core
Rapid7 documentation

What your Rapid7 Incident Command rollout looks like

Weeks 1–2Assess

Scoping and the residency check

Count monitored assets, identify log sources, and settle the data residency question before anything else. Establish whether CERT-In's 180-day in-India log retention applies to your entity. If it does, design the parallel in-India log store now, using Data Exporter, rather than discovering the gap at audit.

Weeks 3–6Deploy

Collector and agent deployment

Stand up Collectors sized at roughly 600 endpoints per CPU core on x86-64 hosts. Roll out the Rapid7 Agent in waves, starting with servers and a pilot desktop group. Test on your busiest database and application servers specifically, since the agent can run hot on high-event systems.

Weeks 5–10Tune

Source onboarding and tuning

Connect firewalls, identity providers, cloud platforms and security tools. Let user behaviour analytics baseline for two to three weeks before judging alert quality. Tune exclusions for known-noisy activity, and deploy deception decoys once the environment is understood well enough to place them convincingly.

Weeks 10–16Operate

Operationalisation

Define who triages alerts and when, build the playbooks that automate repetitive response, and agree escalation paths. Establish the reporting cadence your board or regulator expects, accepting that complex reports may need export rather than native generation. Reassess whether MDR would cover the hours you cannot staff.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Financial Services
The detections were producing real findings inside a fortnight. We had budgeted three months of tuning and did not need it.
Head of Information Security
Financial Services
Manufacturing
Per-asset pricing is why we chose it. Our previous SIEM invoice moved every quarter and nobody could explain why.
IT Director
Manufacturing
IT Services
Honey credentials caught lateral movement during a red team exercise that nothing else in our stack flagged.
Security Analyst
IT Services
Retail
Log search is capable once you learn LEQL, but there is no decent library of starter queries. We worked it out ourselves.
SOC Lead
Retail
Banking
Reporting is the weak point. You can group by one field. Wanting user and destination together means exporting to Excel.
Compliance Manager
Banking
Healthcare
Support is knowledgeable but slow. A medium-priority ticket sat for the better part of a week.
Infrastructure Manager
Healthcare
Logistics
We deployed Collectors sized for the endpoint count and the guidance was accurate. Straightforward rollout overall.
Systems Administrator
Logistics
Non-Banking Financial Company
Our auditors asked where the logs are stored. Tokyo was not the answer we needed for CERT-In. Plan for this early.
CISO
Non-Banking Financial Company
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Rapid7This page

Mid-market platform — one agent, one contract.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
Rapid7This page

Breadth over depth — that is the deliberate trade.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Rapid7 Incident Command vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionRapid7TenableQualysCrowdStrikeMicrosoft
PositionMid-market platform: exposure, SIEM and MDR on one agentThe strongest scanner in the categoryCloud-native, lowest operational overheadThe endpoint and MDR benchmarkNear-free at the margin with E5
Pricing axisPer monitored asset — not per GB ingestedPer asset, quote-ledPer asset, reported ~$199–250/yr$25–45 per endpoint/month for Falcon CompleteBundled into E5 licensing
Vulnerability managementInsightVM — published price, Active Risk scoring219,000+ plugins, dedicated OT productCloud-native, native patching includedExposure module if you already run FalconWeak on non-Microsoft OS and network devices
SIEMChallenger in the 2025 MQ — not a LeaderNot a SIEM vendorNot a SIEM vendorFalcon Next-Gen SIEMSentinel — a Leader
MDRFrost Radar Leader; VM and unlimited IR bundled inNot an MDR vendorManaged services availableFalcon Complete — the benchmarkDefender Experts
DeploymentSIEM and MDR cloud-only; InsightVM console is yoursCloud or on-premisesCloud-native onlyCloud-native onlyAzure-hosted
India data residencyNO India region — InsightVM console is the exceptionRegion options; verify for your productIndia platform, Pune-engineeredVerify per productAzure India regions
The thing to plan aroundNo India region; agent mandatory; FY26 guided downPriced above Rapid7 at most tiersSupport quality rated well; scanning less deepThe most expensive option hereOnly economic if you already hold E5
Best fitMid-market wanting VM, SIEM and MDR from one vendorDeepest scanning, or operational technologyLowest operational overhead, native patchingBest-in-class endpoint and managed responseMicrosoft-standardised estates with E5
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Rapid7 Incident Command fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Incident Command if…

  • Per-asset pricing matters more to you than the deepest analytics — a chatty firewall never moves the invoice
  • You have no detection-engineering function and want detections that work on day one
  • You are roughly 500–5,000 endpoints with a security team in single figures
  • Your logs may legally sit offshore — settle this FIRST, it decides the deal

Choose Tenable if…

  • You need the deepest scanning coverage — 219,000+ plugins
  • You have operational technology or industrial environments
  • Dashboard flexibility and scan efficiency are your priorities

Choose Qualys if…

  • You want no console to host, patch and size — it is cloud-native
  • Native patch management matters rather than integrating out to SCCM
  • An India platform answers your residency question directly

Choose CrowdStrike if…

  • You already run Falcon, so there is no second agent to deploy
  • You want best-in-class endpoint detection and managed response
  • You can accept the premium — $25–45 per endpoint per month

Choose Microsoft if…

  • You hold E5 licences, which changes the economics entirely
  • Your estate is standardised on Microsoft 365 and Azure
  • Azure India regions answer a residency obligation Rapid7 cannot

Rapid7 Incident Command is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.

750
25010,000
150
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.

An ingest-metered SIEM, at your GB/day
₹4,50,00,000
Saved vs an ingest-priced SIEM’s user meter
₹4,08,29,250
₹20,41,46,250 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Rapid7 does not publish a list price for Incident Command — it is quote-only, metered per monitored asset rather than per gigabyte, with volume discounts above 500 assets. The most reliable public figures are Rapid7’s own AWS Marketplace listings for up to 500 assets over twelve months. One contradiction to settle in writing before you sign: Gartner describes the licensing as unlimited ingestion, while the packaged marketplace SKUs carry explicit 0.5–0.8 TB monthly data allowances. Ask what happens on overage. TechBag quotes in INR with GST.

Essential

~$21,479/yr up to 500 assets

The entry tier

  • 90-day log retention — the dividing line that matters
  • 13-month alert and audit retention, as every tier has
  • Same SLAs as Ultimate if you add MDR — tiers do not buy speed

Advanced

~$33,682/yr up to 500 assets

Where most buyers land

  • 180-day log retention
  • AI triage and deception available as add-ons
  • The tier to model against a 180-day retention obligation

Ultimate

~$46,149/yr up to 500 assets

Everything included

  • 180-day retention plus agentic AI workflows and deception included
  • Roughly $92 per asset per year at this band
  • Above 500 assets everything is custom — negotiate

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Data residency

Where will our logs physically sit, and does that satisfy CERT-In's 180-day in-India requirement for our entity?

2
Asset count

How many hosts run a workstation or server operating system and will report data in a thirty-day window?

3
Retention

Is 90 days enough, or do we need the 180-day tier plus a retention add-on to meet our regulator?

4
Detection ownership

Do we want Rapid7 to write detection content, or do we have engineers who want to build their own?

5
Custom rules

Will 200 custom detection rules accommodate our use cases, and have we asked for a higher limit in writing?

6
Reporting

Have we tested generating the specific reports our auditors demand, given single-field grouping?

7
Infrastructure

Have we sized and budgeted Collectors on x86-64 hosts, excluding ARM and Graviton instances?

8
Coverage hours

Who watches alerts overnight and at weekends, and is MDR cheaper than staffing that ourselves?

FAQ

Questions buyers ask

Yes. Rapid7 announced Incident Command on 29 July 2025 and showcased it at Black Hat that August. It is the same SIEM, repositioned around AI-native security operations, with agentic investigation workflows built from Rapid7's own SOC playbooks added to the existing detection, investigation and response capability. The naming is genuinely messy and worth understanding before you go shopping. Rapid7's marketing pages say Incident Command. Its technical documentation still reads "SIEM (InsightIDR)" in many places. Gartner evaluated it as InsightIDR in the 2025 Magic Quadrant. Third-party review sites carry both names, sometimes on separate pages with different review counts. If you are comparing figures across sources, check which name each one used, because you may otherwise think you are looking at two products. For buyers this has one practical consequence: when you search for reviews, pricing data or community discussion, search both names. Most of the accumulated practitioner knowledge on the internet still sits under InsightIDR, because the product carried that name from 2015 to 2025. The rename does not change your contract, your deployment or your data, and existing customers were moved to the new branding without action required. There is no functional split between the names either — there is no "legacy InsightIDR" and "new Incident Command" running in parallel. It is one product with one codebase and two names in circulation, and Rapid7 will eventually retire the old one from the documentation.

Ready to evaluate Rapid7 Incident Command?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.