The SIEM formerly sold as InsightIDR — Rapid7 Incident Command is licensed per monitored asset, not per gigabyte, so a verbose log source never moves the invoice. Rapid7 writes the detection content, which is why it produces useful alerts in days rather than months.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Where data lives
Offshore — there is NO India region
Rapid7’s platform runs in five regions: the United States, Canada, Europe, Japan and Australia. Verified against Rapid7’s own trust page. For an Indian entity that means Tokyo or further afield, and it is the constraint most likely to decide this purchase.
Where it is processed
Rapid7’s cloud; SOC has no contractual geography
Detection and analyst work happen in Rapid7’s cloud. The Pune Global Capability Centre, opened April 2025, is a real SOC delivery node — but Rapid7’s contracts specify no geography, so there is no guarantee your alerts are handled in India, and people in India are not the same thing as data in India.
13-month retention exceeds CERT-In’s 180 days on duration and fails on location — two different tests, and only one is satisfied. One nuance that cuts against our own interest in selling you a second system: CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs remain producible in reasonable time, and many organisations keep source logs on-premises and treat this platform as a copy. Where it becomes unambiguous is sectoral — IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, see InsightVM, where the console is yours, or an India-hosted alternative.
Quick answer
This page covers Rapid7 Incident Command — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Rapid7’s cloud-delivered SIEM, renamed from InsightIDR in July 2025. Collects logs, endpoint telemetry and third-party events, then applies detection content Rapid7 writes and maintains.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Incident Command |
|---|---|---|
| Detection basis | Rules you wrote in advance | Baselines, and deviation from them |
| Stolen credentials | Nothing malformed to match | Behaviour is wrong, so it scores |
| Pricing axis | Per GB ingested — grows on its own | Per monitored asset — grows with the estate |
| Deployment | Cloud-only, or on-prem-only | Both, with a mature product each side |
| Existing SIEM | Rip and replace | Analytics can augment what you have |
| Investigation | Analyst queries for the timeline | Smart Timelines assembled for them |
| Honest caveat | — | Two platforms post-merger — ask the roadmap |
| Best fit | — | Big volume, small team — or on-prem |
The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The same agent that serves InsightVM, installed once on Windows, Linux and macOS. It collects process starts, Windows event logs, authentication activity and file information, and supports endpoint detection and containment. Rapid7 engineers have acknowledged it can run hot on high-event systems such as busy database servers, so test on your noisiest hosts rather than a quiet desktop.
A virtual machine you host that aggregates log sources and forwards them to Rapid7's platform, and proxies agent traffic. Sized at roughly 600 endpoints per CPU core, so a four-core instance handles around 2,400 agents. Requires 8 GB RAM and 60 GB of disk. It is x86-64 only, so ARM and AWS Graviton are unsupported. Add another Collector above 40 percent sustained CPU.
An optional passive sensor attached to a SPAN port, mirror port or network TAP at a traffic aggregation point. It runs a Suricata intrusion detection engine with Rapid7-curated rules and extracts DNS and DHCP metadata. Being passive and out of band it cannot block traffic and adds no latency, but it needs a genuine aggregation point to see anything useful.
Rapid7's AWS-hosted cloud where detection rules, user behaviour analytics and attacker behaviour analytics run against collected data. This is where investigations are raised, searched with LEQL and worked. Available in seven regional endpoints across the US, Canada, Europe, Japan and Australia. There is no on-premises deployment option and no India region.
Exports normalised event data to external platforms including Splunk, ServiceNow, HP ArcSight, Jira and generic webhooks. This matters for two reasons: it lets you keep an existing enterprise SIEM as a system of record, and it provides the route to push a copy of your logs into an in-India store where CERT-In localisation applies.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Collects logs from firewalls, servers, cloud platforms and security tools into one searchable store.
Captures process execution, authentication events and file activity from every host running the Rapid7 Agent.
Inspects mirrored traffic with a curated intrusion detection ruleset and extracts DNS and DHCP metadata.
Pulls activity from AWS, Azure, Microsoft 365 and identity providers into the same timeline as on-premises events.
Baselines normal account activity and flags anomalies such as impossible travel or first-time administrative access.
Matches observed activity against known attacker techniques curated by Rapid7 Labs from real incident data.
Ships and updates detection content written by Rapid7's own SOC so detections work without in-house engineering.
Plants decoy hosts, users, files and credentials that produce a high-confidence alert the moment an intruder touches them.
Enriches events with indicators from Rapid7 Labs, Project Lorelei honeypots and the AttackerKB community.
Queries collected data with select, where and groupby clauses, plus a natural-language option for common questions.
Runs automated response workflows such as ticket creation, account suspension and enrichment without analyst intervention.
Executes multi-step investigations built from Rapid7's own SOC playbooks and proposes a disposition for analyst review.
Endpoint protection, XDR and Security Copilot.
The SIEM, presented by Rapid7.
The same product under its former name.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).
Most SIEM platforms bill by data ingested, which creates a perverse dynamic: every improvement in logging coverage increases the invoice, so teams under-log to control cost and then cannot investigate properly. Incident Command meters by monitored asset instead — a host with a workstation or server operating system that has reported data in the last thirty days. Turn on verbose logging for a noisy application and the licence does not move. For Indian mid-market buyers this solves a real procurement problem: a finance director can approve a number that will not drift, and the security team can log what it should rather than what it can afford. Volume discounts begin above 500 assets. One caveat to check in writing: Rapid7's packaged marketplace listings do carry monthly data allowances, so the "unlimited ingestion" framing and the packaged SKU terms do not perfectly agree.
The defining question for any SIEM purchase is who writes the detection content. Splunk and Microsoft Sentinel are enormously capable, and both assume you have engineers to build and tune correlation logic. Most Indian mid-market security teams have three to eight people covering everything from patching to compliance, and no capacity for that. Rapid7 writes and maintains the detection content itself, drawn from its own managed SOC's experience across more than 11,500 customers. Attacker behaviour analytics encode observed techniques; user behaviour analytics baseline account activity automatically. The practical consequence is that the platform produces useful alerts within days of deployment rather than months. This is the single strongest argument for Incident Command, and the reason IDC placed Rapid7 as a Leader for SIEM in the SMB segment even while Gartner rates it a Challenger overall.
Most SIEM alerts are probabilistic — this login looks unusual, this process is uncommon — and analysts spend their day deciding which probabilistic signals deserve attention. Deception inverts that. Incident Command lets you plant four kinds of decoy: honeypots (a hardened Ubuntu virtual appliance), honey users (an account that looks like a domain administrator but is used by nobody), honey files (documents nobody should open) and honey credentials (credentials that appear in memory but authenticate nothing). Legitimate users never touch any of these. So when one fires, the false-positive rate is close to zero and you are almost certainly watching an intruder performing reconnaissance or lateral movement. For a small team drowning in probabilistic alerts, a handful of near-certain ones is disproportionately valuable. Deception ships in Ultimate and is available as an add-on at Advanced.
The Rapid7 Agent feeds both Incident Command and InsightVM from a single installation. For an organisation running a few thousand endpoints, deploying, maintaining and troubleshooting one agent rather than two is a real reduction in operational burden and in the political cost of asking desktop teams for another rollout. The integration goes beyond deployment convenience: a detection in the SIEM can be read alongside the vulnerability posture of the same host, so an analyst triaging suspicious activity on a server can immediately see whether that server carries an actively exploited vulnerability. Active Risk prioritisation appears in both products. If you intend to buy vulnerability management and log monitoring anyway, this coherence is worth something concrete — and Managed Threat Complete bundles unlimited InsightVM scanning into the MDR price.
Gartner's published 2025 cautions are direct, and we repeat them rather than soften them. Incident Command lacks advanced analytics such as supervised machine learning and custom deep-learning models, and lacks the breadth of out-of-the-box compliance reports competing platforms offer. Reviewers add specifics: reports group by only one field at a time, so you cannot group by user and destination simultaneously; the platform ships without a useful library of pre-built queries, so writing effective LEQL takes trial and error; and there is a default cap of 200 custom detection rules per organisation, raisable on request but a real ceiling. Gartner also notes customers get the most value when the product is used alongside the rest of the Rapid7 suite, which is a fair description of both a platform benefit and a switching cost. Threat-intelligence depth rates below Splunk and QRadar. Support response times draw consistent criticism. And it is cloud-only — no on-premises deployment, which excludes some regulated Indian environments outright.
Incident Command is the right SIEM for a mid-market organisation that needs credible 24/7 detection coverage and does not have, and does not intend to hire, a detection-engineering function. Between roughly 500 and 5,000 endpoints, with a security team in single figures, it is frequently the best-value choice available, and the per-asset model removes the budget anxiety that characterises this category. It is the wrong SIEM in three situations. If you run a large, complex, multi-vendor enterprise with engineers who want to build sophisticated correlation logic, Splunk is the better platform. If your estate is predominantly Microsoft and you hold E5 licences, Sentinel's native integration and bundled economics are very hard to beat. If Indian data localisation binds you — and CERT-In's 180-day in-India log rule binds a great many regulated entities — Rapid7's lack of an India region is disqualifying for the SIEM specifically, however well the product otherwise fits. We sell Splunk and Microsoft security alongside Rapid7. If your situation is one of those three, we will tell you so before you run an evaluation.
Count monitored assets, identify log sources, and settle the data residency question before anything else. Establish whether CERT-In's 180-day in-India log retention applies to your entity. If it does, design the parallel in-India log store now, using Data Exporter, rather than discovering the gap at audit.
Stand up Collectors sized at roughly 600 endpoints per CPU core on x86-64 hosts. Roll out the Rapid7 Agent in waves, starting with servers and a pilot desktop group. Test on your busiest database and application servers specifically, since the agent can run hot on high-event systems.
Connect firewalls, identity providers, cloud platforms and security tools. Let user behaviour analytics baseline for two to three weeks before judging alert quality. Tune exclusions for known-noisy activity, and deploy deception decoys once the environment is understood well enough to place them convincingly.
Define who triages alerts and when, build the playbooks that automate repetitive response, and agree escalation paths. Establish the reporting cadence your board or regulator expects, accepting that complex reports may need export rather than native generation. Reassess whether MDR would cover the hours you cannot staff.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“The detections were producing real findings inside a fortnight. We had budgeted three months of tuning and did not need it.”
“Per-asset pricing is why we chose it. Our previous SIEM invoice moved every quarter and nobody could explain why.”
“Honey credentials caught lateral movement during a red team exercise that nothing else in our stack flagged.”
“Log search is capable once you learn LEQL, but there is no decent library of starter queries. We worked it out ourselves.”
“Reporting is the weak point. You can group by one field. Wanting user and destination together means exporting to Excel.”
“Support is knowledgeable but slow. A medium-priority ticket sat for the better part of a week.”
“We deployed Collectors sized for the endpoint count and the guidance was accurate. Straightforward rollout overall.”
“Our auditors asked where the logs are stored. Tokyo was not the answer we needed for CERT-In. Plan for this early.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Mid-market platform — one agent, one contract.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Breadth over depth — that is the deliberate trade.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).
| Dimension | Rapid7 | Tenable | Qualys | CrowdStrike | Microsoft |
|---|---|---|---|---|---|
| Position | Mid-market platform: exposure, SIEM and MDR on one agent | The strongest scanner in the category | Cloud-native, lowest operational overhead | The endpoint and MDR benchmark | Near-free at the margin with E5 |
| Pricing axis | Per monitored asset — not per GB ingested | Per asset, quote-led | Per asset, reported ~$199–250/yr | $25–45 per endpoint/month for Falcon Complete | Bundled into E5 licensing |
| Vulnerability management | InsightVM — published price, Active Risk scoring | 219,000+ plugins, dedicated OT product | Cloud-native, native patching included | Exposure module if you already run Falcon | Weak on non-Microsoft OS and network devices |
| SIEM | Challenger in the 2025 MQ — not a Leader | Not a SIEM vendor | Not a SIEM vendor | Falcon Next-Gen SIEM | Sentinel — a Leader |
| MDR | Frost Radar Leader; VM and unlimited IR bundled in | Not an MDR vendor | Managed services available | Falcon Complete — the benchmark | Defender Experts |
| Deployment | SIEM and MDR cloud-only; InsightVM console is yours | Cloud or on-premises | Cloud-native only | Cloud-native only | Azure-hosted |
| India data residency | NO India region — InsightVM console is the exception | Region options; verify for your product | India platform, Pune-engineered | Verify per product | Azure India regions |
| The thing to plan around | No India region; agent mandatory; FY26 guided down | Priced above Rapid7 at most tiers | Support quality rated well; scanning less deep | The most expensive option here | Only economic if you already hold E5 |
| Best fit | Mid-market wanting VM, SIEM and MDR from one vendor | Deepest scanning, or operational technology | Lowest operational overhead, native patching | Best-in-class endpoint and managed response | Microsoft-standardised estates with E5 |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Rapid7 Incident Command is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Rapid7 meters per monitored asset; most rival SIEMs meter per gigabyte ingested. That is the comparison worth modelling, because it is the one that decides the deal. Move both sliders: the asset count you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number — Rapid7 is quote-only — it is the shape: per-asset cost tracks headcount and hardware, which change slowly, while per-GB cost tracks how much you log, which only ever goes up. Indicative Indian-market rates.
If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. The structural argument for per-asset pricing is not that it is always cheaper — it is that it stops the bill punishing you for collecting more, which is what makes teams under-log and miss things. Weigh that against the residency constraint before you decide.
Rapid7 does not publish a list price for Incident Command — it is quote-only, metered per monitored asset rather than per gigabyte, with volume discounts above 500 assets. The most reliable public figures are Rapid7’s own AWS Marketplace listings for up to 500 assets over twelve months. One contradiction to settle in writing before you sign: Gartner describes the licensing as unlimited ingestion, while the packaged marketplace SKUs carry explicit 0.5–0.8 TB monthly data allowances. Ask what happens on overage. TechBag quotes in INR with GST.
The entry tier
Where most buyers land
Everything included
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Where will our logs physically sit, and does that satisfy CERT-In's 180-day in-India requirement for our entity?
How many hosts run a workstation or server operating system and will report data in a thirty-day window?
Is 90 days enough, or do we need the 180-day tier plus a retention add-on to meet our regulator?
Do we want Rapid7 to write detection content, or do we have engineers who want to build their own?
Will 200 custom detection rules accommodate our use cases, and have we asked for a higher limit in writing?
Have we tested generating the specific reports our auditors demand, given single-field grouping?
Have we sized and budgeted Collectors on x86-64 hosts, excluding ARM and Graviton instances?
Who watches alerts overnight and at weekends, and is MDR cheaper than staffing that ourselves?
Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.