integration-docs
Loading

Rapid7 InsightVM

Version 2.2.0 (View all)
Compatible Kibana version(s) 8.19.0 or higher
9.1.0 or higher
Supported Serverless project types
What's this?
Security
Observability
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic

The Rapid7 InsightVM integration allows users to monitor Asset and Vulnerability Events. Rapid7 InsightVM discovers risks across all your endpoints, cloud, and virtualized infrastructure. Prioritize risks and provide step-by-step directions to IT and DevOps for more efficient remediation. View your risk in real-time right from your dashboard. Measure and communicate progress on your program goals.

Use the Rapid7 InsightVM integration to collect and parse data from the REST APIs. Then visualize that data in Kibana.

The Rapid7 InsightVM integration collects two type of events: Asset and Vulnerability.

Asset (Deprecated) is used to get details related to inventory, assessment, and summary details of assets that the user has access to. See more details in the API documentation here. It is deprecated in version 2.0.0. Instead, use the Asset Vulnerability data stream for enriched vulnerability documents and improved mappings.

Asset Vulnerability is used to gather and aggregate data on assets and vulnerabilities to support Native CDR Workflows.

Vulnerability is used to retrieve all vulnerabilities that can be assessed. See more details in the API documentation here.

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ.

Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

This module uses InsightVM Cloud Integrations API v4.

  1. Generate the platform API key to access all Rapid7 InsightVM APIs. For more details, see Documentation.

Version 2.0.0 of the Rapid7 InsightVM integration adds support for Elastic Cloud Security workflow. The enhancement enables the users of Rapid7 InsightVM integration to ingest their enriched asset vulnerabilities from Rapid7 InsightVM platform into Elastic and get insights directly from Elastic Vulnerability Findings page. This update adds Elastic Latest Transform which copies the latest vulnerability findings from source indices matching the pattern logs-rapid7_insightvm.asset_vulnerability-* into new destination indices matching the pattern security_solution-rapid7_insightvm.vulnerability_latest-*. The Elastic Vulnerability Findings page will display vulnerabilities based on the destination indices.

For existing users of Rapid7 InsightVM integration, before upgrading to 2.0.0 please ensure following requirements are met:

  1. Users need Elastic Security solution which has requirements documented here.
  2. To use transforms, users must have:
    • at least one transform node,
    • management features visible in the Kibana space, and
    • security privileges that:
      • grant use of transforms, and
      • grant access to source and destination indices For more details on Transform Setup, refer to the link here
  3. Because the latest copy of vulnerabilities is now indexed in two places, i.e., in both source and destination indices, users must anticipate storage requirements accordingly.

This is the asset dataset.

This is the asset_vulnerability dataset.

This is the vulnerability dataset.