SIEMRapid7 InsightIDR

Rapid7 InsightIDR

Configure Rapid7 InsightIDR integration with RAD Security for user behavior analytics and threat detection.

This guide walks you through integrating Rapid7 InsightIDR with RAD Security for advanced user behavior analytics, threat detection, and incident investigation, enabling you to correlate security events and leverage InsightIDR's SIEM capabilities.

Rapid7 InsightIDR provides user behavior analytics, attacker behavior detection, and automated investigation capabilities for comprehensive security monitoring.

Prerequisites

Before you begin, ensure you have:

  • Admin access to Rapid7 InsightIDR
  • Ability to create users in your Rapid7 organization
  • Access to the email account you'll use for the service user
  • Access to RAD Security workspace with integration permissions

Service User Recommended: Create a dedicated service user for this integration rather than using a personal account. This ensures continuity when team members change roles.


Creating a dedicated service user allows you to limit API key permissions and maintain better security hygiene.

Log in as Administrator

Log in to Rapid7 InsightIDR with an administrator account

Navigate to User Management

Click the settings gear icon in the top right corner and select Users

Create New User

Click the Create User button

Enter User Details

Fill in the user information:

  • First Name (e.g., "RAD Security")
  • Last Name (e.g., "Integration")
  • Email Address (use a service email account)

You'll need access to this email to activate the account. In production, use a service account email (e.g., security-integrations@company.com) to ensure the integration remains active when employees change roles.

Assign Product Access

Assign the user to the Insight IDR product

Assign Roles

Assign the following roles to the user:

  • Insight IDR Analyst
  • Log Search View Only

These are the minimum roles required for the integration to function properly. You can assign higher-level roles if additional permissions are needed for your use case.

Create User

Click Add User to confirm creation

Log Out

Log out of your administrator account

Activate Service User

  1. Open the email account associated with the new user
  2. Find the activation link from Rapid7
  3. Click the link to activate the account
  4. Complete the activation process and set a password

Save the activation link! Make sure to activate the account promptly. If you lose the activation email, you may need to request a new one from your administrator.


Step 2: Create Platform API Key

Log in as Service User

Log in to Rapid7 InsightIDR using the service user credentials you just created (or the existing user you want to use)

Navigate to API Keys

Click the settings gear icon in the top right corner and select API Keys

Create User Platform API Key

Follow Rapid7's documentation for creating a User Platform API key

  1. Click New User Key
  2. Enter a descriptive name (e.g., "RAD Security Integration")
  3. Click Generate

Copy and Save API Key

Immediately copy the API key to a secure location

This is your only chance to view the key! If you lose it, you cannot retrieve it and will need to generate a new one.


Step 3: Determine Regional API URL

Rapid7 InsightIDR uses different API endpoints based on your data center location.


Step 4: Configure in RAD Security

Navigate to your RAD Security workspace and configure the Rapid7 InsightIDR integration with the following parameters:

Required Parameters

ParameterDescriptionExample
URLRegional base URL for Rapid7 InsightIDR API (no path components)https://us2.api.insight.rapid7.com
TokenPlatform API key from Step 2your-api-key-here

Verify Integration

After completing the setup, verify your integration is working:

  1. Navigate to Data Sources > Integrations > SIEM in RAD Security
  2. Locate your Rapid7 InsightIDR integration
  3. Check the connection status shows as Connected
  4. Verify security events are being synced

Your Rapid7 InsightIDR integration is now configured! RAD Security can now correlate security events with InsightIDR's user behavior analytics and threat detection capabilities.

What Data is Synced

Once configured, RAD Security will sync the following data with Rapid7 InsightIDR:

Use Cases

User Behavior Analytics Correlate RAD Security runtime events with InsightIDR's user behavior analytics to detect anomalous activities.

Attacker Behavior Detection Identify attacker tactics, techniques, and procedures (TTPs) across endpoints and containerized infrastructure.

Automated Investigation Leverage InsightIDR's automated investigation capabilities with RAD Security's runtime context.

Incident Response Streamline incident response by correlating container security events with broader organizational security data.

Troubleshooting

Security Best Practices

Use Service Accounts Create a dedicated service account with a service email address to ensure continuity.

Least Privilege Roles Only assign Insight IDR Analyst and Log Search View Only roles unless higher permissions are specifically required.

Rotate API Keys Periodically rotate API keys as part of your security hygiene practices.

Secure Key Storage Store API keys in a secure password manager or secrets vault. Never commit them to version control.

Monitor API Usage Review API key usage in Rapid7 to detect any anomalous activity.

Audit User Access Regularly review service user permissions and ensure they remain appropriate.

API Key Management

To manage your API keys:

View Existing Keys

Log in as the service user and navigate to API Keys to view all active keys

Rotate Keys

  1. Create a new API key with a different name
  2. Update RAD Security with the new key
  3. Verify the integration works
  4. Delete the old key

Revoke Compromised Keys

If a key is compromised, immediately revoke it and generate a new one

Additional Resources

Next Steps