SIEM (InsightIDR) Integration
Copy link

With the SIEM integration, a bidirectional relationship is created between Threat Intelligence and Rapid7 SIEM.

This integration is available for users who have licenses for Digital Risk Protection and for SIEM. Users must also be migrated to the Rapid7 Insight Platform.

The integration is enabled within SIEM, as described in the SIEM documentation . There is no need to install anything on the Digital Risk Protection side.

The basis for the integration is the sending of open Digital Risk Protection alerts to SIEM for ingestion and management. Each alert ingested creates an SIEM investigation. Alerts that were closed by a policy are not sent.

SIEM users can benefit from the following:

  • Pivot from SIEM (InsightIDR) investigation back to Digital Risk Protection for [alert remediation](doc:  or to ask an analyst  about an alert.
  • Tune Threat Intelligence policies from SIEM adjusting rule actions and priority and adding exceptions.
  • Determine which alert types and scenarios will be ingested into SIEM (InsightIDR).

The following points are relevant to this integration:

  • Closing an investigation in SIEM will close the Digital Risk Protection alert (but not in the other direction).
  • Changes made to Digital Risk Protection alerts after their initial creation will not be sent to SIEM (InsightIDR).