SIEM integration
Automate Rapid7 InsightIDR SIEM with plain language
Read InsightIDR investigations, alerts and assets, and open an investigation from a VernacSecure SuperBot™ finding.
What you can do
Rapid7 InsightIDR — Investigations REST API v2
- List investigations and their status
- Read alerts and assets
- Create an investigation
Connection: header authentication against https://us.api.insight.rapid7.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Rapid7 InsightIDR”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch investigations — Lists investigations.
- Fetch alerts — Lists alerts attached to investigations.
Write actions
- Create investigation — Opens an investigation for the named endpoint.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM