Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,457,575
Community Members
 
Community Events
176
Community Groups

Opsgenie Rapid7/InsightIDR Integration

We have a requirement to throw the alerts from InsightIDR. Right now it is being sent as email which is not really helping us.

We are considering Opsgenie to leverage as alert and notification tool to sit between Rapid7 and JSM where it could accept the alerts and notify the correct oncalls while maintaining a full integration with JSM.

There is no API integration for Opsgenie and even the integration in Jira is limited only to Story issue types: Create a ServiceNow or JIRA Ticket | InsightIDR Documentation (rapid7.com)

I came across the webhook for InsightIDR Universal Webhook | InsightIDR Documentation (rapid7.com) which I would like to explore if possible (before upgrading our OpsGenie to Standard Plan).

Appreciate any help.

1 answer

0 votes
Nick H Atlassian Team Apr 06, 2022

Hi @Rowell ,

Seems like you could leverage an Email Integration to connect InsightIDR with Opsgenie, and have these emails from InsightIDR create alerts in Opsgenie. Then have Opsgenie sit between Rapid7 and JSM to create issues from these alerts.

Within the JSM integration, you should be able to specify which types of issues are created by the alerts:

r71.jpg

 

The image above is our old integration framework which is limited to only creating one issue type per integration - so multiple integrations would be needed if you were hoping for more than one.

Having said that, our new integration framework provides more flexibility with the ability to created different issues types depending on the alerts and data being parsed in the payload:

r72.jpgr73.jpg

 

As for the InsightIDR Universal Webhook, not entirely sure we've come across this in the past with other customers. We do also offer an API integration - which I understand is a bit different - but might be able to integrate with Opsgenie.

Hope that helps. The suggestions above might be limited if you are on the Essentials plan though. But please let us know if you have any other questions.

Thanks for this Nick!

Right now, Email is the only integration we have like I said but the emails being thrown by InsightIDR is neither informative nor helpful for alert investigation. It only sends a link to Rapid7 for the events for Ops to visit.

I forgot to mention that we have a certain requirement to preset most of the fields such as Entity and especially Priority when setting up alerts to help with the routing in Opsgenie. This is not possible through email only since emails from InsightIDR *can not* be customized.

The above requirement has brought me to explore Webhooks instead.

Hope this makes sense.

Suggest an answer

Log in or Sign up to answer
TAGS

Atlassian Community Events