You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
We have a requirement to throw the alerts from InsightIDR. Right now it is being sent as email which is not really helping us.
We are considering Opsgenie to leverage as alert and notification tool to sit between Rapid7 and JSM where it could accept the alerts and notify the correct oncalls while maintaining a full integration with JSM.
There is no API integration for Opsgenie and even the integration in Jira is limited only to Story issue types: Create a ServiceNow or JIRA Ticket | InsightIDR Documentation (rapid7.com)
I came across the webhook for InsightIDR Universal Webhook | InsightIDR Documentation (rapid7.com) which I would like to explore if possible (before upgrading our OpsGenie to Standard Plan).
Appreciate any help.
Hi @Rowell ,
Seems like you could leverage an Email Integration to connect InsightIDR with Opsgenie, and have these emails from InsightIDR create alerts in Opsgenie. Then have Opsgenie sit between Rapid7 and JSM to create issues from these alerts.
Within the JSM integration, you should be able to specify which types of issues are created by the alerts:
The image above is our old integration framework which is limited to only creating one issue type per integration - so multiple integrations would be needed if you were hoping for more than one.
Having said that, our new integration framework provides more flexibility with the ability to created different issues types depending on the alerts and data being parsed in the payload:
As for the InsightIDR Universal Webhook, not entirely sure we've come across this in the past with other customers. We do also offer an API integration - which I understand is a bit different - but might be able to integrate with Opsgenie.
Hope that helps. The suggestions above might be limited if you are on the Essentials plan though. But please let us know if you have any other questions.
Thanks for this Nick!
Right now, Email is the only integration we have like I said but the emails being thrown by InsightIDR is neither informative nor helpful for alert investigation. It only sends a link to Rapid7 for the events for Ops to visit.
I forgot to mention that we have a certain requirement to preset most of the fields such as Entity and especially Priority when setting up alerts to help with the routing in Opsgenie. This is not possible through email only since emails from InsightIDR *can not* be customized.
The above requirement has brought me to explore Webhooks instead.
Hope this makes sense.