Overview
The Rapid7 integration enables ThreatAware to collect data from your Rapid7 InsightIDR platform, providing visibility into security events, threat detection, and investigation data.Connection Method: API
Setup Time: 15 minutes
Access Required: Rapid7 Organisation Administrator account
Data collected
The Rapid7 integration provides:- Security event data
- Threat detection information
- Investigation metadata
- Asset vulnerability information
- User investigation data
Use cases
Security Event Monitoring
Monitor security events and threats detected across your infrastructure
Threat Detection Integration
View threat detections from InsightIDR within ThreatAware
Investigation Support
Access investigation data and findings from Rapid7 analysts
Compliance Evidence
Generate reports showing security monitoring coverage and detections
Setup instructions
1
Log in to ThreatAware Dashboard
Navigate to your ThreatAware instance and go to Settings > Systems.
2
Search for Rapid7
Use the search bar to find “Rapid7” in the integrations list.
3
Click Connect
Click Connect to open the connection popup window. Keep this window open.
4
Access Rapid7 Platform
Log in to your Rapid7 Platform using your administrator credentials.
5
Generate Organisation API Key
In the Rapid7 console:
- Navigate to Settings > API Keys from the top-right menu
- Click Generate New Key
- Select Organisation Key
- Name it “ThreatAware” for easy identification
- Copy the generated key for use in ThreatAware
6
Obtain Organisation ID
Still in Rapid7 Settings:
- Navigate to Organisation Settings on the left sidebar
- Locate and copy your Organisation ID
- This ID is required for ThreatAware configuration
7
Identify API Region
Determine your Rapid7 API region:
- Access Insight IDR and check the URL format:
{region}.idr.insight.rapid7.com - The region will be one of: us, us2, us3, eu, ca, au, or ap
- Note this region for ThreatAware configuration
8
Input Details into ThreatAware
Return to the ThreatAware integration popup and enter:
- API Key: The organisation API key from step 5
- Organisation ID: From step 6
- API Region: From step 7
- Click Connect to establish the integration
9
Verify Connection
After connecting:
- Check that the Integration Status shows as Active
- Verify data is appearing in ThreatAware by viewing security events
- Wait up to 15 minutes for the first data sync
Required credentials
API Key
API Key
Field Name: Rapid7 Organisation API Key
Type: Password (encrypted)
Description: The API key generated in Rapid7 for organisation-level accessThis must be an Organisation Key, not a personal API key.
Organisation ID
Organisation ID
Field Name: Rapid7 Organisation ID
Type: String
Description: Your unique Rapid7 organisation identifierFound in Settings > Organisation Settings
API Region
API Region
Field Name: Rapid7 API Region
Type: String
Description: The region of your Rapid7 InsightIDR instanceValid Values: us, us2, us3, eu, ca, au, ap
Example: us2
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm Rapid7 shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 15 minutes for the initial data poll
- Check for security events in ThreatAware
- Verify event data matches what you see in Rapid7
-
Test Queries
- Create a test query to filter events from Rapid7
- Verify the results match your expectations
Troubleshooting
Invalid API Key Error
Invalid API Key Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the API Key is correct and was copied without extra spaces
- Ensure the API key is an Organisation Key, not a personal key
- Check that the API key has not been revoked in Rapid7
- Ensure your administrator account is still active
- Generate a new API key if needed
Invalid Organisation ID
Invalid Organisation ID
Symptoms: Connection fails with organisation ID errorSolutions:
- Verify the Organisation ID is correct
- Navigate to Settings > Organisation Settings in Rapid7 to confirm
- Ensure the Organisation ID was copied without extra spaces
- Check that you have the correct Rapid7 organisation
Invalid API Region
Invalid API Region
Symptoms: Connection fails with region errorSolutions:
- Verify the API Region matches your Rapid7 instance
- Check your Rapid7 InsightIDR URL for the region:
{region}.idr.insight.rapid7.com - Valid regions are: us, us2, us3, eu, ca, au, ap
- Ensure the region was entered in lowercase
No Data After 15 Minutes
No Data After 15 Minutes
Symptoms: Integration shows active but no security event data appearsSolutions:
- Verify there is security event data in Rapid7 to collect
- Check the API key permissions in Rapid7
- Confirm your organisation has active threat investigations
- Review ThreatAware integration logs (contact support if needed)
- Wait up to 30 minutes for initial data sync to complete
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify your Rapid7 platform is accessible and online
- Check firewall rules allow outbound HTTPS (443) to Rapid7
- Test the region URL in a browser to ensure it’s reachable
- Verify your internet connection is stable
- Try connecting again after waiting a few minutes
Additional resources
Rapid7 API Documentation
Official Rapid7 API documentation for detailed API information
ThreatAware Support
Contact ThreatAware support for integration assistance