Rapid7 Insight IDR
The Dropzone platform integrates with Rapid7 Insight IDR, a cloud-native SIEM and XDR solution. The Data source integration will allow Dropzone to perform the following actions:
LEQL query skill - generate and run LEQL (Log Entry Query Language) queries against configured log sets
Process tree – retrieve process trees for an alert by alert RRN
Device enrichment – access asset context (hostname, IP) from InsightIDR assets
User enrichment - access account/user context from InsightIDR accounts
Normal activity - access User, IP, and device network activity over the normal-activity lookback window
Integrations Overview
To enable these integrations you will perform the following actions:
Create an API key
Identify your data region
Install the credentials into your Dropzone tenant (Data Source and Alert Source)
Select integration parameters
Create an API Key
Rapid7 InsightIDR requires an API key from the Insight platform API to enable.
To obtain an Organization API Key, do the following:
As a platform administrator, log into your Rapid7 Command Platform
In the left menu, click "Administration"
Click "API Key management"
Click "Admin API Keys," then navigate to "Organization Keys"
Click "New Admin Key"
Select "Organization Admin Key"
Select your organization
Name the key something memorable, such as Dropzone AI
Click "Generate"
Copy the key value shown for use later in the Dropzone UI, where it is called API Key
To obtain a User API key, do the following:
In the left menu of the Rapid7 Command Platform Home page, click "Administration"
Click "API Key Management"
Click "User Key"
Click "New user Key"
Select your organization
Name the key something memorable, such as Dropzone AI
Click "Generate"
Copy the key value shown for use later in the Dropzone UI, where it is called API Key
Identify your data region
Dropzone needs the region code for your InsightIDR data storage region (for example us, not a full hostname).
To obtain your data region, do one of the following:
Open any Rapid7 product you have access to (for example InsightIDR)
Locate the browser URL subdomain prefix before
.idr.insight.rapid7.com(or a similar Rapid7 product hostname)Enter that prefix in Dropzone as the Region value
For example, if your URL is
https://us.idr.insight.rapid7.com, enterusin Dropzone.
For more detail, see Rapid7's Check your data region documentation.
In the Rapid7 Command Platform, navigate to Administration > Settings > Organization Settings
Locate your Data Storage Region (aka the display name for your tenant)
Map that label to the Region value for Dropzone using the table below
United States - 1
us
United States - 2
us2
Canada
ca
Europe
eu
Australia
au
Japan / Asia-Pacific
ap
For the full list of supported regions and API base URLs, see Rapid7's Supported regions documentation.
Enable Rapid7 Insight IDR
To enable the Data Source integration, you'll need the following information:
API Key
The API Key you generated earlier
Region
Your Rapid7 data storage region, typically visible in your InsightIDR URL, e.g. us.api.insight.rapid7.com
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, click Settings > Integrations

Click "Library"

In the Search bar, search Rapid7 Insight IDR, then click "Configure"

Input the API Key and Region
Click "Test & Save" to finish
After saving, Dropzone will trigger an integration scan that discovers log sets, field hints, and display names for your tenant. LEQL queries rely on that scanner metadata. If a scan is still running or failed, log-set selection during investigations may be limited until discovery completes.
If you have any errors engage your Dropzone AI support representative.
Troubleshooting
When you save or test the data source, Dropzone verifies connectivity by listing log sets from the Log Search API. A wrong Region or API key can produce an error like:
If you experience any errors, do the following:
Confirm the Region matches your Rapid7 URL prefix or the Organization Settings table (enter
us, notus.api.insight.rapid7.comorus.rest.logs.insight.rapid7.com)Re-open InsightIDR and verify the subdomain prefix (for example
us2vsus)If Region is correct, verify the API key is an organization key with InsightIDR access and was copied without extra spaces
If both Region and API key look correct, engage your Dropzone AI support representative.
Last updated
Was this helpful?