Skip to main content
Rapid7 InsightIDR is Rapid7’s cloud SIEM and detection and response product. After you add a Universal Webhook data exporter to a data collector in InsightIDR, the collector posts to Flashduty On-call each time an investigation is generated. Each investigation maps to one Flashduty alert. InsightIDR only sends “investigation created”. It does not send updates or closures, so alerts do not recover on their own. Turn on auto-close in the channel that receives them, with a suggested window of 24 hours, or adjust it to how quickly your team handles investigations.

In Flashduty On-call


You can get the push URL in either of the following ways.

Use a dedicated integration

  1. In the Flashduty console, select Channels and open a channel
  2. Select Settings → Integrations → Dedicated integrations, then click Add an integration
  3. Select Rapid7 InsightIDR and click Save
  4. Open the generated integration card and copy the push URL

Use a shared integration

  1. In the Flashduty console, select Integration Center → Alert Events
  2. Select Rapid7 InsightIDR and enter an integration name
  3. Configure the default route and select a channel; you can add more rules under Routes after creation
  4. Click Save and copy the generated push URL

In Rapid7 InsightIDR


1

Add a Universal Webhook data exporter

  1. Sign in to InsightIDR, go to Data Connectors → SIEM → Data Collectors, and open the Data Exporters tab
  2. Click Add Data Exporter and choose Universal Webhook
  3. Select the collector to use and optionally enter a name
  4. Paste the full Flashduty push URL into URL. It must include integration_key. HTTPS is recommended
  5. Keep the pre-filled Secret. InsightIDR uses it to sign the request body (X-Rapid7-Signature header). Flashduty does not verify the signature
  6. Keep the default data export type, Investigations
  7. Click Save
2

Verify

When the exporter is saved or the collector starts, InsightIDR sends a test request (X-Rapid7-Event: test). Flashduty creates an Info alert titled Rapid7 InsightIDR test notification. It does not recover on its own, so close it by hand after checking.After that, every investigation InsightIDR generates is pushed as one alert.

Event types


Alert Key


Flashduty uses investigationId, the fixed ID InsightIDR assigns to each investigation, as the Alert Key. Changes to the title, description, or time do not change it. A request without investigationId is rejected.

Status and severity


The InsightIDR payload carries no severity, so every investigation is treated as Warning. To separate levels, adjust them in the integration’s Alert processing by title or label.

Labels


User emails and AD distinguished names (distinguishedName) are not written to labels.

About signatures


InsightIDR signs the request body with the Secret (X-Rapid7-Signature). Flashduty does not verify it, so the integration_key in the push URL is the only credential; keep it private. You can also add custom headers on the exporter; Flashduty does not require them.

Troubleshooting


  • Flashduty receives nothing: the collector is hosted by you. Confirm it can reach the internet and that the URL is complete and includes integration_key
  • Parameter error: a missing investigationId means the request is not an investigation; an unsupported event means X-Rapid7-Event is neither idr_investigation_created nor test
  • Alerts never close: InsightIDR does not send investigation closures, so turn on auto-close
  • The test alert stays open: the Info alert from the test request must be closed by hand
For more details, see Rapid7’s Universal Webhook documentation.