> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flashduty.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Rapid7 InsightIDR alert integration

> Send investigations generated by Rapid7 InsightIDR to Flashduty On-call through a Universal Webhook data exporter.

Rapid7 InsightIDR is Rapid7's cloud SIEM and detection and response product. After you add a Universal Webhook data exporter to a data collector in InsightIDR, the collector posts to Flashduty On-call each time an investigation is generated. Each investigation maps to one Flashduty alert.

InsightIDR only sends "investigation created". It does not send updates or closures, so alerts do not recover on their own. Turn on [auto-close](/en/on-call/channel/create-edit) in the channel that receives them, with a suggested window of 24 hours, or adjust it to how quickly your team handles investigations.

<div className="hide">
  ## In Flashduty On-call

  ***

  You can get the push URL in either of the following ways.

  ### Use a dedicated integration

  1. In the Flashduty console, select **Channels** and open a channel
  2. Select **Settings** → **Integrations** → **Dedicated integrations**, then click **Add an integration**
  3. Select **Rapid7 InsightIDR** and click **Save**
  4. Open the generated integration card and copy the **push URL**

  ### Use a shared integration

  1. In the Flashduty console, select **Integration Center → Alert Events**
  2. Select **Rapid7 InsightIDR** and enter an integration name
  3. Configure the default route and select a channel; you can add more rules under **Routes** after creation
  4. Click **Save** and copy the generated **push URL**
</div>

## In Rapid7 InsightIDR

***

<Steps>
  <Step title="Add a Universal Webhook data exporter">
    1. Sign in to InsightIDR, go to **Data Connectors** → **SIEM** → **Data Collectors**, and open the **Data Exporters** tab
    2. Click **Add Data Exporter** and choose **Universal Webhook**
    3. Select the collector to use and optionally enter a name
    4. Paste the full Flashduty push URL into **URL**. It must include `integration_key`. HTTPS is recommended
    5. Keep the pre-filled **Secret**. InsightIDR uses it to sign the request body (`X-Rapid7-Signature` header). Flashduty does not verify the signature
    6. Keep the default data export type, **Investigations**
    7. Click **Save**
  </Step>

  <Step title="Verify">
    When the exporter is saved or the collector starts, InsightIDR sends a test request (`X-Rapid7-Event: test`). Flashduty creates an Info alert titled `Rapid7 InsightIDR test notification`. It does not recover on its own, so close it by hand after checking.

    After that, every investigation InsightIDR generates is pushed as one alert.
  </Step>
</Steps>

## Event types

***

| `X-Rapid7-Event` | Effect in Flashduty |
| :- | :- |
| `idr_investigation_created` | Triggers an alert |
| `test` | Creates a separate Info alert that does not recover |
| Any other value | The request is rejected with a parameter error |

## Alert Key

***

Flashduty uses `investigationId`, the fixed ID InsightIDR assigns to each investigation, as the Alert Key. Changes to the title, description, or time do not change it. A request without `investigationId` is rejected.

## Status and severity

***

The InsightIDR payload carries no severity, so every investigation is treated as Warning. To separate levels, adjust them in the integration's **Alert processing** by title or label.

## Labels

***

| Label | Source |
| :- | :- |
| `check` | Investigation title (`title`) |
| `investigation_id` / `investigation_rrn` | Investigation ID and resource name |
| `link` | Link to the investigation in InsightIDR |
| `hosts` | Host names involved, de-duplicated and sorted, up to 10, comma-separated |
| `users` | Display names of users involved, de-duplicated and sorted, up to 10, comma-separated |

User emails and AD distinguished names (`distinguishedName`) are not written to labels.

## About signatures

***

InsightIDR signs the request body with the Secret (`X-Rapid7-Signature`). Flashduty does not verify it, so the `integration_key` in the push URL is the only credential; keep it private. You can also add custom headers on the exporter; Flashduty does not require them.

## Troubleshooting

***

* **Flashduty receives nothing**: the collector is hosted by you. Confirm it can reach the internet and that the URL is complete and includes `integration_key`
* **Parameter error**: a missing `investigationId` means the request is not an investigation; an unsupported event means `X-Rapid7-Event` is neither `idr_investigation_created` nor `test`
* **Alerts never close**: InsightIDR does not send investigation closures, so turn on **auto-close**
* **The test alert stays open**: the Info alert from the test request must be closed by hand

For more details, see [Rapid7's Universal Webhook documentation](https://docs.rapid7.com/insightidr/webhook/).
