Fortinet Document Library

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

External Systems Configuration Guide

Rapid7 InsightVM Integration

Integration points

Protocol Information collected Used for
InsightVM API Vulnerability scan data Security and Compliance

Rapid7 InsightVM API Integration

FortiSIEM can pull vulnerability scan data from Rapid7 InsightVM Server via InsightVM API.

InsightVM scan data contains vulnerabilities found on a host. Each host vulnerability is converted into a separate FortiSIEM event with event type Rapid7-InsightVM-Vuln-Detected.

Configuring Rapid7 InsightVM Server

Create an account to be used for FortiSIEM communication.

Configuring FortiSIEM

Use the account in previous step to enable FortiSIEM access:

  1. Login to FortiSIEM.
  2. Go to Admin > Setup > Credential.
  3. Click New to create a Rapid7 InsightVM credential.
    1. Choose Device Type = Rapid7 InsightVM (Vendor = Rapid7, Model = InsightVM).
    2. Choose Access Protocol = InsightVM API.
    3. Choose Pull Interval = 5 minutes.
    4. Choose HTTPS Port (default 3780).
    5. Choose User name and Password for the account created while Configuring Rapid7 InsightVM Server.
    6. Choose the Organization if it is an MSP deployment and the same credential is to be used for multiple customers.
    7. Click Save.
  4. Enter an IP Range to Credential Association:
    1. Set IP to the IP address of the Rapid7 InsightVM Server.
    2. Select the Credential created in step 3
    3. Click Save.
  5. Perform Test Connectivity to make sure that the credential works correctly.
  6. Discover the Rapid7 InsightVM Server using the IP address used in Step 4. Make sure Discover succeeds.
  7. An entry will be created in Admin > Setup > Pull Events corresponding to this event pulling job. FortiSIEM will start to pull events from Rapid7 InsightVM Server using the InsightVM REST API.

To test for received InsightVM Vulnerability events:

  1. Go to Admin > Setup > Pull Events
  2. Select the InsightVM entry and click Report.

The system will take you to the Analytics tab and run a query to display the events received from InsightVM Server in the last 15 minutes. You can modify the time interval to get more events.

Rapid7 InsightVM Integration

Integration points

Protocol Information collected Used for
InsightVM API Vulnerability scan data Security and Compliance

Rapid7 InsightVM API Integration

FortiSIEM can pull vulnerability scan data from Rapid7 InsightVM Server via InsightVM API.

InsightVM scan data contains vulnerabilities found on a host. Each host vulnerability is converted into a separate FortiSIEM event with event type Rapid7-InsightVM-Vuln-Detected.

Configuring Rapid7 InsightVM Server

Create an account to be used for FortiSIEM communication.

Configuring FortiSIEM

Use the account in previous step to enable FortiSIEM access:

  1. Login to FortiSIEM.
  2. Go to Admin > Setup > Credential.
  3. Click New to create a Rapid7 InsightVM credential.
    1. Choose Device Type = Rapid7 InsightVM (Vendor = Rapid7, Model = InsightVM).
    2. Choose Access Protocol = InsightVM API.
    3. Choose Pull Interval = 5 minutes.
    4. Choose HTTPS Port (default 3780).
    5. Choose User name and Password for the account created while Configuring Rapid7 InsightVM Server.
    6. Choose the Organization if it is an MSP deployment and the same credential is to be used for multiple customers.
    7. Click Save.
  4. Enter an IP Range to Credential Association:
    1. Set IP to the IP address of the Rapid7 InsightVM Server.
    2. Select the Credential created in step 3
    3. Click Save.
  5. Perform Test Connectivity to make sure that the credential works correctly.
  6. Discover the Rapid7 InsightVM Server using the IP address used in Step 4. Make sure Discover succeeds.
  7. An entry will be created in Admin > Setup > Pull Events corresponding to this event pulling job. FortiSIEM will start to pull events from Rapid7 InsightVM Server using the InsightVM REST API.

To test for received InsightVM Vulnerability events:

  1. Go to Admin > Setup > Pull Events
  2. Select the InsightVM entry and click Report.

The system will take you to the Analytics tab and run a query to display the events received from InsightVM Server in the last 15 minutes. You can modify the time interval to get more events.