Rapid7 Logs (Beta)

Connecting Rapid7 logs to your Panther Console

Overview

Rapid7 Audit Logs ingestion is in open beta starting with Panther version 1.111, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther can pull in Rapid7's audit logs via InsightIDR.

How to onboard Rapid7 AuditLogs to Panther

Step 1: Enable audit logging in Rapid7

Step 2: Generate an API key in Rapid7

Step 3: Create a new Rapid7 log source in Panther

  1. In the left-side navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Rapid7,” then click its tile.

  4. On the slide-out panel, click Start Setup.

    In the Panther Console, the Configure > Log Sources > Add New Source page is shown. There is an arrow drawn from the Rapid7 tile to the Start Setup button on its slide-out panel.
  5. On the next screen, enter a descriptive name for the source, e.g., My Rapid7 logs.

  6. On the Set Credentials page, fill in the fields:

    • Storage Region: Enter the shortened version of the Data Storage Region you noted from Rapid7 in Step 1. For example, if your region is United States - 3, enter us3.

      • If you need to find this value again, you can do so in the Rapid7 Platform console, within the Home section of the Settings page. You may also be able to see it in your Rapid7's console URL.

    • API Key: Enter the API key you generated in Rapid7 in Step 2.

    Under "Fill in the form below with your credentials" are two empty fields: Storage Region and API Key.

  7. Click Setup. You will be directed to a success screen:

    The success screen reads, "Everything looks good! Panther will now automatically pull & process logs from your account"
    • You can optionally enable one or more Detection Packs.

    • The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.

      The "Trigger an alert when no events are processed" toggle is set to YES. The "How long should Panther wait before it sends you an alert that no events have been processed" setting is set to 1 Day

Supported Log Types

Rapid7.AuditLog

Last updated

Was this helpful?