Skip to main content

Rapid7 InsightVM

Integrate Rapid7 InsightVM with Cloudaware to inventory assets and vulnerability context for unified reporting.

info
  • Audience: Cloudaware administrators, SecOps teams, vulnerability management teams, and cloud operations teams
  • Outcome: Rapid7 InsightVM assets and vulnerability context are available in CMDB for asset correlation, risk visibility, coverage review, and reporting

Capabilities

The integration supports:

  • Read-only discovery of Rapid7 InsightVM assets and related metadata
  • Relationship mappings between core InsightVM assets in the CMDB
  • Search and reporting for InsightVM objects using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • InsightVM API endpoint URL.
  • InsightVM username and password with API access.
  • TunHub configured for private endpoints, if required.

Add a Rapid7 InsightVM Account to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Rapid7 InsightVM, then click + ADD.
  3. Enter the following values:
    • Name: Enter a display name for the Rapid7 InsightVM integration.
    • URL: Enter the InsightVM API endpoint URL (in the format https://insightvm.<companyname>.com:0000).
    • User: Enter the InsightVM username.
    • Password: Enter the InsightVM password.
    • Trust Certificate: Enable this option for private endpoints accessed through TunHub, if required.
  4. Click CHECK to validate the connection.
  5. Click Save.
  6. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Rapid7 InsightVM Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select INSIGHTVM.
  3. Open an object list, e.g., InsightVM Assets, to view records.

Supported Objects

Cloudaware ingests the following Rapid7 InsightVM objects:

InsightVM ObjectCMDB Object API Name
InsightVM AccountCA10R7__CaInsightVmAccount__c
InsightVM AssetCA10R7__CaInsightVmAsset__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Failed or Integration Shows Red Status

  • Verify that the InsightVM API endpoint URL is correct.
  • Confirm that the InsightVM username and password are valid and active.
  • Check that the InsightVM user has API access and read permissions for the required assets.
  • Re-enter the credentials by editing the integration in Cloudaware.

InsightVM Assets Are Missing

  • Allow the initial discovery cycle to complete.
  • Confirm that the InsightVM user has access to the missing assets.
  • Validate asset counts against InsightVM.
  • In CMDB Navigator, verify that you are viewing the INSIGHTVM section and related resources.

Private Endpoint Connection Fails

  • Confirm that the TunHub route to the InsightVM endpoint is configured and healthy.
  • Verify that the InsightVM endpoint is reachable from the internal host where the Cloudaware Breeze Agent is installed.
  • Check whether Trust Certificate is enabled for the private endpoint.
  • Confirm that the URL value matches the endpoint exposed through TunHub.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate credentials or update endpoint settings, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Rapid7 InsightVM.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Rapid7 InsightVM.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated InsightVM account with the minimum API permissions required for Cloudaware discovery.
  • Avoid using a personal administrator account for long-running integrations.
  • Store InsightVM credentials only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
  • Rotate InsightVM credentials according to your organization's credential-rotation policy and immediately after suspected exposure.
  • Restrict TunHub routes to the specific InsightVM endpoint and port required by the integration.
  • Review InsightVM account permissions regularly to confirm that Cloudaware can access only the assets and vulnerability context required for discovery.
  • Update the Cloudaware Rapid7 InsightVM integration immediately if the InsightVM password is reset, revoked, or replaced.