icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Rapid7 InsightVM Dashboard for Splunk
SHA256 checksum (rapid7-insightvm-dashboard-for-splunk_100.tgz) 57878637c92eac66623ba1e6ab738ea60fecb9092d2dd823fdae1d34e6b7d275
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Rapid7 InsightVM Dashboard for Splunk

Splunk AppInspect Passed
Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
Overview
Details
The Rapid7 InsightVM Dashboard is used for visualizing data that has been ingested from InsightVM via the Rapid7
InsightVM Technology Add-On. The dashboard is intended to be a starting point for data visualization, and users are
encouraged to further enhance and customize the dashboard as desired.

There are two dashboards included to start: the InsightVM Assets dashboard used for visualizing asset details, and
the InsightVM Vulnerability Findings dashboard used for visualizing details of vulnerability instances found within
assets. This Dashboard is meant to complement the `Rapid7 InsightVM Technology Add-On` listed on Splunkbase.

Rapid7 InsightVM Dashboard

Installation

There are two ways to install the dashboard - via the Splunk app listing, or manually with a provided dashboard
package. To install the dashboard via the app listing, follow these steps:

  1. From the Apps menu in Splunk, select Manage Apps
  2. Select Browse More Apps
  3. Do a search for the "Rapid7 InsightVM Dashboard"
  4. Select Install from the app listing
  5. Perform a restart of Splunk when prompted

To install the add-on manually, follow these steps:

  1. From the Apps menu in Splunk, select Manage Apps
  2. Select Install app from file
  3. Select the InsightVM Dashboard
  4. Perform a restart of Splunk when prompted

The add-on should now appear as Rapid7 InsightVM Dashboard under the Apps menu in Splunk.

Configuration

This dashboard must be used alongside the Rapid7 InsightVM Technology Add-On. The add-on serves as the method for
retrieving asset and vulnerability data, which is then visualized with this dashboard. There are three sourcetypes to
keep in mind when searching or creating visualizations of this data:

  • rapid7:insightvm:asset
  • rapid7:insightvm:asset:vulnerability_finding
  • rapid7:insightvm:vulnerability_definition

InsightVM Asset Dashboard

There are a few different components in the Asset Dashboard that display or visualize the imported InsightVM asset
data. It's important to ensure that the correct index is selected here, as otherwise you may not see any data. The
default index for the Dashboard follows that of the Technology Add-On and will be set to rapid7, but you can update
this if a different one was chosen for data import.

Additional filtering can be done with the Tags dropdown, which uses tags - aggregates of site, asset groups, and
asset tags - retrieved from InsightVM, and the Time Period dropdown, which allows you to select a date range for
your data.

Field Description
Total Assets Scanned The total number scanned across imported assets
Total Asset Riskscore The total risk score across imported assets
Average Asset Riskscore The average risk score across imported assets
Most Common Operating Systems A chart showing a breakdown of operating systems in the environment
Most Vulnerable Hosts A table listing most vulnerable hosts based on risk score

InsightVM Vulnerability Findings Dashboard

There are a few different components in the Vulnerability Dashboard that display or visualize the imported InsightVM
vulnerability data. It's important to ensure that the correct index is selected here, as otherwise you may not see
any data.

Additional filtering can be done with the Time Period dropdown, which allows you to select a date range for your
data.

Field Description
New Vulnerability Findings A count of new vulnerability findings based on the latest import of InsightVM data
Remediated Vulnerability Findings A count of remediated vulnerability findings based on the latest import of InsightVM data
Active Vulnerabilities by Solution Type A chart showing a breakdown of solutions available for active vulnerabilities
Top Vulnerability Occurrences A table listing the most frequently occurring vulnerabilities across assets
Top Solutions by Asset Count A table listing the top solutions based on their applicability across assets

Changelog:

1.0.0 - Initial release of Dashboard for use with Rapid7 InsightVM Technology Add-On

Release Notes

Version 1.0.0
July 1, 2020

1.0.0 - Initial release of Dashboard for use with Rapid7 InsightVM Technology Add-On

72
Installs
69
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.